Jump to content


- - - - -

Malware Using Right to Left Override Unicode


  • Please log in to reply
6 replies to this topic

#1 Sina_DiR

Sina_DiR

    Newbie

  • (Junior+)
  • 14 posts
  • Gender:Male

Posted 21 August 2011 - 04:54 PM

This is the new trick in Unicode string that could deceive users to open and exe file that showing pdf txt etc.
It could be new way to spammers Posted Image

Posted Image

For more information check out F-Secure analyze:
Redirect to F-Secure
UnREal RCE - Persian Crackers

#2 deepzero

deepzero

    Postmaster

  • (Full Member)
  • 729 posts
  • Gender:Male

Posted 21 August 2011 - 06:34 PM

yup, that`s why you should always make sure the last three chars before the file extension aren`t "exe" ;)
not new, though.... :)
Scientia potentia est.

#3 Teddy Rogers

Teddy Rogers

    Site Administrator

  • (Administrator)
  • 9,627 posts
  • Gender:Male
  • Location:Australia

Posted 22 August 2011 - 01:44 AM

Seen this before to but it still catches people out and I am surprised this hasn't been used more extensively. Possibly this is something that should be patched in Windows core?

Ted.

Posted Image
I would love to change the world, but they won't give me the source code...


#4 Sina_DiR

Sina_DiR

    Newbie

  • (Junior+)
  • 14 posts
  • Gender:Male

Posted 22 August 2011 - 06:52 AM

I didn't think, cause it's not bug, its just a trick, it caused in Linux, Mac OS and the other OS that include Unicode characters...
UnREal RCE - Persian Crackers

#5 deepzero

deepzero

    Postmaster

  • (Full Member)
  • 729 posts
  • Gender:Male

Posted 22 August 2011 - 08:45 AM

Quote

it's not bug

true, it`s a standard unicode char...
However, how could you use it "for good"?
Scientia potentia est.

#6 GamingMasteR

GamingMasteR

    Where are my weeds ?

  • (Full Member)
  • 166 posts
  • Gender:Male

Posted 22 August 2011 - 03:07 PM

Unicode can be really annoying :)
http://blogs.technet...e-our-eyes.aspx

#7 Sina_DiR

Sina_DiR

    Newbie

  • (Junior+)
  • 14 posts
  • Gender:Male

Posted 22 August 2011 - 07:44 PM

Quote

However, how could you use it "for good"?

I have no idea about use this in good stuffz ! Posted Image
@GamingMasteR
Thanks for that, I saw somethings like this b4 and I can't realization about that Posted Image
UnREal RCE - Persian Crackers




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users