Sinisterly
Cortana Vulnerability Hackers Bypass Windows 10 - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: General (https://sinister.ly/Forum-General)
+--- Forum: World News (https://sinister.ly/Forum-World-News)
+--- Thread: Cortana Vulnerability Hackers Bypass Windows 10 (/Thread-Cortana-Vulnerability-Hackers-Bypass-Windows-10)



Cortana Vulnerability Hackers Bypass Windows 10 - mothered - 03-30-2018

Greetings everyone,

This Is somewhat old news (around 3 weeks ago) but those who've missed It, will surely find this of Interest. I cannot fathom how such a simplistic vulnerability remained unnoticed. Yet another Issue added to Microsoft's on-going problems.

Quote:Security researchers have discovered a flaw with Microsoft's Cortana voice assistant that could enable hackers to bypass the login screen in Windows 10 and infect a system with malware.

The Israeli researchers, Tal Be'ery and Amichai Shulman, found the vulnerability after finding out that Cortana is always on and responds to voice commands, even when a machine is locked.

According to reports by Motherboard, a hacker could plug in a USB stick with a network adapter into the computer, then tell Cortana to launch the computer's browser and go to an unencrypted URL (non-HTTP). This adaptor the intercepts this session to send the browser to a malicious website, downloading malware and infecting the system.

Pretty straightforward? Definitely so.

Source.


RE: Cortana Vulnerability Hackers Bypass Windows 10 - Bish0pQ - 04-05-2018

This is actually kind of funny, you'd think this is one of the first things to try out when vulnerability testing the software. Guess they just skipped that step entirely. I don't trust things like Google Home, Cortana or Siri anyway. I think it's easy to have and use but I think there are going to be way more security issues with these kind of applications in the future.