[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 1774219405734450.png (194 KB, 500x500)
194 KB PNG
What's the best way to setup a sandbox PC to test if your warez are malicious or legitimate? I don't want to put my main system at risk should anything bearing the name m0nkrus or fitgirl turn out to be less than benevolent, so I'd rather do that on a separate machine.
>>
you already run MAS anyway
>>
>>109618704
>What's the best way to setup a sandbox PC to test if your warez are malicious or legitimate?
Just get it from reputable sources. Malware can detect the sandbox and not run.
>>
>>109618723
>Malware can detect the sandbox and not run.
Not a sandbox, a standalone, normal, physical computer with nothing on it that is either air gapped and offline or has a local internet connection, and onboard diagnostic tools installed or on a flash drive (assuming that doesn't get infected or infects the moment it is inserted) for analysis to see everything the program is doing or who it is talking to. Capturing network traffic from infostealers would be a priority.
>>
>>109618751
You know malware also detects open and installed analysis software, yeah?
>>
File: 1769671038093273.png (921 KB, 1500x1000)
921 KB PNG
>>109618723
>Malware can detect the sandbox and not run.
>>109618761
>malware also detects open and installed analysis software
Malware could be in this very room because you turned to look behind your chair for it, or on your main desktop computer because it is written smart enough to turn off all activity the moment it detects task manager, wireshark, regshot, process explorer, or anything else is used
That infostealer you ran from a dll, bin, or executable file you had uploaded to virustotal and remained skeptical about? Already done its job
Now what are you gonna do about it?
>>
It's become abundantly clear then it should be customary practice to periodically reformat the installation drive, wipe all the hard disks because their file systems could be littered with malicious files that have infected legitimate executable files and cannot be trusted, incinerate all flash drives because they could have malware hiding in on them. Hell, incinerate the entire computer because the malware could have infected the firmware, BIOS, UEFI, PSP, ME, or god knows what else and be undetected. Same goes for all network devices like modems or routers. If it has a MAC address, it can and will be hacked.

It is time to adopt a zero-trust security model as the standard. Nothing runs on its own or gets access automatically without manual approval. Especially if you are a pirate and need to install 3DS Max to start modding Halo or Half-Life 2 or something.
>>
>>109618776
Nothing
>>
>>109618799
>malware could have infected the firmware, BIOS, UEFI, PSP, ME
You are a nobody. You aren't going to get infected with this stuff.
>It's become abundantly clear then it should be customary practice to periodically reformat the installation drive, wipe all the hard disks because their file systems could be littered with malicious files that have infected legitimate executable files and cannot be trusted,
Nobody makes infecting malware anymore.
>>
>>109618807
China does
>>
File: 1777225451512690.png (225 KB, 590x421)
225 KB PNG
>>109618761
Can the malware detect another computer intercepting network cable traffic?
>>
>>109618822
No. But it can detect Wireshark running on the current computer
>>
If I insert my Ventoy flash drive, assuming it is infected, how would wiping it and reformatting it and all of its partitions not kill the malware if I then also reformatted the Windows machine I did this on? What if I just use a Linux laptop instead?
>>
>>109618883
>how would wiping it and reformatting it and all of its partitions not kill the malware
That's literally impossible. The malware will be deleted.
>>
>>109618897
And yet we hear stories how even a standard Windows program that is malicious, with administrative access and the use of exploits can accomplish feats such as being able to rewrite the firmware of connected peripherals (like network cards, hard drives, or USB controllers) to hide malware or intercept data, or modify the motherboard firmware to implant persistent malware that survives hard drive wipes, OS reinstalls, and drive replacements.

How is this not paranoia fuel from the moment you read up on it if you've been downloading programs, cracks, torrents, or even seemingly legitimate software off the internet onto a machine that has a massive repository of programs both new and old/irreplaceable, especially if its a workstation? I still have nightmares about those old viruses from the Windows 9X era that could silently write themselves to every executable or file you access.

I have my doubts that even reformatting is enough on its own to be a foolproof nuclear option.
>>
>>109618947
>And yet we hear stories how even a standard Windows program that is malicious, with administrative access and the use of exploits can accomplish feats such as being able to rewrite the firmware of connected peripherals (like network cards, hard drives, or USB controllers) to hide malware or intercept data, or modify the motherboard firmware to implant persistent malware that survives hard drive wipes, OS reinstalls, and drive replacements.
Literally zero stories we hear. You don't know shit about how motherboard protects the SPI flash and the firmware or PCI Option ROMs.
>How is this not paranoia fuel from the moment you read up on it if you've been downloading programs, cracks, torrents, or even seemingly legitimate software off the internet onto a machine that has a massive repository of programs both new and old/irreplaceable, especially if its a workstation? I still have nightmares about those old viruses from the Windows 9X era that could silently write themselves to every executable or file you access.
Nobody makes them anymore. Malware is a money game.
>I have my doubts that even reformatting is enough on its own to be a foolproof nuclear option.
You should see a therapist.
>>
>>109618704
Just do anything involving money or real identity on a barebones cheap laptop without any risky software, and everything else on the gaming rig.
>>
>>109619126
>the barebones cheap laptop without any risky software it's self was compromised because you downloaded and wrote an iso to a flash drive from a compromised machine or plugged in an infected USB device or peripheral
Wat nao
>>
>>109618959
>You should see a therapist.
Paranoia and threat pattern recognition is healthy in cybersecurity, anon.



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.