isc.sans.edu
Exploitation of Windows Finger Command for Malicious File Transfers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Security researchers have identified that the Windows finger.exe command can be exploited to download or steal files, functioning as a living-off-the-land binary (LoLBin). Discovered by John Page, this vulnerability allows attackers to use finger.exe as a makeshift command and control (C2) server, enabling data exfiltration without detection by Windows Defender. The attack method involves encoding files in Base64 to evade security measures and utilizing Windows NetSh Portproxy to bypass firewall restrictions. Organizations using explicit proxies may be safe, but those with transparent proxies could be vulnerable. The threat is compounded by the growing list of LoLBins in Windows, which includes tools like certutil.exe and desktopimgdownldr.exe. Proof-of-concept scripts have been released to demonstrate the exploit's effectiveness. The potential for widespread impact is significant, especially in environments where security measures are lax.
Key Points: • Windows finger.exe can be exploited to download files undetected. • Attackers can use Base64 encoding to evade security measures. • Organizations with transparent proxies may be at risk of exploitation.