• nymnympseudonym@piefed.social
    link
    fedilink
    English
    arrow-up
    57
    ·
    6 days ago

    Related:

    • If you are about to have sex with an extremely sketchy stranger you just met behind a dive bar, use a condom
    • If you are about to open an extremely sketchy download you just torrented off a link on Dread, use a VM
    • massive_bereavement@fedia.io
      link
      fedilink
      arrow-up
      25
      arrow-down
      1
      ·
      6 days ago

      Funny thing some malware checks if your hardware is virtualized. It is a bit tough to make a VM appear legit, so I tend to use a sacrificial laptop I have for this kind of work.

      Your advise is good as it will tell you if the thing is real but the malware might not trigger.

      • Dave@lemmy.nz
        link
        fedilink
        English
        arrow-up
        14
        ·
        6 days ago

        My favourite story of this is that ransomware virus that was taking out places like the NHS, and some security researcher noticed it kept pinging some domain that was a random bunch of characters.

        He registered the domain, and suddenly the ransomware shut down, freeing all the places the ransomware had infected.

        It turns out when researching a virus the environments commonly treat all domains as valid so they can capture the traffic and see what the virus is doing. To prevent this, the ransomware was designed to shut down if this clearly fake domain came back as valid (and I guess this was the release switch if the ransom was paid). That was it would shut down if in this kind of a sandboxed environment.

        The story is here, written by the researcher so it’s a bit technical. There were lots of news stories about it at the time too.

      • thisbenzingring@lemmy.today
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        10
        ·
        6 days ago

        Add to this, use Linux when dealing with sketchy things that you downloaded from sketchy places. If you configured it correctly, it won’t be too difficult to undo any potential issues

        • SchmidtGenetics@lemmy.world
          link
          fedilink
          English
          arrow-up
          7
          arrow-down
          1
          ·
          6 days ago

          What about Linux is easier than a similarly prepped windows device?

          Unless it’s changed recently, windows you just need to press a button during load (like bios) to boot into safe mode. And from there you can reload a variety of “snapshots” to recover from most malware issues.

          How is Linux easier than that, I don’t use Linux, but windows is incredibly simple already.

          • zurohki@aussie.zone
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            6 days ago

            Mostly that the malware has a much higher chance of escaping containment on a Windows install, because it’s designed to attack Windows.

            • SchmidtGenetics@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              1
              ·
              5 days ago

              Do you not know what loading a recovery snap shot does? It doesn’t matter if it escapes. Whatever was new is removed since it’s restoring your harddrive to a previous state. It’s like a backup harddrive, without being external.

              There’s ways for the malware to disable recovery mode, but I would assume the same could happen to Linux as well.

        • plantfanatic@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          4
          ·
          6 days ago

          Boot into windows safe mode and load a recovery image? Are you implying that it’s somehow difficult on windows just to bash them?

    • Ajen@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      2
      ·
      6 days ago

      VMs have vulnerabilities, if you really want to be safe use a dedicated air-gapped pc, or don’t run it at all.

      • noobface@lemmy.world
        link
        fedilink
        English
        arrow-up
        13
        ·
        6 days ago

        You sitting on some hypervisor zero days worth fucking millions over here to infect some idiot trying to run GTA6?

      • mlg@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 days ago

        I somewhat doubt the malware devs chucking their probably pirated copy of some cred stealer have implemented some zero day VM breakout exploit lol.

        • Ajen@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          5 days ago

          So do I, but there are enough people running out of date software that old vulnerabilities are still being actively exploited.