e621_reg_dropper

command
v1.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 7, 2023 License: CC0-1.0 Imports: 7 Imported by: 0

README

e621_reg_dropper

This is a code snippet from the script kiddie that claimed to have access to the database for e621. They claimed that this access would let them dump a database of all e621 users.

After a month no such database has been released.

The Go program in this folder will create a .reg file that automatically downloads and runs an arbitrary program that the attacker specifies. It additionally tries to cloak itself by inserting a bunch of garbage into the registry. The attacker-defined program will run when the machine reboots, allowing a gap between infection and activation.

Somehow, these generated .reg files are not detected by virus scanners and a social engineering attack would be required to use this as a stage in a longer attack.

This is overwhelmingly bad code though, I wouldn't let this pass in code reviews.

Documentation

The Go Gopher

There is no documentation for this package.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL