A few Weeks ago, I installed the "AVG" on my winxp machine.
Today, when I started the AVG, it automatically downloaded executable files from their website and installed them without asking me. AFTER the upgrade, a message "Application successfully upgraded!" was displayed.
If i'm not mistaken, it should be easy for an attacker to use (e.g.) dns-poisoning to redirect "auto-update website such as the AVG website" to his own webserver, offer his own version of the the AVG Update with a very high version number, and just wait for the victim to start up the AVG (default option: autostart with windows startup), auto-download and auto-execute whatever he wants to (trojan horses, network sniffers, viruses, etc.). If the functionality of the original AVG was preserved, the victim wouldn't even notice he was under attack.
What security measures would possibly stop such an attacker?
Note: Many software vendors offer online upgrades. It just sounds like a bad idea to me to allow this update without asking the user, and without any authentification.
Today, when I started the AVG, it automatically downloaded executable files from their website and installed them without asking me. AFTER the upgrade, a message "Application successfully upgraded!" was displayed.
If i'm not mistaken, it should be easy for an attacker to use (e.g.) dns-poisoning to redirect "auto-update website such as the AVG website" to his own webserver, offer his own version of the the AVG Update with a very high version number, and just wait for the victim to start up the AVG (default option: autostart with windows startup), auto-download and auto-execute whatever he wants to (trojan horses, network sniffers, viruses, etc.). If the functionality of the original AVG was preserved, the victim wouldn't even notice he was under attack.
What security measures would possibly stop such an attacker?
Note: Many software vendors offer online upgrades. It just sounds like a bad idea to me to allow this update without asking the user, and without any authentification.
Comment