Saturday, May 8, 2021

Polymorphism in Google Drive and Google Chrome (wrt Handling an Exe File)



Important Note: We are not trying to arrive at a very concrete conclusion or result here. The testing was done to identify the behavior of 'Google Drive' and 'Google Chrome' when 'Google Drive' thinks a file could be a virus.

User1: This user is the original author of the file and has shared the folder with User2.

1 - incognito, no-user, two virus alerts
2 - incognito, no user - A virus was detected you can't download this file (gmat2.zip)
3 - incognito, User2, virus detected, can't download
4 - incognito, User2, polymorphism, cannot delete file in shared folder from other person
5 - normal view, User1, file with virus alert can still be downloaded from original author's account
6 - incognito, User2, different type of alert for an exe file that gdrive says could be virus but did not alert before
7 - incognito, User2, can't download file, enable third-party cookies for GDrive
8 - normal view, User1, original author can remove a file from folder shared by him
9 - inconito firefox, User2, potentially infected exe file not downloadable from incognito chrome is allowed to be downloaded here
10 - a view of gdrive trash of original author User1 with removed files
11 - incognito, User2, you do not get remove rights on a file but you do get remove rights on the entire directory shared with you
12 - Incognito chrome, User2, Still cannot download the suspected folder, asks to enable third party cookies
The Files That Were Causing Virus Alerts in Google Drive When Scanned on Windows 10's 'Anti-Virus Defender' Did Not Produce Alert List View: 1 ~\110809IMS_Student_CD_Setup.exe ~\files.html ~\gmat1 ~\gmat1.zip ~\gmat2 ~\gmat2.zip ~\gmat1\gmat1mx.exe ~\gmat1\gmat1vx.exe ~\gmat1\gmat2mx.exe ~\gmat1\gmat2vx.exe ~\gmat1\gmat3mx.exe ~\gmat1\gmat3vx.exe ~\gmat1\gmat4mx.exe ~\gmat1\gmat4vx.exe ~\gmat2\gmat5mx.exe ~\gmat2\gmat5vx.exe List View: 2 Volume in drive C is Windows Volume Serial Number is 8139-90C0 Directory of ~ 05/08/2021 10:00 PM <DIR> . 05/08/2021 10:00 PM <DIR> .. 05/08/2021 09:12 PM 42,742,301 110809IMS_Student_CD_Setup.exe 05/08/2021 10:00 PM 766 files.html 05/08/2021 10:00 PM 0 files2.html 05/08/2021 08:52 PM <DIR> gmat1 05/08/2021 08:49 PM 880,985 gmat1.zip 05/08/2021 08:52 PM <DIR> gmat2 05/08/2021 01:01 PM 210,131 gmat2.zip 5 File(s) 43,834,183 bytes Directory of ~\gmat1 05/08/2021 08:52 PM <DIR> . 05/08/2021 08:52 PM <DIR> .. 10/30/2000 05:41 PM 486,400 gmat1mx.exe 03/21/2001 01:29 AM 504,320 gmat1vx.exe 05/17/2001 09:21 PM 418,816 gmat2mx.exe 03/29/2001 07:54 PM 501,760 gmat2vx.exe 05/17/2001 09:18 PM 424,448 gmat3mx.exe 03/09/2001 11:17 AM 485,376 gmat3vx.exe 05/17/2001 09:27 PM 432,128 gmat4mx.exe 03/21/2001 01:35 AM 631,808 gmat4vx.exe 8 File(s) 3,885,056 bytes Directory of ~\gmat2 05/08/2021 08:52 PM <DIR> . 05/08/2021 08:52 PM <DIR> .. 05/17/2001 09:32 PM 425,984 gmat5mx.exe 03/09/2001 11:47 AM 486,912 gmat5vx.exe 2 File(s) 912,896 bytes Total Files Listed: 15 File(s) 48,632,135 bytes 8 Dir(s) 70,736,945,152 bytes free Tags: Technology,Cyber Security,Cloud,

No comments:

Post a Comment