[Full-disclosure] Download Accelerator Plus can be tricked to download malicious file



Product(ONLY TESTED ON): Download Accelerator Plus 7.4.0.2 (unregistered)
Test Environment: Winxp Pro sp2 (patch level latest)
Risk Type: Rare exception
Threat Level: High
Vendor website:www.speedbit.com

POC screenshots: http://img482.imageshack.us/img482/4205/31uk.jpg
http://img425.imageshack.us/img425/4380/15an.jpg

speedbit.com claims to have 110 million users of DAP world wide and is
one of the popular and best download manager for windows. One of its
biggest strength to download big files in a faster connection at
optimum speed is, it can automatically search for best mirrors and
download different parts of the file form multiple location.

BUT Download Accelerator Plus(DAP) may switch its download to a un
trusted or malicious website while searching for fastest mirrors for a
particular file under certain conditions. If the ACTUAL, trusted host
providing the file is DOWN or due to network congestions the users may
get and execute a malicious file instead.

I've included two screenshots which should be self explanatory. Check
out the url's in each screenshot and see from where the file is being
received at the end.

In the screenshot I'm trying to download 'Windows 2003 sp1' from
download.microsoft.com but DAP automatically chooses to download it
only from ftp.planet.nl as my network was having tooooooooo low
internet bandwidth at that time.

Further more, on some network/OS there might be rules for MAX
CONNECTION PER HOST and (say)if in the network someone is already
downloading some file from download.microsoft.com the outcome will
surely be a VIRTUAL network congensation for download.microsoft.com
within that DMZ.

For my test I used another client computer behind the gateway to send
continuous ping ( 17 different instants, fat ping requests ;0) to
download.microsoft.com As a result, for my network
download.microsoft.com was off the radar. So, in my another computer
DAP chooses to download Win2003 sp1 from ftp.planet.nl instead. So,
even after my network gained its full throttle... no-wounder DAP was
still downloading the file from ftp.planet.nl

My test network setup was a 3 computer PC which was left on default
configuration with Winxp sp2 (patchlevel: latest)

Changes: This advisory is slightly modified than the one that I
emailed to the vendor about a week back and tried contacting it, but
with no response till now!

Result: I was receiving the file from an unknown and un-trusted source
which could be infected with a malicious program.

BUT fyi: I haven't researched on HOW and WHERE 'DAP' queries to get
other possible mirrors for the particular file.

Conclusion: I insist NOT to use download managers that does the same
while downloading important files. Or either force your download
manager and check whether the file is being downloaded from the
original URL or not.

Regards,
-Bipin Gautam
_______________________________________________Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Relevant Pages

  • [Full-disclosure] Re: Download Accelerator Plus can be tricked to download malicious file
    ... DAP searches for all its mirrors from mirrorsearch.speedbit.com ... I have no knowledge about HOW the mirrors are gathered. ... > one of the popular and best download manager for windows. ... > providing the file is DOWN or due to network congestions the users may ...
    (Full-Disclosure)
  • Re: Thinking out loud....
    ... create their own private P2P network which only consists of whoever is ... which is a server program operated by the entity wishing to ... download the DLLs it needs as it needs them. ... we have a few too many file-sharing applications with no real open standards ...
    (microsoft.public.dotnet.general)
  • Re: Browser freeze
    ... IMHO) will graphically show you what network traffic is present on your system. ... Process Explorer will show you what processes, foreground and background, ... They're all free - and most pretty small, so they download quickly enough. ... Now check for, and remove, spyware. ...
    (microsoft.public.windowsxp.perform_maintain)
  • RE: Download Accelerator Plus can be tricked to download malicious file
    ... I didn't see this as a DAP fail, is normal to have out because of network ... Download Accelerator Plus can be tricked to download malicious file ...
    (Bugtraq)
  • Re: OT: BitTorrent
    ... Whenever I have a bittorrent client open, it makes the internet across my entire network unusable, as in 60 seconds to load the Google homepage slow, so basically if anyone at home or in the office wants to do anything internet related I can't use it. ... to download 1.6 million headers from wach group. ... sounds appealing given the download speeds you've described. ...
    (uk.games.video.xbox)