Forum Home
Press F1
 
Thread ID: 141915 2016-03-22 22:57:00 Teamviewer vulnerable KarameaDave (15222) Press F1
Post ID Timestamp Content User
1417960 2016-03-22 22:57:00 As a few on here are users of this, a heads-up is in order.

news.softpedia.com
KarameaDave (15222)
1417961 2016-03-22 22:59:00 Thanks for the 'heads-up' Dave. Richard (739)
1417962 2016-03-22 23:37:00 or perhaps not :)

"As Surprise ransomware victims noticed that they all had TeamViewer installed, they went on to search TeamViewer's logs, and all discovered that someone accessed their computer via TeamViewer, downloaded the suprise.exe file (ransomware's payload), and then launched it into execution, encrypting their files"

So, it could be a hacker installed TV
It could be an email asking user to 'login' into TV a/c via a bogus weblink in the email
it could be user ran a TV support link , that belonged to a hacker
it could be TV password was obtained some other way, eg , common password, password store program hacked or accessed
etc etc

"(1) Up to now, none of the reported cases is based on a TeamViewer security breach" TV's response
1101 (13337)
1417963 2016-03-22 23:40:00 From the forum link
"You may want to plug your email into this site and see if your credentials were ever leaked: haveibeenpwned.com

"mmm Unfortunatly i have some email address affected"
:badpc:


There may be a genuine TV issue, but I wouldnt jump to conclusions , yet.
1101 (13337)
1417964 2016-03-23 00:11:00 or perhaps not :)

"As Surprise ransomware victims noticed that they all had TeamViewer installed, they went on to search TeamViewer's logs, and all discovered that someone accessed their computer via TeamViewer, downloaded the suprise.exe file (ransomware's payload), and then launched it into execution, encrypting their files"

So, it could be a hacker installed TV
It could be an email asking user to 'login' into TV a/c via a bogus weblink in the email
it could be user ran a TV support link , that belonged to a hacker
it could be TV password was obtained some other way, eg , common password, password store program hacked or accessed
etc etc

"(1) Up to now, none of the reported cases is based on a TeamViewer security breach" TV's response

But TV is the common factor in this, Yes?
KarameaDave (15222)
1417965 2016-03-23 00:50:00 But TV is the common factor in this, Yes?

Yep.
But nothing is proven, one way or the other, yet. A bit of caution never hurts, but surely we arnt at panic mode yet ?


I wonder, does TV have build in protection against brute force attacks ? Will TV drop/block attempts to connect after
too many wrong password attempts . Is this sort of thing recorded at TV's server (should be , surely)

If TV was compromised, why did they not pick the corporate or rich clients to hack into first ? That would have been the best pickin .
1101 (13337)
1417966 2016-03-23 01:05:00 No panic here, I don't use it.:)
I was merely trying to be helpful...
KarameaDave (15222)
1417967 2016-03-23 01:47:00 I've never liked using those things....leaves a bloody big hole in the users PC pctek (84)
1417968 2016-03-23 21:08:00 No panic here, I don't use it.:)
I was merely trying to be helpful...

I appreciated the heads up, but Id bet theres more to the story
Perhaps they were all the type of user that goes to 'certain' websites . All links & all instances of this (I could find) point back to that forum & only users in that forum (that I could find)


I never install TV & leave it running (unattended access mode).
No need to, just leave the TV exe on the desktop, get the user to run it in "run only " mode when its needed. When finished, TV closes .

Its the cheaper clones of TV that make me nervous , they are a bargain price but could never bring myself to trust them .
1101 (13337)
1417969 2016-03-23 22:23:00 I'm sure further detail will come to light over time. KarameaDave (15222)
1 2