Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Winget.yml #384

Merged
merged 6 commits into from
Aug 17, 2024
Merged

Update Winget.yml #384

merged 6 commits into from
Aug 17, 2024

Conversation

unrooted
Copy link
Contributor

Hi, I've spotted this only recently.

Even tho MS Store is blocked on my machine:
signal-2024-07-12-234525_002

I've been able to use winget to install a program with source from msstore, using it's store ID (compared both, the ID in winget is the same as the ID on the MS Store), as seen on the screenshots below

signal-2024-07-12-234525_003

signal-2024-07-12-234525_004

(Kali WSL only as an example ofc)

it's not a big thing, but interesting that it doesn't care that MS Store is blocked and still allows programs with source from the MS Store to be installed on the machine

I don't see a lot of potential in here, nowhere near what's been previously added to the winget description, but would be interesting in someone pushing malicious programs into the MS Store and then utilizing winget to get past MS Store being blocked on the machine

Also, I think that MitreID T1072 suits this the best, however, correct me if I'm wrong

Copy link
Member

@wietze wietze left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice find - although this is somewhat 'expected' functionality for winget, I agree it is ultimately unexpected because it bypasses something that is blocked in the GUI. Thank you for your contribution.

@wietze wietze merged commit 659a024 into LOLBAS-Project:master Aug 17, 2024
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants