You better disable update checks in KeePass 2 (by gHacks)

Av Gurus

Level 29
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
A security vulnerability in the popular password manager KeePass 2 was disclosed recently affecting all versions of the password manager but only if automatic update checks are enabled.

KeePass 2 ships with an option to check periodically for program updates. While update checks are performed if the feature is enabled, automatic downloads and installations of updates is not supported.

Basically, what happens is that KeePass communicates with a service to see if an update is available. Users may then click on the update notification if an update is available to open a page on the Internet that provides them with a download of the new version of the password manager.

The vulnerability exploits the fact that KeePass 2 performs update checks over HTTP and not HTTPS. An attacker could exploit this by intercepting update requests, for instance on a local network, sending manipulated update information to the KeePass 2 client, and getting users to open a site on the Internet where a fake version of KeePass is offered on (or other things happen, e.g. drive by downloads).

The developer of KeePass won’t fix the issue according to the report.

How to protect yourself

KeePass-2-update-checks.png



Existing KeePass users have two options when it comes to the issue. The easier option involves disabling update checks in the client.

This is done in the following way:

  1. Open the KeePass 2 software on your system.
  2. Select Tools > Options from the menu at the top.
  3. Switch to the Advanced tab in the options window, and remove the checkmark from “Check for update at KeePass startup” there.
The downside of the method is that you would have to find a way to stay informed in regards to updates. You could visit the developer website regularly for that, or subscribe to the KeePass RSS Feed instead if you are using a RSS reader.

You could keep update checks enabled on the other hand but instead of clicking on the link provided by KeePass when updates are found, visit the KeePass website manually instead to download updates from it this way.

Both methods work just fine but add a level of inconvenience to the update checking and downloading process. Still, it is recommended to make use of either one of them to protect one of the most important programs on the computer.
 
Last edited:

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
Not updating software gives hackers and opportune chance to exploit previous builds. For me I would personally go right to a new password manager. :)
 
  • Like
Reactions: DardiM

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Sometimes there are really good and bad on not updating the software however no matter you weigh in; only one thing solution at all.

Update it regularly in any circumstances.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top