Live data from Hacker News

Did I just win?

twitter.com

21–30 of 140 posts

Re: Did I just win?

#23
post #19

Earlier quoted context omitted.

Individually, no, but statistically...perhaps?

Perhaps. There's also the depressing reality that you can't actually stop social engineering conclusively. A sysadmin is always going to need to have a login with administrative privileges, and they're always going to be fallible.

True. This thread has me thinking about how a controlled social engineering hacking event might play out just for the sake of education and awareness. (especially since one of my clients got hit badly with a phishing attack recently...less than a single percentage 'success' rate by the attacker but still cost them almost $100K).

Tough problem.

Re: Did I just win?

#26
post #21

What exactly happened here? All I see is a highlighted line that seems to have already been there.

A guy issued a challenge saying he'd give $100 to anyone who could trick him into inserting a certain string into any of his software projects.

Another guy responded "You should put this challenge on your website."

The first guy said "Good idea" and proceeded to do so, thus including the string in one of his software projects: his website.

GG

Re: Did I just win?

#27
post #21

What exactly happened here? All I see is a highlighted line that seems to have already been there.

A guy issued a challenge saying he'd give $100 to anyone who could trick him into inserting a certain string into any of his software projects. Another guy responded "You should put this challenge on your website." The first guy said "Good idea" and proceeded to do so, thus including the string in one of his software projects: his website. GG

Ah, totally didn't read the whole twitter thread. Brilliant.

Re: Did I just win?

#28
post #21

What exactly happened here? All I see is a highlighted line that seems to have already been there.

So by the hacker asking the victim to add the details of the contest, he tricked the victim into including the winning string in a software project.

Re: Did I just win?

#29
Another way to win this bounty would be to share some code with the string BackdoorPoCTwitter with the same color as the page background. If he copy and paste the code it could work. ^^

Re: Did I just win?

#30
post #19

Earlier quoted context omitted.

Perhaps. There's also the depressing reality that you can't actually stop social engineering conclusively. A sysadmin is always going to need to have a login with administrative privileges, and they're always going to be fallible.

True. This thread has me thinking about how a controlled social engineering hacking event might play out just for the sake of education and awareness. (especially since one of my clients got hit badly with a phishing attack recently...less than a single percentage 'success' rate by the attacker but still cost them almost $100K). Tough problem.

There are commercially-available off-the-shelf phishing training services, such as https://www.knowbe4.com/phishing-security-test-offer .

Disclaimer: My employer has used this, but I was uninvolved with the choice and have no stake in knowbe4. Just using it as an example I have to hand. I believe there are quite a few choices.

Post reply on HN