Two extremes as displayed on same day: a. Gizmodo says Facebook Is Giving Advertisers Access to Your Shadow Contact Information and HNers are concerned b. IRL, Roommate also gave them their Facebook email and password (for $15/mth)
Found hooked up to my router
71–80 of 358 posts
Re: Found hooked up to my router
#72I don't see how this 'man' in the middle could actually intercept passwords, except for http, but who runs auth over http anyway. For https, the 'man' would have to substitute its own certificate and then the browser / client software wouldn't trust the cert/domain combination without the end user being extremely stupid (and knowledgeable enough to achieve the stupidity).
What about DNS spoofing[1] at the local network level? [1] https://en.wikipedia.org/wiki/DNS_spoofing
Re: Found hooked up to my router
#73How is this thing intercepting all his Facebook and bank traffic?
I don't think it is. Here's another thread which may be for the same thing or something similar. https://www.reddit.com/r/Scams/comments/2vd1g8/scam_rentyour... It's apparently a "rent a Facebook account" scam. (The roommate apparently also provided his Facebook credentials.)
Also, the participant is supposed to get paid after they send the Raspberry Pi back after the account got banned, i.e. once the user has absolutely zero value for the scammer... I don't see why the scammer would pay... (although it may be chump change compared to the money they make from getting a percentage of the ad spend, so maybe it's worth paying that to get a better reputation).
Re: Found hooked up to my router
#74Interesting that it is "worth" $15/month. Maybe they were never going to pay up. But if they were, that seems expensive when they could just use compromised PCs and devices for ... whatever they are going to do? Plus they had to buy and supply the dongle.
It may be worth it to just sacrifice it after a month. I am sure it is profitable, but as people become more aware, it will be harder for them to do this.
Re: Found hooked up to my router
#75I don't see how this 'man' in the middle could actually intercept passwords, except for http, but who runs auth over http anyway. For https, the 'man' would have to substitute its own certificate and then the browser / client software wouldn't trust the cert/domain combination without the end user being extremely stupid (and knowledgeable enough to achieve the stupidity).
The malware doesn't have to add a new root certificate, either, though that's completely possible. The Zeus trojan [3] does "man-in-the-browser" to intercept banking information, for example.
[1] https://github.com/secretsquirrel/BDFProxy
[2] https://www.pcworld.com/article/2839152/tor-project-flags-ru...
Re: Found hooked up to my router
#76Re: Found hooked up to my router
#77* What sites do they visit?
* How long do they spend on each site?
* What apps do they use? (apps make http requests, after all)
* How long do they spend on these apps (providing it's making consistent http requests)
* What devices are they using to access these sites/apps?
Kind of like Neilson ratings but for the web.
Re: Found hooked up to my router
#78If someone would ship this to our office with a note like "attach this to a LAN port" chances are it will get attached. And we're a software house. People tend to pay attention to viruses, etc.. but not physical security.
Re: Found hooked up to my router
#79Earlier quoted context omitted.
In general it's best practice to leave unused ports on managed switches in an admin down/shut state until something you know is connected. Or live, but in a quarantine VLAN. Your idea, however, is not totally uncommon to have a raspbery pi sized device at an offsite location, specifically not plugged into any sort of UPS, which is monitored by various alerting systems. In addition to the alerts that one should get du…
My college used to do similar. If you did not register your MAC address, you would be DHCP assigned into a walled-garden IP block. We found we could run an IP scanner on the authorized subnet (from a computer with a whitelisted MAC), and find the unused IPs, and just set those statically for 'visitors'. No need to register any more MAC addresses.
Re: Found hooked up to my router
#80Whilst it's certainly a scam to do with advertising [0], I doesn't look like there's any evidence that the scam has anything to do with 'stealing' anything from network / network traffic: > Facebook has several mechanisms in place to protect your account. We make every attempt to work within the these constraints. In order to keep your account from being locked we use a small device called a Raspberry Pi. This device…
>Why do you need my account? Why not use your own? We have plenty of our own accounts. We need you because no matter how many accounts we have internally, Facebook limits the amount we can spend per account. By working with people like you, we are able to scale our business. Can somebody explain if this makes sense? Why are there limits on account spending?