Live data from Hacker News

Hackers ship their exploits directly to their target’s mailroom

techcrunch.com

1–10 of 172 posts

Re: Hackers ship their exploits directly to their target’s mailroom

#4
Add one more item to the list of things to keep the Chief Security Officer up at night... though I've got to imagine this type of attack is at least a decade old even if it's only becoming well known right now. I've got to wonder if spear-phishers have been able to combine this type of attack with getting someone at a company to buy/accept and plug in some type of electronic novelty device...

Re: Hackers ship their exploits directly to their target’s mailroom

#6

That seems like a lot of hassle and a pretty big federal crime for only being able to attack Wi-Fi networks. Why not just park your car outside and use a laptop?

How long can you sit outside a company running Kali Linux and a high gain antenna array before you attract attention? If you ship someone on the DevOps team a WiFi-connected plush toy that listens for webhooks from your CI/CD platform to make happy/sad noises when the build passes/fails -- AND THEY PLUG IT IN AND LEAVE IT ON -- then the ability to have passive access to the network for a long period of time will be less noticed.

The example of the WiFi connected stuffed animal listening for webhooks isn't a made-up example -- I read a blog post about that years ago. Some team had a "build bunny" whose ears perked up and made happy noises when the build passed and the ears drooped and made a sad trombone noise when builds failed. The thing is already RF-active... would anyone break out a spectrum analyzer to notice if the thing was also transmitting/receiving on LTE and not just WiFi?

Re: Hackers ship their exploits directly to their target’s mailroom

#7
IBM have a service to sell. Hence this 'fear'.

Real world attacks using this method?

Show me one.

It is like putting superglue in locks. In theory anyone could invest in $5 of superglue and put a large building out of business for a few hours. It doesn't happen. But if you were an IBM type of company you could offer this as a service to companies wanting to test their contingency plans. Seems that is what is going on here.

Re: Hackers ship their exploits directly to their target’s mailroom

#8
>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a readable Wi-Fi password.

Breaking a hash to obtain the Wi-Fi password? Surely this is impossible?

Re: Hackers ship their exploits directly to their target’s mailroom

#9

>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a reada…

There are numerous attacks to crack wifi hashes. In theory, a properly implemented hash should not be crackable -- but theory often does not match the real world.

Re: Hackers ship their exploits directly to their target’s mailroom

#10

>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a reada…

[deleted]
Post reply on HN