Live data from Hacker News

Hackers ship their exploits directly to their target’s mailroom

techcrunch.com

71–80 of 172 posts

Re: Hackers ship their exploits directly to their target’s mailroom

#71
post #65

Earlier quoted context omitted.

Not really, this is a known "vulnerability" with WPA2 and has been demonstrated to work a lot of times. https://www.aircrack-ng.org/doku.php?id=cracking_wpa#step_4_... This is done completely offline once you have the handshake captured and can be easily scaled.

Hacking obsolete protocols is shooting fish in a barrel. Classy hackers hack modern protocols like WPA 3. https://en.wikipedia.org/wiki/Wi-Fi_Protected_Access#Dragonb...

which nobody uses yet. last time I checked around a month ago there was only one WPA3 on WiGLE.

there are next to nil WPA3 fish in the barrel yet.

Re: Hackers ship their exploits directly to their target’s mailroom

#72
post #36

Earlier quoted context omitted.

IDK. If they put it in a stuffed animal like the pic in the article, how many would rip it open to see what's inside?

But what is more suspicious - a phone nobody ordered or (in the worst case of discovery) a stuffed animal nobody ordered with custom electronics in it?

How likely are they to rip open a stuffed animal and find the electronics? Depends on the security level, and the weight.

Re: Hackers ship their exploits directly to their target’s mailroom

#73
post #2

If your network security relies on promixity for ultimate security, you've done something very wrong.

Yep. You can do the same thing sitting outside on the street with a high gain antenna. Or one of the many rarely updated, vulnerability-ridden Android phones that are inside the building in people pockets.

The difference being that you can send multiple packages all over the globe for reasonably cheap.

But you cannot ship yourself to said parking-lots that fast, cheap and never in parrallel.

Re: Hackers ship their exploits directly to their target’s mailroom

#74

Earlier quoted context omitted.

Not really, this is a known "vulnerability" with WPA2 and has been demonstrated to work a lot of times. https://www.aircrack-ng.org/doku.php?id=cracking_wpa#step_4_... This is done completely offline once you have the handshake captured and can be easily scaled.

When I’ve been hired to do red teams we always use giant antennas and find a nice parking lot a few blocks away to capture the necessary handshakes. This works great even in downtown SF where the RF interference is absurd.

Yea, this ^. This attack approach is interesting but any company that's serious about security needs to realize that anything opened up on wifi is a big hole - this used to be more amusingly exploited by war-driving, just driving around a neighborhood looking for someone with an open network that spills out into the street so you could download the latest episode of friends.

I don't work in this sort of security and it seems terrifying, the social engineering side is especially crazy.

Re: Hackers ship their exploits directly to their target’s mailroom

#75

I had an idea to do exactly this but I never did it

Careful. The Norwegian postal service almost ripped me a new one for having the gall to ship a microcontroller, a thermometer and a couple of accelerometers to myself; apparently, buried somewhere deep in some regulation is the fact that shipping live datalogging equipment is a big no-no. Their legal department assured me this was par for the course for UPI (International Postal Union) menber countries.

Among the observations I made was that the tallest drop a package had to endure going through the sorting machine in Trondheim was 62cm (2ft).

Re: Hackers ship their exploits directly to their target’s mailroom

#76
post #6

Earlier quoted context omitted.

How long can you sit outside a company running Kali Linux and a high gain antenna array before you attract attention? If you ship someone on the DevOps team a WiFi-connected plush toy that listens for webhooks from your CI/CD platform to make happy/sad noises when the build passes/fails -- AND THEY PLUG IT IN AND LEAVE IT ON -- then the ability to have passive access to the network for a long period of time will be l…

But this device won't work for more than a few days anyway.

Just piggyback it onto something the recipient would want to plug in. Problem solved.

Re: Hackers ship their exploits directly to their target’s mailroom

#77
post #17

>Once the warship locates a Wi-Fi network from the mail room or the recipient’s desk, it listens for wireless data packets it can use to break into the network. The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a reada…

If the password is a predictable, low-length alphanumeric password it’s not going to take long for something like a multi-GPU machine with some dictionaries to break it.

Well for wpa2 the minimum is 8 characters and that is 2.6 days on the largest AWS instance at a peak cost of around $1560 if you got a PMK packet and about 50x longer if you don't.

Re: Hackers ship their exploits directly to their target’s mailroom

#78

Seems like doing this with a rooted phone would be even sneakier. You've got everything you need built in: battery, modem, etc. When it eventually does get opened, the mailroom person is going to think "oh someone ordered a phone" instead of "holy shit, this bunch of wires and circuit boards is maybe a bomb and definitely something I should tell the police about".

The really nasty one is compromising the return supply chain. Many (especially unopened) returned electronic devices go right back into the supply chain. For many retailers it's literally a free attack to carry out, with the only downside being you don't get to pick your target (although you can probably get ok odds on a target population).

Re: Hackers ship their exploits directly to their target’s mailroom

#79
post #4

Add one more item to the list of things to keep the Chief Security Officer up at night... though I've got to imagine this type of attack is at least a decade old even if it's only becoming well known right now. I've got to wonder if spear-phishers have been able to combine this type of attack with getting someone at a company to buy/accept and plug in some type of electronic novelty device...

Why even bother with a novelty? Send some USBs or even drop a few outside the building. Curiosity is a massive vulnerability

I work close to IT (being software) for a company ~400 people. We were doing a security audit and this is one of the things they tested. USB's were loaded up with curious sounding files that when opened alerted our IT department. It was shocking how many people picked up and used these random USB's they found laying around.

Re: Hackers ship their exploits directly to their target’s mailroom

#80
post #74

Earlier quoted context omitted.

When I’ve been hired to do red teams we always use giant antennas and find a nice parking lot a few blocks away to capture the necessary handshakes. This works great even in downtown SF where the RF interference is absurd.

Yea, this ^. This attack approach is interesting but any company that's serious about security needs to realize that anything opened up on wifi is a big hole - this used to be more amusingly exploited by war-driving, just driving around a neighborhood looking for someone with an open network that spills out into the street so you could download the latest episode of friends. I don't work in this sort of security and…

I used to do this as a kid in rural Texas, when we could only afford dial-up at the house and my parents didn't let me on the network very often. Good times! I'm terrified of the prospect now, but back then I really appreciated all my neighbors who ran unsecured wireless networks named "linksys"
Post reply on HN