Live data from Hacker News

Hackers ship their exploits directly to their target’s mailroom

techcrunch.com

91–100 of 172 posts

Re: Hackers ship their exploits directly to their target’s mailroom

#91

That seems like a lot of hassle and a pretty big federal crime for only being able to attack Wi-Fi networks. Why not just park your car outside and use a laptop?

Or drop off a solar powered Pineapple [1] on the roof with a drone and maybe an extra battery. Assuming you are in the same geographic area, that is.

[1] - https://shop.hak5.org/products/wifi-pineapple

Re: Hackers ship their exploits directly to their target’s mailroom

#92
post #36

Earlier quoted context omitted.

IDK. If they put it in a stuffed animal like the pic in the article, how many would rip it open to see what's inside?

But what is more suspicious - a phone nobody ordered or (in the worst case of discovery) a stuffed animal nobody ordered with custom electronics in it?

Just disguise your electronics to look like a voice box. Heck, you could even make it functional; microphone, speaker, and a tiny bit of software would make a convincing toy.

Re: Hackers ship their exploits directly to their target’s mailroom

#93
Am I missing something or does this depend on the company having a WiFi network that's connected to the company's normal internal network and its only authentication is an somewhat insecure Wifi password?

Because I would think that's a very uncommon case, everywhere I've worked either didn't have WiFi or the WiFi was a completely external network.

Re: Hackers ship their exploits directly to their target’s mailroom

#94

The WiFi network is an interesting attack vector, although I've seen lots of places that don't have wifi setup with direct internal network access, only for internet access. That could limit the effectiveness of the warship somewhat. When I started the article the first it came to me was that, once that package actually arrived at someone's desk, the main goal of the attackers would be to exploit Bluetooth attack vec…

Presumably WiFi hijacking would get you access to a lot of systems at a lot of places, but it does seem like the most intriguing targets (and those most hardened against other attacks) are least likely to be susceptible.

But now I wonder how many other attacks can be launched from a sealed box in a mailroom. Van Eck phreaking will get you a decent image off an LCD monitor from 10+ meters away through multiple interior walls, and can survive significant channel noise. Other side-channel attacks can directly pick up keys during decryption, though the proofs are short-range and it's not clear whether increasing device size/power would boost that.

It'd be tricky and expensive to arrange, especially with the risk of ending up pointed in a boring direction. But it seems like an absolutely wild idea for remote access to the contents of even air-gapped monitors.

Re: Hackers ship their exploits directly to their target’s mailroom

#95

Earlier quoted context omitted.

Why even bother with a novelty? Send some USBs or even drop a few outside the building. Curiosity is a massive vulnerability

I work close to IT (being software) for a company ~400 people. We were doing a security audit and this is one of the things they tested. USB's were loaded up with curious sounding files that when opened alerted our IT department. It was shocking how many people picked up and used these random USB's they found laying around.

>curious sounding files

You left out the good part, what sort of file names did you use?

Re: Hackers ship their exploits directly to their target’s mailroom

#96
post #6

That seems like a lot of hassle and a pretty big federal crime for only being able to attack Wi-Fi networks. Why not just park your car outside and use a laptop?

How long can you sit outside a company running Kali Linux and a high gain antenna array before you attract attention? If you ship someone on the DevOps team a WiFi-connected plush toy that listens for webhooks from your CI/CD platform to make happy/sad noises when the build passes/fails -- AND THEY PLUG IT IN AND LEAVE IT ON -- then the ability to have passive access to the network for a long period of time will be l…

A typical SUV or minivan with tinted windows that only parks there during business hours probably wouldn't attract much attention if the business was large enough that no one knew everyone that worked there. Integrate the yagi antenna into some part of the car like a bike rack or hide it inside a plastic roof carrier. Show up around the time that people are starting to come in so you can get a good spot for the antenna and leave when everyone else does.

Re: Hackers ship their exploits directly to their target’s mailroom

#97
post #75

I had an idea to do exactly this but I never did it

Careful. The Norwegian postal service almost ripped me a new one for having the gall to ship a microcontroller, a thermometer and a couple of accelerometers to myself; apparently, buried somewhere deep in some regulation is the fact that shipping live datalogging equipment is a big no-no. Their legal department assured me this was par for the course for UPI (International Postal Union) menber countries. Among the obs…

[deleted]

Re: Hackers ship their exploits directly to their target’s mailroom

#98
post #93

Am I missing something or does this depend on the company having a WiFi network that's connected to the company's normal internal network and its only authentication is an somewhat insecure Wifi password? Because I would think that's a very uncommon case, everywhere I've worked either didn't have WiFi or the WiFi was a completely external network.

There are companies with offices that have no Ethernet wiring, where WiFi is the only network. Some of them write software. (The last time $DAYJOB was office-shopping, there was one candidate space then occupied by, I think, a games developer which ran exclusively on WiFi; the cost and time required to wire the place up was one reason we wound up going elsewhere.)

Re: Hackers ship their exploits directly to their target’s mailroom

#99

Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…

One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day.

People are going to come at you from your blindside, if they can find it. And if you consider a certain class of people invisible, then that's what a hacker wants to be.

Re: Hackers ship their exploits directly to their target’s mailroom

#100
post #84

Earlier quoted context omitted.

Or just give them a giant wooden carving of the US presidential seal: https://en.wikipedia.org/wiki/The_Thing_(listening_device)

given the cheapness and compactness of modern electronics any furniture can carry a factory (or during shipping) installed chip these days, even without getting into smart/cloud connected office tables and chairs territory. One can hope at least NSA X-rays their furniture :)

I read somewhere years ago that they do. I don't remember where though, sorry.

Unrelated: WTF? I just had to do a reCAPTCHA on HN to log in!

Post reply on HN