Live data from Hacker News

Hackers ship their exploits directly to their target’s mailroom

techcrunch.com

111–120 of 172 posts

Re: Hackers ship their exploits directly to their target’s mailroom

#111

The WiFi network is an interesting attack vector, although I've seen lots of places that don't have wifi setup with direct internal network access, only for internet access. That could limit the effectiveness of the warship somewhat. When I started the article the first it came to me was that, once that package actually arrived at someone's desk, the main goal of the attackers would be to exploit Bluetooth attack vec…

Presumably WiFi hijacking would get you access to a lot of systems at a lot of places, but it does seem like the most intriguing targets (and those most hardened against other attacks) are least likely to be susceptible. But now I wonder how many other attacks can be launched from a sealed box in a mailroom. Van Eck phreaking will get you a decent image off an LCD monitor from 10+ meters away through multiple interio…

Right. Or just ship a free, already compromised monitor. A free 32-inch 4K monitor could quickly find itself attached to pretty interesting places.

24/7 power, a platform to mount attacks via Bluetooth, WiFi, microphone, integrated USB hub, and heck, aren't the new monitors often attached to Thunderbolt, which is almost the same as PCIe. And even in case it's not Thunderbolt, it's likely going to be USB-C — not too shabby for evil keyboard emulation, memory sticks, fake ethernet adapters etc.

Perfect visibility to keyboards as well.

3G for return channel.

Re: Hackers ship their exploits directly to their target’s mailroom

#112
post #59

This makes me think of an even more straightforward attack. How hard would it be to actually just ship them computer hardware and hope it makes it into the system? I mean, if a package that looks like it came from NewEgg containing a router shows up, especially if it matches the type the company usually uses, which wouldn't be too hard to figure out, what are the chances it just gets tossed on a shelf to be used next…

Or just leave a usb stick (really have it be a usb rubby ducky or bash bunny) in the parking lot. Someone will find it and be like "OH I wonder whose this is, it could be important, I better plug it in and found out." TaDa, you now have a shell to their network.

Re: Hackers ship their exploits directly to their target’s mailroom

#113
post #99

Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…

One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…

I once stayed late and noticed a cleaner was wearing a polo from the company I used to work for. I asked him about it and it turned out he was an engineer and was filling in for his girlfriend who owned the cleaning business. Holy red flag! I made some noise and that cleaning company was let go.

Re: Hackers ship their exploits directly to their target’s mailroom

#114

Earlier quoted context omitted.

Why even bother with a novelty? Send some USBs or even drop a few outside the building. Curiosity is a massive vulnerability

I work close to IT (being software) for a company ~400 people. We were doing a security audit and this is one of the things they tested. USB's were loaded up with curious sounding files that when opened alerted our IT department. It was shocking how many people picked up and used these random USB's they found laying around.

> It was shocking how many people picked up and used these random USB's they found laying around.

"Oh no some one lost their USB stick! I better plug it and try to figure out who so I can return it."

Re: Hackers ship their exploits directly to their target’s mailroom

#115
post #99

Earlier quoted context omitted.

One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…

I once stayed late and noticed a cleaner was wearing a polo from the company I used to work for. I asked him about it and it turned out he was an engineer and was filling in for his girlfriend who owned the cleaning business. Holy red flag! I made some noise and that cleaning company was let go.

Pro-tip for anyone that finds themselves in this situation when trying to steal another company's data - say you bought the shirt for 50c at a second hand store. That, or don't wear your company polo on an espionage mission.

Re: Hackers ship their exploits directly to their target’s mailroom

#116
> The researchers developed a proof-of-concept device — the warship, which has a similar size to a small phone — into a package and dropped it off in the mail. The device, which cost about $100 to build, was equipped with a 3G-enabled modem, allowing it to be remote-controlled so long as it had cell service. With its onboard wireless chip, the device would periodically scan for nearby networks — like most laptops do when they’re switched on — to track the location of the device in its parcel.

This is beyond belief to me and an example of why there are more security breaches than would happen if everyone out there (security researcher in particular and ironic) wasn't eager for their glory of discovering an exploit that very well might have taken years to uncover if at all.

So they come up with an idea, create and proof of concept, then they publicize it so that actual hackers can be turned on to a new idea under the guise that they are going to prevent a problem so that people can protect against it.

> “If we can educate a company about an attack vector like this, it dramatically reduces the likelihood of the success of it by criminals,” Henderson said.

Like all the other similar 'research' it completely ignores that it is also educating people who will now know of the exploit and it will give them ideas on what can be done.

Re: Hackers ship their exploits directly to their target’s mailroom

#117
One of my favorite security stories came from a well known security researcher who was asked to try to penetrate the computer system of a national research lab. On the day of the test he came in and logged in using his own credential and had full system access. Leaving everyone in the room stunned.

The system was made by DEC and DEC had the process of sending software updates by magnetic tape. This researcher had made a follow up meeting request and brought with them a tape that looked exactly like an update tape with label and all the trimmings. Further they dropped it on to a mail delivery cart that was already through the 'verify the mail' process. As a result the tape got delivered to the operators, they mounted it and installed the "updates." Of course that created an account the pentester used to log in.

Caught the customer by surprise of course, nobody likes to be surprised by the pentesters but it is always a good thing to have them find something rather than be penetrated.

The story (which has clearly stuck with me for a long time) left me with an appreciation for looking at things which aren't normally considered "part of the IT infrastructure" as part of the attack surface that needs to be protected.

Re: Hackers ship their exploits directly to their target’s mailroom

#118

Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…

I'm always amaze at how many computer screens/keyboards are visible from windows. It would be so easy to plant a webcam with some good optics on an opposite building and just get the passwords of the victim quite easily. you could have easily a few dozens of victims on a single company with a single camera.

Re: Hackers ship their exploits directly to their target’s mailroom

#119
post #110
post #99

Earlier quoted context omitted.

One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…

Many companies treat the cleaning crew like trash. Unpredictable scheduling, no benefits, minimum wage pay combine to make it so a very small bribe would get an attacker into a building, where they could plant gear in the drop ceiling and more. Doing right by your workers would go a long way towards plugging this vulnerability.

While you should always treat your employees well, I'm not talking about creating a disgruntled employee leading to problems.

The example given was a route someone could use to be invited into the building. Nothing is stopping you from being a blue collar worker, especially if you're willing to fake a work history.

Post reply on HN