Earlier quoted context omitted.
I'm not sure I see why the cleaning company was the problem.
"his girlfriend who owned the cleaning business" He wasn't just some guy.
Hackers ship their exploits directly to their target’s mailroom
131–140 of 172 posts
Re: Hackers ship their exploits directly to their target’s mailroom
#132Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…
I'm always amaze at how many computer screens/keyboards are visible from windows. It would be so easy to plant a webcam with some good optics on an opposite building and just get the passwords of the victim quite easily. you could have easily a few dozens of victims on a single company with a single camera.
Re: Hackers ship their exploits directly to their target’s mailroom
#133Re: Hackers ship their exploits directly to their target’s mailroom
#134This makes me think of an even more straightforward attack. How hard would it be to actually just ship them computer hardware and hope it makes it into the system? I mean, if a package that looks like it came from NewEgg containing a router shows up, especially if it matches the type the company usually uses, which wouldn't be too hard to figure out, what are the chances it just gets tossed on a shelf to be used next…
Re: Hackers ship their exploits directly to their target’s mailroom
#135> The researchers developed a proof-of-concept device — the warship, which has a similar size to a small phone — into a package and dropped it off in the mail. The device, which cost about $100 to build, was equipped with a 3G-enabled modem, allowing it to be remote-controlled so long as it had cell service. With its onboard wireless chip, the device would periodically scan for nearby networks — like most laptops do…
Re: Hackers ship their exploits directly to their target’s mailroom
#136Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…
One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…
Re: Hackers ship their exploits directly to their target’s mailroom
#137Earlier quoted context omitted.
One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…
Yeah, I never understood that. At the first half sensitive job I had, the cleaning crew had access to all the computer rooms, including the server one. I had thought of trying to push my boss into using encryption for our emails but abandoned after realizing that. I still believe it was dangerous to use gmail for the company emails when Google was one of our competitors in our niche.
Re: Hackers ship their exploits directly to their target’s mailroom
#138Earlier quoted context omitted.
Or just give them a giant wooden carving of the US presidential seal: https://en.wikipedia.org/wiki/The_Thing_(listening_device)
given the cheapness and compactness of modern electronics any furniture can carry a factory (or during shipping) installed chip these days, even without getting into smart/cloud connected office tables and chairs territory. One can hope at least NSA X-rays their furniture :)
Re: Hackers ship their exploits directly to their target’s mailroom
#139Earlier quoted context omitted.
Or just give them a giant wooden carving of the US presidential seal: https://en.wikipedia.org/wiki/The_Thing_(listening_device)
given the cheapness and compactness of modern electronics any furniture can carry a factory (or during shipping) installed chip these days, even without getting into smart/cloud connected office tables and chairs territory. One can hope at least NSA X-rays their furniture :)
Re: Hackers ship their exploits directly to their target’s mailroom
#140Earlier quoted context omitted.
I work close to IT (being software) for a company ~400 people. We were doing a security audit and this is one of the things they tested. USB's were loaded up with curious sounding files that when opened alerted our IT department. It was shocking how many people picked up and used these random USB's they found laying around.
>curious sounding files You left out the good part, what sort of file names did you use?