Live data from Hacker News

Hackers ship their exploits directly to their target’s mailroom

techcrunch.com

131–140 of 172 posts

Re: Hackers ship their exploits directly to their target’s mailroom

#131

Earlier quoted context omitted.

I'm not sure I see why the cleaning company was the problem.

"his girlfriend who owned the cleaning business" He wasn't just some guy.

He was working for the cleaning business, though. If the company was letting in anyone who works for that cleaner without further investigation, that's their problem. That's the situation we were talking about upthread, so I assumed zcrackerz would have said something if it were different.

Re: Hackers ship their exploits directly to their target’s mailroom

#132
post #118

Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…

I'm always amaze at how many computer screens/keyboards are visible from windows. It would be so easy to plant a webcam with some good optics on an opposite building and just get the passwords of the victim quite easily. you could have easily a few dozens of victims on a single company with a single camera.

This is a real problem. While I was working at XBox, we made giant pictures over the windows using colored post-it notes. I remember a really good pixel art megaman that was my favorite. Internal offices sometimes used newspapers to cover over the windows (but maybe that was just advertising, here's someone who works on something you want to see!).

Re: Hackers ship their exploits directly to their target’s mailroom

#133

Earlier quoted context omitted.

Great plan, but we have to test it. Can you upload a sample dataset of you typing for 1 week so we can try this approach?

What's your address? I can send it on a usb key.

You can just mail it to

9800 Savage Rd. Suite 6272

Ft. Meade, MD 20755-6000

Re: Hackers ship their exploits directly to their target’s mailroom

#134
post #59

This makes me think of an even more straightforward attack. How hard would it be to actually just ship them computer hardware and hope it makes it into the system? I mean, if a package that looks like it came from NewEgg containing a router shows up, especially if it matches the type the company usually uses, which wouldn't be too hard to figure out, what are the chances it just gets tossed on a shelf to be used next…

Package everything up in a Kinesis Advantage.

Re: Hackers ship their exploits directly to their target’s mailroom

#135
post #116

> The researchers developed a proof-of-concept device — the warship, which has a similar size to a small phone — into a package and dropped it off in the mail. The device, which cost about $100 to build, was equipped with a 3G-enabled modem, allowing it to be remote-controlled so long as it had cell service. With its onboard wireless chip, the device would periodically scan for nearby networks — like most laptops do…

We're in a predator-prey relationship. And the stakes are enormous. You can bet something like this actually has been done in the wild before. In fact, governments do things like this regularly. The only question is if it's worth your effort to protect yourself from it.

Re: Hackers ship their exploits directly to their target’s mailroom

#136
post #99

Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…

One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…

To corroborate that, I once helped a family friend clean banks in the middle of the night. That was her job. Far as I can tell, she was just the lowest bidder on it with a consistent work ethic. We had access to almost everything. Could've gotten to most of the computers. I told her as much with her laughing that it was ridiculous.

Re: Hackers ship their exploits directly to their target’s mailroom

#137
post #130
post #99

Earlier quoted context omitted.

One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…

Yeah, I never understood that. At the first half sensitive job I had, the cleaning crew had access to all the computer rooms, including the server one. I had thought of trying to push my boss into using encryption for our emails but abandoned after realizing that. I still believe it was dangerous to use gmail for the company emails when Google was one of our competitors in our niche.

And I think your belief is justified. Look at how many niche products people built on AWS and Amazon caught wind of their success and rolled out a competitor!

Re: Hackers ship their exploits directly to their target’s mailroom

#138
post #84

Earlier quoted context omitted.

Or just give them a giant wooden carving of the US presidential seal: https://en.wikipedia.org/wiki/The_Thing_(listening_device)

given the cheapness and compactness of modern electronics any furniture can carry a factory (or during shipping) installed chip these days, even without getting into smart/cloud connected office tables and chairs territory. One can hope at least NSA X-rays their furniture :)

https://en.wikipedia.org/wiki/Nonlinear_junction_detector

Re: Hackers ship their exploits directly to their target’s mailroom

#139
post #84

Earlier quoted context omitted.

Or just give them a giant wooden carving of the US presidential seal: https://en.wikipedia.org/wiki/The_Thing_(listening_device)

given the cheapness and compactness of modern electronics any furniture can carry a factory (or during shipping) installed chip these days, even without getting into smart/cloud connected office tables and chairs territory. One can hope at least NSA X-rays their furniture :)

Even better if you integrate into something like a motorized standing desk, they'll plug it in for you.

Re: Hackers ship their exploits directly to their target’s mailroom

#140
post #95

Earlier quoted context omitted.

I work close to IT (being software) for a company ~400 people. We were doing a security audit and this is one of the things they tested. USB's were loaded up with curious sounding files that when opened alerted our IT department. It was shocking how many people picked up and used these random USB's they found laying around.

>curious sounding files You left out the good part, what sort of file names did you use?

settlement_proposal.docx 2019-05-25_bachelor-party.mov GAME_OF_THRONES_S1E06.mp4 salaries.xlsx
Post reply on HN