Live data from Hacker News

Hackers ship their exploits directly to their target’s mailroom

techcrunch.com

141–150 of 172 posts

Re: Hackers ship their exploits directly to their target’s mailroom

#141
post #125
post #103

Earlier quoted context omitted.

I very much doubt you could discover anything with X-rays. You can place whole device inside a screw or the circuit can be very thin with little to no metal etc. I would assume it's becoming a a software war. You monitor all frequencies with SDR and try to shield as much as possible while on the offending side you try to push information on different frequencies and making it look a like like stuff that's already in…

You also don't even need to use RF. You can also use high-frequency audio to communicate to other devices, though I guess I'm not sure how you get it out of the building. It has been said that covert agencies have monitored conversations through windows by measuring the acoustic vibrations with a laser. So maybe that will work, but I have no idea how well that works with higher frequencies outside of human perception…

Higher frequencies will get filtered out. They don't have the power to vibrate the glass unless it's very loud.

Re: Hackers ship their exploits directly to their target’s mailroom

#142
post #30

IBM have a service to sell. Hence this 'fear'. Real world attacks using this method? Show me one. It is like putting superglue in locks. In theory anyone could invest in $5 of superglue and put a large building out of business for a few hours. It doesn't happen. But if you were an IBM type of company you could offer this as a service to companies wanting to test their contingency plans. Seems that is what is going on…

Agreed: this is an IBM "offensive operations unit" publicity piece. Key items from TFA: * TFA quotes Charles Henderson, " who heads up the IBM offensive operations unit. " * "This newly named technique — dubbed “warshipping” — is not a new concept." * "All of this could be done covertly without anyone noticing — so long as nobody opens the parcel. " A much more practical implementation of this attack vector is the "M…

That hackaday article has a great comment at the bottom

> One time I had a colony of ants build up inside an APC UPS. Every day, the system would make a little popping sound, then switch to battery inversion for about two seconds, then switch back to mains. For the longest time I was baffled.

> Then one day I noticed some ants making a trail and investigated. It was crazy how many ants were living inside it. Apparently, every once in a while an ant would come too close to crossing the AC wires and the power would short through it, killing the ant instantly and causing the protection circuit to put it on battery.

> I find myself wondering if a similar ant infestation would destroy the RasPi.

Re: Hackers ship their exploits directly to their target’s mailroom

#144
post #141
post #125

Earlier quoted context omitted.

You also don't even need to use RF. You can also use high-frequency audio to communicate to other devices, though I guess I'm not sure how you get it out of the building. It has been said that covert agencies have monitored conversations through windows by measuring the acoustic vibrations with a laser. So maybe that will work, but I have no idea how well that works with higher frequencies outside of human perception…

Higher frequencies will get filtered out. They don't have the power to vibrate the glass unless it's very loud.

[deleted]

Re: Hackers ship their exploits directly to their target’s mailroom

#145
post #141
post #125

Earlier quoted context omitted.

You also don't even need to use RF. You can also use high-frequency audio to communicate to other devices, though I guess I'm not sure how you get it out of the building. It has been said that covert agencies have monitored conversations through windows by measuring the acoustic vibrations with a laser. So maybe that will work, but I have no idea how well that works with higher frequencies outside of human perception…

Higher frequencies will get filtered out. They don't have the power to vibrate the glass unless it's very loud.

Cuban sounds as an [ultrasound intermodular distortion based] attack on electronics with humans seeming to be a side effect:

https://www.google.com/amp/s/spectrum.ieee.org/semiconductor...

Re: Hackers ship their exploits directly to their target’s mailroom

#146
post #103
post #84

Earlier quoted context omitted.

given the cheapness and compactness of modern electronics any furniture can carry a factory (or during shipping) installed chip these days, even without getting into smart/cloud connected office tables and chairs territory. One can hope at least NSA X-rays their furniture :)

I very much doubt you could discover anything with X-rays. You can place whole device inside a screw or the circuit can be very thin with little to no metal etc. I would assume it's becoming a a software war. You monitor all frequencies with SDR and try to shield as much as possible while on the offending side you try to push information on different frequencies and making it look a like like stuff that's already in…

So sounds like you'd also want a room that can give off emp pulses to fry electronics that you can't see as a failsafe

Re: Hackers ship their exploits directly to their target’s mailroom

#147

Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…

The illuminated globe example is much better than the one in the OP imo. The one in the OP isn't much different from parking a van outside the target office.

Re: Hackers ship their exploits directly to their target’s mailroom

#149

Earlier quoted context omitted.

"his girlfriend who owned the cleaning business" He wasn't just some guy.

He was working for the cleaning business, though. If the company was letting in anyone who works for that cleaner without further investigation, that's their problem. That's the situation we were talking about upthread, so I assumed zcrackerz would have said something if it were different.

Where I work, each cleaner gets a badge, just like the engineers. Presumably she gave her badge to a random other person, aka her boyfriend, so he could let himself in. Nothing stops me from doing that as an engineer either, but it would absolutely be a firing offence if caught.

Re: Hackers ship their exploits directly to their target’s mailroom

#150
post #99

Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…

One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…

I left my iPod on the desk overnight once while working at a large international investment bank. It vanished, presumably lifted by the cleaners. Security were remarkably uninterested in this, refused to do anything whatsoever (including checking the CCTV) although they did ask me to give them the crime number if I reported it.
Post reply on HN