Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

201–210 of 364 posts

Re: A fake job offer took down Axie Infinity

#201

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

I'm so confused by #2 as well.

If pdf is compromised, is it fixed? This seems like the kind of vulnerability that would ruin pdf's reputation permanently. It was the safe alternative to sending someone a .doc particularly because of it's limited functionality.

Re: A fake job offer took down Axie Infinity

#202
post #114
post #48

Earlier quoted context omitted.

The right move here would have been to have separate work/personal computers so that this PDF never landed on a system with access to the Ronin network. I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.

what would stop a developer from checking personal email on a work machine?

Themselves. I'm saying developers (and employees in general) should not do any personal stuff on work machines or any work stuff on personal machines.

This has benefits for the employee, not just the company, in that it keeps the employees personal data out of the hands of the IT department.

Re: A fake job offer took down Axie Infinity

#203
post #114

Earlier quoted context omitted.

what would stop a developer from checking personal email on a work machine?

Or more to the point, what would stop someone from sending malicious documents to the employees' work emails? Figure out a company uses register a phishing domain (e.g. gith.ub) send them an email with important info about their account, and a PDF attachment with more details. If it's that easy to compromise a system all you have to do is get a few employees to open the PDF right?

And this is exactly why your IT department sends out those simulated phishing emails everyone likes to complain about.

Re: A fake job offer took down Axie Infinity

#204
post #48

Earlier quoted context omitted.

Here's a demonstration of some example attacks using pdf: executing arbitrary js, and connecting to a samba server: https://www.sentinelone.com/blog/malicious-pdfs-revealing-te... I'm not sure about this attack specifically, though, and in Ronin's post mortem they aren't really talking about that: https://roninblockchain.substack.com/p/back-to-building-roni... . To some extent, the PDF viewer/OS doesn't matter. A ded…

The right move here would have been to have separate work/personal computers so that this PDF never landed on a system with access to the Ronin network. I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.

So then the attackers can only get my bank password?

I think the clear move here should be to avoid pdf, just like the move is to avoid doc

Re: A fake job offer took down Axie Infinity

#205
post #91

Curious if anyone has been able to find technical details of how this attack works/worked. I'm under the impression most PDF viewers would prevent this sort of attack (e.g. opening a PDF in your browser should sandbox it to the browsing context), but really keen to know what PDF viewer / OS was used by the dev.

On Windows, Acrobat Reader has Protected Mode (sandbox) and Protected View (most features disabled) features [0], but people tend to disable it, in particular the Protected View, or don’t enable it for all locations. Or maybe the vulnerability wasn’t on Windows, or was in something like font rendering, or they used a different reader without sandboxing. [0] https://helpx.adobe.com/reader/using/protected-mode-windows.…

Why is Protected mode not the default?

Re: A fake job offer took down Axie Infinity

#206
Is this the moment we need for LaTeX to become standard? pdf is clearly to blame here imo. This guy isn't the only one to trust it.

It seems like the entire legal profession, for instance, should be crippled by this vulnerability disclosure, if true.

Re: A fake job offer took down Axie Infinity

#207

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

I only use titles such as 'Employee' 'Worker' 'Carbon Based Life Form'.. on Linkedin. It also significantly reduces the amount of spam and cold calls.

Re: A fake job offer took down Axie Infinity

#208
post #106

Earlier quoted context omitted.

I still can't believe that they opened the PDF on the company computer. I always use my home computer and the poor hacker would get bored of seeing all of my Raspberry Pi projects that I haven't done.

If you're looking for work, you have to interview during the day, which you're probably in office (things are very different now). I know I'm guilty of having my personal emailed signed into my work computer (albeit with a separate browser). I've also done virtual interviews in the office meeting/phone room.

You've done interviews in the office of your (then) current employer??? Gutsy. I wouldn't dream of using employer's equipment, time or space while negotiating for a new employment.

Re: A fake job offer took down Axie Infinity

#209
post #106

Earlier quoted context omitted.

I still can't believe that they opened the PDF on the company computer. I always use my home computer and the poor hacker would get bored of seeing all of my Raspberry Pi projects that I haven't done.

Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.

I think you are joking to bait us. At least use a VM running a VPN within it. It won't protect you from screen captures or keyloggers your employer put on your machine, but it will segregate files and network activity.

Re: A fake job offer took down Axie Infinity

#210
post #206

Is this the moment we need for LaTeX to become standard? pdf is clearly to blame here imo. This guy isn't the only one to trust it. It seems like the entire legal profession, for instance, should be crippled by this vulnerability disclosure, if true.

hahaha
Post reply on HN