Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

341–350 of 364 posts

Re: A fake job offer took down Axie Infinity

#341
post #229

Earlier quoted context omitted.

The article actually covers that it required 5 out of 9 people to sign off. They got 4 via PDF attacks and 1 via legacy access that was never properly terminated.

I think it's worth noting that the people did not sign off, only the keys did. The system does not require people to sign off, but for the keys to sign off. I don't think it's worth calling this a hack, the keys are what owned the moneies, and it's the keys that decided what to do with it. People have access to keys, they don't own them

No post body was provided.

Re: A fake job offer took down Axie Infinity

#342

Earlier quoted context omitted.

> I'm assuming that by compromising one employee's workstation they somehow got access to multiple other machines (which if true is itself a bit of a f* up) Q: If you assume the bad guys have already compromised your workstation, how sure are you that they won't be able to compromise other machines you connect to?

because the workstation was compromised by opening a corrupted pdf, but that vector wouldn't compromise the other machines unless users on them could be induced to open the same pdf. not to say it can't be done, but it was unexplained

It does not have to be via the same method; what the attackers discover from the first compromised machine may give them access to other machines. It seems clear this is what happened here:

Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised... The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.

Re: A fake job offer took down Axie Infinity

#343

Earlier quoted context omitted.

Yep, internal security is brittle. The initial pdf vector would be only the start of a long sequence of hacks, including social engineering. e.g. sending email from managers -- or slack messages as you mention.

How do you defend against getting email from internal people, especially from people you expect email from?

Don't keep your security keys capable of root access on anything that's not a hardware token locked in a safe.

Of course if you can access the software running the blockchain and get everyone to install an update, that works too

Re: A fake job offer took down Axie Infinity

#344

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

How usable is LinkedIn with a pseudonym? Is that a security industry only practice or could a regular dev get away with that too? I've always been shy about having a profile with my actual name but id consider one with a thin veil of anonymity.

But every single time there is an AskHN on the topic of how people got their current gigs, LinkedIn overwhelmingly dominates other channels.

Just something to keep in mind. This post will have a lot of negative LI reviews simply because it was used as a sort of attack vector.

Re: A fake job offer took down Axie Infinity

#345
post #294
post #229

Earlier quoted context omitted.

I think it's worth noting that the people did not sign off, only the keys did. The system does not require people to sign off, but for the keys to sign off. I don't think it's worth calling this a hack, the keys are what owned the moneies, and it's the keys that decided what to do with it. People have access to keys, they don't own them

Ok. So by your logic, my house keys owns my house? But don’t I own my house keys too?

Your keychain owns your house keys.

It should be paying your mortgage, by the way.

Re: A fake job offer took down Axie Infinity

#346
post #244
post #83

Earlier quoted context omitted.

That's the only thing it's good for, but that thing actually works. My last three job offers were from LinkedIn (I ultimately rejected one because my employer at the time gave me a counteroffer when I handed my notice, but I did accept the other two). The "content" on LI (feelhgood / motivational BS) is do ridiculous that I sort of contempt-read it ("hateread" would be to strong a word) for the heck of it, but I can'…

When I first signed up for LI I honestly couldn't tell the difference between the actual feed and a what I imagined a parody site would look like. The posts that proclaim themselves to hold controversial ideas, followed by the most banal cliches possible, crack me up. Once in a while I check the feed for kicks and it's always 100% spam, cliches, humble brags, and not-so-humble brags.

These seem to work best for engagement

Re: A fake job offer took down Axie Infinity

#347
post #282

Earlier quoted context omitted.

I open all sorts of PDFs, all the time, regardless of which computer I'm using. Is PDF as an attack vector such a widespread threat? I never payed much attention to them, assuming it's a document format that is relatively harmless even if it can include javascript. This is an honest question, by the way.

https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=PDF+documen... PDFs are "harmless" on their own, but they are user-generated documents that conform to a complex specification. Viewing them requires software that parses them. These parsers are often written in unsafe low level languages. The (in)security of unsafe parsers reading user-generated input is a tale as old as time itself.

> PDFs are "harmless" on their own, but they are user-generated documents that conform to a complex specification. Viewing them requires software that parses them. These parsers are often written in unsafe low level languages.

Yes, I understand this, keep in mind I'm a software engineer.

Let me re-phrase. It's understood that, in general, document formats are more or less harmless unless they execute macros/code, and even then, this code must be able to exploit the platform's vulnerabilities to be able to do harm.

What is different about PDF than, say, JPEGs? I don't know of anyone who would hesitate to open an image file on their work computer, yet they are also complex formats requiring readers (viewers) which are often written in unsafe low-level languages. Yet I have never ever head of someone recommending "be careful before opening a JPEG (or PNG, or whatever) file".

I'm assuming we are not talking about ye olde "PDF.exe" or "JPEG.exe" trick here, but actual vulnerabilities in document files (not just renamed executables).

Re: A fake job offer took down Axie Infinity

#348

Earlier quoted context omitted.

Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.

I hope this is satire.

No, it's not satire! I use a separate chrome profile for my personal life, and I keep my personal files in google drive. I'm not sure what the fuss is about?

Re: A fake job offer took down Axie Infinity

#349

Earlier quoted context omitted.

Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.

I think you are joking to bait us. At least use a VM running a VPN within it. It won't protect you from screen captures or keyloggers your employer put on your machine, but it will segregate files and network activity.

Nope, not joking. I use a separate chrome profile for my personal life, and I keep my personal files in google drive. Even if your employer is monitoring you (which I doubt), what are you doing that you think will be so interesting to them?

Re: A fake job offer took down Axie Infinity

#350
post #337
post #326

Earlier quoted context omitted.

Most Ponzi scheme victims got in because of greed. That doesn’t absolve the con artist for running one though

> That doesn’t absolve the con artist for running one though Who are you going to prosecute in this case? The developers of Ethereum who are making a digital peer2peer smart contract system and have no interest in running a ponzi scheme? Are you going to arrest Bram Cohen for inventing Bittorrent for what happens on it? What about the people behind Tor?

In the case of a literal Ponzi scheme it is pretty obvious who to prosecute. In the blockchain space many players have figured out ways to avoid being prosecuted for their schemes (many of which are little more than outright scams), but that doesn’t make what they’re doing ethical
Post reply on HN