Earlier quoted context omitted.
The article actually covers that it required 5 out of 9 people to sign off. They got 4 via PDF attacks and 1 via legacy access that was never properly terminated.
I think it's worth noting that the people did not sign off, only the keys did. The system does not require people to sign off, but for the keys to sign off. I don't think it's worth calling this a hack, the keys are what owned the moneies, and it's the keys that decided what to do with it. People have access to keys, they don't own them
A fake job offer took down Axie Infinity
341–350 of 364 posts
Re: A fake job offer took down Axie Infinity
#342Earlier quoted context omitted.
> I'm assuming that by compromising one employee's workstation they somehow got access to multiple other machines (which if true is itself a bit of a f* up) Q: If you assume the bad guys have already compromised your workstation, how sure are you that they won't be able to compromise other machines you connect to?
because the workstation was compromised by opening a corrupted pdf, but that vector wouldn't compromise the other machines unless users on them could be induced to open the same pdf. not to say it can't be done, but it was unexplained
Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised... The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.
Re: A fake job offer took down Axie Infinity
#343Earlier quoted context omitted.
Yep, internal security is brittle. The initial pdf vector would be only the start of a long sequence of hacks, including social engineering. e.g. sending email from managers -- or slack messages as you mention.
How do you defend against getting email from internal people, especially from people you expect email from?
Of course if you can access the software running the blockchain and get everyone to install an update, that works too
Re: A fake job offer took down Axie Infinity
#344Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…
How usable is LinkedIn with a pseudonym? Is that a security industry only practice or could a regular dev get away with that too? I've always been shy about having a profile with my actual name but id consider one with a thin veil of anonymity.
Just something to keep in mind. This post will have a lot of negative LI reviews simply because it was used as a sort of attack vector.
Re: A fake job offer took down Axie Infinity
#345Earlier quoted context omitted.
I think it's worth noting that the people did not sign off, only the keys did. The system does not require people to sign off, but for the keys to sign off. I don't think it's worth calling this a hack, the keys are what owned the moneies, and it's the keys that decided what to do with it. People have access to keys, they don't own them
Ok. So by your logic, my house keys owns my house? But don’t I own my house keys too?
It should be paying your mortgage, by the way.
Re: A fake job offer took down Axie Infinity
#346Earlier quoted context omitted.
That's the only thing it's good for, but that thing actually works. My last three job offers were from LinkedIn (I ultimately rejected one because my employer at the time gave me a counteroffer when I handed my notice, but I did accept the other two). The "content" on LI (feelhgood / motivational BS) is do ridiculous that I sort of contempt-read it ("hateread" would be to strong a word) for the heck of it, but I can'…
When I first signed up for LI I honestly couldn't tell the difference between the actual feed and a what I imagined a parody site would look like. The posts that proclaim themselves to hold controversial ideas, followed by the most banal cliches possible, crack me up. Once in a while I check the feed for kicks and it's always 100% spam, cliches, humble brags, and not-so-humble brags.
Re: A fake job offer took down Axie Infinity
#347Earlier quoted context omitted.
I open all sorts of PDFs, all the time, regardless of which computer I'm using. Is PDF as an attack vector such a widespread threat? I never payed much attention to them, assuming it's a document format that is relatively harmless even if it can include javascript. This is an honest question, by the way.
https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=PDF+documen... PDFs are "harmless" on their own, but they are user-generated documents that conform to a complex specification. Viewing them requires software that parses them. These parsers are often written in unsafe low level languages. The (in)security of unsafe parsers reading user-generated input is a tale as old as time itself.
Yes, I understand this, keep in mind I'm a software engineer.
Let me re-phrase. It's understood that, in general, document formats are more or less harmless unless they execute macros/code, and even then, this code must be able to exploit the platform's vulnerabilities to be able to do harm.
What is different about PDF than, say, JPEGs? I don't know of anyone who would hesitate to open an image file on their work computer, yet they are also complex formats requiring readers (viewers) which are often written in unsafe low-level languages. Yet I have never ever head of someone recommending "be careful before opening a JPEG (or PNG, or whatever) file".
I'm assuming we are not talking about ye olde "PDF.exe" or "JPEG.exe" trick here, but actual vulnerabilities in document files (not just renamed executables).
Re: A fake job offer took down Axie Infinity
#348Earlier quoted context omitted.
Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.
I hope this is satire.
Re: A fake job offer took down Axie Infinity
#349Earlier quoted context omitted.
Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.
I think you are joking to bait us. At least use a VM running a VPN within it. It won't protect you from screen captures or keyloggers your employer put on your machine, but it will segregate files and network activity.
Re: A fake job offer took down Axie Infinity
#350Earlier quoted context omitted.
Most Ponzi scheme victims got in because of greed. That doesn’t absolve the con artist for running one though
> That doesn’t absolve the con artist for running one though Who are you going to prosecute in this case? The developers of Ethereum who are making a digital peer2peer smart contract system and have no interest in running a ponzi scheme? Are you going to arrest Bram Cohen for inventing Bittorrent for what happens on it? What about the people behind Tor?