Live data from Hacker News

Github scam investigation: Thousands of “mods” and “cracks” stealing data

timsh.org

21–30 of 165 posts

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#21
post #18
post #17

Earlier quoted context omitted.

I use (redacted).on Microsoft.com tenant which is free of cost to me as a sandbox to learn about office 365 admin stuff. I don't work on it every day but it is nice to have this sandbox. I don't send spam or phishing emails. I don't send emails from this tenant at all to others, only to my own email addresses or to people I know for testing purposes.

Presumably you don't send out emails appearing to come from service@paypal.com saying things like "Reminder: You've still got a money request", with an HTML body that looks exactly like Paypal but contains a fraudulent link and phone number, so you should be fine.

No, I didn't. I did get those emails a lot on my university dot edu email. I understand there are legacy/compatibility challenges with the telephone infrastructure but you'd think this problem is entirely solvable with emails. :/

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#22
"Or why you should never download game mods"...

Like everything else, you shouldn't blindly search on github - or any other download site.

Only download from links referred from the official site if there's any, or the game's forum, or any other trustable and human reviewed source.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#23
post #2

Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

Good point instead of deleting, treat it like an invalid https cert. Lots of warnings and are you sures before you get to clone or fork.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#26
post #11

I think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam/malware comments and links, but even internally their teams can't reach anyone to get it fixed. Example https://feedback.azure.com/d365community/idea/9d0b22d8-c025-...

> 9 years ago

> This is still coming. The work is being completed now and we will be able to expose it in a few months.

I'm glad the official response has no date associated, so you won't know whether they published that yesterday of 8 years ago.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#27
post #2

Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

To me those repos seems an abuse of what GitHub is for. I'm 100% fine with a repo hosting malware if it's there for security researchers and anybody else interested in the topic to study, etc. Even better if there is also documentation. I'm not fine with using GitHub (or any other site) as a distribution platform for malware, hiding the fact that the software is malicious in the first point.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#28
post #19

Earlier quoted context omitted.

There used to be some sort of forum they had, I don't remember what it was, MSDN forums or Technet or something, but it used to dominate search results, and all the answers were from like, senior hobbyists who couldn't suggest much more than restarting or suggesting checking for updates. Maybe that was before every search result was Reddit or SO though.

That's MSDN, and these "senior hobbyists" were given a badge by MS to look credible: "MVP" (most valuable professional). Cherry on top: you used to pay to have an MSDN membership and access this wonderful community. To be fair though, the early MSDN was really good, and in a distant past MVP was a real achievement (say early 2000s). Now it's a weird mix real issues and "my printer blinks red, how to fix?" I don't thi…

I wasn't even talking about people who paid for a cert, just people signing up to try and help. They are generally more annoying then helpful to people who can do anything more than install and uninstall programs. Without a doubt every search result I found on that forum from someone having a similar issue never resulted in a useful lead.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#29
In my opinion, Microsoft’s entire support is at a tragically poor and hopeless level. GitHub is flooded with open issues that remain open for years without any response from Microsoft. The same applies to Azure. The technical support there is also truly terrible, and it’s easy to find horror stories online about people losing access to their accounts and being unable to restore them.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#30
post #29

In my opinion, Microsoft’s entire support is at a tragically poor and hopeless level. GitHub is flooded with open issues that remain open for years without any response from Microsoft. The same applies to Azure. The technical support there is also truly terrible, and it’s easy to find horror stories online about people losing access to their accounts and being unable to restore them.

When GoodbyeDPI malware was spreading using the similar template (lots of forked repos with password-protected archives), Github abuse team have instantly deleted it upon my request. Mean response time was 10-15 minutes.

I also deleted files on the file sharing websites, such as mediafire and mega.

My abuse emails followed the clear and understandable email template: your service is hosting malware, here's the link, it's password protected and the password is X, here are virustotal results, here's the original repo which it impersonates, and I want you to delete it.

Post reply on HN