In my opinion, Microsoft’s entire support is at a tragically poor and hopeless level. GitHub is flooded with open issues that remain open for years without any response from Microsoft. The same applies to Azure. The technical support there is also truly terrible, and it’s easy to find horror stories online about people losing access to their accounts and being unable to restore them.
When GoodbyeDPI malware was spreading using the similar template (lots of forked repos with password-protected archives), Github abuse team have instantly deleted it upon my request. Mean response time was 10-15 minutes. I also deleted files on the file sharing websites, such as mediafire and mega. My abuse emails followed the clear and understandable email template: your service is hosting malware, here's the link,…
Github scam investigation: Thousands of “mods” and “cracks” stealing data
31–40 of 165 posts
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#32Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#33If I download and install a mod for minecraft, it should never have access to anything on my computer, except for the minecraft game files itself. If I open a spreadsheet in Excel, the excel process should have access only to that file and it's own config files.
Something similar to how android works, were the app has to explicitly ask the user to access their files.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#34Fun fact: if you come across one of these discord webhooks you can delete them. Just curl -X DELETE https://discord.com/api/webhooks/ [...]
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#35Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#36Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#37First image in the article reminds me of draw.io diagrams. Is this a drawio theme/library or some other tool was used to create it?
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#38I think the core of problem here is that applications are not isolated on the OS level. If I download and install a mod for minecraft, it should never have access to anything on my computer, except for the minecraft game files itself. If I open a spreadsheet in Excel, the excel process should have access only to that file and it's own config files. Something similar to how android works, were the app has to explicitl…
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#39If you've identified GitHub repositories hosting malware, you can report them directly to GitHub via their Abuse Report page, providing links and any relevant details. GitHub typically removes repositories that violate their Acceptable Use Policy, but response times may vary. If the malware is actively being used for harm, you may also consider reporting it to security organizations or CERT teams.
Waiting six months for Github to remove malicious repositories is unacceptable.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#40Earlier quoted context omitted.
I use (redacted).on Microsoft.com tenant which is free of cost to me as a sandbox to learn about office 365 admin stuff. I don't work on it every day but it is nice to have this sandbox. I don't send spam or phishing emails. I don't send emails from this tenant at all to others, only to my own email addresses or to people I know for testing purposes.
Presumably you don't send out emails appearing to come from service@paypal.com saying things like "Reminder: You've still got a money request", with an HTML body that looks exactly like Paypal but contains a fraudulent link and phone number, so you should be fine.
https://www.fortinet.com/blog/threat-research/phish-free-pay...