Is it really a problem to host malware on github?
Github scam investigation: Thousands of “mods” and “cracks” stealing data
91–100 of 165 posts
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#92Earlier quoted context omitted.
I think I read somewhere that scammers set up an email distribution list / alias / forwarding from one something.onmicrosoft.com account to dozens of victims, and then they trigger a (real!) paypal email with that one something.onmicrosoft.com address as the recipient. So the email has a valid DKIM signature from paypal, then microsoft forwards that email to all the victims, which will still pass DKIM while amplifyin…
Is there a legitimate reason for them to forward paypal emails? Why not just not let that happen under any circumstances?
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#93This raises a big question: How effective is GitHub’s abuse reporting system against large-scale malware campaigns? If 1,000+ malicious repos can persist for months, does this mean GitHub lacks automated scanning or relies too much on user reports?
Response times can very from hours to what feels like months, and they rarely handle reports based on patterns of abuse.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#94Earlier quoted context omitted.
I think I read somewhere that scammers set up an email distribution list / alias / forwarding from one something.onmicrosoft.com account to dozens of victims, and then they trigger a (real!) paypal email with that one something.onmicrosoft.com address as the recipient. So the email has a valid DKIM signature from paypal, then microsoft forwards that email to all the victims, which will still pass DKIM while amplifyin…
Is there a legitimate reason for them to forward paypal emails? Why not just not let that happen under any circumstances?
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#95I think the core of problem here is that applications are not isolated on the OS level. If I download and install a mod for minecraft, it should never have access to anything on my computer, except for the minecraft game files itself. If I open a spreadsheet in Excel, the excel process should have access only to that file and it's own config files. Something similar to how android works, were the app has to explicitl…
You're describing Qubes, which is great but I found it tedious to use as a daily driver.
Yes, qubes is harder, but it's also very niche, barely supported, and difficult to use.
There's really a lot of middle ground "any application can do whatever on your system as the user running it" and "any application runs in a separate OS with no rights and just 120 lines of hardened hypervisor code in common.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#96I think to an extent Microsoft is the guilty party here. For may cracks Windows Defender will trip saying "Win32/Keygen" even if there's no actual malware https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo... This trains people that do a lot of piracy to be used to turning off their antivirus to let something through, which is fine until it's not. It's like drugs, if we know a subset of the population will…
You also need to look at the bigger picture: Keygens are something you very much do not want anywhere in a corporate environment for obvious reasons. Being able to flag them on Windows machines is very valuable.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#97Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#98I don't know why anyone running one of these schemes to distribute malware would even enable the issues tab on github, let alone not delete every issue posted containing keywords like malware, trojan, virus, etc. with a script.
Are hidden until approved issues not supported on github? Is this caused by some limitation of creating these repos programmatically?
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#99Earlier quoted context omitted.
That's MSDN, and these "senior hobbyists" were given a badge by MS to look credible: "MVP" (most valuable professional). Cherry on top: you used to pay to have an MSDN membership and access this wonderful community. To be fair though, the early MSDN was really good, and in a distant past MVP was a real achievement (say early 2000s). Now it's a weird mix real issues and "my printer blinks red, how to fix?" I don't thi…
I wasn't even talking about people who paid for a cert, just people signing up to try and help. They are generally more annoying then helpful to people who can do anything more than install and uninstall programs. Without a doubt every search result I found on that forum from someone having a similar issue never resulted in a useful lead.
This was subsumed into answers.microsoft.com and it's turned into a few of those original "good with computers" retirees spending all day answering from within their own knowledge, now overwhelmed by countless individuals with names or flavors of English suggesting emerging economic zones "answering" everything with copy paste non-responsive responses.
If the asker persists through enough (5 - 8?) turns until the copy paster grasps that they don't understand the problem, then it turns into (paraphrasing) "no clue, I'm not real but was just trying to help, try Microsoft support".
This is so consistent, I wonder what is driving it. They seem to try to look official, but eventually say they are not actually Microsoft, and punt. What is this accomplishing? Why are they spending all this time? Is it some kind of training exercise or on-ramp to support jobs? Inquiring minds want to know!