Live data from Hacker News

Github scam investigation: Thousands of “mods” and “cracks” stealing data

timsh.org

151–160 of 165 posts

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#151
post #33

I think the core of problem here is that applications are not isolated on the OS level. If I download and install a mod for minecraft, it should never have access to anything on my computer, except for the minecraft game files itself. If I open a spreadsheet in Excel, the excel process should have access only to that file and it's own config files. Something similar to how android works, were the app has to explicitl…

>If I open a spreadsheet in Excel, the excel process should have access only to that file and it's own config files.

So ya, you've just broken a thousand enterprise application and integrations.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#152

Earlier quoted context omitted.

I wasn't even talking about people who paid for a cert, just people signing up to try and help. They are generally more annoying then helpful to people who can do anything more than install and uninstall programs. Without a doubt every search result I found on that forum from someone having a similar issue never resulted in a useful lead.

> Without a doubt every search result I found on that forum from someone having a similar issue never resulted in a useful lead. This was subsumed into answers.microsoft.com and it's turned into a few of those original "good with computers" retirees spending all day answering from within their own knowledge, now overwhelmed by countless individuals with names or flavors of English suggesting emerging economic zones "…

> This is so consistent, I wonder what is driving it.

Microsoft has a cert called "Most Valuable Professional" that gives out a ton of free stuff (free MSDN subscription, free admission to a conference that gives away hardware, etc). It also probably looks good on your resume to hiring managers who don't know any better. Renewing the cert involves doing "community work", and the easiest way to do community work is to post a lot on Microsoft's forums. Microsoft doesn't care about the quality of the posts, or whether they solve the problem, solely about the number. This is why whenever you look up a Windows issue and go to Microsoft's forums, you always see people posting the same copy-pasted "Hi, I'm a Microsoft community expert who has been providing independent Windows advice for the past 10 years. blah blah blah Have you tried running sfc /scannow?" response to every single problem.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#153
post #90

Earlier quoted context omitted.

Amazon has an ask a question feature and it will email a lot of people who previously bought the product, not sure how it works. Anyway, I saw tons of responses from elderly people with nonsense answers like “I don’t know the answers please don’t email me”. People felt compelled to respond, now I see why Nigerian prince scams are so successful.

Also see Yahoo Answers, who got the gamification completely wrong (Stack Overflow later got it right). Users would answer "I don't know" to every question they saw, just to get a point for answering.

> Users would answer "I don't know" to every question they saw, just to get a point for answering.

lol, I remember that but I forgot all about that until I saw your comment. Man that late 90s early 2000s internet was something else.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#154

Earlier quoted context omitted.

This isn't really related to the parent comment, but I can't help myself from asking. I've been getting emails that look like they're from my own email address. They usually threaten to share my browser history unless I pay money. Has anyone else seen these kinds of scam emails? How can I stop them? I use two-factor authentication, so my account should be safe, but these emails still worry me. Any tips would be great…

If you are in control of the domain of your email address, enable SPF and DKIM for that domain, together with strict policies that mail servers should reject spoofed mails claiming to come from that domain. If your own mail server supports validating SPF and DKIM, you would no longer receive such forged mails, nor anyone else behind a mail server supporting SPF and DKIM. If you aren't in control... just ignore it lik…

The thing that enforces the existence of either SPF or DKIM is called DMARC, setting that to "reject" or "quarantine" is the most critical step for preventing forgeries like that.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#155

Earlier quoted context omitted.

> going so far as to ban the accounts The responsible thing would be also to release all related data, icluding personal information (IP adresses, emails, list of contacts, chat logs) to investigation (police, etc)

I’m sure they report serious crimes and at least retain records for questionable activity. I don’t get visibility into internal Discord operations, though. We just see that the perpetrators lost both their Discord server and their accounts disappeared from other Discords they were in. They angrily returned later with new usernames.

That would be a tremendous amount of work, at best they might be forwarding it to some CERT. But I doubt even that. Shutting down the accounts is probably the best they can do.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#156

> Less then 10% of them have open issues with complaints - others look just fine. I don't know why anyone running one of these schemes to distribute malware would even enable the issues tab on github, let alone not delete every issue posted containing keywords like malware, trojan, virus, etc. with a script. Are hidden until approved issues not supported on github? Is this caused by some limitation of creating these…

These people are following a guide. They don’t know the details of GitHub. They don’t care about people who know enough to check the issues. They’re fishing for the people who blindly download and run things, not who look under the hood.

Good point. I hadn't considered it might be intentional, like spam emails using poor grammar and appearing more scammy to select for easier marks.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#157
post #22

"Or why you should never download game mods"... Like everything else, you shouldn't blindly search on github - or any other download site. Only download from links referred from the official site if there's any, or the game's forum, or any other trustable and human reviewed source.

Best part is people downloading them and turning EVERYTHING off - running it as admin, antivirus off, everything. How can you trust something random off the internet that much?

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#158
post #15
post #11

I think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam/malware comments and links, but even internally their teams can't reach anyone to get it fixed. Example https://feedback.azure.com/d365community/idea/9d0b22d8-c025-...

As another data point: MSFT have some sort of open mail server/service called onmicrosoft.com which (in my experience anyway) is only being used to send out fraudulent paypal messages. Because it lets the spammer set the From to service@paypal.com and also contains valid DKIM etc, it sails past spam filtering. There are so many complaints about this on (real) paypal.com forums, but Microsoft are apparently unable to…

Honestly i cant believe how much spam at Google gets through Gmail but they blocked my small startups emails from being delivered.

Funny enough if I stayed at Google another year I would have been lucky enough to fix it myself and make an actually decent spam blocker.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#160
post #57
post #15

Earlier quoted context omitted.

As another data point: MSFT have some sort of open mail server/service called onmicrosoft.com which (in my experience anyway) is only being used to send out fraudulent paypal messages. Because it lets the spammer set the From to service@paypal.com and also contains valid DKIM etc, it sails past spam filtering. There are so many complaints about this on (real) paypal.com forums, but Microsoft are apparently unable to…

I think I read somewhere that scammers set up an email distribution list / alias / forwarding from one something.onmicrosoft.com account to dozens of victims, and then they trigger a (real!) paypal email with that one something.onmicrosoft.com address as the recipient. So the email has a valid DKIM signature from paypal, then microsoft forwards that email to all the victims, which will still pass DKIM while amplifyin…

Messages pass DMARC because they originate at paypal servers (and have valid DKIM) but O365 abused to spread these messages and MS doing little to stop abuse.
Post reply on HN