Live data from Hacker News

How I attacked a fellow student

shaanan.cohney.info

41–50 of 50 posts

Re: How I attacked a fellow student

#41
post #23

Earlier quoted context omitted.

It's actually "bear with me". I'm not sure what "bare with me" would mean.

> I'm not sure what "bare with me" would mean. "Come to a nudist colony with me."

Back when I was a lowly customer services rep for an online store I replied to a customer email with that spelling. She did not see the funny side..!

Re: How I attacked a fellow student

#42

Interesting. If the author is still around, I have a question - would the whois data have given you away, or was this faked/spoofed in some way?

You can quite cheaply (for around $3 depending on the registrar) opt into Whois privacy protection.

For a prestigious company to use a Whois hiding shell company service would be suspicious, though.

Re: How I attacked a fellow student

#43
post #37

Well played... Missing to redact X.com's phone number allows "social engineering" of the company name, though.

It's an interesting time now. It used to frustrate me how I couldn't find an address with just the phone number - despite having a white pages that contained the info. I know this was buy design, for privacy. Now if you search for a number, your bound to get a hit for it, and can work out who it belongs to. I'm sure this will fail me one day, but it hasn't yet.

Germany's online telephone book does reverse look-up. (People can opt out, but you know how it is..) Is that really so uncommon?

Checking some more countries.. the UK doesn't seem to have it, France does. Oh, there's a page for the US: http://www.whitepages.com/reverse_phone

Today reverse look-up is by design, it seems. The limitation before was probably printing paper and not just a design decision, I'd guess. I'm not sure whether I like the new situation, but then none of my friends actually has a landline.

Re: How I attacked a fellow student

#44

> With this level of trust it would be feasible to gain access to information protecting online accounts, a very scary thought. Does he mean 'feasible to gain access to login information for online accounts'? I have read the page, and i'm not seeing it. Yes, according to the page they had access to some degree of personal information beyond the more publicly accessible. But that isn't the same as having access to the…

"indormation protecting online accounts" makes me think of password reset questions.

Re: How I attacked a fellow student

#45

The best attacks are always the ones where the victim is truly surprised at how far you were willing to go to pull it off. So are the best magic tricks.

There's a great quote by Teller on that:

"You will be fooled by a trick if it involves more time, money and practice than you (or any other sane onlooker) would be willing to invest. My partner, Penn, and I once produced 500 live cockroaches from a top hat on the desk of talk-show host David Letterman. To prepare this took weeks. We hired an entomologist who provided slow-moving, camera-friendly cockroaches (the kind from under your stove don’t hang around for close-ups) and taught us to pick the bugs up without screaming like preadolescent girls. Then we built a secret compartment out of foam-core (one of the few materials cockroaches can’t cling to) and worked out a devious routine for sneaking the compartment into the hat. More trouble than the trick was worth? To you, probably. But not to magicians."

From: http://www.smithsonianmag.com/arts-culture/Teller-Reveals-Hi...

Re: How I attacked a fellow student

#47

Earlier quoted context omitted.

You can quite cheaply (for around $3 depending on the registrar) opt into Whois privacy protection.

For a prestigious company to use a Whois hiding shell company service would be suspicious, though.

But if they are a security-oriented company, maybe not so much. Hiding potential attack vectors (contact info of technical contact) can prevent or delay spear phishing attempts. Now, if Xrecruiting.com and X.com don't match, then that would be a red flag.

Re: How I attacked a fellow student

#48

Earlier quoted context omitted.

For a prestigious company to use a Whois hiding shell company service would be suspicious, though.

But if they are a security-oriented company, maybe not so much. Hiding potential attack vectors (contact info of technical contact) can prevent or delay spear phishing attempts. Now, if Xrecruiting.com and X.com don't match, then that would be a red flag.

My point (in agreement with TazeTSchnitzel) was essentially this - if X was a large enough company, I would expect them not to hide their registration details, especially, I would argue, in the case of a security company, so that potential clients and employees can be certain of the veracity the communications they receive. If I were to receive a communication from an email adress not associated with the main domain of the company, I would be instantly suspicious if the whois data was obscured or concealed.

Re: How I attacked a fellow student

#49

Interesting. If the author is still around, I have a question - would the whois data have given you away, or was this faked/spoofed in some way?

It would've given me away. I wasn't super concerned that it would be looked up though. If this was a real attack and not just a demo for class, it would've been a better idea to fake the whois info.

Re: How I attacked a fellow student

#50

Earlier quoted context omitted.

But if they are a security-oriented company, maybe not so much. Hiding potential attack vectors (contact info of technical contact) can prevent or delay spear phishing attempts. Now, if Xrecruiting.com and X.com don't match, then that would be a red flag.

My point (in agreement with TazeTSchnitzel) was essentially this - if X was a large enough company, I would expect them not to hide their registration details, especially, I would argue, in the case of a security company, so that potential clients and employees can be certain of the veracity the communications they receive. If I were to receive a communication from an email adress not associated with the main domain…

Indeed, as would I. But what makes a successful social engineering attack (or scam, in general) is giving people what they want before they have an opportunity to ask questions. While this exact attack wouldn't work on me now, it might have when I was looking to graduate from university. My desire for an industry job (and a prestigious one at that) might have clouded my typical judgment. So, hiding whois information can be immediately justified by "well, they are a security company", with any doubts expelled. Grifters and illusionists work in much the same way; the plot is full of holes, but over and over people see what they want to see.
Post reply on HN