Hackers ship their exploits directly to their target’s mailroom
121–130 of 172 posts
Re: Hackers ship their exploits directly to their target’s mailroom
#122Earlier quoted context omitted.
One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…
I once stayed late and noticed a cleaner was wearing a polo from the company I used to work for. I asked him about it and it turned out he was an engineer and was filling in for his girlfriend who owned the cleaning business. Holy red flag! I made some noise and that cleaning company was let go.
Re: Hackers ship their exploits directly to their target’s mailroom
#123Earlier quoted context omitted.
I once stayed late and noticed a cleaner was wearing a polo from the company I used to work for. I asked him about it and it turned out he was an engineer and was filling in for his girlfriend who owned the cleaning business. Holy red flag! I made some noise and that cleaning company was let go.
I'm not sure I see why the cleaning company was the problem.
He wasn't just some guy.
Re: Hackers ship their exploits directly to their target’s mailroom
#124Earlier quoted context omitted.
Only the main question remains: why do you need this if you could simply crack your neighbour's wifi by using a high-gain antenna hidden behind the walls of your own flat?
This comment reminds me of the initial response to Dropbox [1]. Sure, you or I, a very technical group, could set this up manually. But I was suggesting you manufacture, or part together a very simple box. The idea is this would be easy for non-technical people to get their wifi. Basically, plug in this box and in 30 days, you will have your neighbor's wifi password. [1]: https://news.ycombinator.com/item?id=8863
What I am asking is: how is this device better than another (used-friendly, packaged) device, that can work from your own flat? Moreover, selling that device with a high-gain antenna isn't any more against user-friendliness that selling a few boards you're supposed to hide yourself.
Sending a device to your neighbour is essentially a liability. A liability that, compared to simply listening to the traffic of your neighbour - can easily give the enforcement agencies enough material to lock you up.
The truth is that hiding the same device inside something else should be done by the user, because the moment you start putting those into a specific model of a plush bear, the picture of that plush bear will immediately appear in security advisories.
Re: Hackers ship their exploits directly to their target’s mailroom
#125Earlier quoted context omitted.
given the cheapness and compactness of modern electronics any furniture can carry a factory (or during shipping) installed chip these days, even without getting into smart/cloud connected office tables and chairs territory. One can hope at least NSA X-rays their furniture :)
I very much doubt you could discover anything with X-rays. You can place whole device inside a screw or the circuit can be very thin with little to no metal etc. I would assume it's becoming a a software war. You monitor all frequencies with SDR and try to shield as much as possible while on the offending side you try to push information on different frequencies and making it look a like like stuff that's already in…
It has been said that covert agencies have monitored conversations through windows by measuring the acoustic vibrations with a laser. So maybe that will work, but I have no idea how well that works with higher frequencies outside of human perception.
Re: Hackers ship their exploits directly to their target’s mailroom
#126Why an attacker should spend 100$ , sending hardware to the target that could be potentially tracked following the path between the resellers, could transport evidences like fingerprints or DNA, using a telephone connection that could also be tracked when the same thing could be done with a good radio equipment and more discretion ? Anyway, I am the kind of guy that inspects the ATM praying to find out a skimmer to d…
Also, its easy to get a FedEx/UPS/DHL uniform and deliver a package yourself.
Re: Hackers ship their exploits directly to their target’s mailroom
#127Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…
Re: Hackers ship their exploits directly to their target’s mailroom
#128Earlier quoted context omitted.
I once stayed late and noticed a cleaner was wearing a polo from the company I used to work for. I asked him about it and it turned out he was an engineer and was filling in for his girlfriend who owned the cleaning business. Holy red flag! I made some noise and that cleaning company was let go.
I'm not sure I see why the cleaning company was the problem.
Re: Hackers ship their exploits directly to their target’s mailroom
#129Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…
I'm always amaze at how many computer screens/keyboards are visible from windows. It would be so easy to plant a webcam with some good optics on an opposite building and just get the passwords of the victim quite easily. you could have easily a few dozens of victims on a single company with a single camera.
Re: Hackers ship their exploits directly to their target’s mailroom
#130Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…
One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…
I still believe it was dangerous to use gmail for the company emails when Google was one of our competitors in our niche.