So the attack goes: 1) compromise some site to serve arbitrary JS 2) have it serve simple JS that requests other JS that contains the real malicious payload. And the reason for this two-step architecture is to make it convenient to change the real payload. And the problem is where to host the real payload. The first idea was Cloudflare, but Cloudflare keeps taking that sort of thing down. So now they host it "on the…
According to the following blog post, it uses a web API exposed by the Binance Smart Chain (BSC) platform: https://labs.guard.io/etherhiding-hiding-web2-malicious-code... This diagram show the full flow of the attack: https://miro.medium.com/v2/resize:fit:1400/format:webp/1*by4... Because reads from blockchain are "free" (meaning, there is no cryptocurrency payment required to read data from the smart contracts on BS…
The fake browser update scam gets a makeover
131–140 of 196 posts
Re: The fake browser update scam gets a makeover
#132Earlier quoted context omitted.
According to the following blog post, it uses a web API exposed by the Binance Smart Chain (BSC) platform: https://labs.guard.io/etherhiding-hiding-web2-malicious-code... This diagram show the full flow of the attack: https://miro.medium.com/v2/resize:fit:1400/format:webp/1*by4... Because reads from blockchain are "free" (meaning, there is no cryptocurrency payment required to read data from the smart contracts on BS…
Why is this considered abuse? Blockchains are for storing data, and these people are storing data on it.
Re: The fake browser update scam gets a makeover
#133Re: The fake browser update scam gets a makeover
#134So the attack goes: 1) compromise some site to serve arbitrary JS 2) have it serve simple JS that requests other JS that contains the real malicious payload. And the reason for this two-step architecture is to make it convenient to change the real payload. And the problem is where to host the real payload. The first idea was Cloudflare, but Cloudflare keeps taking that sort of thing down. So now they host it "on the…
Re: The fake browser update scam gets a makeover
#135Earlier quoted context omitted.
According to the following blog post, it uses a web API exposed by the Binance Smart Chain (BSC) platform: https://labs.guard.io/etherhiding-hiding-web2-malicious-code... This diagram show the full flow of the attack: https://miro.medium.com/v2/resize:fit:1400/format:webp/1*by4... Because reads from blockchain are "free" (meaning, there is no cryptocurrency payment required to read data from the smart contracts on BS…
lol > In response to questions from KrebsOnSecurity, the BNB Smart Chain (BSC) said its team is aware of the malware abusing its blockchain, and is actively addressing the issue. The company said all addresses associated with the spread of the malware have been blacklisted, and that its technicians had developed a model to detect future smart contracts that use similar methods to host malicious scripts. Earlier in th…
even binance operated nodes
the only thing Binance did was do the exact same thing that Cloudflare did, both on their HTTP routes. Binance just had one for convenience and to attract use of their blockchain, which … worked?
its actually lazy and amateurish that the hackers are using HTTP to access this code on the blockchain, they dont have to
Re: The fake browser update scam gets a makeover
#136Earlier quoted context omitted.
seems like "blockchain" has nothing to do with it... they could just host the file on a server they do control. "Blockchains" aren't magic.
It's not magic but it is a radically different pricing model: pay once, host forever. I see it as a massive bet on storage prices continuing to decrease.
many devs will always post their applications on blockchains, and simply do system design conducive to that environment, because web 2.0 cloud models do not compete in pricing especially if you have a burst of activity
many devs bring their whole audience over, and the audience is willing to pay to update the state of the application with no overhead cost to the dev, which is also impossible to implement in web 2.0 cloud offerings, aside from just searching and hoping for free tiers
who cares if none of those applications match your use case, just call it the entertainment sector then and you still have value and utility to someone, that self perpetuates
Re: The fake browser update scam gets a makeover
#137The quality of full screen takeover pages seems to have dramatically risen recently. My family members, who don’t know the Escape key exists, accidentally click one from a banner ad every week now taking them to a page like examplefoobar38561.cloudfront.net and the use of elements that imitate browser or OS chrome (generally imitating Windows Defender or similar) has reached near perfection. All browsers should have…
> All browsers should have a setting to permanently block full screen mode for all sites (not “ask”). Never going to happen, because that's breaking YouTube.
Re: The fake browser update scam gets a makeover
#138Re: The fake browser update scam gets a makeover
#139Earlier quoted context omitted.
The suffocating irony of this forum being called "Hacker News" when it is filled with comments like this never fails to amaze me. A truly unimaginative bunch.
Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?
Take your favorite payment provider (PayPal, Stripe, whichever bank provides your Visa/MasterCard, etc.), and look at their terms of service. Enumerate all the prohibited usages. From that list, delete illegal activities, of course.
The remaining items on the list are your practical examples of use cases. It's roughly the set of things that are legal, but that big corporations have decided you can't do because they're morally questionable or financially risky.
Stripe has an excellent list of examples (https://stripe.com/legal/restricted-businesses). Here is a selection:
* Pornography and other mature audience content (including literature, imagery and other media) depicting nudity or explicit sexual acts
* Online dating services
* Bankruptcy attorneys and bail bonds
* Sports forecasting or odds making with a monetary or material prize
* Charity sweepstakes and raffles for the explicit purpose of fundraising
* Unauthorized sale of brand name or designer products or services
And so on. All these are legal, but in a cashless society without decentralized currency, they might as well be illegal because no centralized payment processor will allow them.
But hey, Bitcoin can also be used for CSAM, unlike VPNs, Tor, or cash, which is why the HN cognoscenti condemns it.
Re: The fake browser update scam gets a makeover
#140Earlier quoted context omitted.
Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?
Preserving privacy, reliable transactions with no, i repeat, no bank or govmnt involvement, no kyc. No/low fees (on some currencies), public immutable databases...