Live data from Hacker News

I was seven words away from being spear-phished

robertheaton.com

141–150 of 187 posts

Re: I was seven words away from being spear-phished

#141
post #50
post #45

Earlier quoted context omitted.

That’s likely true for the Nigerian prince scammers, but when they’ve got a browser zero day, they can successfully attack people that aren’t suckers.

True, but we don't know the next stage of their attack. Perhaps after compromising the target's machine the attackers would have to then engage in some social engineering.

Once you drop a trojan on someone's machine, why do you need social engineering?

Re: I was seven words away from being spear-phished

#142

The specifics of this - the request to judge a prize one is clearly unqualified for - are we as software engineers particularly vulnerable to? Most people would, I think, conclude "this is fake, because why would I be asked to do this?". But I often think that as software engineers we fancy ourselves to have more insight into other fields than we really do. Does this ring true to anyone else?

In general that's a hazard of any knowledge worker job. Aren't physicists kind of infamous for thinking they can weigh in on other scientific fields, as if physics trumps everything else?

In any case, I think the "judge an economics prize" angle wasn't really intended to be a "software engineers are vain", but rather "people involved with cryptocurrency are likely to consider themselves to be experts on economics and think that they know better than most" so that actually seems like a very well-targeted phishing attempt.

Re: I was seven words away from being spear-phished

#143

Earlier quoted context omitted.

I doubt it in this case. It sounds like they had a browser zero-day, and could potentially steal cryptocurrencies from people they were targeting. You don't particularly care how gullible someone is; if you get your zero-day to successfully work on them and steal all their Bitcoin, there's nothing they can do about it. I think the default assumption is the correct one here; the attacker(s) are a solo or small group o…

You may be overestimating the writing ability of native English speakers.

Agreed. The best example of this for me is nextdoor. The spelling and grammar for most of the posts are terrible and the posters are predominantly white and over 50.

Re: I was seven words away from being spear-phished

#144

This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn'…

Besides the possibility that the mistakes were made deliberately, like other comments said, I can totally see how these two mistakes slipped through.

> He was also lucky that I didn’t care that he’d missed a “the” in We need your assistance in evaluating several projects for Adam Smith Prize.

Slavic languages, like Russian, don't have articles. In my experience the proper use of definite and indefinite articles is the most typical error native Slavic language speakers make.

> Apparently I further didn’t care that he’d unnecessarily capitalized the word Organizers in Adam Smith Prize Organizers, or that he didn’t seem to understand that a paragraph can contain more than a single sentence.

German capitalizes all nouns and German and English have plenty of nouns that are close enough that it's hard not get confused. Add to that all the exceptions where you do capitalize words in English, this is a hard problem for Germans.

My armchair linguists bet is that the mail was written by a German with Slavic roots.

Re: I was seven words away from being spear-phished

#145

This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn'…

Dropping 'the' is a common error for Russians writing English. It's part of how the 2016 election meddling was blamed on the Russians.

Re: I was seven words away from being spear-phished

#146
That's interesting - there is indeed a grh37 at Cambridge but he's an undergraduate studying Chemistry at Selwyn. No idea about how that happened, but there's been a bunch of really poorly written Emotet/Heodo spam emails floating around the email system the past few years. I'd guess that he managed to get his account compromised while logged into Windows on a UCS computer (which would be a feat in itself, given how poorly written the first stage dropper is), his UCS account got compromised, and someone uploaded the malicious website to his public_html folder.

EDIT: Apparently they've blocked new user signups for DS-Web, but this is kinda pointless given that every new student is automatically given their very own live website until they graduate.

Re: I was seven words away from being spear-phished

#147
post #118

Funny that the browser that has been selling so much on privacy falls victim to such a vulnerability. In any case, if a site says "this site must be viewed in Firefox" that would be a huge red flag, and all the more reason for me to leave. There aren't really any features in Firefox that other browsers don't have.

>Funny that the browser that has been selling so much on privacy falls victim to such a vulnerability.

How so? Privacy is not inherently synonymous with security.

Re: I was seven words away from being spear-phished

#149
I thought myself fairly well informed about macOS, having run it since the 10.1 days, administering it over the years, etc. But TIL that the quarantine bit and gatekeeper which normally prevent unauthorized executables from running is trivially bypassed, as was the case in this attack.

My paranoia level has increased.

https://objective-see.com/blog/blog_0x43.html

https://speakerd.s3.amazonaws.com/presentations/9e724ea23343...

Yeesh.

Re: I was seven words away from being spear-phished

#150
There are valid points about being tricked here, but it's all kind of irrelevant in the presence of a javascript 0-day. You don't actually have to trick anyone to use one of those; just make an interesting post on tumblr and away the hacks go. Trying to never get hit with a 0-day is a pipe dream.
Post reply on HN