Live data from Hacker News

Hackers ship their exploits directly to their target’s mailroom

techcrunch.com

161–170 of 172 posts

Re: Hackers ship their exploits directly to their target’s mailroom

#161
post #99

Earlier quoted context omitted.

One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…

A small company I once worked for employed a new firm of cleaners. Very good and conscientious for several months, right up to the night they loaded all the computer gear they could find on the premises into their van and disappeared. (After, of course, doing the cleaning and making sure they locked up afterwards)

but did they vacuum the now empty space?

Re: Hackers ship their exploits directly to their target’s mailroom

#162
post #157
post #129

Earlier quoted context omitted.

I notice these things too, but at the end of the day the sad news is nothing so exotic is necessary. There are far easier ways to get what you need from a modern office with typical security hygiene.

> There are far easier ways to get what you need from a modern office with typical security hygiene. Far easier than looking through a window? I'm curious to know! I've seen banks where it would be possible! I expect most of their software to be internal and accessed through a VPN when outside but still.

some of it is that the security is based around already being internal to the network.

you can know my password but unless you can get one of our machines, on our wired network (wireless works but not for business critical) you can't get in.

and then every subsystem has its own password etc.

Re: Hackers ship their exploits directly to their target’s mailroom

#163
post #118

Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…

I'm always amaze at how many computer screens/keyboards are visible from windows. It would be so easy to plant a webcam with some good optics on an opposite building and just get the passwords of the victim quite easily. you could have easily a few dozens of victims on a single company with a single camera.

Our company has extremely deeply tinted and reflective exterior windows that even at night (outside) with lights inside, you can barely see in if your face is 1" away from the glass.

Re: Hackers ship their exploits directly to their target’s mailroom

#164
post #50

Earlier quoted context omitted.

Sure -- if you define the heat death of the universe as "how fast".

You can't guarantee that, and keep reasonable performance, if humans are generating the PSK

I agree, but you can certainly build a system where humans don't generate the key.

Re: Hackers ship their exploits directly to their target’s mailroom

#165
post #118

Earlier quoted context omitted.

I'm always amaze at how many computer screens/keyboards are visible from windows. It would be so easy to plant a webcam with some good optics on an opposite building and just get the passwords of the victim quite easily. you could have easily a few dozens of victims on a single company with a single camera.

Our company has extremely deeply tinted and reflective exterior windows that even at night (outside) with lights inside, you can barely see in if your face is 1" away from the glass.

That seems like a pretty good way to handle this vulnerability!

I was thinking about how hard managing this risk was and except removing all windows (which I hope everyone will agree is quite bad), it's hard to protect ourself against this issue from all angle and that's even knowing the issue and trying to handle it (which most people won't even do).

Re: Hackers ship their exploits directly to their target’s mailroom

#166
post #139
post #84

Earlier quoted context omitted.

given the cheapness and compactness of modern electronics any furniture can carry a factory (or during shipping) installed chip these days, even without getting into smart/cloud connected office tables and chairs territory. One can hope at least NSA X-rays their furniture :)

Even better if you integrate into something like a motorized standing desk, they'll plug it in for you.

Does that USB drive stick trick still work?

Re: Hackers ship their exploits directly to their target’s mailroom

#167
post #130

Earlier quoted context omitted.

Yeah, I never understood that. At the first half sensitive job I had, the cleaning crew had access to all the computer rooms, including the server one. I had thought of trying to push my boss into using encryption for our emails but abandoned after realizing that. I still believe it was dangerous to use gmail for the company emails when Google was one of our competitors in our niche.

And I think your belief is justified. Look at how many niche products people built on AWS and Amazon caught wind of their success and rolled out a competitor!

But I think this is not as cut and clear with an enterprise gmail account. Who really competes with Google? Amazon on the other hand competes with every retailer out there.

Re: Hackers ship their exploits directly to their target’s mailroom

#168
post #139

Earlier quoted context omitted.

Even better if you integrate into something like a motorized standing desk, they'll plug it in for you.

Does that USB drive stick trick still work?

Yes, yes, it does

Re: Hackers ship their exploits directly to their target’s mailroom

#169
post #157
post #129

Earlier quoted context omitted.

I notice these things too, but at the end of the day the sad news is nothing so exotic is necessary. There are far easier ways to get what you need from a modern office with typical security hygiene.

> There are far easier ways to get what you need from a modern office with typical security hygiene. Far easier than looking through a window? I'm curious to know! I've seen banks where it would be possible! I expect most of their software to be internal and accessed through a VPN when outside but still.

Well you'd usually need to work to get access to a room to look through the window, so that's not a given :)

I think sending a parcel like in this article, or leaving a USB stick lying around is often an easier task. Even if you window-surf some credentials you most likely can't use them unless you're on the internal network already. At least at my place of work you'd need a VPN token to make any use of my details unless you have physical access to plug in a cable.

Re: Hackers ship their exploits directly to their target’s mailroom

#170
post #145
post #141

Earlier quoted context omitted.

Higher frequencies will get filtered out. They don't have the power to vibrate the glass unless it's very loud.

Cuban sounds as an [ultrasound intermodular distortion based] attack on electronics with humans seeming to be a side effect: https://www.google.com/amp/s/spectrum.ieee.org/semiconductor...

https://www.nytimes.com/2019/01/04/science/sonic-attack-cuba...
Post reply on HN