Live data from Hacker News

A backdoor in a LinkedIn job offer

roman.pt

211–220 of 331 posts

Re: A backdoor in a LinkedIn job offer

#212
post #206
post #196

Earlier quoted context omitted.

> LinkedIn offers no way for $company to disavow users who claim to work for $company - they will appear on the official company page as long as it's in their profile. I had the opposite problem: my company name was equivalent to the owner of an online casino. It took me a year to figure out that the enormous amount of spam I was getting about ‘guest post placement’, and people contacting me about deals was because L…

> I don’t know how do they even harvest emails from Linkedin. https://haveibeenpwned.com/Breach/LinkedIn

this is from 2016. at time they had ~400 million users,and the breach is 164 million, Now it's close to 1.5 B. People these days use aggregators like Apollo, signal hire, apify. There are 1000s of such tools.

Re: A backdoor in a LinkedIn job offer

#213
> I’ve heard of these attacks and read about them on HN

And, I am reading this on HN right now. What a coincidence!

I read a lot about social engineering and how the human being is considered the weakest layer in the security chain but this is the first time I've came across this pattern. Eye opening indeed.

Re: A backdoor in a LinkedIn job offer

#214

Earlier quoted context omitted.

Some posix like systems mount /home with noexec in fstab. Practically, most systems leave it off because many out-of-band user space script language package ecosystems stop working. =3 There are also adaptive application firewalls that are user friendly. https://github.com/evilsocket/opensnitch

noexec clearly isn't going to help if you run untrusted JavaScript...

Sometimes, but nodejs or npm won't work properly without the headless chromium VM, and would need bypassing local file-access security-sandbox restrictions most normal system Web-browsers enforce by default.

If root installs OS supported VM packages, than it would be pointless to complain the system runs as expected. As a sentient turnip, I probably wouldn't know for sure... =3

Re: A backdoor in a LinkedIn job offer

#215

Earlier quoted context omitted.

You mean @fooco.com? Or @foocousa.com? Or @fooco.xyz? @fooco.ai? @foocoltd.net? @foo.co.uk? How would LinkedIn validate that your email domain belongs to the company you claim to work for?

Presumably because the official company page is registered under it?

Not all companies use email addresses under the same domain as the "official company page" though.

Re: A backdoor in a LinkedIn job offer

#216
post #113

Earlier quoted context omitted.

Taking things down doesn't help much unless the platform has something in place to make it hard to recreate them. >they could do the hard job of combining leads and working with appropriate agencies to maybe find and prevent these things over time At least in the U.S., everyone will cry government overreach and no one will fund it. In other countries, they should probably just ban U.S. platforms unless they're reacha…

> just ban U.S. platforms Try that and see your champagne exports be tarriffed with 100% in no time.

china seems to be doing fine. what are you gonna do, tariff the country that makes all your stuff? 100% tariff on iphones and macbooks?

Re: A backdoor in a LinkedIn job offer

#217
post #8

So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.

The amount of crime in the world -that requires arguably "low skill" time to resolve- that just gets filed away because of low resources is insane. How are forces going to stand up high skill task forces for these kinds of things?

Re: A backdoor in a LinkedIn job offer

#218

Earlier quoted context omitted.

I'm bottom of the ladder but have seeing the option to do it for at least a year.

If it’s an option and not required, then that doesn’t solve it.

Any clue what’s there "Persona" program that they are trying to push hard "so you can have so much positive leads"?

Re: A backdoor in a LinkedIn job offer

#219
post #56
post #16

> a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.” > ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine. > npm runs prepare automatically after npm install, so just…

LinkedIn offers no way for $company to disavow users who claim to work for $company - they will appear on the official company page as long as it's in their profile. We've had fake recruiters that claim to work for us running basically the same scam. These are great fake profiles: LinkedIn Premium, tons of relevant posts, etc... but they don't work for us, and we get angry messages from people saying our recruiter tr…

> LinkedIn offers no way for $company to disavow users who claim to work for $company - they will appear on the official company page as long as it's in their profile.

It isn't at all a neat solution, but you could maintain a list of users on LinkedIn that are authorised to speak for your company, linked prominently on your profile with a warning that anyone else claiming to work for the company is likely a scammer but LinkedIn offers no way for you to stop them claiming to be part of your company.

If that became a common pattern it could highlight how much of a scammer paradise LI can be and maybe they'd be more likely to do something about that particular vector.

Re: A backdoor in a LinkedIn job offer

#220

Earlier quoted context omitted.

Unfortunately most evil cybercriminals know the "one weird trick" of "do your crimes in countries that don't care about the crimes"

I see several comments like this implying nothing can be done. But that is far from the truth. First, an agency that actually answered the phone could coordinate directly with LinkedIn and other tech companies to quickly take down these fake accounts and minimize harm to others. We all know how incredibly hard it is to contact a tech company. Second, an agency that answers the phone could help less technical people f…

Sounds like socializing the harms instead of requiring these companies to bear the burden themselves. Could still be a valid approach but I'm afraid it will make them take less responsibility, not more.
Post reply on HN