Live data from Hacker News

Hackers ship their exploits directly to their target’s mailroom

techcrunch.com

31–40 of 172 posts

Re: Hackers ship their exploits directly to their target’s mailroom

#32
post #27

Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…

How would you be able to pull out any information out of an audio recording of keyboard typing? Wouldn't the training set differ between keyboards too? Sounds interesting it it worked, do you have any sources?

You get a week's worth of typing; you cluster the sounds; then based on statistical frequency analysis you decode which cluster maps to the spacebar and which to the letter 'x'; then you can transcribe the whole typing history and decide which of all that is a password.

Re: Hackers ship their exploits directly to their target’s mailroom

#33

This could be really fun for people who live in apartment complexes. Break your neighbor's wifi by using this little, no-fuss box. You could probably make a killing selling these for $100 - 200 on Etsy or something.

Only the main question remains: why do you need this if you could simply crack your neighbour's wifi by using a high-gain antenna hidden behind the walls of your own flat?

Re: Hackers ship their exploits directly to their target’s mailroom

#34
post #2

If your network security relies on promixity for ultimate security, you've done something very wrong.

Yep. You can do the same thing sitting outside on the street with a high gain antenna. Or one of the many rarely updated, vulnerability-ridden Android phones that are inside the building in people pockets.

Re: Hackers ship their exploits directly to their target’s mailroom

#35
post #6

That seems like a lot of hassle and a pretty big federal crime for only being able to attack Wi-Fi networks. Why not just park your car outside and use a laptop?

How long can you sit outside a company running Kali Linux and a high gain antenna array before you attract attention? If you ship someone on the DevOps team a WiFi-connected plush toy that listens for webhooks from your CI/CD platform to make happy/sad noises when the build passes/fails -- AND THEY PLUG IT IN AND LEAVE IT ON -- then the ability to have passive access to the network for a long period of time will be l…

But this device won't work for more than a few days anyway.

Re: Hackers ship their exploits directly to their target’s mailroom

#36

Seems like doing this with a rooted phone would be even sneakier. You've got everything you need built in: battery, modem, etc. When it eventually does get opened, the mailroom person is going to think "oh someone ordered a phone" instead of "holy shit, this bunch of wires and circuit boards is maybe a bomb and definitely something I should tell the police about".

IDK. If they put it in a stuffed animal like the pic in the article, how many would rip it open to see what's inside?

Re: Hackers ship their exploits directly to their target’s mailroom

#37
post #27

Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…

How would you be able to pull out any information out of an audio recording of keyboard typing? Wouldn't the training set differ between keyboards too? Sounds interesting it it worked, do you have any sources?

Here's one paper:

https://people.eecs.berkeley.edu/~tygar/papers/Keyboard_Acou...

Re: Hackers ship their exploits directly to their target’s mailroom

#38
post #27

Earlier quoted context omitted.

How would you be able to pull out any information out of an audio recording of keyboard typing? Wouldn't the training set differ between keyboards too? Sounds interesting it it worked, do you have any sources?

You get a week's worth of typing; you cluster the sounds; then based on statistical frequency analysis you decode which cluster maps to the spacebar and which to the letter 'x'; then you can transcribe the whole typing history and decide which of all that is a password.

Great plan, but we have to test it. Can you upload a sample dataset of you typing for 1 week so we can try this approach?

Re: Hackers ship their exploits directly to their target’s mailroom

#40

Earlier quoted context omitted.

You get a week's worth of typing; you cluster the sounds; then based on statistical frequency analysis you decode which cluster maps to the spacebar and which to the letter 'x'; then you can transcribe the whole typing history and decide which of all that is a password.

Great plan, but we have to test it. Can you upload a sample dataset of you typing for 1 week so we can try this approach?

I have their dataset. Email me for details.
Post reply on HN