So the attack goes: 1) compromise some site to serve arbitrary JS 2) have it serve simple JS that requests other JS that contains the real malicious payload. And the reason for this two-step architecture is to make it convenient to change the real payload. And the problem is where to host the real payload. The first idea was Cloudflare, but Cloudflare keeps taking that sort of thing down. So now they host it "on the…
The fake browser update scam gets a makeover
31–40 of 196 posts
Re: The fake browser update scam gets a makeover
#32> The company said all addresses associated with the spread of the malware have been blacklisted. I thought web3 was supposed to be uncensored so we could serve and download all the malware we wanted?
Re: The fake browser update scam gets a makeover
#33> New research shows the attackers behind one such scheme have developed an ingenious way of keeping their malware from being taken down by security experts or law enforcement: By hosting the malicious files on a decentralized, anonymous cryptocurrency blockchain Finally a practical use for web3
Re: The fake browser update scam gets a makeover
#34Seriously considering running a JIT-less JavaScript free browser should be the standard for surfing these days, and only whitelisting sites you trust (like your online banking site or Amazon for example). Disabling JS wipes out entire classes of attacks. I know developers assume the user has JS enabled and codes their site to that end, but a small minority disables JS to get rid of various annoyances and for accessib…
Re: The fake browser update scam gets a makeover
#35But the real story is "WordPress websites still hacked in masses".
WordPress, somehow, cannot manage to turn themselves into a secure and tough system. It remains a prime target, it's installations get hacked by the thousands and it's causing real harm at that.
(Yeah, yeah, I know the users, admins, plugins, themes and hosted are to blame. And I know it's possible to truly harden a WP- I've built a WP hosting company that did exactly this. But it's saddening how poor the wider community handles it's security)
Re: The fake browser update scam gets a makeover
#36Seriously considering running a JIT-less JavaScript free browser should be the standard for surfing these days, and only whitelisting sites you trust (like your online banking site or Amazon for example). Disabling JS wipes out entire classes of attacks. I know developers assume the user has JS enabled and codes their site to that end, but a small minority disables JS to get rid of various annoyances and for accessib…
This isn't that complicated. Like everything else in life it's a matter of trust and awareness, not really that technical. I'll never understand why the default stance on HN is always javascript bad .
Re: The fake browser update scam gets a makeover
#37Still a very good practice today.
Re: The fake browser update scam gets a makeover
#38How does this work? Can a single entity really just blacklist certain addresses? How is this decentralized?
Re: The fake browser update scam gets a makeover
#39They could also use ipfs as there are many http proxies for it including cloudflare. All proxies would individually need to blacklist the address. In general it is going to be impossible to block content. We need to charge for bytes or something like that. But that produces other problems which could be worse
I read that 25 year ago as a suggested solution to email spam, and it's many times less feasible today than it was back then.
Re: The fake browser update scam gets a makeover
#40I'm just happy to finally see a practical use case for Blockchain technology.
It’s been great for gambling, cybercrime, and enabling the drug trade practically since its inception.
https://arstechnica.com/information-technology/2021/06/moner...