I don't have a LinkedIn profile. ~50% of jobs listed on who is hiring every month require a LinkedIn profile to submit a job application. In order to find a job, one must bend the knee to LinkedIn first and subjugate themselves to the political (all sides) propaganda on the feed.
A backdoor in a LinkedIn job offer
301–310 of 331 posts
Re: A backdoor in a LinkedIn job offer
#302Earlier quoted context omitted.
And using DNS to prove that a domain is actually owned by this organization
Email domains of employee addresses aren't necessarily owned by the company. For example: - a startup with legacy personal email addresses from one or two universities - a spin-off sharing the email domain (and the whole IT infrastructure) of the parent company - cheapskates using six approved free email services For security purposes, on the other hand, the important part is proving that the LinkedIn account is owne…
Re: A backdoor in a LinkedIn job offer
#303Job candidates keep facing a lot of hurdles, including scams, Trojan horses like the one presented here, ghosting, wasting candidates' time, nepotism, etc. As a candidate you can easily spend more than 8 hours a day looking for opportunities, switching stacks, studying, doing take-home projects, etc, for absolutely nothing. Life is precious and shouldn't be burned like that!
Re: A backdoor in a LinkedIn job offer
#304Re: A backdoor in a LinkedIn job offer
#305> a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.” > ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine. > npm runs prepare automatically after npm install, so just…
never got serious ones before, the occasional, useless headhunters who are clearly not based in the same country, but these were different. They were big companies in Canada, ones I'd definitely heard of and even applied to in the past. They were direct, were recruiters for those companies themselves, and were plugged in, able to answer questions, and engaging.
they constantly sent job ads, but only via .pdf files. I even pushed back on one and said I don't open random pdfs, send me a link and they declined. Same recruiter hit me up for a similar role a month later, also via pdf.
Multiple other members of the IT org, esp. the security and infra teams, also reported similar, aggressive recruitment efforts with pdfs. This was around 2020-2021.
Re: A backdoor in a LinkedIn job offer
#306Earlier quoted context omitted.
Fuck 'em? That's not a insurmountable problem in the slightest. Google or Apple could probably solve this problem themselves by simply not ringing the phone for any call that doesn't meet ID verification.
The behavior of the phone network is set by government regulation. If you refuse to service allowable calls, you are heavily fined or kicked off the network. The government has to update the rules.
Re: A backdoor in a LinkedIn job offer
#307Been through this 3 times in the last 6 months. They're getting better. Very credible LI profiles, code looks OK if you only take a glance... The bell start ringing when they insist you to run locally their sh*t
The big red flag should be giving github access before signing any contracts.
But also online, once or twice I received these Leetcode style sites to register and do a few tests before we meet, which was weird for me and I just ignored it.
One of them later asked "Why I didn't have time to do it yet" and I told them I first meet people and check the fit before I do tests, like who the hell does that differently?
Hope it hasn't become a way more common thing.
Re: A backdoor in a LinkedIn job offer
#308Earlier quoted context omitted.
thanks for following down the rabbit hole, let us know what you find! also... why qwen?
> why qwen I have it running locally, and i don't want to add credentials to the vm with the malware. According to qwen: It's cross platform It has a bunch of persistence mechanisms. It downloads another pack from pub-1fe39d600a4447ba895ef1c848d32e7e.r2.dev, Verified I got the secondary payload This pack looks like a python 3.10 environment along with an executable called cupsd. And downloads another js script from h…
Also what is your go to OS?
Hm, when I think of it an old Raspberry Pi could be my go to for this, but always physically.
Re: A backdoor in a LinkedIn job offer
#309Earlier quoted context omitted.
My brother had been unemployed for a long time due to illness, and finally got a "job offer" on LinkedIn that seemed legit to him. They asked for him to write a check to make a deposit for his company laptop (which seems pretty insane on the face of it), but he was desperate and really happy to finally have a job offer. People who've been unemployed for a long time are often desperate enough to overlook serious red f…
A long time ago, I worked for an ISP that sent out the famous "we'll never ask for your passwords" email. Then, about 3 weeks in, they sent out emails asking people for their passwords. If you told me that this was a happy ending, he sent in a check and they sent a laptop and after 2 paychecks released his deposit, I wouldn't be shocked. Some companies are run by idiots. I even know that most companies could probably…
In the end it fucks me because when I tell my dad "Oh they never ask for you password, so don't say it to nobody no matter what."
He "But when they asked us last year?!"
Re: A backdoor in a LinkedIn job offer
#310Earlier quoted context omitted.
Brazillian law, for instance, defines the crimes of passive and active corruption: The Penal Code, in Article 317, defines the crime of passive corruption as "soliciting or receiving, for oneself or for others, directly or indirectly, even if outside the function or before assuming it, an undue advantage, or accepting a promise of such an advantage." [0] Active corruption, committed by an outsider, who offers or prom…
That is literally just a translation difference for bribery, a common issue for Brazilian Portuguese vs English. [ https://www.jusbrasil.com.br/topicos/10598684/artigo-317-do-... ]. [ https://www.britannica.com/topic/bribery ]
Improper and usually unlawful conduct intended to secure a benefit for oneself or another.
It might as well describe any crime, similar to definition c from earlier. Even still, Britannica memtions gifts, which points to corruption being primarily connected to bribery: In societies with a culture of ritualized gift giving, the line between acceptable and unacceptable gifts is often hard to draw.
I suppose I agree with the lack of formal definition for corruption, but defining "corruption" as simply "evil" makes the word ontologically empty, but adding a corrupting element to it (bribe), makes it more defined.