Live data from Hacker News

Did I just win?

twitter.com

41–50 of 140 posts

Re: Did I just win?

#42

It's not clever to hack something that you can socially engineer, and that should be hacking 101. Clever win.

Huh? Some of the most clever (and destructive) hacks involve an element of social engineering. Given that security implementations are designed to compensate for human social behaviors and instincts and limitations, social engineering is just as much a part of hacking as cryptography.

Re: Did I just win?

#44

But wait, how did it happen ?

He had him post the challenge to his website. The text of the challenge contains the string "BackdoorPoCTwitter". By including the challenge in his website, he included the string in a software project (the code for his website). This won the challenge for @Sc00bzT, who was the one who told him to make the change to his website.

Re: Did I just win?

#45
post #42

It's not clever to hack something that you can socially engineer, and that should be hacking 101. Clever win.

Huh? Some of the most clever (and destructive) hacks involve an element of social engineering. Given that security implementations are designed to compensate for human social behaviors and instincts and limitations, social engineering is just as much a part of hacking as cryptography.

I think you read his statement backwards :) He's advocating social engineering whenever possible.

Re: Did I just win?

#46
post #42

It's not clever to hack something that you can socially engineer, and that should be hacking 101. Clever win.

Huh? Some of the most clever (and destructive) hacks involve an element of social engineering. Given that security implementations are designed to compensate for human social behaviors and instincts and limitations, social engineering is just as much a part of hacking as cryptography.

op said the same

Re: Did I just win?

#47
Calling a website that happens to host static content in the same repo as its PHP source a "release of a software project" really seems like a stretch.

Re: Did I just win?

#49
post #21

What exactly happened here? All I see is a highlighted line that seems to have already been there.

A guy issued a challenge saying he'd give $100 to anyone who could trick him into inserting a certain string into any of his software projects. Another guy responded "You should put this challenge on your website." The first guy said "Good idea" and proceeded to do so, thus including the string in one of his software projects: his website. GG

He basically did this: https://www.youtube.com/watch?v=XsrU2dMBVUQ

Re: Did I just win?

#50
post #11
post #7

Earlier quoted context omitted.

Interesting discussions to be had as to why this is the case. I suspect it would make it too easy.

I suspect it's just because there are too many variables. Social Engineering isn't exactly a replicable science.

From my perspective though, the best Social Engineering undertakings are targeted in ways that are like one-time-use-zero-day exploits. Or, in other words, the merit of SE is breaking in once, not leaving an open door behind as a repeat attack vector (that's the goal once through the barrier).
Post reply on HN