Live data from Hacker News

I reversed a Node.js malware and found the author

medium.com

51–60 of 79 posts

Re: I reversed a Node.js malware and found the author

#51

Earlier quoted context omitted.

I was going to write it earlier but I was content with the statute of limitations so just bring it up when I run for office, it pretty much has nothing to do with what you believe I wrote about what happened, its a different reaction than the person I replied to - who actually visited the person instead of calling the police - there was no prowess associated with my response only that it was different and impersonal…

Quoted post unavailable.

Do you realize that if we’re talking about AIM and ICQ we are talking about 20 years ago? Maybe you didn't realize that, now that’s amusing. The sole purpose of this thread was “I can relate, I would approach it differently, here is a thing that happened”

love the fan account!

Re: I reversed a Node.js malware and found the author

#52
post #48
post #44

Is it not possible for discord to mitigate this vulnerability?

I don't know the specifics, but I'd assume not, Discord has made big steps recently in stopping this sort of malicious activity by adding the "Report Spam" feature as well as creating their own phishing link database to help detect spam in private messages. Discord knows it's a big issue and I'd hope they've attempted to mitigate the malware but there's no way to stop the actual injection, so really all they can do i…

I'm glad to hear they're taking things more seriously. They banned my original Discord account when I showed them a critical bug that allowed for remote viewing of another user's activity, both in real time and in logs.

Re: I reversed a Node.js malware and found the author

#54
post #48

Earlier quoted context omitted.

I don't know the specifics, but I'd assume not, Discord has made big steps recently in stopping this sort of malicious activity by adding the "Report Spam" feature as well as creating their own phishing link database to help detect spam in private messages. Discord knows it's a big issue and I'd hope they've attempted to mitigate the malware but there's no way to stop the actual injection, so really all they can do i…

I'm glad to hear they're taking things more seriously. They banned my original Discord account when I showed them a critical bug that allowed for remote viewing of another user's activity, both in real time and in logs.

Yeah, Discord is still just a bad with that. If you join a server and find it's hosting illegal material and proceed to report the server, Discord will ban all members of that server, which includes you. It's created an environment in which no one wants to report anything to Discord, especially since if you appeal your ban you won't get unbanned as you were in the server.

Re: I reversed a Node.js malware and found the author

#58

I did the same thing to someone who attacked my gf in high school. They got her with subseven which was extremely easy to remove. Rather than just erase it, I took a copy home with me and analyzed it. Running the strings command uncovered the subseven signatures.. Turns out there was tooling that allowed you to modify the binary and redistribute it. Except the binary had an ICQ address to alert him to my gf’s online…

I had fun with people on forums trying to get others to download keyloggers and the like. A lot of these were the stereotypical "script kiddies" who didn't know how much personal data they were giving away or even how the tools they used worked. I distinctly remember a few "C:\Documents and Settings\ \...", from which I could find and sometimes phone them (often their parents would answer), but I drew the line at doi…

> I distinctly remember a few "C:\Documents and Settings\\...", from which I could find and sometimes phone them (often their parents would answer)

so this sounds like a pretty devious attack if you want to get someone, pose as a script kiddie in online forum, put in C:\Documents and Settings\ in stuff, other identifying info maybe and then let others do the work.

Post reply on HN