Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

91–100 of 364 posts

Re: A fake job offer took down Axie Infinity

#91

Curious if anyone has been able to find technical details of how this attack works/worked. I'm under the impression most PDF viewers would prevent this sort of attack (e.g. opening a PDF in your browser should sandbox it to the browsing context), but really keen to know what PDF viewer / OS was used by the dev.

On Windows, Acrobat Reader has Protected Mode (sandbox) and Protected View (most features disabled) features [0], but people tend to disable it, in particular the Protected View, or don’t enable it for all locations. Or maybe the vulnerability wasn’t on Windows, or was in something like font rendering, or they used a different reader without sandboxing.

[0] https://helpx.adobe.com/reader/using/protected-mode-windows....

Re: A fake job offer took down Axie Infinity

#92

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

> I wish there were more information about what the vulnerability was in the PDF in the first place.

Agreed, I thought that opening a read-only PDF was GRAS regardless of the application.

Re: A fake job offer took down Axie Infinity

#93

How do you go through a whole job interview process and not realize that the company you are applying to is fake and doesn't exist?! ...Oh wait, this is crypto

How should we respond if we interview for a non-crypto job, and when we can't get any background on the company, they explain that they're in "stealth mode" to protect the advantage of surprise?

From time to time there are real startups that decide to fly under the radar until they're ready to show the world what they've built. Of course, many such companies turn out to be massive duds... Like Cuil.

https://en.wikipedia.org/wiki/Cuil

Re: A fake job offer took down Axie Infinity

#94
post #79

I've got to say, this is an incredibly cyberpunk article. > Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed. It's not in William Gibson's style, sounds more like Bruce Ster…

Cyberpunk is now, just sans the 80s fashion inspirations :)

Who knows, hackers might be using their $ on fashion but alas the profession makes it hard to flaunt.

Re: A fake job offer took down Axie Infinity

#95

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

I'm not sure this is Linkedin's problem to solve. They are just a directory.

I suppose they could add a phishing warning for messages sent on LinkedIn, but really it's an education problem, teaching people to identify what phishing emails look like and how to avoid them. This is a problem I've been working on since at least 2003, when we realized that the best way to prevent eBay account takeovers was teaching people what phishing is. We also identified that education is the hardest solution to achieve.

It's ironic that the security professionals are the ones hiding their identity, given that they are the best prepared to identify and avoid phishing emails.

Re: A fake job offer took down Axie Infinity

#96

Did this use a code-execution vulnerability in the PDF reader? or did they just trick the user into opening an executable?

I’m assuming it was an exploit in Adobe reader. The target cloud have even been persuaded to install Adobe reader to “e-sign” the document. PDFs don’t have the best track record when it comes to security

Why do pdfs even allow executing code outside of the pdf env ie why isn't there a sandbox/apis that allow very limited operation?

Re: A fake job offer took down Axie Infinity

#97
post #80

They rely on 9 trusted validators, the hacker managed to get access to the private keys of 4 out of the 9 validators. What's the point of using a Blockchain if you end up centralizing validations like that?

Don’t worry, they’re going to have 100 trusted validators, thus solving the problem…FOREVER.

Re: A fake job offer took down Axie Infinity

#98

How do you go through a whole job interview process and not realize that the company you are applying to is fake and doesn't exist?! ...Oh wait, this is crypto

Just interviewed with a crypto company, can confirm. Even "legitimate" companies with a web presence, customers, etc, come off as super sketchy.

That said, for lower income people you'll be absolutely inundated with scams, a good friend of mine just hit me up cuz someone wanted to promise him for $100 or so a week, you'd somehow become a crypto millionaire. I actually think crypto in its entirety is a giant scam, there's just levels of sophistication to it.

Not everyone's going to fall for give me $100 and I'll turn that into $10,000 , but a ton of people fell for buy a bunch of crypto coins and hold ,time the market and sell.

Re: A fake job offer took down Axie Infinity

#99

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

The main problem was using a machine that had access to half a billion dollars to also browse the web and do stuff like applying for jobs.

If you're gonna have access to such amount of money, it's worth buying a dedicated machine and using it very, very cautiously.

Re: A fake job offer took down Axie Infinity

#100
post #82

Earlier quoted context omitted.

Isn't LI owned by MS?

Yup. I'm gonna remove my cynical comment (although I still totally believe it). It's just not helpful. I think people can figure it out, for themselves. Also, people use LI as a way to aggregate information, then send emails that appear to be from LI, but are not. I got one of those, yesterday, and reported it to LI, saying "These guys obviously used your service to construct this honker." And LI's reply was ... enve…

I'd love to hear more about your experience with con artists!
Post reply on HN