I Inspected My Take-Home Interview Project. It Was a Whole Operation
citizendot.github.io - 155 poäng - 31 kommentarer - 6015 sekunder sedan
Kommentarer (10)
- wxw - 2308 sekunder sedan> They embedded a script that checks the victim’s host operating system and silently executes a remote payload.
Seems like this is becoming a recurring theme, similar story was on the front page last month.
- nphardon - 2675 sekunder sedanalways a good day when we get an a post on front actually related to hacking on hackernews.
- lantry - 1175 sekunder sedan> Side note: Why use a raw IP address? If anything, this screams “malware.” At least register a decoy domain like lint-checker.com or jenkins-ci-runner.net. If the threat actors who wrote this are reading: take notes people!
Maybe they don't want to give any identifying info to the domain registrar? Or just minimizing their online presence?
- ge96 - 3252 sekunder sedanThere was a funny video I saw recently someone's running Red Star OS on their computer and a scammer is trying to scam them thinking it's Windows
Unrelated to this git pre commit hook attack but yeah
- sailfast - 634 sekunder sedanReally hate that the USG overreaction on Fable has given us a neutered version of AIs for DEFENSIVE capabilities even when we just want an explanation of what we’re being subjected to with this malware.
Give defenders a better shot…
- darth_avocado - 1384 sekunder sedanIf LinkedIn actually cared about preventing scams, they could implement verification using company emails if you want to list your current employment. And if it is too much of a heavy burden, then at the minimum you should have it as an optional feature that recruiters would have to comply with, if they want to be legitimate.
- ChrisMarshallNY - 3735 sekunder sedanI assume these types of things are going to become more and more common.
Looks like these folks really did their homework.
It's nasty, but I have to respect their skills. I'll bet it works, quite often.
- gtowey - 3280 sekunder sedanMy takeaway from this is that I should use the same defense as when someone calls you "from you bank". When they reach out directly, go to the real company's site to apply and contact a real recruiter. If you can't validate that the business is legit before, then assume malfeasance.
- - 2023 sekunder sedan
- rdksu - 3001 sekunder sedanBruh the harry potter theme song scared the shit out of me as it turned itself on. Bad UX for a personal site. Great article btw !
Nördnytt! 🤓