4 ms·
Their effort to obfuscate their tracks does sound pretty nifty, but part of me is disappointed that it all depended on the target clicking on something they sho
by sgoranson 17y ago
Their effort to obfuscate their tracks does sound pretty nifty, but part of me is disappointed that it all depended on the target clicking on something they shouldn't have. Glorified phishing schemes just don't have the pizazz of a remote buffer overflow exploit, for example.
- maukdaddy 17y agoThis kind of attitude has to stop. "Glorified phishing" might not have pizazz, but it was DAMN effective in this case. Why go to the trouble of finding, coding, exploiting an increasingly difficult target when end users will do all the work for you? This is the kind of scenario that gives security people nightmares. It takes VERY sophisticated processes and technology to find covert backdoors on your network, and very few places devote the manpower or $$$ to the effort.
- sgoranson 17y agoEffective or not, sending some bad links to a bunch of Google employees and hoping one of them clicks is not a 'VERY sophisticated process'. It's just a good example of how users will always be the weakest link in securing a network.
- barrkel 17y agoOpening up a page in a web browser ought to be a safe operation. Letting that page start a plugin, or running something it downloads, or flat out using IE for an unknown link, then I'd be more inclined to blame the user. (This is why I use Foxit for PDF reading, I don't have a PDF plugin enabled in my browser, PDFs download to disk, and similarly QuickTime, RealPlayer, WMP etc. plugins are all disabled, with only Flash enabled but controlled via FlashBlock.)