9 ms·
How I Cracked a Keylogger and Ended Up in Someone's Inbox
- popey456963 10y agoIs the header sticky for anyone else? It seems to take up ~30% of my screen (Windows 7, Chrome Stable) [0]. [0] http://puu.sh/pNYUH/d42d8395fc.jpg http://puu.sh/pNYUH/d42d8395fc.jpg
- thesimon 10y agoSame on Chrome & Safari on Mac, but didn't notice it while reading, only when I read your comment :)
- miahi 10y agoExactly the same. I had to open the page again to see that there's a huge header.
- alexpetralia 10y agoSame here, just noticed upon rechecking
- ipp 10y agoIt leaves just a little over half of a laptop screen for actual article content.
- stephengillie 10y agoTry disabling JavaScript. Without that, other than some iframe code up top, everything seems to display correctly on mobile Chrome.
- deleted 10y ago[deleted]
- wlesieutre 10y agoThis bookmarklet was well received last time I mentioned it, so I'll link it again: https://alisdair.mcdiarmid.org/kill-sticky-headers/ https://alisdair.mcdiarmid.org/kill-sticky-headers/ Finds anything with position:fixed and deletes it. Reload the page to get the elements back if needed.
- ivanca 10y agoA more sensible solution would be to convert all fixed elements into "position: absolute" ones. That is less prone to cause errors and avoids impeding navigation.
- tokensimian 10y agoYou are correct. However, the sites that do the overkill of a sticky header tend to also have poorly thought out site navigation and user experiences. Let's say on a normal site, killing any absolute nav would result in a 5%* decrease in UX. On a site like this, killing any absolute nav might result in a 5% increase in UX.
- 746F7475 10y agoBut that doesn't work as well, since for example on this page there is JS event tied to scrolling the page that moves the header with you. So you'd have to tie your own anti-move trigger to the same event, which might mean same script won't be universal. If you just remove the header with a script, you can still get to the navigation by refreshing the page.
- ivanca 10y agoI actually just tried in this page and it works perfectly even before any scrolling has happened by just using "position:absolute !important" in the "position:fixed" elements;
- wlesieutre 10y agoYou'd think so, but I've seen a lot of websites that dump a sticky "social sidebar" on top of the content, and if it's absolutely positioned you can't read the stuff that it's stuck in front of.
- nchelluri 10y agoIt bothered me as well so I unchecked the width rule on the col-sm-7 CSS class (in the browser inspector) and then saw more text per screen which helped.
- krallja 10y agoYes. Firefox Reader View fixed that problem for me.
- kalleboo 10y agoSafari Reader Mode worked a treat over here
- rmsaksida 10y agoYep. Had to right click, inspect element, delete the header element. Article is unreadable otherwise.
- jacquesm 10y agoScary that a vulnerability that old is still worth exploiting.
- piqufoh 10y agoThat's a great little story, interesting to read how these sorts of scams are carried out, but I also found the code analysis and decompilation tale fun!
- skraelingjar 10y agoI agree, it's amazing how stupid criminals can be, even online. It's scary to think what someone as smart as these security researchers could do if they went black hat...
- matt_wulfeck 10y agoI actually get the feeling that some of these engineers put on their "gray" hats at night.
- ufmace 10y agoI'm thinking that's who's working on stuff like Stuxnet, Flame, etc. I wonder what color hat we would consider Government-sponsored malware to be?
- intern4tional 10y agoI don't think criminals are stupid; they're simply lazy. They put the minimum amount of effort is into a scam like this in order to make it profitable. An off the shelf key logger is used; a couple of stolen email accounts, and a spammer is used for delivery. There are automated tools that will pack the key logger executable in a word document also. As for the part of the security researcher; reversing .net code isn't challenging. This is by design - the framework does not obfuscate or make it challenging to look at the code. The author of the key logger could have built in protections or obfuscated his executable but for one reason or another has not. Most likely all of the reversing or analysis was also done with automated tools, and the analyst simply had to run them. OfficeMalScanner can be used to locate packed executables in MS documents and extract them, and then it is simply a matter of dumping the binary in the .NET decompiler of your choice (the author uses ILSpy, I personally prefer RedGate Reflector) and looking at the code. IMO this is a marketing piece that happens to have an interesting story attached to it.
- libeclipse 10y agoAha I love those little messages at the end telling users to update their software to the latest version. It's a cry to the void.
- zyx321 10y agoOn one hand, the average user will never update his software unless you literally force them to. On the other hand, your free upgrade to Windows 10 is ready. Would you like to install it right now or later tonight?
- libeclipse 10y agoDamn it, even Linux wants me to get windows 10 now?
- matt_wulfeck 10y ago> It also attempts to steal password manager credentials and Windows keys. Ugh I hate reading this. I keep everything in my password manager. If I lose that I'm hosed. I wish more sites supported 2FA.
- LoSboccacc 10y agoor had no authentication at all, just authorization. imagine having only a openid password to memorize... one can dream right
- bobsoap 10y agoWouldn't that just consolidate the attackable footprint? What if openid, or your openid account, got hacked?
- LoSboccacc 10y agoEh same is for email. Anyone with acces to that can trigger a password recovery exchange on most sites or pass an id verification check on the stricter ones.
- gruez 10y agoI'm surprised the .net executable wasn't obfuscated (as they usually are)
- lossolo 10y agoWebsite that we were running was under DDOS couple of years ago, what we did is we took ips of servers that made ddos. Then we scanned the ports, found vulnerability in the application that was running on it then get into the server using this vulnerability. We checked open connections and found one used for command and control server (irc server) then we listened to irc channel. DDOSers were talking private things on that channel... Then we entered their channel and disabled all their bots using their own software that we got source from link pasted on their channel. Then we confronted them, period of silence after they have read what we wrote was priceless. They never ddosed us again.
- armandososa 10y agoI wish HN had a `save` feature so I don't lose gems like these.
- eddyg 10y agoJust up-vote the stories and comments you want to save. When you view your profile on HN, you can see a list of your up-votes.
- gryphonshafer 10y agoWhen I use a desktop browser, I just right-click on the post age data and select "Save link as..." or "Bookmark This Link" or whatever.
- GFK_of_xmaspast 10y agoMost modern browsers still have bookmarking ability.
- reitanqild 10y agoUse bookmarks feature. At least Chrome and FF allows you to sync it between different instances. (Personally I use pinboard.in and would happily recommend it but I don't think everyone need it.)
- 10y ago
- unknown2374 10y agoI just hope someday the general public realize what a poor job Microsoft has done regarding security on Windows operating systems and embrace other (and more promising) alternatives
- nchelluri 10y agobroadly speaking, how would you design things? All I can think of doing is putting explicit permission grants on everything, requiring everyone to click a million times as was done with the first version of Vista's UAC, IIRC, which is no solution IMO.
- digler999 10y agoever heard of code signing ? Maybe MSFT could use some of its 23 BILLION dollars of yearly profit to test some of the programs and conditionally approve them if they pass muster, also based on the historical reputation of the signer (like ebay feedback). Then if they contain sleeper code or other exploits, the keys are pulled, updates are pushed to ALL users of the program that revokes the key, thereby preventing mass exploits Come on, you're talking about the biggest and one of the oldest technological conglomerates on earth. They could fix the ecosystem if they wanted. But since they dont care about users, they'll wait till google does it for them and then sue over IP rights
- lazaroclapp 10y agoSure, because it is not like anyone would accuse them of abusive business practices and of trying to kill open source if they made it impossible to run software not signed by them... /s Even if you assume they would add a UEFI "enable developer mode" setting, this would get them so much bad press (and, also, it would actually make developing and distributing software on Windows a lot harder for smaller and open-source developers, and deploying custom software harder for enterprise costumers).
- digler999 10y ago
- nchelluri 10y agoa few questions I'm wondering about, if anyone can help: - how do those PW stealers work? are they similar to the Steam one, where it'd delete existing creds and then sniff newly entered ones? - can this thing detect certain apps like FileZilla and then say "user entered <FTP site creds>" and send individual fields, and is that what is meant by supporting say FTP and FileZilla? - what does PHP support mean? maybe looks for common stuff like php.ini, various other conf files like FPM, and tries to find DB/cache connection creds? there's one other thing I'm wondering about, which is the light/easily crackable encryption of the keylogger's internals, and I vaguely remember reading about Google's encryption on the new recaptcha and people talking about all this stuff like complicated encryption routines baked into the client side JS that I really didn't understand except at a handwavy level, and wonder if that's the kind of thing some, say, intelligence/espionage outfit could use. very interesting/engaging (fun) article, all in all, for me. and I appreciated the understatement of the (well-deserved) plug at the end.
- jacquesm 10y agoKeyloggers simply record all key presses so if you delete the credentials for a game and someone then tries to run that game the first thing you catch is the credentials to log in again. The most obvious way is to hook the message stream from the window manager to the applications, windows provides some convenient hooks for this.
- nchelluri 10y agoas for the first point, yup, I understood that from the article; I probably should have used "similar to Steam" rather than "like Steam". I mostly meant, you'd get a long stream of characters and you'd have to manually try to dejumble them. Whereas, I believe if you go by your second point, you can see "Ok, the user put username <x> in the username textfield, password <y> in the password field, address <a> in the address textfield, port <p> in the port textfield" and so on, which would make for a more structured data dump. Maybe not possible or feasible for every single application, but if you could get the highest usage targets, like the most common FTP clients, or Steam as they have apparently done, and the browser password storage stuff (or fields for say, most common banking sites, PayPal, etc.) then you could save yourself a lot of time.
- gesman 10y agoThanks to domaintools.com - I also found that the guy (seemaexports3@gmail.com) used to own domain: bdmtsteel.com I also find similarities between above domain and these: transitoin-asia.com seabunker.net See this: http://imgur.com/tsxqwiQ http://imgur.com/tsxqwiQ If someone wants to do more research - would be fun to dig deeper.
- 55555 10y agoGood research. Can I ask what you used to make that graphic?
- shocks 10y agoI'd also like to know the answer to this question! :)
- gesman 10y agoSure, I used Maltego (commercial version + commercial domaintools access): https://en.wikipedia.org/wiki/Maltego https://en.wikipedia.org/wiki/Maltego (although Maltego also has a free version). I love domaintools as it allows to find anything by anything. Like domains (current and historical) by email, or even by fragment of registrant information, such as by phone number or by zip code.
- Koahku 10y agoUsing Volafile to host the keylogger executable seems like a pretty bad choice considering that this website will delete your files after only 2 days. Or maybe this shouldn't surprise me so much considering the "skills" of the attacker.
- wtracy 10y agoThey probably expect to upload a new build every few days, anyway. Note the login credentials hard-coded into the executable. Presumably, people who take more than 48 hours to open their email were deemed an edge case not worth worrying about.
- hw24 10y agoHacker World is professional hackers for hire that providing professional hacking services such as Web/database hacking, Email password hacking & recovery like Yahoo, gmail password, Hacking Hotmail or facebook account. You are in the right place If you are looking to hire a experienced and skilled hacker. Contact : Mail : Hackerworld@sigaint.org Website : http://yyuahqvtgzbkwvdf.onion/ http://yyuahqvtgzbkwvdf.onion/ Do you wanna ask for some service? please feel free contact ?
- hw24 10y agoHacker World is professional hackers for hire that providing professional hacking services such as Web/database hacking, Email password hacking & recovery like Yahoo, gmail password, Hacking Hotmail or facebook account. You are in the right place If you are looking to hire a experienced and skilled hacker. Contact : Mail : Hackerworld@sigaint.org Website : http://yyuahqvtgzbkwvdf.onion/ http://yyuahqvtgzbkwvdf.onion/ Do you wanna ask for some service? please feel free contact ?
- darekdk 10y agoFantastic write up! Good work.
- Zhycrin 10y ago10/10 brilliant. If only i was smart enough to do this...
- Zhycrin 10y agoActually, this is interesting.
- ascotan 10y agoNice writeup.
- vmp 10y agoI've done this a few times for fun, simply search YouTube for a "game code generator" or something like that, take your pick, download their magic "tool" from the link in the video description and get disassembling with ILSpy [1]. A ton of these "account stealers" are written in VB.NET and seem to be generated from a template. Remember to stay safe and use a sandbox or virtual machine when dealing with malicious code. [1] http://ilspy.net/ http://ilspy.net/
- yowmamasita 10y agoAnyone knows a better decompiler for .net other than ilspy? It's a hit or miss for me with ilspy, would like to try something better even if it's paid.
- Sir_Cmpwn 10y agoTry dotPeek: https://www.jetbrains.com/decompiler/ https://www.jetbrains.com/decompiler/
- slipstream- 10y agoI like dnspy, which is a fork of ilspy.
- heisenburgzero 10y agowhere did ).exe came from? I thought you need to use VBscript of some sort to download a file from command line.