5 ms·
> I have a Raspberry Pi right now in my hands fron rentyouraccont.com, i have it running diagnostics on an Air-Gapped pc. This thing is wild. Every second it tr
by browsercoin 8y ago
> I have a Raspberry Pi right now in my hands fron rentyouraccont.com, i have it running diagnostics on an Air-Gapped pc. This thing is wild. Every second it tries to connect to bot-net programs. It not only buys ads on facebook (which btw i cannot find code that it actually does this) but it is creating links to malware ridden embeds. It is part of a Botnet, i can say for sure. Every second it tries to establish a connection to the botnet, its like a bee thats lost its colony. Register for one and put it on an air-gap, you wills see excatly what im talking about. It records EVERY KEYSTROKE sent of the network, even SSL connection.
so this was a linked comment from a thread 3 years ago....
- Pxtl 8y agoHow is that even possible? How does it capture keystrokes (unless you mean Google searches where each key is sent for autocomplete). How does it break SSL?
- deleted 8y ago[deleted]
- krn 8y agoI think that by "every keystroke" he meant "every network packet".
- Zee2 8y agoWhich would capture passwords in plaintext sent from the user side, no?
- Pxtl 8y agoYes, but browsers give huge warnings about password fields on non-SSL sites. Password in the clear won't happen with any major website.
- osrec 8y agoDo they? I don't think so... Try http://login.ebiquity.com http://login.ebiquity.com Do you see any warnings in your browser? I see no warnings in Chrome.
- earenndil 8y agoThis is shown in firefox: https://files.catbox.moe/srdxhe.png https://files.catbox.moe/srdxhe.png
- kalleboo 8y agoSafari shows a red "Website not secure" in the address bar like this https://i.imgur.com/6DXzZ8G.png https://i.imgur.com/6DXzZ8G.png
- ThePadawan 8y agoChrome changes the "Not secure" in the address bar from grey to red (and displays a red explamation mark symbol there) when data is entered into the form.
- SamBam 8y agoWhich version/OS? I have the latest Chrome (69.0.3497.100) on macOS 10.13.3, and I see no red exclamation mark. Nothing changes or warns me at all when I start entering data in the fields. https://imgur.com/a/Q0rZWOS https://imgur.com/a/Q0rZWOS Maybe you have a browser extension, or setting turned on that I'm missing?
- deleted 8y ago[deleted]
- notatoad 8y agothe sort of people who could be convinced to install one of these things on their network in exchange for a theoretical $15 per month wouldn't be detered by a broken SSL warning.
- ownagefool 8y agoIt's probably not this attack but any WiFi device can probably be used to key log you. https://threatpost.com/keystroke-recognition-uses-wi-fi-signals-to-snoop/120135/ https://threatpost.com/keystroke-recognition-uses-wi-fi-sign...
- austinjp 8y agoThis is legitimately astonishing.
- ownagefool 8y agoIt's not great. Some areas of IT are in guarded rooms, with walls of a certain thickness, filtered power, external RF signals killed, and airgapped except for specific patterns for transfering between external systems. You probably just want to buy a yubikey and accept a lot of computing is built on a house of cards with respects to trust. https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thomp...
- slovette 8y agoEh.. no. It’s going to pickup worthless SSL encrypted TCP packets but not keystrokes. People need to calm the hell down here. If you’re connecting HTTPS to most of the web, the only thing this thing is going to do is collect worthless packet traffic. Woot woot. It’s not meant to collect data, it’s meant to act as an agent to a larger network of these things to collectively impact something or another in whatever way. But they could give 2 poops about the traffic on your local network.
- wildrhythms 8y agoI agree, people are really looking into the keylogger theory, but actually I think the goal of the scammer is to have a "legitimate" (residential) internet connection with which to register hundreds of online accounts, or purchase ads, etc. If the IP gets blacklisted by a service (like Facebook), no problem, the account holder will probably notice that they can't get to Facebook anymore, call up the ISP and get a brand new IP address. All this for just $15/month.