4 ms·
Target: the moderators/judges of the facebook coding contest Approach: post links on the contest page to a site that claims to know future questions, write cod
by trotsky 16y ago
Target: the moderators/judges of the facebook coding contest
Approach: post links on the contest page to a site that claims to know future questions, write code for you, process your data whatever. They'll get deleted but some staff will inevitably want to check if it's legit.
Method: Today's money is on the IE CSS use after free bug - unpatched and widely available. Get some ie traffic by "this site requires Internet Explorer". Some other month it'd be a jre/flash/quicktime/pdf.
Execution: Transitory system access on one or more clients. Reverse shell or basic payload, good rootkits are expensive. Simplest is just copy cookies/autofills/saved passwords/ssh keys - for extra credit install a keylogger.
Low and behold, poorly_paid_intern not only despams the contest page but does the same for zuck's pr account.
IMO not a local wireless attack - who on the peninsula would have such a idealized view of facebook's financing? Also US citizen+high profile=bad idea, see doing a year for guessing Sarah's yahoo.