3 ms·
I’m not so sure about that. With enough dedication and time I think you could target a specific company from HN. Start writing a few good blog posts that would
by nathantotten 6y ago
I’m not so sure about that. With enough dedication and time I think you could target a specific company from HN. Start writing a few good blog posts that would appeal to your audience, only run attack when some attribute is true to that company (i.e. their Corp IP addresses).
You could even combine the two. Post the blog to hacker news, then send phishing email pointing to HN post. That is a trusted link. Then the user will likely click the source link in HN.
Obviously, a lot harder and lower chance of success, but not impossible.
- 411111111111111 6y ago> [...] only run attack when some attribute is true to that company (i.e. their Corp IP addresses). [...] Obviously, a lot harder and lower chance of success, but not impossible. In general maybe, in this particular case it's gonna be challenging however, as gitlab is a remote company so most employees will logon from residential ips
- asutekku 6y agoI would imagine they would be using some sort of company vpn to access the files they need to use.
- owenmarshall 6y agoMost companies I’ve encountered have moved towards split-tunneled VPNs so an employee clicking on a phish page would traverse the employees gateway, not corporates.
- tbyehl 6y agoMy experience is the opposite: Part of the justification for moving away from standards-based VPNs is to prevent split-tunneling. My present employer's VPN client goes a step further and mangles the routing table to deny access to my own LAN while connected.
- 411111111111111 6y agointeresting, i heard that some employers did set the default route to go through their vpn, havent had that experience myself either though. it was always only the 10.0.0.0/8 and some /24 ranges from 192.168.0.0/16 at my current job
- o-__-o 6y agoliberty mutual, the largest insurance provider, is in the process of moving from default route on the vpn to no vpn at all and zero trust networks for their apps.
- owenmarshall 6y agoI can’t decide if I hate that more or less than what I’ve seen: client-side blocking of DNS resolution and driving all queries through Cisco Umbrella or friends. I guess they both suck pretty hard.
- tedunangst 6y agoIt's not impossible to determine which of your visitors has login cookies to other sites, such as internal.gitlab.com, and provide different content to them.
- vidarh 6y agoOr just buy ads with suitable targeting.