3 ms·
Just two weeks ago, security researchers (like the kind of people who would be interested in visiting this page) were targeted by hackers which used a still-unp
by mac-chaffee 6y ago
Just two weeks ago, security researchers (like the kind of people who would be interested in visiting this page) were targeted by hackers which used a still-unpatched (as far as we know) Chrome zero-day to install malware: https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/ https://blog.google/threat-analysis-group/new-campaign-targe...
If this page started getting popular, a MitM attack to inject malware is a very real possibility.
- 2112 6y agoOn a large number of high value targets. Like this : http://dirk-loss.de/ssh-port-forwarding.htm http://dirk-loss.de/ssh-port-forwarding.htm In the "A visual guide to SSH tunnels" thread. Not saying it's compromised, but why would fully security conscious people, experts even, not have https:// https:// enabled ? Sounds sketchy as f** to me. > If this page started getting popular ... HN frontpage is about as good as it gets I think. https://addons.mozilla.org/en-US/firefox/addon/https-everywhere/ https://addons.mozilla.org/en-US/firefox/addon/https-everywh... -> will save you from a lazy click on a non-https link. Isn't it the case though that many malicious sites have https:// https:// enabled ?
- 2112 6y agoFrom the link you provided ; > In each of these cases, the researchers have followed a link on Twitter to a write-up hosted on blog.br0vvnn[.]io, and shortly thereafter, a malicious service was installed on the researcher’s system and an in-memory backdoor would begin beaconing to an actor-owned command and control server. At the time of these visits, the victim systems were running fully patched and up-to-date Windows 10 and Chrome browser versions. Like seriously ? Security researchers run Windows 10 and Chrome ? I mean if that's their testing environment I get it, but this sounds like they legit use that in the wild and click funny links sent to them from people claiming to be fellow hackers ? Outsider here, but is that really how it is ? I would think they use hardened OSes and !Chrome ...