3 ms·
But that's what a reverse shell does - the point here was to covertly place a listening service that could be reached from the internet and execute arbitrary co
by beardedwizard 3y ago
But that's what a reverse shell does - the point here was to covertly place a listening service that could be reached from the internet and execute arbitrary code so that an attacker could control the machine.
Maybe I'm misunderstanding your question though, can you clarify?
- deelowe 3y agoThe phrasing in the article sort of makes it sound like the npm package opened up port 5000 vs the shell.
- kevmo314 3y agoI think it's hard to really understand the attack without seeing the code, but listening on a port (at least the chunk of code rendered in the article) is not sufficient to make the machine accessible on the internet unless the wallet machine is publicly addressable, in which case I think running untrusted code is the least of the dev's concerns. I had guessed that perhaps it's intercepting port 5000 and something else like Metamask was connecting to 5000 assuming something more innocuous was running on it, then forwarding that information? But like I said not sure without seeing the code.
- formerly_proven 3y ago> is not sufficient to make the machine accessible on the internet unless the wallet machine is publicly addressable, in which case I think running untrusted code is the least of the dev's concerns Whole raison d’etre of IPv6 is to enable that.
- Volundr 3y agoEvery router I've met still runs a firewall that blocks incoming traffic by default IPv6 or no. My guess on this kind of thing would generally be that the infected computer reacher out to a service controlled by the hacker to establish the shell and the reporter misunderstood, or that the dev connected to a VPN controlled by the attacker, effectively bypassing the firewall, otherwise something is really badly configured on the devs end.
- beardedwizard 3y agoMost shells are connect back, ie the reach out to a known address to deal with NAT, etc