9 ms·
Using Hinge as a Command and Control Server
- bschmidt25002 9mo ago[dead]
- levzettelin 9mo agoCould someone ELI5 what this does?
- tanduv 9mo ago> Congratulations! You're now using Hinge to distribute unassuming abstract expressionist pixel art.
- kls0e 9mo agocreative platform use
- litheon 9mo agoCommand and Control Server (C2) refers to the infrastructure required to command and control malware of various forms. The author basically found a creative use of Hinge’s infrastructure and proved it could be used to control malware.
- lisbbb 9mo agoBut the malware was encoded as an image, how is it runnable on the target's smartphone?
- richbell 9mo agoThe purpose of command and control servers is to send and receive data to victims devices. A secondary goal is to do so while evading detection. This is why many threat actors piggy-back off of legitimate services, it disguises the malware communications and avoids directly exposing the upstream C2 instance.
- hobofan 9mo agoI'm not really into malware, so I was just wondering: - Isn't this really non-viable in practice? The "few headers" that were shown include an Authorization header, that would presumable rotate every ~24 hours and would have to rotate for all the malware clients as well. - Are centralized Command and Control Severs still a thing in the malware space? I would have assumed that this function mainly migrated onto one of the popular blockchains with clients using one of thousands of available gateways for reading.
- jdsnape 9mo agoprobably not so useful in practise, but still fun and interesting. Yes, centralised C2 is definitely still a thing in the malware space, for commodity malware it works well enough that there's little real incentive to move to anything more complex.
- mattwiese 9mo agoRegarding your first point, extraction of the headers could be trivially automated. Also, using Hinge's CDN (which I think is CloudFlare and/or AWS) is more viable imo, as you don't need to provide headers to GET the files. If that also applies to user-uploaded videos then I do think there's some meat on this bone. But as the other user who replied to you pointed out, this was mostly for nerdy delight. Also thanks for bringing up the blockchain C2 use, that's cool and news to me.
- Imustaskforhelp 9mo agoOne could probably use matrix (perhaps might need account creation?) or session or simplex (their accounts are sort of like addresses, easy to make compartively to matrix) I have built dead simple bots on both session/simplex trying both of them out and session was the more ergonomic one to build on but simplex is more decentralized considering session's more crypto related and wants to ask you for money for node whereas simplex doesn't Although on the other hand, simplex wants to do client side verification on their official client and their bot creation was really painful to start with so but I do feel like its more decentralized but not sure, Both have consequences but honestly I just really end up shilling signal in the end for most people's usual use cases which is communication but its super great to know that there are alternatives. Matrix is really cool as well. especially cinny's ui (https://cinny.in https://cinny.in)
- stackghost 9mo agoI think the Hinge being referred to is a dating app? I have no idea. https://hinge.co/ https://hinge.co/
- deleted 9mo ago[deleted]
- fuzzer371 9mo ago[flagged]
- deleted 9mo ago[deleted]
- stackghost 9mo agoApparently I have. Is this particular dating app particularly noteworthy?
- kneel25 9mo agoI envy the fact you had to google it
- stackghost 9mo agoAgain, why? Nothing on its wiki article or the first page of Google results suggests it should be a household name. So unless the default assumption is that everyone on HN is dating (I'm married) I genuinely don't understand why it's weird to not have heard of some random ass dating app
- Sytten 9mo agoBecause it used to be the "best" dating app out there for "serious" people wanting long term relationships. Now all the apps are trash and have predatory monetization.
- kachapopopow 9mo agospeaking of command and control servers, the best one you can get at the moment is to just to use crypto currencies, plenty of available nodes to auto discover or just rely on explorers to query your own wallet, deposit address can encode quite a bit of information since it's a pretty long address and definitely has enough bytes to encode commands
- sneak 9mo agoMany networks block non-http/s traffic.
- octoberfranklin 9mo agoBlock explorer websites expose blockchains over http/s.
- sneak 9mo agoYes, and can easily be blocked if they are commonly used for c&c, like many other sites are (such as gists and pastebins) for the same reason.
- kachapopopow 9mo agoif you add non trivial address generation there simply isn't a good way to block it except for hope and prayers. nobody really wants to play wack-a-mole on blocking addresses for c2 servers and then there will always be websites which straight up do not care.
- monerozcash 9mo agoI mean, at that point, why wouldn't you just rely on a DGA? At least then you wouldn't be flooding block explorer sites with millions or potentially tens of millions of requests per day for your C&C traffic. Essentially the exact approach you propose has been attempted in far cleverer ways, it did not work very well.
- octoberfranklin 9mo agoUm, use an app that requires you submit to video facial recognition to make an account? So that you can then use that account, which is tied to your biometrics, for lawbreaking? Wut?
- Aurornis 9mo agoIn 2025/2026 it’s not hard to generate fake videos that bypass these security gates.
- octoberfranklin 9mo agoThey don't let you upload facefusion videos. The video has to come from the front-facing camera on a phone. There is an extremely profitable company (whose data hoard keeps geting hacked but why should they care?) built around this: https://www.au10tix.com/ Most apps use device attestation (derived from secure boot) to make sure the video stream is really coming from a front-facing camera on a physical device. If Hinge isn't doing this yet they surely will be in 5, 4, 3, 2...
- Imustaskforhelp 9mo agoCan someone not just have an additional device and play a video on top of it? Fundamentally no amount of front facing camera on a physical device or other shenanigan a company might do can really do anything about it?
- qingcharles 9mo agoFront-facing paired with IR depth map would map it an order of magnitude harder, but I don't know what the standards are around that or what the installed base is on Android.
- Aurornis 9mo agoI know, but you need to think like someone trying to get around the limitation with the lowest effort possible. They don't feed it a video clip. They hold the camera in front of a screen playing the video. Use a low-end phone with a blurry camera to increase your chances.
- deleted 9mo ago[deleted]