How I Cracked a Keylogger and Ended Up in Someone's Inbox
trustwave.com
trustwave.com
I’d have expected the DDoSers to have better security
And that's for the people actually hosting the botnet or "booter" (which seems to be what the parent poster found). Most of the time, it's one more layer down: just some kids paying for the right to enter an IP to DDoS temporarily.
Could you give more a more detailed explanation on how you did that?
Me neither, it's damn expensive
That said I found the original joke quite un-amusing and I think it didn't add much
Any kind of active and specific pushback to malicious actors is poking a hornet's nest, and if done on the behalf of an employer, there should be serious discussion and acceptance of the risk of retaliation. Particularly with people running DDoS operations who, in my experience, tend to be a little immature.
(Personally I use pinboard.in and would happily recommend it but I don't think everyone need it.)
That said, pinboard.in is a decent service, and it's useful to have all your bookmarks in a central location.
I also find similarities between above domain and these: transitoin-asia.com seabunker.net
See this: http://imgur.com/tsxqwiQ
If someone wants to do more research - would be fun to dig deeper.
I love domaintools as it allows to find anything by anything. Like domains (current and historical) by email, or even by fragment of registrant information, such as by phone number or by zip code.
Finds anything with position:fixed and deletes it. Reload the page to get the elements back if needed.
However, the sites that do the overkill of a sticky header tend to also have poorly thought out site navigation and user experiences.
Let's say on a normal site, killing any absolute nav would result in a 5%* decrease in UX.
On a site like this, killing any absolute nav might result in a 5% increase in UX.
On the other hand, your free upgrade to Windows 10 is ready. Would you like to install it right now or later tonight?
An off the shelf key logger is used; a couple of stolen email accounts, and a spammer is used for delivery. There are automated tools that will pack the key logger executable in a word document also.
As for the part of the security researcher; reversing .net code isn't challenging. This is by design - the framework does not obfuscate or make it challenging to look at the code. The author of the key logger could have built in protections or obfuscated his executable but for one reason or another has not.
Most likely all of the reversing or analysis was also done with automated tools, and the analyst simply had to run them. OfficeMalScanner can be used to locate packed executables in MS documents and extract them, and then it is simply a matter of dumping the binary in the .NET decompiler of your choice (the author uses ILSpy, I personally prefer RedGate Reflector) and looking at the code.
IMO this is a marketing piece that happens to have an interesting story attached to it.
Criminals come in all shapes and sizes, at all levels of intelligence, skill, and laziness or lack thereof. There are indeed criminals who aren't stupid but are lazy; but in my experience counseling the incarcerated, most criminals (that I spoke to in a non-scientific, non-random sampling) were both stupid and lazy. Of course, maybe that's confirmation bias, because I only spoke to the criminals who got caught.
What I found most fascinating were the criminals who were smart in the short-view, stupid in the long-view, and extraordinarily not lazy. Many young hackers fit into this category. They work long hours and invest a lot of effort in a crime, thinking all the while that the investment had a better return than non-criminal activity over the long-term.
Come on, you're talking about the biggest and one of the oldest technological conglomerates on earth. They could fix the ecosystem if they wanted. But since they dont care about users, they'll wait till google does it for them and then sue over IP rights
Even if you assume they would add a UEFI "enable developer mode" setting, this would get them so much bad press (and, also, it would actually make developing and distributing software on Windows a lot harder for smaller and open-source developers, and deploying custom software harder for enterprise costumers).
See, the signing system doesn't have to be mandated. It could pop up a UAC-like screen but with an actually useful message: this code is known to have malware, we recommend you dont run it. If you absolutely want to, press OK at your own risk.
Another message could say it's completely unsigned, so devs could still write and distribute their own code. But make it free to submit to the "app store" and get reviewed by MS. That would work wonders to improve security across their whole ecosystem, and not force anything down the users' throats.
I fully agree that putting administrator permissions on everything is not a solution, as users will start clicking it away without thought, but there's a good number of things in this article where I could not believe that it does not require administrator permissions.
So, simply a clearer separation would be necessary.
Ugh I hate reading this. I keep everything in my password manager. If I lose that I'm hosed. I wish more sites supported 2FA.
- how do those PW stealers work? are they similar to the Steam one, where it'd delete existing creds and then sniff newly entered ones?
- can this thing detect certain apps like FileZilla and then say "user entered <FTP site creds>" and send individual fields, and is that what is meant by supporting say FTP and FileZilla?
- what does PHP support mean? maybe looks for common stuff like php.ini, various other conf files like FPM, and tries to find DB/cache connection creds?
there's one other thing I'm wondering about, which is the light/easily crackable encryption of the keylogger's internals, and I vaguely remember reading about Google's encryption on the new recaptcha and people talking about all this stuff like complicated encryption routines baked into the client side JS that I really didn't understand except at a handwavy level, and wonder if that's the kind of thing some, say, intelligence/espionage outfit could use.
very interesting/engaging (fun) article, all in all, for me. and I appreciated the understatement of the (well-deserved) plug at the end.
The most obvious way is to hook the message stream from the window manager to the applications, windows provides some convenient hooks for this.
Whereas, I believe if you go by your second point, you can see "Ok, the user put username <x> in the username textfield, password <y> in the password field, address <a> in the address textfield, port <p> in the port textfield" and so on, which would make for a more structured data dump. Maybe not possible or feasible for every single application, but if you could get the highest usage targets, like the most common FTP clients, or Steam as they have apparently done, and the browser password storage stuff (or fields for say, most common banking sites, PayPal, etc.) then you could save yourself a lot of time.
{TAB}{TAB}{CURRENT WINDOW: Steam - Log in}{TAB}username{LEFTCLICK}password{LEFTCLICK}{CURRENT WINDOW CHANGED: Steam: Home}
Could well be. I haven't messed with Win32 in a while, but I'm pretty sure that you can sniff the contents of other applications' windows and dialogs. With a little work, you should be able to take a common app and work out how to detect it's login windows, find the username and password and other relevant fields, and pull out the contents.
I know if I was writing a hostile keylogger, I'd go to a lot of trouble to know exactly what was entered where, instead of having to see a long stream of keyboard input and figure out what the usernames and passwords are, and what services they go with.
FileZilla simply use a file in your personnal directory to store passwords exactly like your browser too.
Presumably, people who take more than 48 hours to open their email were deemed an edge case not worth worrying about.