Operation Luigi: How I hacked my friend without her noticing
defaultnamehere.tumblr.com
defaultnamehere.tumblr.com
It'll trip you up later if it asks again (e.g. When changing a password or setting up mail forwarding) but your session cookie will be valid for quite some time.
Maybe I'm assuming too much that other people are like me, but I interact with Facebook as many times per day as I do per year with LinkedIn.
Then I'd do the same Luigi-like low key messing with them for a while. My favorite was when a friend had a VNC server running on their machine with control capabilities. I would sit next to them and subtly jerk the mouse pointer right before they were about to click on something and it drove them mad for a good 20 minutes before I couldn't hold onto the giggles anymore.
edit: To add a bit of context, this was in the Windows 98 era, before the age of social media where we started putting all of our secrets onto our machines. And it was among a group of friends where everyone was trying to hack everyone else and pretty much anything was considered fair game. All of us were high school kids so there wasn't some super serious reputation we had to protect.
If you were befriending someone with the sole intention of getting their passwords, that might be considered social engineering.
If you are just exploiting the existing trust of friends and family for fun, that's sociopathy.
And that's fine, if it wasn't for the fact that your HN profile advertises your business.
Do you also do this to your clients?
What a great world we live in!
so it was just a prank?
Is that legal? Seems like a good way to get sued/arrested if you annoy the wrong person, or your 'friends' ever report you for it.
But seriously, that's pretty messed up either way really. You're exploiting people that think you're friends with them to get information from their computers without their knowledge. It's at best not ethical and worst not legal.
Kids play pranks on each other. Thats not going to be the end of the world, and nobody is going to be sent to jail.
He also explicitly said that everyone was doing it to everyone else, so obviously this isn't some cyber bullying scenario where someone is getting seriously hurt.
I remember people doing lots of dumb pranks like this in high school, and nobody ever got emotionally scared because someone "hacked" their facebook page (because it was left open as someone went to the bathroom) and changed their "interested in" profile section to "men".
>One of my favorite low key social engineering hacks is that I used to have a keylogger installed on every machine I own. Whenever a friend needs to hop on my machine to show me something, they'd log into an account they own and I would have their password.
This isn't a "low key social engineering hack", it's betraying someone's trust.
>I would sit next to them and subtly jerk the mouse pointer right before they were about to click on something and it drove them mad for a good 20 minutes before I couldn't hold onto the giggles anymore.
This isn't actually funny, it's just being obnoxious and mean.
If you're next to them why not just jerk their arm when they are trying to click? It achieves the same "goal" of "entertaining" yourself and pissing the other person off. Jerk their laptop when you walk by. Throw stuff at them. Smack them in the head. Trip them when they get up to pee. "Hilarious."
>among a group of friends where everyone was trying to hack everyone else and pretty much anything was considered fair game.
This sounds like the bully saying "we were all having fun together."
You don't know the difference between having fun with someone and having fun at their expense - and that's just disturbing.
As someone who lived during the Windows 98 era, I wouldn't want others reading my IMs and emails (I had some very sexual and personal communication over those channels) or viewing my browsing habits.
I've known some kids who went through a phase where you would ask them something like "Did you clean your room?", they'd say "Yes!" and then later, upon confronting them with their messy room, they'd get this self-satisfied sneaky look, and cackle: "Hah! I tricked you!"
While I sympathize with the David-and-Goliath allure of reversing the power-relationship between them and the adults in the household, I tried to explain that such direct lies weren't quite the kind of devious tricksterhood that gets a celebration.
It is juvenile prank, sure, but high schoolers are literally juveniles.
Obviously, you shouldn't do stuff like this to someone who will freak out and get upset about it.
Persistent bullying and harassment is, of course, not ok. But most "cyber crimes" that high schoolers commit against each other are NOT that. They are dumb pranks like changing a person's sexual orientation on facebook.
For most situations, the vast majority of kids would just be embarrassed for like 10 seconds, laugh, and maybe try to prank the person back.
That seems to imply that very little bullying occurs through such means. I'm sceptical of that.
HOWEVER, there's a huge difference between a harmless prank and betraying someone's trust to be mean to them. I consider keylogging and pwning someone's machine deep into the in the "asshole" category. I also think that jerking someone's mouse when they are trying to click is not clever, just annoying, not funny. Especially because it could more effectively be done physically. It's in the same league as tripping someone when they walk by - just dick behavior.
A prank is something the pranked can laugh at, not just the pranker.
Since I was just leaning to explore my sexuality during that time and my IM messages and emails reflected that I'd be pretty horrified to know someone stole my password, pwned my machine, and read them. Like, seriously horrified and very violated.
So while I understand in cases like yours it can be bad, I think calling for legal action and generally freaking out about it as a general rule is pretty lame. Kids will be kids. Shit happens. Life happens. Don't let people use your computer.
We also kept this between ourselves. It's a much different situation if I "pwn" my friend who is attempting to do the same back to me vs. a typical normal kid.
Those practices learned put myself and my friends in a pretty unique mental space for the time. It was an age in time where all this stuff was new, computers truly did not do as much important life stuff, and being a teenager playing pranks and cat and mouse was fun. Just this stupid "real world" experience in your mid/late teens was enough to typically get an entry level job in IT - typically starting off with more skills than your superiors.
What was NOT OK were the few guys who never grew out of that BS. I ended a business partnership after I found out my "partner" had opened my workstation and removed the BIOS battery to reset things, and install a keylogger. At that point it's no longer funny, it was not a novel or interesting attack, and was simply being an untrustworthy asshole.
Here's my summary:
1. Someone gets permission to hack their friend
2. They find their email / phone number online
3. They lookup old password leaks for the email (passwords don't work)
4. They end up setting up a fake page to phish their friend (it works)
5. They wait until their friend falls asleep to reset the twitter password
6. They make their friend follow a bunch of fake Mario accounts on Twitter
7. Friend notices, they meetup to swap stories (the friend doesn't follow the fake Mario accounts) 1. Someone gets permission to hack their friend
2. They find their email / phone number online
3. They lookup old password leaks for the email
3.1. They find their password hash (salted) in the Tumblr dump
3.2. Tumblr turned out to use the same hash for everybody, so the author
finds other accounts with the same hash, follows them to a LinkedIn
leak (unsalted), and successfully recovers the password
3.3. The password turns out not to work (changed some time ago)
4. They end up setting up a fake page to phish their friend
4.1. First phishing attempt produces... the old password that is already
known through point 3.
4.2. Second attempt is modified to reject user input a few times, producing
another password, which happens to work
4.3. The victim grows suspicious of the phishing e-mails, but another
message puts those suspicions to rest
5. They wait until their friend falls asleep to reset the Twitter password and (later, in the same way) capture
their LinkedIn account
6. They photoshop their profile pictures to subtly include a Mario character, and they
make their friend follow a bunch of fake Mario accounts on Twitter
6.1. When that doesn't get noticed, they redo the trick in a much less subtle way
7. Friend notices, they meetup to swap stories (the friend doesn't follow the fake Mario accounts)I really couldn't stand the writing style the author used — I understand peppering your writing with jokes, but there were far too many attempts at 'humour' for my taste.
Fortunately, I had a few minutes to kill while eating lunch, so I read it all.
Irony is only irony if it is not greater than 73% of your life, according to scientists. This person long ago passed that threshold.
I'm sure you could get some funding to provide that as a service.
I have been laughing out loud for the past hour.
But sadly, the project has been discontinued for a couple of years already. I think it lacked incentives for summary writers (for example micro payments from summary readers) and also a monetarization model for the project creators.
The code is still on GitHub: https://github.com/tldrio
I thought about contacting them to get the web service running again on some cheap AWS VM or so, but haven't done it yet.
3.2 Tumblr used same salt for everybody, but author don't know the salt. He searched the hashed password and found 20 other users have same password hash, using same password.
3.3 Linkedin leak have no salt, by looking for the 20 other users he found the plain text password, which should be the target password.
3.4 The password no longer worked.
Also, when I noticed my typo in the 3.2 ("hash" instead of "salt"), I pretty much hit myself in the head :/.
An important part of the story was that the phishing attempt failed, but was followed up by a spear-phishing attempt that was eventually successful.
I suppose it is written to another audience, perhaps the people that use tumblr find this funnier.
I will mention that with the number of footnotes Marco Arment's little in-place footnote pop-up script he uses on his blog and Ben Thompson uses on Stratechery would have been appriciated. I forgot how useful that was compared to 'true' footnotes on long articles with lots of them.
You can't tell me you didn't find this hysterical
- a friend asks author to try and hack him
- author tries a bunch of things in vain, finally decides to use a rogue wireless AP and does a MITM
- identifies that notepad++ has automatic updates turned on and that it's over HTTP
- creates a custom executable and writes a script (or something) to serve this payload when notepad++ tries to download a EXE
- fakes an update (by returning true when notepad++ queries an HTTP endpoint for the latest version on startup)
I'd be really thankful if someone could link me to this post. My usually powerful google-fu has let me down this time (I tried all _sorts_ of things). Notepad++ and MITM are the only things I strongly remember.
Thanks anyway! :)
Edit: this was also more of a story than a how-to like guide.
I used do this to fake screenshots as well. People assumed I edited them with Photoshop!
Instead I've made up some answers that I'll never tell anyone else.
However that doesn't really make those details secure. 2FA is where it's at.
You should make up some answers like ighe9Chik9oorooy. That's what I do.
I'll never forget you, ntnOFT(#9TNSONROe. We had such good times together.
"For security what's your pet's name?"
"I don't have a pet, I just put a bunch of random characters."
--
Due to implementation these questions are actually sometimes hard to answer truthfully sometimes. My fav teacher has a . in her name but "special characters" are not allowed in answers. My pet's name is 4 characters, too short. How did I answer my first car? Year, make, model? Make? Year and model? Just model? Who can remember?
2) The HN post I replied to.
* don't use linkedin
* don't use hotmail
* always use 2FA
* use complicated and different passwords
* security questions matter
* avocado toast?
* change passwords periodicallyA couple of Australian doofuses said that it's millenials' own fault they can't afford homes, because some of them buy expensive meals sometimes. http://time.com/money/4778942/avocados-millennials-home-buyi...
The internet has had a lot of fun with it. https://www.washingtonpost.com/news/food/wp/2017/05/15/dont-...
(0):https://www.cnbc.com/2017/05/16/millionaire-tells-millennial...
1) Family gives you money.
2) Don't squander the money on hookers and blow.
3) Use life opportunities that having wealth brings to create more wealth.[1]
4) Congrats, you're a millionaire.
Anyone can do it!
[1] They say "you need money to make money" and speaking as someone who has both lived with no money and now lives with lots of money, it's sooooooo true. The more money you have the easier it is to acquire even more money.
https://twitter.com/tangelaekhoff/status/864667137138360320?...
Whoa.
This sucks and I wish I could turn it off on accounts that I've set up my yubi key on. It's a strong password at best and my mothers maiden name at worst.
Name of childhood physician: dr. EeNohsh3yaiw3vaHaic4
Beside that I follow basically everything on this list (not avocado toast) :)
A year ago I made the transition from contract developer to employer and therefore have a lot of "developer" keywords and experience on there. My profile makes it very clear that I'm busy running a business and not looking for entry-level contract positions. It also clearly says "no agencies" in the contact details. I still get multiple messages and connection requests from clueless recruiters playing the numbers game to the point where the site actually has a net negative value to me due to wasted time.
Still, I'll probably go check it out now that I've been reminded that it exists... If only to go and clear out my inbox again.
Well if you are using your phone and change countries you end up with lot of issues as I found out the hard way :(
Ugh. And I'm closing the tab. Appreciate the effort with humor, but you really should concentrate on being able to write something that's informative and enjoyable to read, and THEN try your hand at making your writing funny. The first sentence/paragraph needs to be a hook to get people interested, not some meta jokey blurb that doesn't have anything to do with anything.
The first sentence/paragraph needs to be the first sentence/paragraph. I'm personally sick of people optimizing things to "hook" their "audience". I much prefer when people simply write honestly and to the point. Not everything in life has to be a sales pitch.
(This post was definitely not "to the point", but that's a stylistic choice of the author; I can respect that even if I don't like it.)
Loved the write up though.
> If you really tried you could probably find Diana’s Twitter from these. You would then be a hacking genius, binary flowing through your veins, and have a CVE number assigned to your personally. I, a humble wannabee, am relying on your strict ethics to prevent you from, uh, stalking the friend of some guy whose blog post you read. You can do it. I believe in you.
> Having said that, I don’t really have an overwhelming amount of faith in the idea that someone won’t try to do that. You can stay chilled out, dear reader, since before this blog was published Diana and I had a nice chat and fixed up her personal security.
Or... because having to remember more than 3 random combinations of arbitrary letters, numbers, and a subset of extended ASCII, is not a tenable solution. Of course people use things like l33tspeak. We can remember words. I wouldn't say laziness has anything to do with it.
It's absolutely clear that Tumblr did not use a pepper to create the dumped hash values in the article. Multiple users had the same hash, and most of those users had the same password as each other on another site.
Or are you saying that the exact same hash was found in multiple separate database dumps? I didn't see any indication of that in the article.
"The pepper is randomly generated for each value to be hashed (within a limited set of values), and is never stored. When data is tested against a hashed value for a match, this is done by iterating through the set of values valid for the pepper, and each one in turn is added to the data to be tested (usually by suffixing it to the data), before the cryptographic hash function is run on the combined value."
In case you're interested, that is the same scheme as the one used by JoeyH's keysafe[1].
Opsec is hard.
Second quiz: Without investigating, can you tell me when this domain expires, if it is registrar locked, if anyone can purchase this domain once it expires, what the mechanism used to verify a request for certificate for an existing domain is, if anyone can use a free TLS certificate service to create a valid signed site once they own it, and how much time it would take for this to happen if it was automated?
(spoiler alert: the address bar will not tell you any of this)
Related: who on the Chrome team had that "bright" idea to dumb down the website security popup that shows when you click on the padlock next to the address bar? All the relevant info seems to have moved somewhere to Security tab in the Chrome Dev Tools...
I'm actually really impressed by the phishing approach.
Is he hacking her cause of romantic interests?
Is he hacking her for the thrill?
Is he hacking her to be able to write the article?
Is he hacking her to show her that he can?, or to show her that it is possible, or to show her the world she is living in?
Why would he ask that? It is strange.
It is also strange how he tries to trivialize what he is doing. From his perspective it is trivial, but for some people it will not be trivial, why would he write an article about something that he believes is generically trivial. Another alternative is that he does not understand that it might not be trivial to some people.
I did read the article... just quoting is probably not going to answer my question.
To make a blog post about it.
His blog title is The hacker known as "Alex" and his previous articles are similar to this one.
See a discussion about one of his previous articles https://news.ycombinator.com/item?id=11130688
The author got permissions of the target.