I challenged hackers to investigate me and what they found out is chilling
pandodaily.com
pandodaily.com
Basically they got in via phishing? First via a .jar file and then a video? I'd like more info on how the video can take over your computer. But in any case I don't fall for phihing scams.
The best thing I saw there was asking to print out the resume. Had the system been newer it would have worked.
Couldn't they have tried using one of those drive-by Javascript vulnerabilities?
The rest of it once they gain entry is straightforward.
Here is what I am wondering about: I use Google Apps for my email etc. If my company starts competing with Google on some fronta, can't Google just engage in corporate espionage by simply reading the email we store there? They'd also have access to all our accounts. How would this ever come to light?
They didn't do it with a video. The supposed "video" in the zip file was just a bait so the victim has an incentive to open it. Most likely the zip contained a .jar again.
I'd still be more worried about the 1999 attack - social engineering the businesses who hold your information - than about anyone getting it directly from my personal footprint.
An absolutely fascinating article but not good for the old paranoia.
A less scrupulous hacker would simply have broken into the flat by picking the lock, which would have resolved most of their difficulties.
Agreed, emailing .jar is kind of lame. They should have tried with some office/PDF exploits first!
All the attack vectors seem fairly straightforward, but I suppose the combination used on each target changes each time, and that's where the skill comes in.
But it's always good to remind people to apply common sense when using email and the internet and be aware of their digital footprints.