Slashdot Mirror


Researchers Create Social Engineering IRC Bot

An anonymous reader writes "Researchers at the Vienna University of Technology developed an IRC bot that acts as a 'man in the middle' between two unsuspecting users, modifies URLs passed between them, and also is capable of steering the conversation. Not only does this work surprisingly well on IRC — they found a 76.1% click rate for potentially malicious URLs — but four out of 10 people on Facebook Chat also clicked on links after the bot introduced complete strangers to each other. This would have worked even better if the bot were to clone existing friends' profiles and submit friend requests from those, say researchers."

10 of 66 comments (clear)

  1. In other words. by dreamchaser · · Score: 4, Insightful

    In other words, over 7 out of 10 IRC users and 4 out of 10 Facebook users are utter idiots.

    1. Re:In other words. by hitmark · · Score: 3, Insightful

      even if one is not, a small unsuspecting moment is enough to get caught.

      --
      comment first, facts later. http://chem.tufts.edu/AnswersInScience/RelativityofWrong.htm
    2. Re:In other words. by Anonymous Coward · · Score: 3, Insightful

      I'm not so certain about that. IRC users tend to be more technically competent than people that just use Facebook or e-mail. How many of these people had Firefox with NoScript, for example? Malicious links would've been virtually worthless in such a case.

      Merely clicking doesn't prove much without giving out more information, imo.

  2. Council is leading the witness... by garyisabusyguy · · Score: 4, Interesting

    Aside from all of the fun with malicious code and all, the potential to lead people down a mental path through 'conversation' seems to have the potential to expose a LOT of people to make self-incriminating statements

    It's like a photo-radar gun for thought crime, an investigator doesn't even have to be there to do it. Just set your bots out there to lead people into talking about laundering money, seducing teens, killing their neighbor and WHAMO an adventurous district attorney is pressing charges.

    Nah, what was I thinking, we live in way to free of a society for that to ever happen. What a relief

    --
    Wherever You Go, There You Are
  3. And what's new? by Dumnezeu · · Score: 5, Interesting

    I did something similar for a friend, helping him pick up women on IRC. The bot learned his usual questions and if they answered about 10 questions, it meant they were interested in him and the bot would forward the conversation to him and he continued it. Another time, I wrote an IRC bot for myself; it would act as a man-in-the-middle to pick up women by getting female nicknames and then forwarding the messages it got to other female-like nicknames it detected. If the conversation went long enough, it forwarded everything to me and I would pick up the chat from there.

    --
    Yes, it's sarcasm. Deal with it!
    1. Re:And what's new? by Anonymous Coward · · Score: 4, Funny

      That's not creepy AT ALL

  4. Re:No by maxwell+demon · · Score: 3, Funny

    Can we get back to a world where a person said something after they gathered information on it?

    Well, he didn't write that. A bot changed it during submission. :-)

    --
    The Tao of math: The numbers you can count are not the real numbers.
  5. Re:The PSA campaign by maxwell+demon · · Score: 3, Funny

    Indeed, I only trust the zeroes, not the ones.

    --
    The Tao of math: The numbers you can count are not the real numbers.
  6. I did something more interesting... by goruka · · Score: 5, Funny

    For the lulz, about 10 years ago, I created an IRC bot that connected to #sex and #cybersex in dalnet, and pretended to be a young girl awaiting for cyber..
    Then it would interconnect pairs of two who would talk to her and forward the message, but this didn't work for long because they'd soon figure out the opposite partner was of the same sex. So i added a functionality that would flip words, example penis vagina, boobs balls, and would intercept some messages (like if a peer requested a picture, or ASL request) and send a fake ASL or URL of a hot chick. After a few attempts, most of the pairs ended up having cyber anyway!
    Even though bizarre phrases happened (like "I want to insert my 8 inch vagina into your deep wet penis") most people amazingly didn't even find it strange, and even though it was probably left running all night and created more probably a hundred "encounters", no one even suspected a tiny little about what was going on, no one!

    1. Re:I did something more interesting... by noidentity · · Score: 3, Funny

      Even though bizarre phrases happened (like "I want to insert my 8 inch vagina into your deep wet penis") most people amazingly didn't even find it strange, and even though it was probably left running all night and created more probably a hundred "encounters", no one even suspected a tiny little about what was going on, no one!

      So you're the one who made me gay!!!!!!!