Slashdot Mirror


Turning the Tables On "Phone Tech Support" Scammers

mask.of.sanity writes A security pro has released a Metasploit module that can take over computers running the Ammyy Admin remote control software popular among "Hi this is Microsoft, there's a problem with your computer" tech support scammers. The hack detailed in Matthew Weeks' technical post works from the end-user, meaning victims can send scammers the hijacking exploit when they request access to their machines. Victims should provide scammers with their external IP addresses rather than their Ammyy identity numbers as the exploit was not yet built to run over the Ammyy cloud, according to the exploit readme. This is much more efficient than just playing along but "accidentally" being unable to follow their instructions.

1 of 210 comments (clear)

  1. Re:How about by Wycliffe · · Score: 5, Interesting

    THEM: Hi this is Microsoft and...
    US: hang up
      Done. Fuck this war.

    That's exactly what they want. It's the same reason that scammers say they are from nigeria even when they aren't.
    They don't want to talk to you. They want the non-gullible to hang up as quickly as possible so they can quickly find
    the little old lady who they can steal from. They called my mom and luckily she had 2 things going for her. First,
    she doesn't know enough to actually follow their instructions and second, she called me. Otherwise she would
    probably be out some money and I would be left cleaning up the mess. So sure, it's easier to hang up on them but
    you are actually doing them a favor and helping them out by doing so.