Slashdot Mirror


Syrian Social Hack Co-Opts Fighter's Computers

hij (552932) writes "The BBC is reporting that Syrian government forces used a social hack to gain access to opposing forces computers. By acting like women sympathetic to their cause they were able to send images laced with malware to the fighters. From the article: "Fake 'femme fatales' have been used to steal battle plans and other data from Syrian opposition groups, a report suggests. The virtual women had been used in text chat on Skype to engage potential victims, security company FireEye said. And data had been stolen via booby-trapped images of the women to whom the victims had believed they had been chatting."

18 of 71 comments (clear)

  1. booby-trapped by Anonymous Coward · · Score: 5, Funny

    Gives a new meaning to the name.

    1. Re:booby-trapped by doug141 · · Score: 2
  2. Genesis by ColdWetDog · · Score: 2

    It's always a woman's fault.

    --
    Faster! Faster! Faster would be better!
    1. Re:Genesis by GrumpySteen · · Score: 2

      No, it's God's fault. He's omniscient so he knew exactly what was going to happen when he created the tree, the serpent and the fallible humans who wouldn't be able to resist the temptation, but he went ahead and did it anyway. It was a goddamned setup from the very beginning.

  3. Honey Dicked by Anonymous Coward · · Score: 2, Funny

    Honey Dicked

  4. who still falls for this picture.jpg.exe nonsense? by Anonymous Coward · · Score: 5, Interesting

    A random stranger sends you an executable file and tells you it's their picture. Go ahead, click on it.

    Yeah, seems legit. Come on.

    Anyone who falls for such transparent hacking attempts deserves what they get.

  5. In related news... by dfn5 · · Score: 5, Funny

    Opposition forces complain sympathetic women never look like their photos.

    --
    -- Thou hast strayed far from the path of the Avatar.
  6. If you want to see a sexy shot of my ankle by NotDrWho · · Score: 3, Funny

    "I'll lift my burka slightly if you'll click on this exe file"

    "Okay, sexy girl. But I should warn you that afterwards there is a good chance I'm going to stone you to death for being a whore."

    --
    SJW's don't eliminate discrimination. They just expropriate it for themselves.
  7. Re:who still falls for this picture.jpg.exe nonsen by tlhIngan · · Score: 4, Informative

    A random stranger sends you an executable file and tells you it's their picture. Go ahead, click on it.

    Yeah, seems legit. Come on.

    Anyone who falls for such transparent hacking attempts deserves what they get.

    Lots of people do. it's called Dancing Pigs (or rabbits) and is probably the biggest security hole in computing today.

    We like to complain about Apple's walled garden and such, but such a security model isn't governed from Jobs' ass - it came from deep understanding that humans are vulnerable, and most malware attacks take advantage of that vector. From sending seniors "hey, I'm your nephew, send me $100" scams to "I'm trapped in London, wire me $2000 for a plane ticket" sent to friends.

    It doesn't take much to go beyond that - just get the person's trust and you can accomplish a lot. It's a lot more like spear phishing than anything - the user trusts the source and the guard goes down. Hell, I'm sure if you did a survey, most parents would click on an attachment if it appeared to be sent from their children, especially if said child works in IT. Perhaps even your parents will think "well, if he sent it, it must be something I need to do".

  8. Re:who still falls for this picture.jpg.exe nonsen by mlts · · Score: 4, Interesting

    One of my E-mail accounts (relegated to being the spam/swill account with filters to scoop up anything from the sources I might use) that has been around since the 1990s still gets plenty of those, either "foo.jpg.exe or "foo.jpg .exe" with plenty of spaces between the two.

    Part of why this happens is the Dancing Bunnies hole. The receiver really wanted to see what the sender wanted to send, so ignored common sense.

    I've had this happen, when I thought the other person decided to have an auto-extracting document. Since it wasn't confidential, I uploaded the executable to virustotal, found that others had uploaded the same thing, it was a known Trojan. End of story. Had I still been unsure, I'd have put it in a virtual machine that is isolated from any physical network as a sandboxed user with zero privs. This, I do sometimes if I need to download some program from a download mirror, one notorious for wrapping the installer with their own scumware, so I can pull out the actual program installer out of the archive. The scumware happily installs and seizes control of the VM, but I then can use the extracted original files on a clean VM after I roll back to a known good snapshot.

    The best defense we have against malware is virtualization. Infecting a machine is relatively easy. Jumping out and nailing the hypervisor or the bare metal... not so much.

  9. Re:who still falls for this picture.jpg.exe nonsen by Anonymous Coward · · Score: 2, Interesting

    According to the second link (PDF warning) it was "picture.pif" which was just a renamed self-extracting RAR containing both a photo and a RAT payload.

    Now how many people - nerds included - could tell you what a .pif is off the top of their head? Admit it, plenty of you (myself included) would have to look it up because it's probably not something we encounter every day. The real difference between someone who falls for it and someone who won't is that the latter will think "If I don't recognize it I'm not touching it with a 10 foot pole" and the former goes "PIF sort of resembles PICture, maybe it's a PIcture File? Screw it, I want to see if she's a hottie." So yeah, sadly this kind of bait (with sex) and switch stuff still works and probably won't stop working until our species is extinct.

  10. Doesn't matter how 'religious' these guys are by fustakrakich · · Score: 2

    The porn will get 'em every time. An exploit that is very difficult to patch without employing a most unpalatable procedure.

    --
    “He’s not deformed, he’s just drunk!”
    1. Re:Doesn't matter how 'religious' these guys are by bobbied · · Score: 3, Insightful

      The porn will get 'em every time. An exploit that is very difficult to patch without employing a most unpalatable procedure.

      You mean using Unix?

      --
      "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
  11. Re:who still falls for this picture.jpg.exe nonsen by TheCarp · · Score: 3, Funny

    Doesn't even need to be that sophisticated. I was dealing with one of these "Fake women" once who I was stringing along because I knew it was a scam and so it was kind of fun to toy with the scammer.

    It was simple, I uploaded a random picture to a webserver I controlled and told "her" to check it out and when I saw her reply without any logs on my server, I asked a question that would require looking at the photo to answer.... bingo.

    I waited a few more minutes of chat while I looked up the IP registration info and shocked "her" by revealing I knew "she" was in Nigeria. Oh that was funny.

    Soon after the game changed, and now he wanted to recruit me to remail packages. Strung him along for many weeks, it was kind of a fun hobby for a while.

    --
    "I opened my eyes, and everything went dark again"
  12. Re:who still falls for this picture.jpg.exe nonsen by penguinoid · · Score: 2

    Anyone who falls for such transparent hacking attempts deserves what they get.

    Well, considering that these are people who are willing to risk their lives to fight against the government, possibly having been recruited by social engineering, they might not be the sort of people who give a crap about risk. Or to put it another way, having a lot of balls may make them more susceptible to booby traps (now featuring real boobies!).

    Also, forgive me if I don't cheer for either side, when one side is the oppressive dictators favoring an unpopular secular/Shi'ite religious view, and the other side is the rebels favoring a more oppressive Sunni religious regime.

    --
    Don't waste your vote! Vote for whoever you want, unless you live in a swing state it won't matter anyways
  13. Re:Alien vs Predator by HornWumpus · · Score: 2

    Root for? You must be Australian.

    You supply whoever is losing at the moment with a few extra rounds. Maintain the stalemate. See also Iran/Iraq under Reagan.

    --
    John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
  14. Re:who still falls for this picture.jpg.exe nonsen by spitzak · · Score: 2

    So what they see is "picture.jpg" If they don't notice the picture icon next to it that would be the same as a .exe, then they fall for it.

    Actually it will show the embedded icon from the .exe which can easily be set to look like a picture file.

    But what has always confused me is the filename actually shows as "picture.jpg", while an actual picture.jpg would show as just "picture", right? Therefore it should still be possible to distinguish them because a real one does not have ".jpg". Though I can imagine people not noticing, I'm wondering if there is (or was) a much worse bug, such as the display truncating at the first period while file-type lookup used the last period?

    Anybody know? I don't have windows here to test.

  15. Re:Or actual women, something better to do. Works by gerddie · · Score: 2

    Or get them some actual women, ...

    The sad truth is that they actually have women ... enslaved.