[HN Gopher] How are cyber criminals rolling in 2025?
___________________________________________________________________
How are cyber criminals rolling in 2025?
Author : vin10
Score : 147 points
Date : 2025-05-05 15:33 UTC (7 hours ago)
(HTM) web link (vin01.github.io)
(TXT) w3m dump (vin01.github.io)
| SoftTalker wrote:
| Among the common vulnerabilities listed:
|
| > Outdated Wordpress plugins and CMS systems
|
| No surprise, having worked in edu the following scenario was very
| common:
|
| 1) Researcher gets a grant for a project
|
| 2) Grad student sets up a Drupal site for the project
|
| 3) Things are maintained and updated for a couple of years
|
| 4) Grant runs out, project wraps up, student graduates, everyone
| forgets about the server which sits unattended and unmaintained.
|
| Still happens, but most universites have really clamped down on
| the ability to just stand up a web server on the network. Many
| are requiring everything to be on a centrally managed enterprise
| CMS which is a PITA but that's the fallout for too much sloppy
| administration.
| notyourwork wrote:
| Yep, I remember having ssh access to production servers from a
| non-work machine at a well known university.
|
| We could also get external ips and connectivity without much
| supervision. Core security needs to be prioritized to avoid
| this from happening.
| semi-extrinsic wrote:
| At my old university ~15 years ago, all IPs of all computers
| were _public IPV4 addresses_. Any computer plugged in to any
| ethernet port on campus was given such a "quasi-static" IP
| address. All normal ports were open - ssh, http(s), you name
| it. It was the OG zero trust architecture.
| yjftsjthsd-h wrote:
| > At my old university ~15 years ago, all IPs of all
| computers were public IPV4 addresses. Any computer plugged in
| to any ethernet port on campus was given such a "quasi-
| static" IP address.
|
| Well that's fine; my school did the same thing and other than
| feeling wasteful there was no-
|
| > All normal ports were open - ssh, http(s), you name it. It
| was the OG zero trust architecture.
|
| _Oh._ Yeah, open ports by default is... and interesting life
| choice.
| morkalork wrote:
| When you're living in the residences and there's a DC++
| server running, it's pretty sweet. Ours had a whole 1.5TB
| of stuff on it!
| VoidWhisperer wrote:
| Was this RIT by any chance?
| fecal_henge wrote:
| This just got cancelled at my institution. I could have
| retained it if I argued strongly enough.
| foobarian wrote:
| Ah the good old days of putting my head down at my desk
| lulled into a nap by the once-a-second sounds of ssh login
| attempt logs being written to the spinning rust drive...
| guappa wrote:
| How am I going to work from home if my computer at university
| is not recheable?
| DaSHacka wrote:
| My university does the same, except they understand the
| concept of "firewalls"
| kevin_thibedeau wrote:
| The low friction solution is to serve public_html from a home
| dir and direct users to generate static sites.
| leftcenterright wrote:
| > Norton, Kaspersky, Zscaler, F-secure, NordVPN, Virustotal, Palo
| Alto: all of them marked these links as safe.
|
| This is sad to see, these tools are forced down so many companies
| in name of "compliance" while totally not worth the maintenance
| and cost overhead. Apparently they haven't got any better in the
| last decade.
| charcircuit wrote:
| I'm curious if the link inside the pdf would have been
| detected.
| vin10 wrote:
| It is the same for nested links as well. They mostly have a
| chain of links, each one taking you to a new one with hop
| count ranging anywhere from 5 up to 10 or more.
| Muromec wrote:
| Well, that's exactly the difference between complience and
| security
| markbeare wrote:
| I work for a cybersecurity company, and I think that the method
| they used to check these links with the mentioned security
| companies was not a reflection of how they detect. I'm sure
| that many of these companies do not have these domains in their
| DBs of bad sites but if you were to run these products and then
| visit the site then heuristic detection would have likely
| flagged the sites.
| superkuh wrote:
| These days most "cyber" crimes are commited by corporations
| against their customers/users (just like most theft is wage
| theft). These small fish/phish putting sites on exploited servers
| are a drop in the bucket. It is sad when some university resource
| gets shut down because they didn't mantain it after the grad
| student that set it up graduates though. We really need to teach
| the people that set up these things to use .html pages instead of
| dynamic languages and databases.
| neffy wrote:
| Sure. Corporations commit ransomware attacks all the time.
| gitroom wrote:
| damn, i remember seeing old servers just getting dusty and full
| of holes after the student left. kinda crazy how much messy stuff
| is hiding in corners like that lol
| 3abiton wrote:
| >
|
| I have been advised not to disclose specific vulnerabilities
| since the parties involved are not most friendly and transparent
| in handling security reports. While most of these got reported
| and some even got fixed, I can only disclose high-level details
| of the compromise path. Some just ghosted me after conveniently
| fixing the flaws, and one even gave me a phone call, which was
| somewhat scary and perhaps not worth the adrenaline.
|
| What an unprofessional sysadmin move, borderline infuriating.
| fckgw wrote:
| I've noticed on some scam forums and subreddits I frequent that
| scammers have been using target site's own support searches to
| redirect users to scam phone numbers.
|
| On both Ticketmaster and Facebook, and many other sites, when you
| perform a search on their support site it spits back your query
| in big letters at the top of the page. If you craft the correct
| search and then buy Google Ads pretending to be Ticketmaster,
| then you can redirect users to your call center and scam them.
| And because they link for your ad actually links to Ticketmaster
| the ad passes validation and appears to be a legit link in the
| eyes of Google.
|
| Example of a crafted search term:
| https://help.ticketmaster.com/hc/en-us/search?utf8=%E2%9C%93...
| lifeisstillgood wrote:
| So, I craft a search where the search query is "call 1 800
| scam", then I buy a google ad with key word of "ticketmaster
| help", the ad links to real ticketmaster with my query, and
| google shows that ad to someone having trouble and hey presto
| they call my scam line at 4 quid a minute from their mobile?
|
| Yuck all round. I mean ticketmaster is just a sin eater for
| greedy popstars but yuck ..
| albertgoeswoof wrote:
| But why does google allow unverified owners of a domain to
| buy ads for it? Surely only ticketmaster or agencies approved
| by ticket master should be allowed to do this?
| fckgw wrote:
| Not necessarily, if you have an affiliate program or
| something like that you could buy ads for, say, eBay using
| your affiliate link in the hopes of you generating more
| profit than the ads cost.
| progbits wrote:
| Because most of the ads are created by external ad
| agencies, and the people involved are not competent enough
| to do any verification.
|
| Source: I've also thought this was ridiculous and asked
| someone working on the adsense team. Apparently tried
| enforcing some domain verification mechanism in an
| experiment, but most companies and agencies struggled to
| get the verification done and of course the $ metrics on
| this launch dropped, causing execs to force them to stop.
| simonw wrote:
| Maybe a partial solution here would be to offer some kind
| of "domain locking" option?
|
| Allow sites that are heavy targets of this kind of scam -
| like ticketmaster - to add a "AdSense: locked" line to
| their robots.txt (or similar) - if that line is present
| then advertisers have to go through an additional domain
| verification step in order to place an ad.
| charlieyu1 wrote:
| There was a time when you search for WhatsApp in Google the
| first sponsored result is a scam site
| fckgw wrote:
| If you search for "HP Support" or "Dell Phone Number" you
| will get a scam site 50% of the time now.
| jancsika wrote:
| > Yuck all round.
|
| Yes, but also it's an impressive digital Jedi mind trick on a
| website.
|
| _signs a question mark with hand_
|
| "This is the support number you're looking for."
|
| And the victim is extra primed here because so many companies
| make it nearly impossible to talk to a human. Yikes!
|
| Almost seems like there's room here for a grey hat to come in
| and use this trick to do a good faith job trying to help the
| customer through their problem. Then tell them at the end
| that a recent anti-trust suit requires them to tell the
| customer about alternate independent venues in their area
| where they can support live music.
| fckgw wrote:
| Exactly. And when you try and help these people and explain
| that you didn't actually call Ticketmaster support they will
| tell you that they found the phone number on the official
| Ticketmaster website and Google said it was a verified link.
|
| Here's a real example from the same thing happening on FB
| (don't call that number) https://i.redd.it/w9htjqflgjle1.jpeg
| amelius wrote:
| On top of that, you receive private information about people
| from Google, because if someone calls your number, then you
| know that they were on ticketmaster. Replace ticketmaster by
| e.g. a swingers club, and now Google's ad businessmodel is in
| real trouble because it leaks sensitive information.
| RGamma wrote:
| How desperate one has to be...
| OkGoDoIt wrote:
| Have you tried getting ticketing support from Ticketmaster?
| Even a sketchy phone number is better than no option at
| all...
| RGamma wrote:
| I don't mean reaching for support. I mean setting up a scam
| like this. It seems so bottom of the barrel scummy,
| creative too, but mostly scummy.
|
| Imagine you have the creativity and criminal energy to
| conceptualize and operate something like this (and the rat
| tail of justice evasion, laundering money, etc). It seems
| so much easier to make money in the honest economy.
|
| Unless of course you're operating for a rogue state...
| advael wrote:
| You've got a shocking amount of faith in the honest
| economy for this moment in time
| levocardia wrote:
| Wow. Programmatic SEO and its consequences. Genius...
| miki123211 wrote:
| This actually makes sense to me; if you're an artist selling
| tickets on Ticketmaster, it's in everybody's interests to let
| you show ads for those tickets to your fans.
|
| If only the Ticketmaster team could show ads on that domain,
| all these ads would have to go through their marketing team
| (and use ticketmaster's budget, with all the accounting and
| invoicing this requires), which would massively slow things
| down.
|
| Instead, it seems that Google has some kind of protection
| where ads mentioning Ticketmaster must link to their official
| domain, to prevent things like this from happening. The
| scammers just found a way for that domain to display
| arbitrary text.
| redeux wrote:
| I found and removed one of these from my company's forums. When
| I Googled the number I could see it was on a ton of other
| support forums.
| Cyphase wrote:
| I've been seeing similar scams via PayPal. The scammers
| apparently add the target email address as a forwarding address
| on a hacked or created-for-purpose email account. And that
| bouncer email address is signed up for PayPal. So the scam
| email is actually from PayPal, bounced through some other
| inbox. The To name and address is of the bouncer email address
| PayPal sent it to.
|
| One version involves sending money to someone with the PayPal
| account (so the target might think it was sent from their own
| account) with a "note" to the transaction recipient, which the
| target sees, which says PayPal has detected unusual activity
| and please call this phone number to request a refund.
|
| Another involves a "Your ITEM NAME order is on its way" email
| where the item being ordered is called something like, "Some
| Company, Inc: Don't recognize the seller? Call us at SOME PHONE
| NUMBER".
|
| A third is like the second, except it's a "You paid CURRENCY to
| SELLER" email. This one has the PayPal user's name at the top,
| so not as convincing perhaps.
| pnw wrote:
| FWIW I sent this to a friend on the dev team at Ticketmaster
| and they escalated it.
| DyslexicAtheist wrote:
| john wick site:europa.eu
| https://www.google.com/search?q=john+wick+site%3Aeuropa.eu&h...
|
| gta 5 site:europa.eu
| https://www.google.com/search?q=gta+5+site%3Aeuropa.eu&hl=en
|
| Watch full site:europa.eu
| https://www.google.com/search?q=Watch+full+site%3Aeuropa.eu&...
| leftcenterright wrote:
| could someone with legal/data-privacy expertise comment if this
| would be something they have to disclose under data breach
| disclosure laws?
|
| Technically it might not be a "data leak", but it very well
| could result in one if arbitrary content (including js?) can be
| uploaded to these webpages?
| DyslexicAtheist wrote:
| they've been contacted through the "proper channels" over 18
| months ago by several (more than 1) security researchers.
|
| After some people started publicly naming and shaming on
| LinkedIn and tagging ENISA, the issue got some exposure, but
| still was not fixed. It only made it more evident that
| several people independently reported these issues, and they
| became aware of peers stumbling over the issue. Still nothing
| happened.
|
| ENISA is supposed to act as a CNA and expects to be notified
| of data breaches from EU based orgs for PSIRT / CSIRT as part
| of the Cybersec Resiliance Act and other laws.
|
| Would I trust that vulnerability data that gets reported as a
| CVE, or a breach notification is safe with ENSIA ?
|
| ... feck no!
|
| Would I trust that documents that europa.eu hosts on its
| infra are authentic? (such as security-compliance documents
| telling orgs how to properly implement security, but
| literally any public communication under one of the domains)
|
| ... hecking heck no!
|
| ... At this stage I think everyone else except ENISA has
| control over their infrastructure.
| b0m wrote:
| When clicked, all show: page not found
|
| So, fixed now?
| Alex-Programs wrote:
| Is it just me or is cybersecurity... Calming down? I feel like a
| few years ago there was constant news of ransomware, intrusions,
| vulnerabilities, etc, but more recently the defensive side seems
| to have the upper hand.
| chelmzy wrote:
| Not particularly. The only thing I have noticed in the past
| decade is the decline of the "American Hacker". Most groups are
| foreign but will partner with younger Americans for social
| engineering (ex. Scattered Spider). You just don't have people
| like Albert Gonzalez/Stephen Watt in America now. However, I
| suspect that many American hackers have shifted to targeting
| overseas countries that are not friendly with the US.
| alcover wrote:
| > You just don't have people like Albert Gonzalez/Stephen
| Watt in America now
|
| I don't know what the state of big corps netsec is today but
| these guys had it somewhat easy. They got initial access
| through weak wifi then pivoted with SQL injects and such.
| candiddevmike wrote:
| You only hear about the offensive side winning when the company
| can't prevent it from leaking. Rest assured, the only thing
| "calming down" in cybersecurity is the nihilism that nothing
| involving a human will ever be secure.
| wood_spirit wrote:
| They create meme coins etc?
| mhuffman wrote:
| I am surprised no one mentioned using LLMs to spell and grammar
| check their emails and vibe-code bank landing-pages to continue a
| more polished version of scamming elderly people out of their
| life savings.
| curiousgal wrote:
| The misspellings/shitty grammar are on purpose.
| mhuffman wrote:
| I have heard that theory from some cybersecurity experts
| online but have never seen it substantiated in any way (by
| interviewing some scammers, for example) and frankly don't
| believe it.
|
| The misspellings and grammatical errors (used to?) continue
| on the fake sites that are created to steal credentials, and
| the excuses for most of the reasoning regarding emails do not
| hold there.
| yapyap wrote:
| Honestly you are always (half) a step behind and that's for the
| worst cyber criminals cause the state sponsored ones are multiple
| steps ahead.
|
| It's very interesting to look at from the outside, thanks for
| sharing.
| ValdikSS wrote:
| Once upon a time I typed something like `r57shell gov` and got a
| PHP webshell on *.gov.br
___________________________________________________________________
(page generated 2025-05-05 23:00 UTC)