Do not trust anything I write down. I have this horrible habit of not checking sources.

  • 1 Post
  • 25 Comments
Joined 1 year ago
cake
Cake day: July 3rd, 2023

help-circle






  • Key Points

    GitHub search manipulation: Attackers create malicious repositories with popular names and topics, using techniques like automated updates and fake stars to boost search rankings and deceive users.
    
    
    Malicious code is often hidden within Visual Studio project files (.csproj or .vcxproj) to evade detection, automatically executing when the project is built.
    The attacker had set up the stage to modify the payload based on the victim's origin, checking specifically if the victim is based in Russia. At this point, we don't see this ability activated.
    
    
    
    The recent malware campaign involves a large, padded executable file that shares similarities with the "Keyzetsu clipper" malware, targeting cryptocurrency wallets.
    The malware establishes persistence on infected Windows machines by creating a scheduled task that runs the malicious executable daily at 4AM without user confirmation.
    
    
    
    Developers should be cautious when using code from public repositories and watch for suspicious repository properties, such as high commit frequencies and stargazers with recently created accounts.
    

    edit: formatting










  • you missed this part:

    For Terrapin to be viable, the connection it interferes with also must be secured by either “ChaCha20-Poly1305” or “CBC with Encrypt-then-MAC,” both of which are cipher modes added to the SSH protocol (in 2013 and 2012, respectively). A scan performed by the researchers found that 77 percent of SSH servers exposed to the Internet support at least one of the vulnerable encryption modes, while 57 percent of them list a vulnerable encryption mode as the preferred choice.





  • I agree. Moving to another country, even if it is on paper requires money. So does a therapist. I’m in a better position than op and I don’t get a therapist although I could use one.

    Self study is important though. speaking from experience with the same life experience as op, learning a new trade and going with it has changed my life for the better by a lot. finding the right (paying) employerin the trade is a bit of work (years). some jobs just don’t pay enough to live off. I know it’s wrong.

    A tip I can give op is to put the savings in a bank account you don’t have access to. in the same of somebody else. I went through a period of cash only. This was pre-smartphone, so transfers between accounts required me to go to the bank. Perhaps move financial applications to a secondary phone if you have one, or install when needed.