Comment on Israeli Mossad launches cyber challengeComments−tdhoot7yIn case you didn't want to wait for the slow-typing to load the entire message:"Welcome Agent.A team of field operatives is currently on-site in enemy territory, working to retrieve intel on an imminent terrorist attack.The intel is contained in a safe, the plans for which are available to authorized clients via an app [0].Our client ID is d09ff4ec651c48f89f7f7aa19160bd55Your mission is to retrieve those plans, and allow our team to break into the safe.Good luck!, M." [0]: http://3d375032374147a7865753e4bbc92682.xyz/static/app.apk−ChuckNorris897yAre they seriously expecting people to sideload a mossad apk on their phones?−nickelcitymario7yIf you're dumb enough to do that... maybe they blacklist you from their recruitment efforts moving forward.You could always install it on a virtual phone in a sandboxed VM.−dclusin7yWhat do you do if they have sandbox escapes you don't know about? The kind of person that runs it in a VM is someone they'd probably want to be looking at.Paranoia++ :)−pmiller27yDownload to a burner machine, then airgap it by removing/disabling all networking hardware, inside a room with no other computers. ;)−Scoundreller7yThen sell the system to an unsuspecting soul on eBay.−Paraesthetic7yOr gumtree−saagarjha7yYou’re probably expected to load it into your favorite static analysis tool.−TheLoneTechNerd7yOf course not, it would be prohibitively difficult to deconstruct the apk from the phone itself.−dontbenebby7yI couldn't even get to refusing to trust an apk because their message doesn't render if you have a JS whitelisting extension such as NoScript.−kps7yIt's all in the page source, though.
Comments
In case you didn't want to wait for the slow-typing to load the entire message:
"Welcome Agent.
A team of field operatives is currently on-site in enemy territory, working to retrieve intel on an imminent terrorist attack.
The intel is contained in a safe, the plans for which are available to authorized clients via an app [0].
Our client ID is d09ff4ec651c48f89f7f7aa19160bd55
Your mission is to retrieve those plans, and allow our team to break into the safe.
Good luck!,
[0]: http://3d375032374147a7865753e4bbc92682.xyz/static/app.apkAre they seriously expecting people to sideload a mossad apk on their phones?
If you're dumb enough to do that... maybe they blacklist you from their recruitment efforts moving forward.
You could always install it on a virtual phone in a sandboxed VM.
What do you do if they have sandbox escapes you don't know about? The kind of person that runs it in a VM is someone they'd probably want to be looking at.
Paranoia++ :)
Download to a burner machine, then airgap it by removing/disabling all networking hardware, inside a room with no other computers. ;)
Then sell the system to an unsuspecting soul on eBay.
Or gumtree
You’re probably expected to load it into your favorite static analysis tool.
Of course not, it would be prohibitively difficult to deconstruct the apk from the phone itself.
I couldn't even get to refusing to trust an apk because their message doesn't render if you have a JS whitelisting extension such as NoScript.
It's all in the page source, though.