Skip to content

Comment on Israeli Mossad launches cyber challenge

Comments

In case you didn't want to wait for the slow-typing to load the entire message:

"Welcome Agent.

A team of field operatives is currently on-site in enemy territory, working to retrieve intel on an imminent terrorist attack.

The intel is contained in a safe, the plans for which are available to authorized clients via an app [0].

Our client ID is d09ff4ec651c48f89f7f7aa19160bd55

Your mission is to retrieve those plans, and allow our team to break into the safe.

Good luck!,

    M."
[0]: http://3d375032374147a7865753e4bbc92682.xyz/static/app.apk

Are they seriously expecting people to sideload a mossad apk on their phones?

If you're dumb enough to do that... maybe they blacklist you from their recruitment efforts moving forward.

You could always install it on a virtual phone in a sandboxed VM.

What do you do if they have sandbox escapes you don't know about? The kind of person that runs it in a VM is someone they'd probably want to be looking at.

Paranoia++ :)

Download to a burner machine, then airgap it by removing/disabling all networking hardware, inside a room with no other computers. ;)

Then sell the system to an unsuspecting soul on eBay.

Or gumtree

You’re probably expected to load it into your favorite static analysis tool.

Of course not, it would be prohibitively difficult to deconstruct the apk from the phone itself.

I couldn't even get to refusing to trust an apk because their message doesn't render if you have a JS whitelisting extension such as NoScript.

It's all in the page source, though.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.