Skip to content

Comment on Iranian Hackers Post Images Over JFK Airport From UAV That Was Hijacked In Marchparent

Comments

...why? Because it's arabic? Ooohhh, scary arabic. Or they're talking about spies and bombs? Don't we talk about those things on hacker news too?

I can't read it, I'm working my way through the google translation and just starting, so maybe it's all "bad" stuff, but to be honest, I hope iranians can shed some light on what our government is doing - the US government itself certainly isn't going to help with that.

It's Persian :) Very similar script, completely different language family. Persian is closer to English than Arabic.

[deleted]

[deleted]

I guess it would really blow your mind if we told you that this language is also in the same language family as English, German, and French (Indo-European).

Actually the challenge is drive-by injection not the site per-se. Chrome didn't flag it as such but if you spend time crawling the web you will notice that it is a not-unusual weapon in the arsenal to put up a <attractive to people we're looking for> web site, and have it inject visitors with a tracking cookie/script/trojan. Sort of a variation on honeypots.

Thus it helps to be alert when popping into such sites.

If you know enough to be scared of drive-by injections, it's better to use NoScript than rely on other people always giving warnings. What if the poster (with an account 4 days old) was actively trying to be malicious, and nobody had noticed it yet?

Do not run JS or Flash on untrusted websites.

Or display any compressed image, or even download compressed javascript that you aren't going to run. A number of exploits that malwaredomains.com finds are objects that are either normally or optionally compressed, and constructed in such a way to exploit an issue with the decompression software used.

If I'm both curious and suspicious (so in my most tin-hatish of moods) I fire up a virtualbox instance with a clean image, look at the site, and then delete that virtual machine image. That seems to also have an unintended prophylactic effect since virus investigators like to run viruses in VMs so malicious payloads don't fire if they detect they are running in a VM (at least according to the F-secure blog).

But either way, my point was that just visiting a site that wants to get you is a risk, whether or not you think you are protected.

I googled "site:malwaredomains.com compression" and nothing turned up. Can you recall any instances? Do you know where they get the data from? I must be missing something obvious but I don't see where the describe the how the list is created.

NB: I am not disagreeing with you I am just curious to look at some of the recent compression vulnerabilities.

Here is a great place to start: https://www.google.com/search?q=jpeg+decoder+exploit&oq=jpeg...

Note there have been various fixes, and you can often tell when you see one because you get a 'broken image' icon rather than a picture and an new friend. The compressed Javascript exploits were primarily tied to pdfs apparently (you can search for 'compressed js exploit') and then look for "gif decoder exploit" and of course the whole cross site scripting thing which when you're building a web site to compromise people its not a 'bug' that it has a cross site exploit vulnerability per se :-)

Basically anything that 'decompresses' is effectively a data driven computation engine where the bad guys can feed an arbitrary stream of data into that engine to make it do unexpected things. Whether it was the font exploits in Stuxnet and elsewhere or pdf exploits or jpeg exploits. Sadly it has been a target rich environment in the past.

My fault. I was looking for the javascript compression vulnerabilities. I'm sorry I did not mention that.

You know, I feel the same way. They may be our enemies and want to destroy us, but being able to see their side of things is refreshing. We can't continue to act like we're the perfect country and everyone else is 100% evil. It's not that simple.

The Iranian government has no point of view worth its salt. It's a repressive regime and the more we buy into their crap the more we're actually harming the people of that country.

You may be right that they have no worthwhile point of view and I don't think I know anyone who actually "buys into their crap".

But the idea of somehow avoiding ever encountering a certain point of view on the global internet is even more stupid.

I wonder if right now we could replace the word "Iranian" with "US" and it would still be true?

Hey easy on the hot keywords we are all gonna get flagged by the thought police.

The thought police flag anyone who thinks about the thought police.

Maybe we should do what they do in china when speaking on such topics… idea sentries has a nice ring.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.