logoalt Hacker News

Using Hinge as a Command and Control Server

101 pointsby mattwieselast Sunday at 2:08 PM49 commentsview on HN

Comments

hobofanlast Sunday at 6:03 PM

I'm not really into malware, so I was just wondering:

- Isn't this really non-viable in practice? The "few headers" that were shown include an Authorization header, that would presumable rotate every ~24 hours and would have to rotate for all the malware clients as well.

- Are centralized Command and Control Severs still a thing in the malware space? I would have assumed that this function mainly migrated onto one of the popular blockchains with clients using one of thousands of available gateways for reading.

show 3 replies
kachapopopowlast Sunday at 7:26 PM

speaking of command and control servers, the best one you can get at the moment is to just to use crypto currencies, plenty of available nodes to auto discover or just rely on explorers to query your own wallet, deposit address can encode quite a bit of information since it's a pretty long address and definitely has enough bytes to encode commands

show 2 replies
stackghostlast Sunday at 6:07 PM

I think the Hinge being referred to is a dating app? I have no idea.

https://hinge.co/

show 3 replies
levzettelinlast Sunday at 5:37 PM

Could someone ELI5 what this does?

show 3 replies
octoberfranklinlast Sunday at 7:33 PM

Um, use an app that requires you submit to video facial recognition to make an account?

So that you can then use that account, which is tied to your biometrics, for lawbreaking?

Wut?

show 2 replies
bschmidt25002last Sunday at 9:02 PM

[dead]