logoalt Hacker News

thedougdtoday at 12:58 PM2 repliesview on HN

I've done this exact approach before. It's a good way to exfiltrate data. Post the software on GitHub pages, or a popular CDN that co-hosts other shared libraries and you've got a very difficult to block method.

Really goes to show that it's very difficult to stop a motivated and informed actor.


Replies

skinfaxitoday at 1:30 PM

If you can connect to Github pages couldn't you exfil that way? This takes 2 mins for 100KB.

show 1 reply
skeptic_aitoday at 2:42 PM

Npm install qr-made-up-name Can show qr in console. How do you stop that?

show 1 reply