🪟 Windows TippsHow to Enable Windows 11 Screen Savers(07.09.2026 um 12:41 Uhr)
🪟 Windows TippsMicrosoft Phone Link Not Showing Messages on Windows 11? Fix It(09.09.2026 um 07:52 Uhr)
⚠️ Malware / Trojaner / VirenPost-DEF CON phishing campaign delivered AMOS and NetSupport malware(24.08.2026 um 09:42 Uhr)
💾 IT Security ToolsHow to Use BloodHound Active Directory Setup Attack Path Analysis(10.09.2026 um 14:35 Uhr)
🕵️ SicherheitslückenCompliance Alert: EU Cyber Resilience Act 24-Hour Reporting Enforced(11.09.2026 um 06:25 Uhr)
🕵️ SicherheitslückenAWS IAM Privilege Escalation: Cheat Sheet And Defense(11.09.2026 um 07:43 Uhr)
🕵️ SicherheitslückenArista warns customers ahead of next week’s security disclosures(02.09.2026 um 23:34 Uhr)
🕵️ SicherheitslückenKARR Security vulnerability(02.09.2026 um 03:15 Uhr)
🪟 Windows TippsHow to Enable Windows 11 Screen Savers(07.09.2026 um 12:41 Uhr)
🪟 Windows TippsMicrosoft Phone Link Not Showing Messages on Windows 11? Fix It(09.09.2026 um 07:52 Uhr)
⚠️ Malware / Trojaner / VirenPost-DEF CON phishing campaign delivered AMOS and NetSupport malware(24.08.2026 um 09:42 Uhr)
💾 IT Security ToolsHow to Use BloodHound Active Directory Setup Attack Path Analysis(10.09.2026 um 14:35 Uhr)
🕵️ SicherheitslückenCompliance Alert: EU Cyber Resilience Act 24-Hour Reporting Enforced(11.09.2026 um 06:25 Uhr)
🕵️ SicherheitslückenAWS IAM Privilege Escalation: Cheat Sheet And Defense(11.09.2026 um 07:43 Uhr)
🕵️ SicherheitslückenArista warns customers ahead of next week’s security disclosures(02.09.2026 um 23:34 Uhr)
🕵️ SicherheitslückenKARR Security vulnerability(02.09.2026 um 03:15 Uhr)
1 Tag Serie
🕵️ Reverse Engineering 🕛 vor 10 Jahren 5 Min Lesezeit
0

When Scriptkiddies Attack

↗ Quelle (malwaretech.com)
🗣️ Stimme:
Usually I don't blog about the hundreds of ridiculous or down right crazy emails I receive each year, but this exchange makes all the others seem completely reasonable in comparison. Normally my unwanted emails range from people asking obviously blackhat questions presented as whitehat questions to offers of under the table payments in return for coding malware, but this email was something special.

If you don't follow me on twitter (Why don't you follow me on twitter? ), I've been spending a while working on

Within a couple of minutes of tweeting, I received the following email from someone with a name matching that of one of my followers.

I particularly like this one for a couple reasons: If I wasn't such an upstanding citizen, I think my idea of being "blackhat for one second" would involve something a little more profitable and ambitious than giving out free malware to scriptkiddies (but I guess that's what blackhats do???) and the fact that he claims to have a remote RDP exploit and flash zeroday, but the best monetary amount he can offer is $50.

You can probably guess what the next email is if you're familiar with the popular phrase: "If at first you don't succeed, then result to blackmail".

I also looked up his facebook page and went through the pictures, but due to some CIA grade redaction I doubt we'll ever know his real name.


The hosting service he was using to "bumb" me kept killing the flood due to failures, so my inbox was hardly being overwhelmed by the volume. After about an hour of the world's lamest email flood, it ceased and i received another few mails from our friendly neighborhood hacker.


It's quite common for colleges and universities to allocate official sub-domains for different faculties and delegate management to faculty staff and even students, resulting in them often getting hacked. This specific sub-domain seems to have been accessed by various different hackers and the directories are full of strange files (I'm not really sure who to contact about the shell, so if you're associated with Harvard feel free to email from an official mail for the full link or contact the site administrator.).

Based on the shell link, I had already figured what his next threat would be and had saved some screenshots of the emails and link just in case; sure enough after another hour I received these two emails around 5 minutes apart.

Damn it Paul, stop chmodding your directory to 777Creating a sub-page in a sub-directory of a sub-domain of a sub-domain, wow this MalwareTech guy really knows his stuff...

As of writing this the deface page is still up, but that's not really a surprised seeming as it's not even an index page or in an actively used directory.

in one of my tweet threads, this could potentially be high risks as sub-domains have the ability to read certain cookies set using the parent domain, i.e .harvard.eu.

But wait! The fun didn't even stop there: before I went to bed I received a few more threats.


This is the point where he realized I'd been live tweeting the whole thing and decided to instead blackmail me into deleting my tweets (because obviously blackmailing me had gone well for him so far?).

I then received one final email before he gave up with the threats (or at least I assume he did).


lol, gg.


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf malwaretech.com.
↗ Original-Artikel auf malwaretech.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
Microsoft Phone Link Not Showing Messages on Windows 11? Fix It
1 Quelle
How to Enable Windows 11 Screen Savers
1 Quelle
Post-DEF CON phishing campaign delivered AMOS and NetSupport malware
Ähnliche Beiträge
🔍 Verwandte News

Ähnliche Beiträge zu When Scriptkiddies Attack

Thematisch verwandte Begriffe: When, Scriptkiddies, Attack · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...