• ColdWater@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    I tried it and it’s not working for me, my terminal is super+T and paste is Ctrl+Shift+V

  • LillyPip@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    Kinda brilliant to disguise malware as a captcha, though. I won’t be surprised.

    • dan@upvote.au
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 days ago

      Except for the fact that a lot of less tech savvy people will fall for it.

  • ghurab@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    This reminds of when I was 13 I used to tell my opponents in Warcraft 3 that pessing alt+q+q quickly reveals the map. It’s a shortcut for closing the game. Worked way to many times

    I do see this working

  • seth@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    Followed instructions but verification failed, seems like nothing happened except dick got stuck in toaster again. Using Arch, btw.

  • cmrn@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    As someone tech literate that looks hilarious to follow through with.

    But if not, that really does seem similar to a normal captcha with fairly simple steps.

  • x00za@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    Anybody got more info on the actual payload?

    powershell.exe -eC [payload_w_base64] is mentioned here.

    -eC just means encoded command afaik.

  • BetaDoggo_@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    This is actually pretty smart because it switches the context of the action. Most intermediate users avoid clicking random executables by instinct but this is different enough that it doesn’t immediately trigger that association and response.

  • kittenzrulz123@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    Thats why on Linux you need to run the sudo command and type the root password (or user password) to install something. I get this isn’t Linux but its a serious security vulnerability that someone could run a super user level command by clicking yes on a confirmation box that pops up so often that nobody thinks twice.

    • Honytawk@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      5 days ago

      If Linux was more popular, you would definitely see a Linux variant of this doing the exact same thing.

    • cley_faye@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 days ago

      The goal is not always to “take control” of the whole system. A cryptolocker that makes all your files unreadable will happily run in user space.

      Also, you’re forgetting that windows also have UAC, and that people will happily type the admin password of their device when asked to, because they’ve been conditioned to not care by badly made stuff. And, while win+r is unlikely to work in most Linux DE I know about, triggering a visual prompt that ask for your password is also a thing.

      There is not much difference between common Linux distro and windows as far as seizing user files with malware is concerned, aside from the fact that no website will care to try telling you “press alt+space” instead of “win+r”.

    • brucethemoose@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      5 days ago

      The behavior is configurable just like it is on linux, UAC can be set to require a password every time.

      But I think its not set this way by default because many users don’t remember their passwords, lol. You think I’m kidding, you should meet my family…

      Also, scripts can do plenty without elevation, on linux or Windows.

    • dch82@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 days ago

      But something like this can still erase everything stored in your home folder or launch further exploits to gain root or something.

      • kittenzrulz123@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        0
        ·
        5 days ago

        Its a lot harder and can do significantly less damage if it doesnt have root privileges, its like how putting a lock on the door to your house wont stop thieves but its better then not having one.

        • dch82@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          ·
          5 days ago

          Bruh, let’s say an attacker deleted all of my important documents, say book drafts, and assume I don’t have a backup.

          Now my progress has been set back six months and the publisher is angry.

          Would I care if they deleted my system files or not?

  • Tylerdurdon@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    So inventive these guys. If only we could harness that ingenuity for the common good instead, it would have a huge impact.

    • GraniteM@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 days ago

      “To prove that you are human, donate $$$ to Doctors Without Borders.”

      “To prove that you are human, register to vote.”

      “To prove that you are human, adopt a pet from the local animal shelter.”

    • CosmicTurtle0@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 days ago

      Fwiw there are a large number of people who volunteer their time and effort toward worthwhile projects. It’s just they don’t get rewarded anywhere near the level of benefit that they provide.