Proxyjacking for Profit: The Latest Cybercriminal Side Hustle

แชร์
ฝัง
  • เผยแพร่เมื่อ 14 ก.ค. 2024
  • Talk by Allen West
    www.socallinuxexpo.org/scale/...
    In the evolving landscape of cyber threats, proxyjacking for profit is emerging as a silent adversary. While the cyber realm is familiar with hijacking resources for cryptomining and conventional malicious uses of proxies, exploiting victims' bandwidth for direct and tangible profit is a newer challenge. This presentation delves into the intricacies of proxyjacking and its challenges for cybersecurity defenders. Attendees will gain insights into its prevalence, potential future trajectories, and, crucially, defensive measures to combat this under-discussed threat.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 44

  • @eyezikandexploits
    @eyezikandexploits 11 วันที่ผ่านมา +6

    Great talk loved the breakdown

  • @KIP-lh1ln
    @KIP-lh1ln วันที่ผ่านมา +1

    I see proxyjacking as a risk to the victims, as high risk traffic could be tunneled to these unsuspecting victims.

  • @andresdelorbe9638
    @andresdelorbe9638 7 วันที่ผ่านมา +7

    I really miss the old linode logo !

  • @gooniesfan7911
    @gooniesfan7911 11 วันที่ผ่านมา +7

    im hearing impaired and the transcript is hard to search through. is this vulnerability involving modifying DNS requests via the proxy end?

    • @DiverSteenberg
      @DiverSteenberg 11 วันที่ผ่านมา +1

      I just started watching so i can't answer, but maybe you could benefit from a strategy I use to study: I copy and paste the transcript into an AI and ask it questions

    • @bearwolffish
      @bearwolffish 8 วันที่ผ่านมา +4

      @@DiverSteenberg You verify the answers the AI gives you?

    • @rxpe
      @rxpe 7 วันที่ผ่านมา +2

      Via the proxy end? It's just using infected machines as proxies and selling their access.

    • @MacGuffin1
      @MacGuffin1 5 วันที่ผ่านมา

      Yeah IU cant read his overhead stuff on a very large screen in 4k :[

  • @BillAnt
    @BillAnt 11 วันที่ผ่านมา +24

    A proxy is similar to a VPN for changing different static or dynamic IP's. The only difference difference is that a VPN also encrypts the DNS requests. I'm using a proxy every day for my business to access certain sites, because changing IP's forces me to log in an verify it again the IP again. It's a completely legit use.

    • @bobbyrandomguy1489
      @bobbyrandomguy1489 11 วันที่ผ่านมา +8

      A proxy does not inherently promise encryption. All VPN connections provide encryption. Just make sure you use the correct protocols!

    • @BillAnt
      @BillAnt 10 วันที่ผ่านมา

      ​@@bobbyrandomguy1489 - That what I said, a proxy is just for changing IP's. But with 99% of websites nowadays the actual traffic is encrypted via HTTPS/TTS. The only things a VPN is better at, is hiding DNS queries so an attacker won't know the url/IP of the sites you're visiting. Honestly I don't trust either proxy and VPN services, could be honey-pots all we know. "Trust me bro, no logs!" lmao

    • @exciteproductions4two0
      @exciteproductions4two0 7 วันที่ผ่านมา

      ​@@bobbyrandomguy1489tell that to lemons vpn after they sold all their customers information to a Chinese web company.

    • @Heapsray
      @Heapsray 7 วันที่ผ่านมา +1

      This claim is false

    • @Heapsray
      @Heapsray 7 วันที่ผ่านมา +3

      A VPN completely replicates the network stack and encapsulates it in an encrypted way, while a proxy just forwards requests for you and acts as man-in-the-middle

  • @zgintasz
    @zgintasz 6 ชั่วโมงที่ผ่านมา

    Is this new? I suspected proxyjacking the first time I saw a service named “residential proxies”

  • @rebane2001
    @rebane2001 6 วันที่ผ่านมา +1

    16:35 no thats not the right hackernews 😭

  • @Akash.Chopra
    @Akash.Chopra 6 วันที่ผ่านมา +6

    Please move the mic away from the center of your mouth bro..

  • @nickhodges4315
    @nickhodges4315 12 วันที่ผ่านมา +27

    This talk is easily 14 years out of relevance.

    • @andrewferguson6901
      @andrewferguson6901 11 วันที่ผ่านมา +30

      That would mean something if vulnerabilities 14 years out of relevance werent still being exploited for fun and profit

    • @nickhodges4315
      @nickhodges4315 11 วันที่ผ่านมา +1

      ​@@andrewferguson6901 Fun and profit is a dog-headed point of view. Do you think you are better than a dog?
      The most successful hackers are god-headed political idealogues with tragic tales; not run of the mill crooks or goons.
      Political idealogues look at crypto and networking technology companies and sees it for what it is. State-sponsored fascism with a bunch of pretty graphs.
      If you can't learn to understand the motives of your adversaries you can never hope to stop them, much less compete with them.
      Low-brow attacks like what this talk covers only exists because this country is one large honeypot.
      Hackers know better than professionals what is real and what is not.

    • @ericschroeman5020
      @ericschroeman5020 11 วันที่ผ่านมา +9

      eh not really, some is old info but most is pretty current

    • @bezillions
      @bezillions 10 วันที่ผ่านมา +18

      If it's not patched or moot it's relevant

  • @vuufke4327
    @vuufke4327 9 วันที่ผ่านมา +10

    Entirely useless talk, save you time.

    • @MouadScriptz
      @MouadScriptz 8 วันที่ผ่านมา +3

      not true

    • @frag0638
      @frag0638 8 วันที่ผ่านมา +5

      This is 15 years late

    • @vuufke4327
      @vuufke4327 7 วันที่ผ่านมา

      @@frag0638 proxyjacking has been a thing pretty much from the day smartphones became popular, I wouldn't call it "the latest side hustle"

    • @corpingtons
      @corpingtons 7 วันที่ผ่านมา +3

      How is it useless it’s still being used? If a computer has malware anything is possible if it’s ud