
masahito alphonse fujishima
32.4K posts

masahito alphonse fujishima
@alphonse_sec
ネコかぶってたのに引っ張り出されました。金融事業会社を渡り歩きながら長いことCISSPやってます。(ISC)2、IPSJ、OWASP member. あとAMLなんちゃら。 アイコンはMicrosoftのAIに柴犬判定された我が家のミケ子









More than 10 of my bitcoin friends got hacked in the past month. All had 2FA enabled. It didn’t help. Here’s how they almost got me too 👇 HOW THEY FOOL YOU 1️⃣ Someone from your contacts messages you to schedule a call. This is already a stolen account. A friend who got scammed before you. 2️⃣ They send you a calendar invite first. Then, right before the call, they send a Zoom link. At a quick glance it looks legit. The preview looks identical to real Zoom. The trick is subtle: the hostname and subdomain are swapped. This is the fake Zoom link they sent me. A real Zoom link would have those two words around the dot swapped. 👀 https:// zoom (DOT) webus05. us/j/47369507762?pwd=7kiAzRm6PNBvNFdBBEY04cr6LLzHPk.1 Easy to miss, even if you know what to look for. Especially when it comes from someone you trust. 3️⃣ The fake Zoom app looks flawless. Perfect copy of the real Zoom UI. No red flags. 4️⃣ You immediately see your friend on video. This is NOT A DEEPFAKE. It’s a recording of your friend from seconds before they got scammed in the previous session. That’s why it looks perfect and trustworthy. HOW THEY GAIN CONTROL 5️⃣ The fake Zoom app says your audio is broken and asks you to update. 6️⃣ The update “fails” and you’re shown a command line troubleshooting guide. ⚠️7️⃣ If you paste that command into your terminal, it’s over. You just gave the attacker remote access to your computer. HOW THEY ROB YOU 8️⃣ The malware they install remotely is simple and runs fast. It takes one or two seconds. It usually does two things: A) Scans your computer for bitcoin wallets and steals access. ⚠️B) Steals session cookies from chat apps. This is how they bypass your 2FA later. ELI5 SESSION COOKIES When you log into Telegram on your laptop, you enter your password and 2FA once. Telegram then saves a session token on your computer so you don’t have to do it every time. That token is basically: “Yes, this is the same person who gave you the password and 2FA earlier.” When attackers steal it, they present it to Telegram, which sees it as a valid session and lets them in. So they don’t need your password or your 2FA code. THEY ARE YOU. If someone gets access to your computer, you’re done. At that point, it’s just damage control. MY GOLDEN RULE Life is short and beautiful. No client call is important enough to mess with command line troubleshooting. Be lazy. Be safe. PS: unrelated, but we just launched Braiins Hashpower. On-demand bitcoin hashrate. Try it. It’s awesome. Like ice cream when you’re 12 😁




【速報!情報処理技術者試験 大幅刷新!】 ※シェア&ブックマークをお願いします 令和9年度からは、応用情報やネスペ、デスペなどが丸々消えます。 情報処理安全確保支援士は残ります。このあと動画で説明するので、ぜひご覧ください。




>そんな確率はおそろしく極めてすごくめっちゃ低いはず、 いや、それはよくある誤解だと思います。SSDと同様に、HDDも製造時期と工場、それにロット番号まで同一だとほぼ同時期に壊れる確率が非常に高くなりますからね。この辺りは私の前職時代に同僚だった浅野さん @Hironobu_Asano が私よりも遥かに詳しいと思います。 > という前提で成り立ってるのがRAID5のはずだが・・・ 上のような話もあるので、もはやRAID 5は基本どうしても容量を稼ぐ必要でもない限りは使わないのが一番…というのは最近では常識かと思ってましたけど、まだまだ現場ではそうでもない感じでしょうか。





