新足迹

 找回密码
 注册

精华好帖回顾

· 纪念麦克 于2009年6月27日 (2009-6-28) luming · 更新:番外篇-租家具,选中介,拍卖技巧,SOLD。7个月老house里外翻新 (2020-4-18) gbdlg
· 养金鱼 (2007-3-14) coldair · 4月5日墨尔本小琴友聚会后记 (2009-4-6) daffodil
Advertisement
Advertisement
查看: 2200|回复: 25

This guy is a guenis 绝对做老板的料啊~ [复制链接]

发表于 2013-1-17 08:28 |显示全部楼层
此文章由 zliu18 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 zliu18 所有!转贴必须注明作者、出处和本声明,并保持内容完整
weibo上看到的,觉得很有意思。
这位同学,拿6位数的工资,拿出1/5把自己的活外包给中国公司,几年下来 年年公司里的best developer, 人才啊~
不幸的是,VPN暴露了...

Verizon finds US developer outsourced his job to China so he could surf Reddit and watch cat videos

No, this is not the Onion, it’s not April Fools, and I’m not making this up. All of this comes straight from Verizon, or more specifically, a case study from 2012 outlined by its security team.

The story goes a little something like this. A developer at a US-based critical infrastructure company, referred to as “Bob,” was caught last year outsourcing his work to China, paying someone else less than one fifth of his six-figure salary to do his job. As a result, Bob had a lot of time on his hands; in fact, during the investigation, his browsing history revealed this was his typical work day:

    9:00 a.m. – Arrive and surf Reddit for a couple of hours. Watch cat videos.
    11:30 a.m. – Take lunch.
    1:00 p.m. – Ebay time.
    2:00 – ish p.m Facebook updates – LinkedIn.
    4:30 p.m. – End of day update e-mail to management.
    5:00 p.m. – Go home.

Again, I want to emphasize that I haven’t invented this schedule for the sake of making this story more interesting or to have a snazzy headline. This comes straight from Verizon; take that as you will.

Apparently Bob had the same scam going across multiple companies in the area (this part is a little unclear given that he clearly couldn’t physically go into work for all of them), earning “several hundred thousand dollars a year,” and only paying the Chinese consulting firm “about fifty grand annually.” At the unnamed company, he apparently received excellent performance reviews for the last several years in a row, even being hailed the best developer in the building: his code was clean, well-written, and submitted in a timely fashion.

Folks, you can’t make this stuff up. Here are the rest of the crazy details, which Verizon says it released because although this wasn’t a large-scale data breach that made headlines, the case had a unique attack vector.

Apparently the scheme was discovered accidentally. Verizon received a request from the US company asking for help in understanding anomalous activity it was witnessing in its VPN logs: an open and active connection from Shenyang, China.

This was alarming because the company had implemented two-factor authentication for these VPN connections, the second factor being a rotating token RSA key fob. Yet somehow, although the developer whose credentials were being used was sitting at his desk staring into his monitor, the logs showed he was logged in from China.

This unnamed company initially suspected some kind of unknown (0-day) malware that was able to initiate VPN connections from Bob’s desktop workstation via external proxy, route that VPN traffic to China, and then back. When Verizon investigated, it eventually noticed that the VPN connection from Shenyang was at least six months old, which is how far back the VPN logs went, and it occurred almost daily and occasionally spanned the entire workday.

Unable to explain how an intruder could have possibly been accessing the company’s internal system on such a frequent basis, Verizon decided to look more closely at Bob, since it was his credentials that were being used. Here’s how his the case study described him:

    Employee profile –mid-40′s software developer versed in C, C++, perl, java, Ruby, php, python, etc. Relatively long tenure with the company, family man, inoffensive and quiet. Someone you wouldn’t look at twice in an elevator.

All it took was a look a forensic image of Bob’s desktop workstation to discover hundreds of PDF invoices from a Chinese consulting firm in Shenyang. How did he get around the security requirements? He physically FedExed his RSA token to China.

http://thenextweb.com/shareables ... d-watch-cat-videos/
Advertisement
Advertisement

发表于 2013-1-17 08:37 |显示全部楼层
此文章由 kidz821 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 kidz821 所有!转贴必须注明作者、出处和本声明,并保持内容完整
oh.....................

发表于 2013-1-17 08:37 |显示全部楼层
此文章由 eric_gao 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 eric_gao 所有!转贴必须注明作者、出处和本声明,并保持内容完整
本帖最后由 eric_gao 于 2013-1-17 07:39 编辑

应该在自己家里弄个vpn啥的,让外包的沈阳公司先连接他家,再连到公司,然后撒谎说自己必须先连接到家里,再连公司。

评分

参与人数 1积分 +3 收起 理由
商务车 + 3 你太有才了

查看全部评分

Sunday Afternoons UPF50+防晒帽专卖
oursteps.com.au/bbs/forum.php?mod=viewthread&tid=934220

发表于 2013-1-17 08:39 |显示全部楼层
此文章由 Poweregg 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 Poweregg 所有!转贴必须注明作者、出处和本声明,并保持内容完整
watch cat videos?

发表于 2013-1-17 08:40 |显示全部楼层
此文章由 frankielynna 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 frankielynna 所有!转贴必须注明作者、出处和本声明,并保持内容完整
没有明白为什么要让外包的直接用vpn连公司,应该都到他私人那里,比如自己家里搞个server, 啥东西都传那里去。

发表于 2013-1-17 08:41 |显示全部楼层
此文章由 牵黄擎苍 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 牵黄擎苍 所有!转贴必须注明作者、出处和本声明,并保持内容完整
这家伙安全意识太差
Advertisement
Advertisement

发表于 2013-1-17 09:28 |显示全部楼层
此文章由 zliu18 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 zliu18 所有!转贴必须注明作者、出处和本声明,并保持内容完整
Poweregg 发表于 2013-1-17 08:39
watch cat videos?

估计家里养猫,装了监视器了~

发表于 2013-1-17 09:29 |显示全部楼层
此文章由 zliu18 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 zliu18 所有!转贴必须注明作者、出处和本声明,并保持内容完整
At the unnamed company, he apparently received excellent performance reviews for the last several years in a row, even being hailed the best developer in the building: his code was clean, well-written, and submitted in a timely fashion.

发表于 2013-1-17 09:29 |显示全部楼层
此文章由 yangwulong1978 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 yangwulong1978 所有!转贴必须注明作者、出处和本声明,并保持内容完整
估计不是他一个

发表于 2013-1-17 09:36 |显示全部楼层
此文章由 Network 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 Network 所有!转贴必须注明作者、出处和本声明,并保持内容完整
人才啊。
他老板会不会就留他一个下来负责外包,其他developers都开了。

发表于 2013-1-17 09:42 |显示全部楼层
此文章由 realfenglin 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 realfenglin 所有!转贴必须注明作者、出处和本声明,并保持内容完整
太二了
Advertisement
Advertisement
头像被屏蔽

禁止发言

发表于 2013-1-17 09:47 |显示全部楼层
此文章由 lubber 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 lubber 所有!转贴必须注明作者、出处和本声明,并保持内容完整
this guy is super

发表于 2013-1-17 09:53 |显示全部楼层
此文章由 000567 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 000567 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2013-1-17 10:22 |显示全部楼层
此文章由 brahmasky 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 brahmasky 所有!转贴必须注明作者、出处和本声明,并保持内容完整
强人,不过整天在网上逛不会闷么

发表于 2013-1-17 14:18 |显示全部楼层
此文章由 atm 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 atm 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2013-1-21 21:52 |显示全部楼层
此文章由 HISOKA 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 HISOKA 所有!转贴必须注明作者、出处和本声明,并保持内容完整
Poweregg 发表于 2013-1-17 06:39
watch cat videos?

网上搞笑的猫视频吧  以前team里英国人经常上班开youtube看
Advertisement
Advertisement

发表于 2013-1-21 22:04 |显示全部楼层
此文章由 绿茶芝士蛋糕 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 绿茶芝士蛋糕 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2013-1-21 22:05 |显示全部楼层
此文章由 绿茶芝士蛋糕 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 绿茶芝士蛋糕 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2013-1-31 10:01 来自手机 |显示全部楼层
此文章由 bluesfans 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 bluesfans 所有!转贴必须注明作者、出处和本声明,并保持内容完整
挺好的,给国内接活的公司顺带打了广告。

发表于 2013-2-4 16:08 |显示全部楼层
此文章由 gifox 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 gifox 所有!转贴必须注明作者、出处和本声明,并保持内容完整
想法很好,但是一点危机意识都没有。如果他愿意自己take up 部分工作。把公司的task用自己的说法改写一次。发回去中国,中国做完后发到他的家里。要么通过usb 之类的把原始代码带回公司自己再补妆一下。
再发上去。那么可以说毫无破绽吧。

虽然这样每天也要工作点时间....

发表于 2013-2-4 16:12 |显示全部楼层
此文章由 IsDonIsGood 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 IsDonIsGood 所有!转贴必须注明作者、出处和本声明,并保持内容完整
gifox 发表于 2013-2-4 15:08
想法很好,但是一点危机意识都没有。如果他愿意自己take up 部分工作。把公司的task用自己的说法改写一次。 ...

蛮怀疑新闻是真的假的,明摆着可以掩饰得更好,非要用这样的方法,这么聪明的方法都想到了,掩饰得方法却想不到?
2020目标: 活着
Advertisement
Advertisement

发表于 2013-2-4 16:15 |显示全部楼层
此文章由 gifox 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 gifox 所有!转贴必须注明作者、出处和本声明,并保持内容完整
IsDonIsGood 发表于 2013-2-4 15:12
蛮怀疑新闻是真的假的,明摆着可以掩饰得更好,非要用这样的方法,这么聪明的方法都想到了,掩饰得方法却 ...

嗯,如果是真的,不要说几分之一的薪水。就是一半的薪水我也愿意。因为都没有什么付出。成本很低,白赚。
自己把多出来的时间考虑干干别的行当。比如说帮本地其他公司接私货,当然也要考虑outsource回去中国。

发表于 2013-2-4 18:06 |显示全部楼层
此文章由 CCNBand 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 CCNBand 所有!转贴必须注明作者、出处和本声明,并保持内容完整
gifox 发表于 2013-2-4 15:08
想法很好,但是一点危机意识都没有。如果他愿意自己take up 部分工作。把公司的task用自己的说法改写一次。 ...

估计刚开始这么小心,几年下来没事儿安全意识就变得薄弱了。

发表于 2013-3-27 15:33 |显示全部楼层
此文章由 whitecool 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 whitecool 所有!转贴必须注明作者、出处和本声明,并保持内容完整
人才

发表于 2013-3-29 00:13 |显示全部楼层
此文章由 southstar 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 southstar 所有!转贴必须注明作者、出处和本声明,并保持内容完整
浪费了

发表于 2013-3-29 04:01 |显示全部楼层
此文章由 jetty 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 jetty 所有!转贴必须注明作者、出处和本声明,并保持内容完整
老帖子又上来了。太大意了。很简单,在自己家开个VPN中转就对了。
Advertisement
Advertisement

发表回复

您需要登录后才可以回帖 登录 | 注册

本版积分规则

Advertisement
Advertisement
返回顶部