frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

An exposed .git folder let us dox a phishing campaign

18•spirovskib•1h ago
This past Friday afternoon, a member in our Discord server reported a phishing email pointing to a fake login page.

We took up to research it and because of clumsy decisions by the attacker we got their GitHub and their operational Telegram bot.

Screenshots: https://imgur.com/a/FTy4mrH

Sometimes the attacker incompetence can be a defender's best weapon ¯\_(ツ)_/¯

The phishing page was a standard clone of an "email", unbranded anf generic service. A bit of gobuster reconnaissance and we got the site's .git directory publicly accessible and listing its contents.

Inspecting of the requests also got us the first Telegram bot token. This is the digital equivalent of leaving the blueprints to your entire operation, including past versions and deleted files, lying on the front lawn.

We pulled the repository, found automated deployments and multiple fake pages with different hardcoded Telegram bot tokens and Chat IDs.

With the source code, repo and the active Telegram bot token, we filed detailed abuse reports:

- GitHub: We reported the repository containing the phishing kit's source code. It was taken down for violating TOS.

- Telegram: We reported the bot using the provided token and chat ID, leading to its removal.

- Hosting Provider: The malicious site was reported and taken offline.

Lesson learned? Never deploy a .git folder to production. Even if you are a criminal.

Acknowledgement: This was a collaborative effort by members of the BeyondMachines Discord community. The crowdsourced speed and collaboration helped us take this down very fast.

Comments

poly2it•48m ago
Could've traced the attacker for a bit before burning all bridges.
ekjhgkejhgk•38m ago
Sounds like they got off easy.
spirovskib•9m ago
They probably did. But it's a volunteer effort, we all contrinbute as much each individual's time permits.
ArcHound•25m ago
It is great that they got taken down. From my experience, these sites are usually parasites on misconfigured Wordpresseses.

We're you able to get the phishing data so that you can help the victims? Is it a good idea to try and do so?

Also, can you please share some bits of the phishing kit for easier detection?

Thank you for your efforts!

spirovskib•12m ago
Thanks for the kind words. We discussed whether to pull the data. We didn't for two reasons: 1. It's not trivial to process that data safely, and all the people in the server are volunteers that pitch in as much as they can. It won't be fair to burden them more. 2. The bots were posting to what appeared to be private or moderated channels. We didn't find an easy way in. Maybe there was a way in, but see item 1 above. So we went with "nuke it from orbit"

CRX – Need help to complete my project

https://github.com/vincent2o1/CRX-Lite-2.0
1•Who_99•9m ago•1 comments

Foreign direct investment in semiconductors reconfigured sharply toward the U.S.

https://www.mckinsey.com/featured-insights/week-in-charts/fdi-fuels-chip-shift
1•giuliomagnifico•10m ago•0 comments

Programming Languages in the Age of "AI" Agents

https://alexn.org/blog/2025/11/16/programming-languages-in-the-age-of-ai-agents/
1•todsacerdoti•13m ago•0 comments

We haven't seen ZFS checksum failures for a couple of years

https://utcc.utoronto.ca/~cks/space/blog/solaris/ZFSOurRareChecksumFailuresII
1•psxuaw•14m ago•0 comments

My Summary of the Meditations of Marcus Aurelius – (22 Stoic Principles) [video]

https://www.youtube.com/watch?v=Hu0xDtK3g3Q&list=PLzKrfPkpj5olfny8ao7uoBTydABymwEdu
1•samuel2•17m ago•0 comments

Tips for Faster Rust Compile Times

https://corrode.dev/blog/tips-for-faster-rust-compile-times/
1•vinhnx•18m ago•0 comments

"The Fall of Icarus": You Have Never Seen an Astrophotography Picture Like This

https://www.iflscience.com/the-fall-of-icarus-you-have-never-seen-an-astrophotography-picture-lik...
2•doener•20m ago•0 comments

The delicious flavour with a toxic secret (2017)

https://www.bbc.com/future/article/20170620-the-delicious-flavour-with-a-toxic-secret
2•thunderbong•23m ago•1 comments

The Advent of Compiler Optimisations 2025

https://xania.org/202511/advent-of-compiler-optimisation
1•nly•24m ago•0 comments

Improve your code by separating mechanism from policy

https://lambdaisland.com/blog/2022-03-10-mechanism-vs-policy
1•moonlessday•24m ago•0 comments

Worksheet for Harada Method – PDF, PNG, and LaTeX Code

https://www.adithyan.io/blog/harada-method-worksheet
1•adithyan_win•28m ago•0 comments

Show HN: Listiary – A FOSS wiki engine built on nested, interactive lists

https://github.com/listiary/Listiary
1•demon_of_reason•32m ago•0 comments

Joscha Bach in Epstein Files

https://journaliststudio.google.com/pinpoint/search?collection=092314e384a58618
2•Rebuff5007•43m ago•1 comments

UK's first small nuclear power station to be built in north Wales

https://www.bbc.com/news/articles/c051y3d7myzo
12•ksec•44m ago•1 comments

Speedrunning a CPU: RISC-V in a Week

https://daymare.net/blogs/speedrunning-a-cpu/
2•daymare•44m ago•0 comments

The France National Intelligence Strategy 2025

https://www.dirittoue.info/the-france-national-intelligence-strategy-2025/
1•kaven1234•47m ago•0 comments

Markdown files not openable because of GitHub Copilot (VSCode)

https://github.com/microsoft/vscode/issues/277450
1•pjmlp•54m ago•1 comments

Why I Don't Need a Steam Machine

https://brainbaking.com/post/2025/11/why-i-dont-need-a-steam-machine/
39•ingve•1h ago•45 comments

Maybe You're Not Actually Trying

https://usefulfictions.substack.com/p/maybe-youre-not-actually-trying
4•eatitraw•1h ago•0 comments

Show HN: TunnelBuddy – Share your internet via HTTPS proxy over WebRTC

https://www.tunnelbuddy.net/
1•xrmagnum•1h ago•1 comments

Ten years and 100B dollars later: where is Meta's metaverse?

https://www.heise.de/en/background/Ten-years-and-100-billion-dollars-later-where-is-Meta-s-metave...
6•Prunkton•1h ago•3 comments

Comparing the run-time performance of Fil-C and ASAN

http://bannalia.blogspot.com/2025/11/comparing-run-time-performance-of-fil-c.html
1•ingve•1h ago•0 comments

Show HN: HashCodeTools – 17 Free Privacy-Focused Dev Tools

https://hashcodetools.com/
1•rsunnythota•1h ago•0 comments

Meta Replaced the Native WhatsApp for Windows 11 with a Shitty Web App

https://daringfireball.net/2025/11/meta_whatsapp_windows_shitty_web_app
2•SoKamil•1h ago•0 comments

Examining the cognitive and mental health correlates of short-form video use

https://www.researchgate.net/publication/397584857_Feeds_feelings_and_focus_A_systematic_review_a...
1•ksec•1h ago•0 comments

Personal Business

https://www.are.na/editorial/personal-business
1•vinhnx•1h ago•0 comments

Poet-Diplomat

https://en.wikipedia.org/wiki/Poet-diplomat
1•sph•1h ago•0 comments

Rusty sudo holes quickly welded shut

https://www.theregister.com/2025/11/13/ubuntu_rust_sudo_hole/
2•weinzierl•1h ago•1 comments

New Vatican document examines potential and risks of AI (Jan, 2025)

https://www.holyseegeneva.org/news/new-vatican-document-examines-potential-and-risks-of-ai/
2•totetsu•1h ago•0 comments

Day 45, Term Sheet Signed

https://supremefounder.com/term-sheet-signed.html
1•fmfamaral•1h ago•0 comments