Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Recently a friend of mine sent me a piece of obfuscated JS that was in a phishing page that was being posted around his large gaming related website. Threw the JS into closure compiler with advanced optimisations and pretty print and out comes relatively unobfuscated code- it cleared up the series of horrible regexes anyway. The code injected a Java applet that downloaded a botnet virus. Decompiling the Java applet revealed the steamid of the guy orchestrating this. Added him on steam and had a great conversation in which he accidentally indirectly admitted the botnet was under his control. A fun use of a Sunday. The evidence was never sent to anyone, thinking nothing would come of it.


> Threw the JS into closure compiler with advanced optimisations > and pretty print and out comes relatively unobfuscated code...

Boss hack. That strategy would have never occurred to me. Thanks!


Any idea why would he put his Steam ID in the applet?


It was on a website for trading items on steam. Perhaps he wanted to force them to trade items, then sell the items on for real life money.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: