10

A New LinkedIn Vulnerability Exposes Jobseekers to Phishing Attacks

 3 years ago
source link: https://hackernoon.com/a-new-linkedin-vulnerability-exposes-jobseekers-to-phishing-attacks-jnce35dq
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

A New LinkedIn Vulnerability Exposes Jobseekers to Phishing Attacks

@medhamehtaMedha Mehta

Cybersecurity technical writer and content marketer @TheSSLStore and SectigoStore.

This vulnerability can be exploited by con artists for massive phishing attacks, identity theft, and employment-related scams.

0 reactions
heart.png
light.png
money.png
thumbs-down.png

Security-related controversies are not new for LinkedIn. Here's
the latest one, which was discovered by a cybersecurity firm, The Cyphere, in Aug 2021. As per the company's report, anyone can post jobs on behalf of any company they want, without the consent or knowledge of the original company!

0 reactions
heart.png
light.png
money.png
thumbs-down.png

This means hackers can post jobs impersonating a reputed company and invite the job applications, receiving thousands of CVs on the fake email address, or redirect candidates to a malicious or phishing website!

0 reactions
heart.png
light.png
money.png
thumbs-down.png

Here’s how it works.

0 reactions
heart.png
light.png
money.png
thumbs-down.png
  • First of all, you need to create a company page on LinkedIn. It’s free for all. (This can be any random company’s page and not necessarily the one for which you want to post a job).
  • Then, click on Admin Tools and select Post a free job, as shown in the screenshot below.
0 reactions
heart.png
light.png
money.png
thumbs-down.png
  • You will be redirected to a job posting page, where you can select any company you want to post a job on behalf of! LinkedIn doesn't authenticate whether you are the legit representative of that company.
  • Yes, there are exceptions here. If you try to post jobs on behalf of a handful of big companies like Google, Facebook, Microsoft, Apple, Amazon, etc., you will be shown an error message like below.

Image source: TheCyphere

0 reactions
heart.png
light.png
money.png
thumbs-down.png

Once the job is posted, even the original company’s super admin
can’t do anything about it!

0 reactions
heart.png
light.png
money.png
thumbs-down.png

LinkedIn’s Response

The Cyphere reached to BleepingComputer to reconfirm their claims. After verifying the claims to be credible, BleepingComputer contacted LinkedIn for their comments.

0 reactions
heart.png
light.png
money.png
thumbs-down.png

Here’s a vague reply they received from LinkedIn.

0 reactions
heart.png
light.png
money.png
thumbs-down.png

"Posting fake content, misinformation and fraudulent jobs are clear violations of our terms of service. Before jobs are posted, we use automated and manual defenses to detect and address fake accounts or suspected fraud."

However, the shreds of evidence TheCyphere’s researchers found prove contradictory. LinkedIn didn't do anything further to tackle the issue. That means, the vulnerability still exists and can be exploited by anyone having a LinkedIn account.

0 reactions
heart.png
light.png
money.png
thumbs-down.png

How this LinkedIn Vulnerability Can be Exploited by Hackers?

So, here’s the point where the matter takes a dangerous turn.
LinkedIn gives two options to the job posters. They can either receive the CVs via emails or redirect applicants to a third-party website, which ideally
should be the company's career page. Hackers can exploit this vulnerability in three ways.

0 reactions
heart.png
light.png
money.png
thumbs-down.png

Note: We don't have any information on whether anyone has exploited this vulnerability yet or are there any victims for the same. But it is just a matter of time before hackers learn about this weakness and misuse it in the following ways:

0 reactions
heart.png
light.png
money.png
thumbs-down.png

1) Data theft

0 reactions
heart.png
light.png
money.png
thumbs-down.png

Scammers can easily collect applicants' personally identifiable information (PII) such as name, email address, phone number, employment history, and even physical address from the resume. They can sell this data on the darknet, or misuse it for identity theft-related crimes.

0 reactions
heart.png
light.png
money.png
thumbs-down.png

2) Phishing Attacks

0 reactions
heart.png
light.png
money.png
thumbs-down.png

The con artists pretend to be representatives of a legit company and ask candidates further sensitive information such as bank account numbers to credit the salary, or SSN, and other confidential information for tax purposes. They can also run common employment-related scams such as asking applicants to transfer money for conducting a background check, processing the application, or receiving the training.

0 reactions
heart.png
light.png
money.png
thumbs-down.png

3) Malware Delivery

0 reactions
heart.png
light.png
money.png
thumbs-down.png

Attackers can send malware-laden files in the email attachments and label them as job description, terms and conditions, employment contract, interview schedule, etc. They can also redirect candidates to a malicious or spammy site that automatically downloads malware to the victim's device. In the worst-case scenario, hackers can make the cybersquatting site that looks exactly like the original site with a similar domain name, and trick applicants to share their credentials and other confidential documents.

0 reactions
heart.png
light.png
money.png
thumbs-down.png

How Companies Can Protect Themselves from This Vulnerability?

By now, you must have an idea that anyone can post a job on behalf
of your company and invite applications without your knowledge. This can
significantly affect your business’s goodwill and create trust issues for
potential candidates.

0 reactions
heart.png
light.png
money.png
thumbs-down.png

Unfortunately, you can't do anything much about it - the ball is in
LinkedIn's court
.

0 reactions
heart.png
light.png
money.png
thumbs-down.png

Until LinkedIn recognizes the danger and patches the issues, all you can do is to ask your human resource department to keep a keen eye on all the jobs posted in your company's name. If they recognize any job which is not posted by your company, immediately contact LinkedIn support to report a complaint. You can also report the fake job by following the steps mentioned in this guide.

0 reactions
heart.png
light.png
money.png
thumbs-down.png
5
heart.pngheart.pngheart.pngheart.png
light.pnglight.pnglight.pnglight.png
boat.pngboat.pngboat.pngboat.png
money.pngmoney.pngmoney.pngmoney.png
by Medha Mehta @medhamehta. Cybersecurity technical writer and content marketer @TheSSLStore and SectigoStore. Read my stories

Also Featured In

This story is new, give it time!
Join Hacker Noon

Create your free account to unlock your custom reading experience.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK