The ‘I Don’t Know So I Can’t’ Problem

▶ Watch (01:52)

“I don’t know therefore I can’t” — Johnny Xmas

That phrase is spreading through the security industry, and it’s getting people hurt. The old version was “I don’t know, so let me try.” The new version stops before the attempt. Johnny Xmas runs BBSE, the most-attended hacking meetup in North America, and has been working in security for 12 to 15 years. He still hits things he doesn’t know. The difference is he tries anyway. This talk is what happened when he did.

Pidgin, Supply Chain Attacks, and Social Engineering — the Setup

▶ Watch (06:20)

Pidgin is the longest-running multi-protocol chat client of its kind. Originally called Gaim, it ships with many Linux distributions by default and runs on most operating systems. One person maintains it, picking through every PR and issue alone. Its third-party plugin system is the attack surface here.

Two techniques combined to pull this off. A software supply chain attack compromises what users trust and import, not the core software itself. Social engineering is the surreptitious control of a social situation — the affected parties can’t know it’s happening. The attacker needed to manipulate the one person with power to list a plugin, so he had to build trust first.

The Attacker’s Social Engineering Playbook

▶ Watch (10:41)

On July 1, 2024, the attacker hit every Pidgin support channel at once. He walked through the attacker chat logs — seven pages of social engineering (10:41) live. The plugin had 5,600 lines of C in one file, ran on Debian, Fedora, and Windows, and lived on jabberplugins.net, padded with ten scraped GitHub plugins to look authoritative. He pushed to get it listed under “security and privacy.” Grim said no. The crypto donation pitch ran for weeks: Bitcoin, then Monero, then $2,000 a month, unsolicited. When a third party flagged the plugin as a keylogger, the attacker cited VirusTotal, declared it clean, and begged to be relisted.

Code Analysis — What the Plugin Actually Did

▶ Watch (24:46)

Grim had finally gotten the source code and needed someone to look at it. Johnny Xmas had not written C since university.

“What I said was, ‘Uh, I don’t really know reverse engineering. Uh, but let me take a look because what’s the worst case scenario here?’” — Johnny Xmas

He ran a regex across the source looking for IP addresses and socket connections. The plugin called out to jabberplugins.net, a domain the attacker controlled. The payload used an undocumented Windows multiple-desktop API, present through Windows 10 but never shown to end users, to give the attacker full graphical access on a hidden desktop the victim could not see. He walked through the malware code walkthrough — jabberplugins.net callout and hidden desktop hijack (27:30) live.

Confrontation, Cover Story, and Cleanup

▶ Watch (29:22)

The moment Xmas named the keylogger in chat, the attacker’s server went offline. Jabberplugins.net disappeared. The GitHub, which Xmas had found by picking through strings rather than any disclosure, was wiped clean.

Confronted with all of it, the attacker pivoted: he claimed the keylogger was a law-enforcement tool he used to catch cryptocurrency thieves. He sent videos of unrelated arrests as proof. The same person who had offered $2,000 a month to get a plugin listed now insisted he was one of the good guys. The argument dragged on. As of January, the server was back up, stripped of the webdev plugin but still running. It was down again the day of the talk.

Q&A

Why was the plugin listed in the first place if it was malicious? Grim listed it as a community plugin (not trusted) after the plugin appeared to work as advertised and he skimmed the code, missing the hidden payload. ▶ 33:46

Did they alter the plugin submission policy afterwards? Yes, Grim now requires submitted source code to be reviewed by at least one other person before listing. ▶ 34:48

Do you have statistics on how many users were affected? No firm number, but the plugin was live for only 10-12 days before a GitHub user flagged it, so infections were likely very few. ▶ 35:30

What advice do you have for developers like Grim who want to collaborate with outside contributors? Treat heavy ego-flattery and pressure as red flags, always keep access to review contributor code, and build a trusted network of peers you can ask for a second opinion. ▶ 37:47

Notable Quotes

I don’t know therefore I can’t Johnny Xmas · ▶ 2:00

What I said was, ‘Uh, I don’t really know reverse engineering. Uh, but let me take a look because what’s the worst case scenario here?’ Johnny Xmas · ▶ 25:35

if you see something, please say something. It It actually worked. Johnny Xmas · ▶ 36:00

Key Takeaways

  • Attempt the unfamiliar — ‘I don’t know’ is a starting point, not a stop sign.
  • Ego-flattery and unsolicited crypto donations are social engineering red flags, not generosity.
  • Require open-source code review before listing any third-party plugin as trusted.

About the Speaker

Johnny Xmas

Johnny Xmas, a prominent figure in the Information Security community since 2002, has been a dedicated contributor to public forums, sharing his extensive research and knowledge. Most notably recognized for his pivotal role in exposing the American TSA Master Key leaks (2014-2018), uncovering Venmo stalking vulnerabilities (2018), and being an overall nuisance. Past experience includes being: Director of Cyber Training at security research firm GRIMM, defending against the automated abuse of web infrastructure with Kasada, and as the Lead Researcher on Uptake’s Industrial Cybersecurity Platform. Before this, he spent many years in the field as a penetration tester, security engineer for a global Fortune 500 retail corporation, and Mainframe auditor and Systems Engineer for several IT asset recovery firms. Today, Johnny continues to shape and elevate the Information Security landscape with his expertise and contributions as the President of the Burbsec Information Security Network and the Head of Offensive Security for a massive, global manufacturing and agriculture corporation.