UK, Not North Korea, Is Source of DDoS Attacks
angry tapir writes "The UK was the likely source of a series of attacks last week that took down popular Web sites in the US and South Korea, according to an analysis performed by a Vietnamese computer security researcher. The results contradict assertions made by some in the US and South Korean governments that North Korea was behind the attack. Security analysts had been skeptical of the claims, which were reportedly made in off-the-record briefings and for which proof was never delivered." The Vietnamese security site's blog is linked from the article, but it is very slow even before Slashdotting. The researchers observed 166,908 zombies participating in the attacks — a number far larger than most earlier estimates.
Update: 07/14 21:24 GMT by KD : Wired is reporting that the UK owner of the IP address in question is pointing a finger at a server in Florida, which it says opened a VPN to the UK machine for the attacks. Once again, the attacker could be anywhere.
Update: 07/14 21:24 GMT by KD : Wired is reporting that the UK owner of the IP address in question is pointing a finger at a server in Florida, which it says opened a VPN to the UK machine for the attacks. Once again, the attacker could be anywhere.
North Koreans are still told that the mighty leader Kim-Jong Il brought down the evil western internet.
"The Y chromosome is genetic. The odds are very good that if you are male then your father was too." -Internet Commenter
friendly fire
Why should we believe this report over the other ones? Slashdot mentality always seems to be that any contradicting reports beat the initial report.
The article has no real indication that anything was the source, just that the last hop the analyst was able to track was in the UK...which means?
A Computer in the UK can be controlled by another computer in North Korea.
This whole thing is kind of absurd anyway...
Just secure your shit against DDoS attacks and call it a day.
For the love of Heaven! The war has been over for 226 years! Get over it, already!
Similar to the upcoming US election results
Just because most of the IP's involved were from the UK does not mean that N.Korea wasn't responsible.
I have to wonder how one 'creates' such a geography specific botnet. Do they have UK spam with words like bollocks? Or in the USA is it 'gun porn'? I bet they use 'Tim Hortons' to catch the Canadians. =)
"The price good men pay for indifference to public affairs is to be ruled by evil men." ~Plato (427-347 BC)
If true, this is kind of like the time the US accused North Korea of creating really authentic-looking counterfeit 100 dollar bills, and then it turned out that they are probably coming from within the US - possibly from the CIA to fund covert operations.
I hate to say it, but maybe Kim Jong Il isn't crazy when he claims the Western governments are part of a big conspiracy to falsely ruin his image (hah!)
Even if they attacks were proven to come from the UK... even if they came from North Korea, Nigeria, or Witchita KS..
Does that really tell us about the culprit? It just tells us from where the attacks were launched. This could be because the attacker is from that area, or because the attacker wants to appear to be from that area.
It's a clue. Nothing more.
Fortunately, we can count on the British government to respond with reasoned caution, and with the utmost respect for citizens' future privacy and freedom.
slashdoting the website is enough :)
I'm fairly certain that just because a server in the UK was controlling the botnet, that doesn't necessarily mean a Brit was controlling that server, nor does it rule out that a North Korean was behind it.
$x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
$x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
Cue UK government announcing multi billion plan to make the internet 'safe' with new content filtering, anti-filesharing and communication logging schemes in 5... 4... 3...
This is a substitute for a clever sig that fits within the maximum number of characters.
In April of this year, the NYPD accused hackers in China, and some in the government and media even accused the Chinese government of being involved, in the hacking and disruption of the NYPD computer system. However many posters in the /. comment sections of the posted story theorized that the hacking was not originating from China but rather from a hacking group operating out of New York but fooling the NYPD using 'bot herding'.
I'm not familiar with how to operate and disguise a botnet to look like your hacking from IPs from another country, I would guess that you just infect a group of computer abroad, and run a botnet from there. Here's the original post on /. with comments modified to 4. Just scroll down and you can find posters discussing how the NYPD and U.S. government had misidentified who the hackers probably were.
http://slashdot.org/comments.pl?threshold=4&mode=flat&commentsort=0&op=Change&sid=1209793
Here's the comment that I remembered the most where the user specifically wrote that the hackers were operating most likely within the U.S. and not in China.
http://slashdot.org/comments.pl?sid=1209793&cid=27694281
I guess until governments learn how to trace hackers properly we are going to be seeing more and more of these stories.
Were the zombies filled with rage?
Ascii artist &
This summary masks the true benefit of the information just to turn heads. There is now a paper trail to an anonymous entity. Hopefully if all the international government bodies work together they can stop the activity of this bot net. I'm curious if it has been this difficult to find the master server then how much evidence does the US and SK have to make accusations. Fortunately, for the US and SK their politicians don't need proof to make statements.
The researcher found the computer that was used as the entry point for commands into the botnet.
This has nothing to do with who is responsbile for the attack.
Test your net with Netalyzr
RS
Shoes for Industry. Shoes for the Dead.
Because they would then not be able to tell that the bills were counterfeit.
The trick is they would need bills good enough to not be detected as counterfeit by NOrth Korea, but would be detectable back home as counterfit.
And now we want our Empire back...
I just can't believe that they've blown our cover so soon, I thought that dragging America into end-less wars in Iraq and Afghanistan was a brilliant move (did you seriously think that BUSH came up with the idea?) and the latest shift towards economic desolation via cyber attacks was extremely well thought out.
And why can we do this.... Because WE HAVE A FLAG!
Okay back to plan B of being crap at sports we invent but quite polite about losing.
An Eye for an Eye will make the whole world blind - Gandhi
The Vietnamese are in bed with North Korea. OR This guy is really a North Korean posing as a Vietnamese Computer Scientist.
Just because you are wrong and I called you out on it doesn't mean I am a Troll.
I would think once it was determined that this was not a State sponsored attack, they would stop making such a stink over what country the attacks originated from. Hacking has been going on for 20 + years now, and it has never been a real concern before on the country of origin because State sponsored hacking was such a negligable issue that it was commonly overlooked. I do understand that Russia may have sponsored attacks on Georgia, and maybe China has hacked Taiwan and vice versa, but I mean, short of a concerted Government led effort, I would take this as just another case of Bot Net owner playing with his toys. Not as a sign of intra Governmental hacking as a precursor to some sort of overt warlike effort beginning.
"This is the value of a summer spent and a winter earned"
Unfortunately, the states that sponsored it would be the US and UK, under the auspices of whipping people into a frenzy over "cyber-warfare" and getting people to lay down their liberties online willingly. Create the problem, wait for the panicked reaction, then offer a (usually self-serving and draconian) solution.
If this wasn't a covert op on the part of western intelligence agencies, then I'm the resurrected zombie hellspawn of Carmen Miranda and Kurt Cobian.
I hope the botnet herders had insisted that North Koreans (DPRK) to pay in hard currency, since DPRK has been widely suspected to be the source of "super notes" counterfeit US currencies and as such any USD cash coming out of DPRK cannot be trusted...
Hugh Laurie STAYS in USA!
Send Stephie Fry STAYS too.
We also want Alan Davies and Caroline Quentin.
Wait? are there any good actors in USA to trade to UK?
OK, Here is the deal! You get them all back, if you promise to make Aland Davies the next Doctor Who.
Madonna we ship to North Korea! Oops, That is a violation of the rules of war. WMD used on civilians.
Never trust a man wearing a coat and tie!
As previously Beetles America invasion failed, they now are trying with Zombies. Whats next? Vampires? Werewolves?
...all their bandwidth is being used up sending out DDoS attacks! Doh!
The North Koreans want you to think it was all organised by the friends of Gary McKinnon but they know better.
On July 4th, a "friend" on facebook commented, "I'm so glad we're not under Britain."
I thought, "Wow, he's missing the point."
Oh dear, looks like poor Alan Johnson will be up all night approving extradition warrants.
He can save time by not reading them, because it seems the stupid bitch who preceded him never bothered.
Confucius say, "Find worm in apple - bad. Find half a worm - worse."
Memo to "some" in the US and South Korean governments: so please be careful in future of making loose claims about North Korea doing bad stuff, unless you're sure. We don't need any Gulf of Tonkins and mobile bacteriological weapons labs. Wars have been started over less; indeed, two have. North Korea is scary enough; let's not start seeing it behind every tree.
"How to Do Nothing," kids activities, back in print!
Gary McKinnon?
... that the US will soon be invading.
If it hadn't been the current government, I would have been a lot more worried...
:-)
DDos Attacks, Iraq, AND Afghanistan.
BTW, Has anyone seen or heard Tony Blair lately?
Yours In Communism,
Kilgore Trout
Then I say we outlaw Class C networks. Then only criminals will have Class C networks.
Put anyone with a Class C on the Really Bad Guy Axis of Evil Terrorist Country list.
Maybe we can get a judge in Kentucky to seize all the Class C networks. Then, we can nuke Kentucky.
Politics is the art of looking for trouble, finding it everywhere, diagnosing it incorrectly and applying the wrong fix.
(off topic)
Why have British/Australian journalists never been taught a consistent policy for capitalizing acronyms? Many a British article refers to NATO as Nato, and NASA as Nasa. This FA defines an acronym "Bkis" thusly:
Bach Khoa Internetwork Security (Bkis)
And yet the same article refers to PCs, not Pcs, and DDOS attacks, not Ddos attacks. It's maddening.
That that is is that that that that is not is not.
North Korea could have solicited the services of hackers in the U.K. or else where. It makes sense to outsource when you don't necessarily have the expertise in your own country. I'd like to point out here there are known NK sympathizers.
After logging in slashdot still does not take you back to the page you were on. It's been that way for 20 years.
I just cant decide. Dose he shill for Microsoft (IE) or Microsoft (Bing). At fist glance it would appear obvious that he is shilling for Microsoft (IE). To obvious in fact. That is why I think he is shilling for Microsoft (Bing). You know. Just throwing out the Google name with bad smell and hoping it sticks a bit. Need help must figure out soon if he is s shill for Microsoft or Microsoft. Any insight would be appreciated.
Why is it so hard to only have politicians for a few years, then have them go away?
Gotta love the misleading links, but I was hoping for a rickroll or some goatse in there somewhere just to top it off.
Anything can be found funny, from a certain point of view.
Just seeing a lot of fake video search results on google.
I made a vid of Safari on my Mac getting the trojan dmg pushed out.
http://www.youtube.com/watch?v=c3syWWeQu9s
Just feeling a lot of effort for fake vids links under many normal search terms.
Someone is building something on Macs and Win.
Domestic spying is now "Benign Information Gathering"
So, what you're saying is that North Korea controls the United Kingdom?
Damn, I always thought that was the case - that would explain all their animosity towards the Irish -- after all, the North Koreans have always been jealous of Guinness.
Now I understand everything........except why do dogs turn their heads away when you blow lightly in their faces, yet will always hang their heads out of an auto window when the car is going over 100 miles per hour?
I dare you to try to explain that one.....
Brilliant remark, Sherlock.....
Damn it! I forgot to erase the hard drive when I sent that used laptop - the one sold on E-Bay - to that address in North Korea. What the Hell does the Big Man of Pyongyang sould like to you? Would that be official-sounding????
why do dogs turn their heads away when you blow lightly in their faces, yet will always hang their heads out of an auto window when the car is going over 100 miles per hour?
Two words: breath mint.