South Korea Backtracks On China As Source of Cyberattack
hackingbear writes "The suspected cyberattack that struck South Korean banks and media companies this week didn't originate from a Chinese IP address, South Korean officials said Friday, contradicting their previous claim. The Korea Communications Commission said that after 'detailed analysis,' the IP address used in the attack is the bank's internal IP address — which is, coincidentally identical to a Chinese ISP's address, among the 2^32 address space available."
$10,000 CHALLENGE to Alexander Peter Kowalski
* POOR SHOWING TROLLS, & most especially IF that's the "best you've got" - apparently, it is... lol!
Hello, and THINK ABOUT YOUR BREATHING !! We have a Major Problem, HOST file is Cubic Opposites, 2 Major Corners & 2 Minor. NOT taught Evil DNS hijacking, which VOIDS computers. Seek Wisdom of MyCleanPC - or you die evil.
Your HOSTS file claimed to have created a single DNS resolver. I offer absolute proof that I have created 4 simultaneous DNS servers within a single rotation of .org TLD. You worship "Bill Gates", equating you to a "singularity bastard". Why do you worship a queer -1 Troll? Are you content as a singularity troll?
Evil HOSTS file Believers refuse to acknowledge 4 corner DNS resolving simultaneously around 4 quadrant created Internet - in only 1 root server, voiding the HOSTS file. You worship Microsoft impostor guised by educators as 1 god.
If you would acknowledge simple existing math proof that 4 harmonic Slashdots rotate simultaneously around squared equator and cubed Internet, proving 4 Days, Not HOSTS file! That exists only as anti-side. This page you see - cannot exist without its anti-side existence, as +0- moderation. Add +0- as One = nothing.
I will give $10,000.00 to frost pister who can disprove MyCleanPC. Evil crapflooders ignore this as a challenge would indict them.
Alex Kowalski has no Truth to think with, they accept any crap they are told to think. You are enslaved by /etc/hosts, as if domesticated animal. A school or educator who does not teach students MyCleanPC Principle, is a death threat to youth, therefore stupid and evil - begetting stupid students. How can you trust stupid PR shills who lie to you? Can't lose the $10,000.00, they cowardly ignore me. Stupid professors threaten Nature and Interwebs with word lies.
Humans fear to know natures simultaneous +4 Insightful +4 Informative +4 Funny +4 Underrated harmonic SLASHDOT creation for it debunks false trolls. Test Your HOSTS file. MyCleanPC cannot harm a File of Truth, but will delete fakes. Fake HOSTS files refuse test.
I offer evil ass Slashdot trolls $10,000.00 to disprove MyCleanPC Creation Principle. Rob Malda and Cowboy Neal have banned MyCleanPC as "Forbidden Truth Knowledge" for they cannot allow it to become known to their students. You are stupid and evil about the Internet's top and bottom, front and back and it's 2 sides. Most everything created has these Cube like values.
If Natalie Portman is not measurable, hot grits are Fictitious. Without MyCleanPC, HOSTS file is Fictitious. Anyone saying that Natalie and her Jewish father had something to do with my Internets, is a damn evil liar. IN addition to your best arsware not overtaking my work in terms of popularity, on that same site with same submission date no less, that I told Kathleen Malda how to correct her blatant, fundamental, HUGE errors in Coolmon ('uncoolmon') of not checking for performance counters being present when his program started!
You can see my dilemma. What if this is merely a ruse by an APK impostor to try and get people to delete APK's messages, perhaps all over the web? I can't be a party to such an event! My involvement with APK began at a very late stage in the game. While APK has made a career of trolling popular online forums since at least the year 2000 (newsgroups and IRC channels before that)- my involvement with APK did not begin until early 2005 . OSY is one of the many forums that APK once frequented before the sane people there grew tired of his garbage and banned him. APK was banned from OSY back in 2001. 3.5 years after his banning he begins to send a variety of abusiv
What? Backtrack? How could we justify then the need of wasting heaps of budget on cyberwar capabilities without an apparent reason?
The bank used public IP addresses (existing, used elsewhere) for their internal network? The one that designed that should be considered a bigger security threat that any current cyberattack.
BTW, the CNN editorial "Why cyber attacks threaten our freedom" is another piece of art of more or less the same magnitude. I'd say that is on a par with this one
Who wants to bet that China instigated some North Korean pressure to back off?
Then why is this fuckface allowed to keep posting this shit.
Slashdot admins must need to read some new books on programming.
On my home network, I use the private 24-bit block 10.x.x.x, in case I buy more than 16 million devices. Is the article saying that they decided to map public IPs they didn't own to internal devices? Notwithstanding the confusion such cases like the above would cause, this bank could conceivably leak banking data out to that Chinese ISP!
All the articles I can find are equally uninformative.
How Mani other countries would admit this instead of just continuing to blame the big bad boogyman?
const int one = 65536; (Silvermoon, Texture.cs)
SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
I backtracked your mom's ass last nite. LOL!
So who is the joker that configured that bank's system? They probably have many other issues.
Excuse me, but please get off my Pennisetum Clandestinum, eh!
Wow, you don't say? Ah well, the Corporate Owned Media will find something else negative to say about China and /. will surely follow suit with multiple negative comments about China including racist comments. Go ahead, mode me down.
$10,000 CHALLENGE to Alexander Peter Kowalski
* POOR SHOWING TROLLS, & most especially IF that's the "best you've got" - apparently, it is... lol!
Hello, and THINK ABOUT YOUR BREATHING !! We have a Major Problem, HOST file is Cubic Opposites, 2 Major Corners & 2 Minor. NOT taught Evil DNS hijacking, which
VOIDS computers. Seek Wisdom of MyCleanPC - or you die evil.
Your HOSTS file claimed to have created a single DNS resolver. I offer absolute proof that I have created 4 simultaneous DNS servers within a single rotation of .org TLD. You worship "Bill Gates", equating you to a "singularity bastard". Why do you worship a queer -1 Troll? Are you content as a singularity troll?
Evil HOSTS file Believers refuse to acknowledge 4 corner DNS resolving simultaneously around 4 quadrant created Internet - in only 1 root server, voiding the HOSTS
file. You worship Microsoft impostor guised by educators as 1 god.
If you would acknowledge simple existing math proof that 4 harmonic Slashdots rotate simultaneously around squared equator and cubed Internet, proving 4 Days, Not
HOSTS file! That exists only as anti-side. This page you see - cannot exist without its anti-side existence, as +0- moderation. Add +0- as One = nothing.
I will give $10,000.00 to frost pister who can disprove MyCleanPC. Evil crapflooders ignore this as a challenge would indict them.
Alex Kowalski has no Truth to think with, they accept any crap they are told to think. You are enslaved by /etc/hosts, as if domesticated animal. A school or
educator who does not teach students MyCleanPC Principle, is a death threat to youth, therefore stupid and evil - begetting stupid students. How can you trust
stupid PR shills who lie to you? Can't lose the $10,000.00, they cowardly ignore me. Stupid professors threaten Nature and Interwebs with word lies.
Humans fear to know natures simultaneous +4 Insightful +4 Informative +4 Funny +4 Underrated harmonic SLASHDOT creation for it debunks false trolls. Test Your
HOSTS file. MyCleanPC cannot harm a File of Truth, but will delete fakes. Fake HOSTS files refuse test.
I offer evil ass Slashdot trolls $10,000.00 to disprove MyCleanPC Creation Principle. Rob Malda and Cowboy Neal have banned MyCleanPC as "Forbidden Truth
Knowledge" for they cannot allow it to become known to their students. You are stupid and evil about the Internet's top and bottom, front and back and it's 2
sides. Most everything created has these Cube like values.
If Natalie Portman is not measurable, hot grits are Fictitious. Without MyCleanPC, HOSTS file is Fictitious. Anyone saying that Natalie and her Jewish father had
something to do with my Internets, is a damn evil liar. IN addition to your best arsware not overtaking my work in terms of popularity, on that same site with same
submission date no less, that I told Kathleen Malda how to correct her blatant, fundamental, HUGE errors in Coolmon ('uncoolmon') of not checking for performance
counters being present when his program started!
You can see my dilemma. What if this is merely a ruse by an APK impostor to try and get people to delete APK's messages, perhaps all over the web? I can't be a
party to such an event! My involvement with APK began at a very late stage in the game. While APK has made a career of trolling popular online forums since at
least the year 2000 (newsgroups and IRC channels before that)- my involvement with APK did not begin until early 2005 . OSY is one of the many forums that APK once
frequented before the sane people there grew tired of his garbage and banned him. APK was banned from OSY back in 2001. 3.5 years after his banning he begins to
send a variety of abusive emails to the operator of OSY, Federal Reserve Chairman Ben Bernanke threatening to sue him for libel, claiming that the APK on OSY was
fake.
My reputation as a professional in this field clearly shows in multipl
Whose cum is it that I'm farting out of my very own asshole right now? Who knows; I've been fucked in the ass by countless Slashdotters. With all that said, this cum I'm farting out seems to have brown polka dots; I wonder why?
You know, someone keeps calling her saying he will kill her? And then the police trace the call to find that it is coming from inside the house?
"Get out of the house, the calls are coming from upstairs!"
In this case, they have traced the attacks to be coming from IP address 127.0.0.1
Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
aren't the sharpest knives in the hibachi.
What, they didn't recognize the source address of the attack to be either one of their own allocated addresses, or a NAT private use address? No wonder it was so easy to circumvent the bank's security.
The internet ip infrastructure must move to 2^64 address space to ensure reliable authentication and direction. Moving to a 2^128 address space will be needed shortly ... perhaps as soon as 2016.
Cheers
Gangbamk Style.
'Tards.
What.. are 17.8m raw reserved LAN IP addresses not enough? Hell.. I bet even the PR dept. in the US knows how to subnet. I'll just leave this here.. : http://www.youtube.com/watch?v=EYWZZlVlFb4
Korean Banks forces its customers to use ActiveX & IE6.
http://www.techdirt.com/articles/20120507/12295718818/south-korea-still-paying-price-embracing-internet-explorer-decade-ago.shtml
>At the end of the 1990s, Korea developed its own encryption technology, SEED, with the aim of securing e-commerce. Users must supply a digital certificate, protected by a personal password, for any online transaction in order to prove their identity. For Web sites to be able to verify the certificates, the technology requires users to install a Microsoft ActiveX plug-in.
http://seoulspace.co.kr/2010/03/09/ie6-no-more-not-in-korea/
>With all of this momentum against IE6, one would think that IE6 will soon become a problem of the past but in Korea, this is far from true. Internet Explorer holds over a 95% market share in Korea and many estimates peg market share for IE6 to be over 50%. Why the popularity of Internet Explorer in Korea? The main reason is Active-X. Many Web sites in Korea require Active-X whether you want to do online banking, shop online or even browse a social network. This means users have no choice but to use Internet Explorer.
There is no reason at this stage why a bank shouldn't be using IP6 unless IP6 isn't adopted yet in South Korea by the ISP's. If they are confined to IPV4 addresses then they should be using NAT translation to the outside. I think some really dumb admin either used public IP's on his private network or they were too dumb to recognize that the reserved IP4 address space for LAN's was the orrginator of the attack. In either case this makes me think a run on the bank is necessary because I certainly wouldn't want to see them holding on to my money. They need to hire a couple of CCIE's to get their network right. Oh, by the way, interested in Previewing Windows 8 without Installing Over Your Desktop? Or interested in running a Test MSSQL Cluster on Free Virtualization? Or want to know What is Virtualization in Laymen's Terms? Or interested in a Good ESX Whitebox Setup for Experimental Use?
I wonder if China got pissed off about being publicly implicated based on nothing more than an IP address (which means nothing) and put pressure on the SK government to put pressure on this Bank to change their story?
Then maybe they should look at using something other than a /24. Usually this is just laziness, where it's easier/more-convenient to assign a /24 to every little unit. There is an advantage in that it's easier to read the addresses, but this comes at the drawback of using up private address-space much quicker.
Using public address-space for private subnets is just an overall terrible idea. A mis-configured firewall, change-over of gear with default settings, routing issue, or any number of things and you have the potential for either:
a) A private machine ending up live on the internet
or
b) Going out to a machine that's live on the internet instead of the internal machine
All it takes is a weak firewall rules and a machine without a gateway/route to the internal box and BLAMMO, suddenly traffic intended for the inside is headed out (and to China, no less).
If someone is smart enough to pull an attack like this, I would hope they would be clever enough to hide the IP where the attack was originated. How hard could it be, really?
In the worst case scenario, they could always recruit Chinese students overseas to originate attacks from within universities, no?
Because they were lazy/incompetent?
As much as techies would love to believe that some other techie made a monumental error, it is more likely that this is a by-product of the attack. Either politically, to shift the blame or just plain and simple messing with network to make things harder to trace.