Slashdot Mirror


Iranian Hackers Suspected in Worldwide DNS Hijacking Campaign (zdnet.com)

US cybersecurity firm FireEye has uncovered an extremely sophisticated hacking campaign during which a suspected Iranian group redirected traffic from companies all over their globe through their own malicious servers, recording company credentials for future attacks. From a news report: Affected organizations include telecoms, ISPs, internet infrastructure providers, government, and sensitive commercial entities across the Middle East, North Africa, Europe, and North America. FireEye analysts believe an Iranian-based group is behind the attacks, although there is no definitive proof for exact attribution just yet. Researchers said the entities targeted by the group have no financial value, but they would be of interest to the Iranian government.

47 comments

  1. The enemy du jour by fustakrakich · · Score: 0

    People actually believe this stuff? Don't answer, rhetorical question. Just curious...

    --
    “He’s not deformed, he’s just drunk!”
    1. Re:The enemy du jour by fustakrakich · · Score: 1

      "no definitive proof"

      Hey! Good enough for me! Hang the bastards, right??

      This is sick! "no definitive proof", but let's put it in the headline anyway. Sells more papers. The entire "news' scene has become tabloid gossip!

      --
      “He’s not deformed, he’s just drunk!”
    2. Re:The enemy du jour by haruchai · · Score: 1

      "no definitive proof"

      Hey! Good enough for me! Hang the bastards, right??

      This is sick! "no definitive proof", but let's put it in the headline anyway. Sells more papers. The entire "news' scene has become tabloid gossip!

      Read the article. It may not be "definitive" but it's well beyond merely plausible

      --
      Pain is merely failure leaving the body
    3. Re: The enemy du jour by Anonymous Coward · · Score: 0

      Calm down Francine. You have some vested interest in defending Russians or Iranians? Youâ(TM)re acting suspicious and getting defensive.

    4. Re:The enemy du jour by Anonymous Coward · · Score: 0

      Why, do you have compelling evidence that the story is false? If not, go fuck yourself for pretending.

    5. Re: The enemy du jour by Anonymous Coward · · Score: 0

      Oops

    6. Re:The enemy du jour by Anonymous Coward · · Score: 0

      People actually believe this stuff? Don't answer, rhetorical question. Just curious...

      Obviously everyone should believe you rather than any other source, at least that's how it is in the fantasy world you've constructed in which your life
      matters.

      You're in for a life of disappointment and frustration, son. You see, a prole like you doesn't matter any more than an ant which is crushed by the tracks of a tank. You're not even noise in the background in the equation of world events. The sooner you get used to this truth and accept it, the sooner you will have a chance to be happy and quit whining.

    7. Re:The enemy du jour by fustakrakich · · Score: 1

      it's well beyond merely plausible

      Only by an appeal to authority.

      --
      “He’s not deformed, he’s just drunk!”
    8. Re:The enemy du jour by Anonymous Coward · · Score: 0

      Damn! the chickenhawks speak up! And moderate!!

      FYI: The burden of proof is on the prosecutor, absence of real public cross examination verifies nothing...

    9. Re: The enemy du jour by Anonymous Coward · · Score: 0

      Well, everybody knows the best defence is a good offence.

      So, you suck, AC, you utterly totally suck. What am I saying, you fucking suck, you apple-toting hipster, you.

      There. Now it can't have been the Iranians or the Russians.

  2. redirected traffic all over their globe by Megahard · · Score: 1

    So those of us on a different globe are not affected?

    --
    I eat only the real part of complex carbohydrates.
    1. Re:redirected traffic all over their globe by Anonymous Coward · · Score: 0

      Almost, it's not a globe. The Earth is clearly flat. Lies within lies.

    2. Re:redirected traffic all over their globe by Anonymous Coward · · Score: 0

      No worries, like all politicians, those living on a different world are isolated from this problem.

  3. But Obama told us... by Anonymous Coward · · Score: 0

    ... that Iran were the good guys. He even proved it by giving them $400M in cash!

    1. Re:But Obama told us... by Mr.+Dollar+Ton · · Score: 1

      Well, a Saint Ronald made a deal with them once upon a time to hold some hostages a few months more, until he'd won an election. And then sold them advanced weaponry against the law.

  4. The only actually interesting blurb : by Anonymous Coward · · Score: 0

    ""While the precise mechanism by which the DNS records were changed is unknown, we believe that at least some records were changed by compromising a victim's domain registrar account,"

  5. When Republicans lie, keep the noose ready. by Anonymous Coward · · Score: 3, Informative

    When Republicans lie, all they effectively do is make their tiny penis just that much shorter. There are few males left. FYI that was Iran's money that the US had taken illegally and was compelled to give back by a court, in fact, and the way Obama got them to agree to the payment WITHOUT INTEREST was very much in the US best interest as it saved billions in EXTRA money that would have been paid to Iran. So yes, thanks Obama.

    TLDR, basically Republicans are faggots who lie about everything.

    1. Re:When Republicans lie, keep the noose ready. by guruevi · · Score: 0

      Explains all the leftists having to change gender (and literally invert their penis) then.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    2. Re:When Republicans lie, keep the noose ready. by Anonymous Coward · · Score: 0

      What about the hundreds of billions that Iran owes the US for assets seized, damages done, injuries... all of which was still pending? That money was being held until the money Iran owed the US was settled, which is part of why the US Congress passed a law specifically forbidding the government from transferring funds to Iran.
      Also, the transferred funds did include interest, and lots of it.

      TLDR, you are a lying, ignorant buffoon that is obsessed with Republican dick, because it's the only dick you've ever seen.

    3. Re:When Republicans lie, keep the noose ready. by Anonymous Coward · · Score: 0

      find a new insult, man. You're being a biggoted asshole, and its not fair to liken republicans to the gay community.

  6. Isn't this ironic, due to the shutdown and certs.. by ctilsie242 · · Score: 4, Informative

    This is timely. Right now, because of the shutdown, there are a lot of government domains whose certs are not being renewed, because there are no sysadmins able to renew them. So, with an expired cert, all it takes is a DNS attack to redirect someone from foo.gov to foo.ir, as the user is almost certainly not going to examine the cert and manually check its pedigree and dates.

    This is going to cause grave security concerns going forward.

  7. FireEye suspects Iranian group? by najajomo · · Score: 2

    FireEye, is this the same shower that provided security to Equifax:

    Equifax back FireEye for hacker defence:

    “We have this category that Equifax calls unhandled malware, [with] which traditional security approaches haven’t been very helpful. Putting in FireEye has really helped us detect this unhandled malware, then gives us the capability to take action to stay secure.” link

    1. Re:FireEye suspects Iranian group? by Anonymous Coward · · Score: 0

      FireEye is a decent security company, saying that Equifax using their product means that they're shit is just retarded.

    2. Re:FireEye suspects Iranian group? by Mr.+Dollar+Ton · · Score: 1

      Yeah, it is, like, an outfit that is totally independent from government influence, and they are totally not twisting anything on government behalf.

      https://venturebeat.com/2009/1...

  8. Re:Can't harm you when you avoid DNS... apk by Anonymous Coward · · Score: 0

    That actually would not stop this attack. Sorry!

  9. Impeach and hang the traitor. by Anonymous Coward · · Score: 0

    Bingo. Trump's "security concern" about the border (in fact 7 TIMES more terrorist suspects enter at the northern border, but forgetting that for now..) has caused massive security VULNERABILITIES across the board.

    Impeach and hang the traitor.

  10. hahhaha i dont use dns by Anonymous Coward · · Score: 0

    hahhaha i dont use dns

  11. Why not? apk by Anonymous Coward · · Score: 0

    It's an attempt @ redirecting DNS (near same as Kaminsky poisoning flaw does) & if you hardcode proper IP address to hostname in hosts, you not only RESOLVE IT FASTER vs. remote or even local DNS, but you also get there NON-REDIRECTED & where you intended to do (not a malicious doppleganger site OR otherwise non-genuine site).

    * I.E. - You get where you INTENDED to get to - not some BOGUS alternate due to redirected/poisoned DNS...

    APK

    P.S.=> Doing hosts the way my program does allows that & protects vs. threats galore + speeds you up 2 ways, natively (vs. "Bolt-on-'MoAr'" ILLOGIC-LOGIC "solutions" full of security issues I noted in the post you replied to) + avoids DNS requestlog tracking too... apk

  12. Re:Can't harm you when you avoid DNS... apk by Anonymous Coward · · Score: 0

    Ever wonder why APK always posts an an AC?

    Well, it's because APK is a Chinese hacker, and is actually the one responsible for this attack!

    APK Hosts File Engine rerouts all your traffic to Russia, China, and Iran!!

  13. Unidentifiable AC stalker of me says that? by Anonymous Coward · · Score: 0

    Unidentifiable AC stalker of me says what YOU did? Please - lmao! I'm NOT 'the bad guy' (to quote Ben Affleck's Daredevil rendition) & be GLAD I'm not - since IF I were? Believe you me - I'd be writing stuff that would BLOW AWAY any threats being done out there now - by far...

    * I don't DO "bogus" crap though & why? The internet itself really - in my 1/2 century++ of existence, it's one of, if not THE coolest thing I've ever seen done in my lifetime (great learning tool more than ANYTHING imo).

    APK

    P.S.=> I wrote the 1st model of this program in 2001 (some old utilities I wrote still have that model (sucked vs. this version imo)) & didn't get 'serious' about it until 2010 or so when things got REALLY "stupid" out there & it's worse now so, it was needed (to help stop the 'spread of the disease' so-to-speak))... apk

  14. Re:Isn't this ironic, due to the shutdown and cert by fustakrakich · · Score: 1, Funny

    Not to worry. Give him another 5 bil, and he'll give you a glorious new concrete fireWall!

    --
    “He’s not deformed, he’s just drunk!”
  15. Guruevi is an admitted pedo. by Anonymous Coward · · Score: 0

    Guruevi is an admitted pedo. Remember that every time he speaks. (Look in his comments 6 months ago, see for yourself)

  16. US cybersecurity firm by Anonymous Coward · · Score: 0

    And how can we know FireEye had not received an NSL telling them to lie about this?

    By the same logic that US is blocking Huawei, every US company is only one NSL away from being an extension of the US military and intelligence service. Nothing coming from any US firm can be trusted when it comes to anything related to Iran, Russia, China, etc.

    1. Re:US cybersecurity firm by Anonymous Coward · · Score: 0

      And how do we know that China or Iran hasn't planted you here to write that crap?

      How. Do. We. Know.

  17. Quote BLADE from Blade 1... apk by Anonymous Coward · · Score: 0

    See subject & "Remember what we told you" https://tech.slashdot.org/comm... "you keep your eyes open: They're EVERYWHERE..."

    * :)

    APK

    P.S.=> "The world you live in is just a sugar-coated topping - there is ANOTHER WORLD, beneath it - & IF you want to SURVIVE IT, you'd better LEARN to PULL the TRIGGER!"... apk

  18. Quote BLADE from Blade 1... apk by Anonymous Coward · · Score: 0

    See subject & "Remember what we told you" https://tech.slashdot.org/comm... "you keep your eyes open: They're EVERYWHERE..."

    * "There's a war going on out there. Blade, myself & a few others try to keep it from spilling onto the streets - You have to understand: They're everywhere. We hunt 'em you see, tracking their migrations. They're hard to kill, they tend to regenerate..." - Abraham Whistler

    APK

    P.S.=> "The world you live in is just a sugar-coated topping - there is ANOTHER WORLD, beneath it - THE REAL WORLD, & IF you want to SURVIVE IT, you'd better LEARN to PULL the TRIGGER!"... apk

  19. To whoever downmodded me? apk by Anonymous Coward · · Score: 0

    "You'll hunt me. You'll condemn me. Set the dogs on me" Batman from "The Dark Knight" (& you'll FAIL)...

    * "Sometimes, people deserve to have their FAITH REWARDED" per https://tech.slashdot.org/comm...

    Host-domain use in malware's down & I think what I did helped that per https://unit42.paloaltonetwork...

    (Especially all you "Lucius Fox" types - as I make not only malware threats go away but I make trackers & YES DNS REDIRECTS disappear too (right from that scene in the film by analogy))

    (MY FAITH IS REWARDED by that ACT OF FAITH on my part)

    "He didn't do anything wrong" - Jamie Gordon "The Dark Knight"!

    APK

    P.S.=> Any of you with talent/skills should be doing the SAME & Make a Wheel https://isc.sans.edu/forums/di... as I did multiplatform - it's EXACTLY mostly for those who you speak of... apk

    1. Re: To whoever downmodded me? apk by Anonymous Coward · · Score: 0

      I modded down your spam post. I didn't read this post of yours, either.

      SPH

    2. Re: To whoever downmodded me? apk by Anonymous Coward · · Score: 0

      You read it and realize you can't measure up to the challenge it presents to a no talent under-educated unskilled moron like yourself.

  20. Tripple whammy of "repsect my authoritay" by Anonymous Coward · · Score: 0

    It's a "computer security" imperial textile shop well known for shouting "hackers! hacking! with hacks!" in its press releases, a press release copy/pasted by a imperial textile "news" website also well known for shouting "hackers! hacking! with hacks!", and it's about "state-run hackers! with state-hacks! cyber state-backed cyber hacking!"

    And of course msmash would be the first to post this.

  21. Re:Isn't this ironic, due to the shutdown and cert by sheramil · · Score: 1

    Dare I say it... collusion?

  22. Re: Usa Loves Torturous Dictaitors by Anonymous Coward · · Score: 0

    You backed the Shah. You done fucked up.

    The only debts owed from the Iranian Revolution is an APPOLOGY from the American President for suporting the murderous Shah regime.

  23. Re: Youve EXPORTED Terror to Canada You Faggots by Anonymous Coward · · Score: 0

    But keep delluding yourself with Foxnews you mouthbreathing faggot.

  24. Can't harm you if you avoid DNS... apk by Anonymous Coward · · Score: 0

    See subject (+ DNS tracking & security issues like Kaminsky redirect poisoning 95++% of ISP dns aren't patched vs): I do for my TOP 100 fav sites I hardcode @ TOP of hosts files (for fastest possible local RAM based resolution speed along w/ blocking ads, infectors, malware, phishmail payload links, & malcript, etc. - et al) via:

    APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p (remove spaces between chars & download)

    APK Hosts File Engine 10++ SR-1 32/64-bit for Windows https://hosts-file.net/?s=Down... (DL link @ bottom)

    * Soon for MacOS (just got a NEW Mac-Mini to port it there)

    APK

    P.S.=> Accept NO substitutes (especially INFERIOR competitors in 'solutions' FULL of security issues (DNS/Antivirus OR 'souled-out' to NOT work by default (like adblock & other easily detected & nullified browser addons that DO LESS & yet USE MORE)))... apk