Cyberspies Hijacked the Internet Domains of Entire Countries (wired.com)
Trailrunner7 shares a report: The discovery of a new, sophisticated team of hackers spying on dozens of government targets is never good news. But one team of cyberspies has pulled off that scale of espionage with a rare and troubling trick, exploiting a weak link in the internet's cybersecurity that experts have warned about for years: DNS hijacking, a technique that meddles with the fundamental address book of the internet. Researchers at Cisco's Talos security division on Wednesday revealed that a hacker group it's calling Sea Turtle carried out a broad campaign of espionage via DNS hijacking, hitting 40 different organizations.
In the process, they went so far as to compromise multiple country-code top-level domains -- the suffixes like .co.uk, or .ru, that end a foreign web address -- putting all the traffic of every domain in multiple countries at risk. The hackers' victims include telecoms, internet service providers, and domain registrars responsible for implementing the domain name system. But the majority of the victims and the ultimate targets, Cisco believes, were a collection of mostly governmental organizations including ministries of foreign affairs, intelligence agencies, military targets, and energy-related groups, all based in the Middle East and North Africa. By corrupting the internet's directory system, hackers were able to silently use "man-in-the-middle" attacks to intercept all internet data from email to web traffic sent to those victim organizations.
[...] Cisco Talos said it couldn't determine the nationality of the Sea Turtle hackers, and declined to name the specific targets of their spying operations. But it did provide a list of the countries where victims were located: Albania, Armenia, Cypress, Egypt, Iraq, Jordan, Lebanon, Libya, Syria, Turkey, and the United Arab Emirates. Cisco's Craig Williams confirmed that Armenia's .am top-level domain was one 'of the "handful" that were compromised, but wouldn't say which of the other countries' top-level domains were similarly hijacked.
In the process, they went so far as to compromise multiple country-code top-level domains -- the suffixes like .co.uk, or .ru, that end a foreign web address -- putting all the traffic of every domain in multiple countries at risk. The hackers' victims include telecoms, internet service providers, and domain registrars responsible for implementing the domain name system. But the majority of the victims and the ultimate targets, Cisco believes, were a collection of mostly governmental organizations including ministries of foreign affairs, intelligence agencies, military targets, and energy-related groups, all based in the Middle East and North Africa. By corrupting the internet's directory system, hackers were able to silently use "man-in-the-middle" attacks to intercept all internet data from email to web traffic sent to those victim organizations.
[...] Cisco Talos said it couldn't determine the nationality of the Sea Turtle hackers, and declined to name the specific targets of their spying operations. But it did provide a list of the countries where victims were located: Albania, Armenia, Cypress, Egypt, Iraq, Jordan, Lebanon, Libya, Syria, Turkey, and the United Arab Emirates. Cisco's Craig Williams confirmed that Armenia's .am top-level domain was one 'of the "handful" that were compromised, but wouldn't say which of the other countries' top-level domains were similarly hijacked.
I expect this to be rectified as soon as IPV6 gains wide acceptance.
(I can already hear a belgian waffle saying how advanced his country is for adopting ipv6 early and that everyone he knows is on it! Thank you!)
needless to say it's a party right now
Notably missing from the list...interesting.
If only there was a way to secured DNS lookups. /s -_-
Anons need not reply. Questions end with a question mark.
This is why DNSSEC is needed. If these country specific TLDs were signed properly with DNSSEC, this wouldn't have been a problem(unless the keys get compromised, but thats a different problem).
Don't worry about food, worry about guns and roses.
Albania, Armenia, Cypress, Egypt, Iraq, Jordan, Lebanon, Libya, Syria, Turkey, and the United Arab Emirates.
There is not Israel observable in the Cisco's list. So, unlike Cisco Talos, I can determine the nationality of the Sea Turtle hackers...
could it be your unaccounted for tax dollar (US) at work via NSA, CIA, Pentagon, etc...
These "HACKERS" can do EVERYTHING. At least so would the media have you believe.
Its called a Quantum Computer. The NSA got it first, so were all screwed ;(
Or rather Cyprus?
Sent as ripples into the electromagnetic field. No single photon has been harmed in the process.
Around 2006 to 2009, there were a lot of interesting articles being published about advances made in the Quantum computer field.
It looked like SSL encryption would be obsolete in a couple of years.
I saved a bunch of those web pages.
Today -- its like its all been erased from the internet.
In its place is a lot of relatively lame crap that makes Quantum hacking look "impossible".
I never used to "out" myself as a conspiracy theorist -- but then Snowden came along.
These are countries that America has always been interested in destabilizing and establishing platforms for espionage and sabotage in. Cisco knows this exactly, but of course they have to be careful about stepping up against their own government.
I wonder why Cisco's opendns.com is so adamant about not adopting DNSSEC. Hmmmm?
If they cared about security they would enable DNSSEC like Cloudflare already has.
See subject: Via APK Hosts File Engine 2.0++ 64-bit for Linux/BSD h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p
Yields more security/speed/reliability/anonymity vs. any 1 solution (99% of threats use hostnames vs. IP address most firewalls use) more efficiently/FASTER/NATIVELY 4 less!
Vs. "Bolt on 'MoAr' illogic-logic" slowing u hosts speed u up 2 ways: Adblocks + Hardcode fav. sites u spend most time @ vs. competition w/ security bugs (DNS/AntiVir) + overheads slowing u (messagepass 'souled-out' to advertisers easily detected & blocked addons + firewall filtering drivers) & their complexity leads to exploit!
* Hosts protect vs. DNS redirect, being down or dns requestlog tracking + hosts resolve you FASTER too!
APK
P.S.=> Protects vs. scripts/trackers (kernelmode faster vs. usermode slower NoScript vs. 3rd party script)/ads/botnets/malware download/malcript/email malpayload
Odd /. won't report on UBlock/Adblock problems https://nakedsecurity.sophos.c... https://www.bleepingcomputer.c... eh? Not.
* "OpenSORES" BLOWS IT AGAIN is why!
APK
P.S.=> Ask yourselves that question - ESPECIALLY from BLEEPING COMPUTER (which /. uses to NO END for stories) - WHY did /. AVOID "BIG NEWS"? OH, we KNOW why (see above) - & that cannot happen to hosts files (which is WHY whipslash AVOIDS THE STORY - he knows I'll GLOAT)... apk
OpenDNS is patched against the kaminsky redirect poisoning flaw https://www.wired.com/2008/08/... "One alternative Kaminsky recommended last month was to use OpenDNS â" which wasn't affected by the vulnerability."
APK
P.S.=> Which IS how I know that my program gets CORRECT IP address to hostname resolution per my original post here (& why I definitely can't get BOGUS data that way from OpenDNS) https://it.slashdot.org/commen... ... apk
I had typed out a response to that thread, only to get a error that the parent comment wasn't found. Slashdot deleted his comment while I was replying. It was a low quality comment but the original post in the thread about hardcoded DNS was on-topic. Interesting that the hosts comment got deleted, but the antisemitic diatribes are still here. What the fuck is wrong with Slashdot?
Interestingly, I received a message saying "You are not allowed to use this resource." the first time I tried to reply to APK's thread. The editors are quietly deleting posts and probably banning IP addresses from posting for no good reason at all. They haven't commented on their reasons for deleting comments and banning IP addresses, but it's a level of censorship that would NEVER have happened under CmdrTaco.
I don't like APK at all. In fact, he demanded I tell him my name and address so he could fracture my skull. Yes, he made that specific threat toward me. However, Slashdot should not be deleting his comments, especially when they're on-topic. Moderate them to -1 if appropriate, but the censorship is asinine and unhelpful.
Fuck Off APK
See subject: Hosts BLOCK 3rd party scripts too & FASTER than NoScript does (@ kernelmode level & all calls boil down to sys/sockets.h stupid) BEFORE usermode SLOWER NoScript even gets a chance to operate.
* ADVERTISERS DON'T TRUST WEBMASTERS which is WHY the scripts ARE 3rd party idiot.
APK
P.S.=> Give me a BREAK you STUPID little goof - you're TOO EASY to BLOW AWAY w/ facts dumbo, lol... apk
I'll take countries trying to re-expand their territory having already taken half of the Ukraine, meddled in Turkey and Syria who appear to be going after the east end of the Mediterranean, control of the Suez Canal, and encircling Western-allied middle eastern countries with oil supplies, for 10 please Alex.
JEW SHUL OUTSMARTED BY FACT? Yes https://it.slashdot.org/commen...
Yes, you are APK. Although your comments are of very low quality, including the one I'm replying to, I'm saying Slashdot shouldn't be deleting those comments. I obviously have a strong disdain for you, but I'm defending you on this particular issue because I support free speech. In fact, my opinions might carry more weight on this matter because I'm hostile toward you while simultaneously supporting you on this one issue. Unfortunately, you just can't help yourself, and have chosen to pollute this thread with antisemitic bullshit.
u mad bro?
Aw! Programmatic FACT beat you again? STUPID, I block 3rd party trackers IN HOSTS dummy & advertisers don't trust webmasters.
* LMAO - keep up? You DUMB bitch - you're too DUMB to get to me OR get the BETTER of me (check any IP related call - they DO boildown to sys/sockets.h (kernelmode where HOSTS is as part of the IP stack no less for BEST SPEED/most cpu priority).'
DUMBO, obviously, you're a WEBDOUCHE (wannabe coder, lol) & minus GUYS LIKE ME that build what you WANNABES code on? You're lost - YOU PROVED THAT MUCH ALREADY stupid.
APK
P.S.=> Face facts: You're way, Way, WAY TOO STUPID to get the best of me - ever! I hardcode a.fsdn.com dumbo (so I get it faster along w/ EVERY /. domain/subdomain, especially images.slashdot.org too)... apk
No you project you're mad. JEWS from SHUL can't beat fact https://it.slashdot.org/commen... Why are jews kicked from everywhere? Explain that.
See subject: It makes me LMAO when the "wannabes of code" (webdouches) try "take me on" only to go "SPLAT" after I swat them!
* Anyhow/anyways: Per tests I've taken, for whatever THEY are worth that is? Between 135-140 iiirc...
APK
P.S.=> THIS is NOT about "IQ" - it's about EXPERIENCE on levels the WEBDUMBOS (lol) don't have & it SHOWS https://it.slashdot.org/commen... & here too even more (lol) https://it.slashdot.org/commen... after I dispatch these FUCKING stupid UNIDENTIFIABLE anonymous BULLSHITTERS (who are, obviously? WEBDUMMIES, lol)... apk
..on lease to Israel or Saudi Arabia.
#freedumbs
Oy vey!Jew collective SHUL crap lies defeated publicly by fact. Hahahahahahahahahaha!
See subject: I didn't play D1 - never said I did (but I did score on what became the decades long national D1 champ in Syracuse University (where an OLD PAL whom I respected the HELL out of for good reason, Todd Curry told me "NICE SHOT, AL!" (which it was)).
I was D3 (later D2 upgraded who WON THAT NATIONAL CHAMPIONSHIP @ that level & plays SU to THIS DAY to a standstilll - you have to understand something: I WAS BLESSED my entire LIFE being surrounded by GREATNESS - really great people academically & yes, ATHLETICALLY (Hi Todd Curry & Tom Korrie (who taught me to string 'corner pockets' for MY teams)).
I did start as a freshman & was iirc, 2nd or 3rd leading scorer that year (I should have been 1st, my 'bad', imo (we had a GOOD solid 1st string, not much depth)).
I loved the game & miss it but MORE IMPORTANTLY? Being SURROUNDED by greatness - it INSPIRES you to be better & per Ted Williams (a TRUE great in another sport)?
WE HAVE AN OBLIGATION TO MAKE SOMETHING BETTER IF YOU KNOW THAT YOU CAN! & I'm trying in vain it seems to BETTER the "webdummies" around /. (see below, lol).
APK
P.S.=> That's LONG in the past though (LeMoyne OWES ME 9 points off that 1st year too per Kevin McNeill who handles it) BUT it's SOMETHING that FLIMSY 1 dimensional LIMITED WHIMPS like YOU will NEVER, ever do (you're too weak & DUMB lol https://it.slashdot.org/commen... which that link & THIS https://it.slashdot.org/commen... prove lol)... apk
Limited 1 dimensional WHIMP, please https://it.slashdot.org/commen... & I am part of a LeMoyne Lacrosse FACT (record) - we've NEVER been "shutout" (& I stopped THAT vs. both the GREAT SU, whom I grew up w/ their standouts as pals/competitors athletically no less - inspiring people UNLIKE A LOSER LIKE YOU stalking me by UNIDENTIFIABLE anonymous like the FLIMSY WORM you are, lol)).
Both vs. RIT (great team 'tigers' & VERY IMPORTANTLY, in front of Kris Heuring their ALL-TIME soccer leading scorer for women (what a BEAUTIFUL & SMART gal I blew it w/ in highschool)) & SU too.
APK
P.S.=> It was a REAL PLEASURE "smoking" PUNKS like YOU here https://it.slashdot.org/commen... & here too by the way (lmao) https://it.slashdot.org/commen... showing the PLANET how FUCKING WEAK & "wannabe" you DILDOS truly are, lol... apk
Thank you for replying and providing me with a wealth of information.
As you know, the NCAA publishes a lot of information online, including past scores, stats, and records. Unfortunately for you, I didn't find a shred of evidence that you actually played for LeMoyne or, for that matter, any other school. Yes, Todd Curry really did play for Syracuse. However, I see no evidence that you ever played against Syracuse or, for that matter, that you ever played NCAA lacrosse at all. I looked through the records of D1, D2, and D3, but came away empty.
Mostly he just shoved the lacrosse sticks up his ass, and is confusing that with the actual sport.
"relatively lame crap that makes Quantum hacking look "impossible" "
Lame nonsense is right. A quantum computer can't crack a seed that has a length of 270000 bits. The permutations are 30000 decimal digits. That's just for starters. The size of the seed can be multiplied many times.
Then the message can be scrambled many, many times to make it undecipherable.
See subject: & do you REALLY THINK I'd lie publicly? No way. That's for CHUMPS & LOSERS, not for me.
* Tell you what - Write Kristen Heuring about when I scored on RIT - she'll tell you & do me a FAVOR: Tell her I blew it w/ her, she'll understand.
APK
P.S.=> I've had to DEAL with 1 dimensional "goal post movers" like YOU before, ages ago on /. & here is where I SMOKED THEM (probably you loser) on THAT VERY ACCOUNT https://slashdot.org/comments.... dumbo - lol, MOVE GOALPOSTS all you LIKE, flimsy 1 dimensional WHIMP? I STILL SCORE (blowing YOU & "your kind", weezils behind UNIDENTIFIABLE anonymous, away)... apk
LOL! Know what I find INTERESTING? This https://slashdot.org/comments.... shutting your ass down & MORE IMPORTANTLY, the FACT that 'weezils' like YOU try to 'attack me' (great attackman here year 1 in the NCAA but moved to midFUCKINGfield which I hated lol after) only to FAIL!
* It really DOES bother you that you are a LIMITED 1 dimensional whimp - the KIND I BLOW AWAY w/ ease per https://it.slashdot.org/commen... & https://it.slashdot.org/commen...
APK
P.S.=> See, I've got "your number down" - you HATE guys like ME that CRUSH wannabes (like you, lol) & you keep PROVING it STALKING me by UNIDENTIFIABLE anonymous (You'll always be NOBODIES & it is YOUR FAULT, lazy losers)... apk
Today -- its like its all been erased from the internet. In its place is a lot of relatively lame crap that makes Quantum hacking look "impossible".
Conclusion: the available of actual "quantum code-breaking tech" will not be televised.
Know who Neil Olshey is? Write him & ask how my "behind the back" (rare in "them thar days" & I learned it from the Canuck national ALL STARS I played in highschool too no less) assist to him (after I scored a goal vs. University of Buffalo) was... lol).
* Hi Neil it's me "NUCLEAR MISSILE PILOT" (Pete Marino our defenseman will recall that lol)...
He & others (see below) can EASILY substantiate my statements as fact...
APK
P.S.=> OH, I'd NEVER have though that MY "halcyon days of yore" would be USED TO DESTROY weezils like you (be prepared to see how IMPORTANT & POWERFUL my former teammates have become - Bob Bilotti is another too (highschool INTO LeMoyne no less))... ak
"In the process, they went so far as to compromise multiple country-code top-level domains -- the suffixes like .co.uk, or .ru"
Okay, I gotta admit- I find this hilarious but I'm disappointed that the hackers didn't have some real fun with this, like redirecting ALL the traffic for a country to a site full of cat pictures, a RickRoll site, or maybe to the internet's last page.
Just cruising through this digital world at 33 1/3 rpm...
And I'm betting that the USA wouldn't get caught.
So. "vi" or "emacs"?
Wow! What nerve! What gall! What insight! So can like I use this as ... I meant THEY. Could THEY use this article to help perhaps get a raise and better equipment?
... the stuff THEY'RE using now is just pitiful. THEY. It's them. Way over there. Really.
I mean the stuff we've got now is just
If the universe is someone's simulation -- does that mean the stars are just stuck pixels?
You are a liar and that makes you an even worse form of 'troll' loser.
APK
The Wired article is terrible - the author didn't understand the Talos blog.
https://blog.talosintelligence...
The Talso blog post is opaque: they present no evidence that root servers for top level domains, such as .AM were compromised. They say it was possible, but a registrar != a registry, nor does that mean they masqueraded as the tech contact listed at IANA. IANA would have the history of any changes.
Notably, the threat actors were able to gain access to registrars that manage ccTLDs for Amnic, which is listed as the technical contact on IANA for the ccTLD .am. Obtaining access to this ccTLD registrars would have allowed attackers to hijack any domain that used those ccTLDs.
Perhaps you can explore the history here:
https://tldmon.dns-oarc.net/na...
"Maybe you played, but there isn't any corroborating evidence I can obtain with reasonable measures. I'll leave it at that." - by UNIDENTIFIABLE Anonymous Coward STALKER on Thursday April 18, 2019 @05:04PM (#58456558
I leave you EATING YOUR WORDS you unidentifiable anonymous stalker lunatic http://lemoynedolphins.com/spo... LETTER K 1985 = Alex Kowalski i.e. ME (they also owe me 1984 too per my other replies w/ Kevin McNeill in it)
* I not only PLAYED & STARTED in 84 but I also LETTERED in 84/85 too (which means I wasn't a "benchwarmer" but then a LIMITED GEEK LIKE YOU 1 DIMENSIONAL NOBODY would NOT know that...)
APK
P.S.=> You're an imbecile & a mental whacko... apk
Yes you made absurd claims & eat your words https://it.slashdot.org/commen... - enjoy the bitter taste of SELF-defeat (as you STALK me by UNIDENTIFIABLE anonymous NOBODY you are, loser).
APK
P.S.=> You are a PITIFUL sob... apk
I never said I'm "intellgent" but you did & by the same token of the ILLOGIC LOGIC you attempt? I can literally say you're the same AC.
PERIOD.
APK
P.S.=> I see the SAME stalker of me, UNIDENTFIABLE anonymous on BOTH posts so, there you go - evidence is DEFINITELY not in YOUR favor but it IS, mine via FACT (visible undeniable fact)... apk
Take your meds.