Pages

Showing posts with label Chinese hack. Show all posts
Showing posts with label Chinese hack. Show all posts

Friday, February 5, 2010

Cyber warfare begins, Cyber attacks in 2010

I have recently been following the attacks/hacks that have hit several of the internet's biggest "assets".

Is this cyber warfare?  Why is China attacking these companies? Is it really China?  Is china being used as a proxy for these attacks?  Could they be Russian? With the nature of the internet these are questions that cannot be answered until more information is obtained.  The scary fact is that we rely on the internet for just about every part of our daily lives in one way or another.  The internet is not built to handle cyber warfare on a large scale.

The kinds of attacks we are seeing are getting more and more sophisticated where the attacks are no longer a mass scan of computers and hack what is vulnerable.  The attacks we are seeing now are targeting specific computers even specific employees within an organization who have access to privileged data on the networks that other employees may not.  This allows them to create attacks from an inside computer which basically nulls the effectiveness of security lists, firewalls and other security measures put in place.  This also gives them access to sensitive data that an outside attack may not.

While these kinds of attacks are major, I have real concerns about what else these types of attacks are capable of doing.  When you look at possible attack vectors on the internet which are basically paths to hack your way onto a network or computer I come up with a couple more attack vectors that have not been seen yet and that I feel every person, provider, backbone, and entity in the world needs to be prepared to step in and stop.

These attacks include the denial of service attack and distributed denial of service attack.  What happens when the attacks go from country sponsored hack attacks to country sponsored denial of service attacks?  Country sponsored DDOS attacks could potentially shut down an entire countries internet and backbone providers in seconds.

I looked around spots on the internet for prices on hacked computers and I came up with around $100-$150 us dollars for 10000 hacked computers.  Finding out where to buy them was as simple as using Google.

I am taking a wild stab at figures here but let’s say each computer has about a 256kbps upstream.  That is 2500mbps of bandwidth that can be sucked up for around $100.  That is enough traffic to take down hundreds of computers at a data-center, key routers at internet service providers or many other dangerous scenarios.   With the sophistication of the hacking attempts going on, we need to get our networks secure and a plan in place to stop this if it ever happens.


Stay tuned for more, I will continue to follow this story and update on anything interesting as it happens.  For a very in depth audio about some of the recent attacks check out this podcast.



Ill be fighting to legalize freedom tell the day I die.

Friday, January 15, 2010

The chinese hacking attacks on google, adobe etc etc

Well it seems to me that this is a wake up call to ANY AND ALL major backbone corporations.
Its time to rethink security.
There never will be any policing the internet at least not effectively,   the only great policing we have for our networks is to block large portions or even entire countries from accessing networks at backbone levels. and even then this is simple for anyone to get around.  Internet2 is just flat out designed wrong and provides central points of failure from the exact same kind of corporations that have just been attacked.  These attacks from the chinese government on cybersitter, google, adobe and all the others is a major wake up call.  The sophistication of these attacks is much beyond the target a server and scan the ip for vulnerabilities  The attackers knew what operating system,  and what browser version the computer they was attacking,  the email was crafted to that person and was able to get them to a: click a link, b: exploit the vulnerability or c: get them to open a file attachment that has the payload and attack. The emails also appeared to be from coworkers i do believe.  With attacks this targeted,  I want you to stop and think,  if you run a large corporation with thousands of employees each with their own email address,  their own computer, a vpn connection from their home to your network. Everything being a gateway to your data  and just about everything else in your company. This leaves you as vulnerable as the security of each individual employee.   Every company should have a very strong security policy for both technical level and the workplace.  While these attacks are very sophisticated attacks,  that does not mean they are hard to pull off.
China and these other places cannot be allowed to condone business this way in stealing information The fact of the matter is,  most of the botnets you hear about on the news are 80% asian computers.  and the reason those numbers are so high is because the economy there cannot afford better computers,  so they are stuck with some very old insecure computers usually running pirated versions of windows.  or old 486`s running linux in these tiny datacenters all over the place.  i remember back in the day when hacking was in the scan and hack days when people targeted the 211.x.x.x range(korea and whatnot)  because it had more insecure networks than any other range on the internet,  and still leads true to this day judging by all the recent ddos attacks i have had the fun experience of trying to stop this year working for various places.  So basicly what im getting at is china the u.s and major corporations and other big entities have placed themselves in a position to where there entire infrastructure can be compromised by only a handful of people.  Do we really want this out of our leaders?  Google has the biggest database on everything in the world,  Adobe controls software installed on a very very large portion of the internets computers(shockwave flash).  Oracle they make database software not really to sure why they was attacked only thing that comes to mind would be the fact they can stream updates to every company that uses there database software(that number is massive) and posibly allow remote attackers to grab any database from any company receiving the updates or possibly stream a trojan with the update and have full access.  There are more companies that was attacked these companies need to come forward and let people know what these attackers are after, what is in place to protect it?. Till that happens it is impossible for other companies to harden there own security policy.

Ill be fighting to legalize freedom tell the day I die.