Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-27-2008, 06:55 AM   #1
eroticsexxx
Confirmed User
 
eroticsexxx's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Nassau, Bahamas
Posts: 3,133
Revealed: The Internet's Biggest Security Hole

Two security researchers have demonstrated a new technique to stealthily intercept internet traffic on a scale previously presumed to be unavailable to anyone outside of intelligence agencies like the National Security Agency.

The tactic exploits the internet routing protocol BGP (Border Gateway Protocol) to let an attacker surreptitiously monitor unencrypted internet traffic anywhere in the world, and even modify it before it reaches its destination.

The demonstration is only the latest attack to highlight fundamental security weaknesses in some of the internet's core protocols. Those protocols were largely developed in the 1970s with the assumption that every node on the then-nascent network would be trustworthy. The world was reminded of the quaintness of that assumption in July, when researcher Dan Kaminsky disclosed a serious vulnerability in the DNS system. Experts say the new demonstration targets a potentially larger weakness.

"It's a huge issue. It's at least as big an issue as the DNS issue, if not bigger," said Peiter "Mudge" Zatko, noted computer security expert and former member of the L0pht hacking group, who testified to Congress in 1998 that he could bring down the internet in 30 minutes using a similar BGP attack, and disclosed privately to government agents how BGP could also be exploited to eavesdrop. "I went around screaming my head about this about ten or twelve years ago.... We described this to intelligence agencies and to the National Security Council, in detail."

The man-in-the-middle attack exploits BGP to fool routers into re-directing data to an eavesdropper's network.

Anyone with a BGP router (ISPs, large corporations or anyone with space at a carrier hotel) could intercept data headed to a target IP address or group of addresses. The attack intercepts only traffic headed to target addresses, not from them, and it can't always vacuum in traffic within a network -- say, from one AT&T customer to another.

The method conceivably could be used for corporate espionage, nation-state spying or even by intelligence agencies looking to mine internet data without needing the cooperation of ISPs.

http://blog.wired.com/27bstroke6/200...ed-the-in.html
__________________
eroticsexxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 06:57 AM   #2
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,829
you lost me at "Two"...
MaDalton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 07:13 AM   #3
Iron Fist
Too lazy to set a custom title
 
Join Date: Dec 2006
Posts: 23,400
Because we all have access to backbone BGP routing... why I'll just head on over to the datacenter and just walk right on in!
__________________
i like waffles
Iron Fist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 07:14 AM   #4
Angry Jew Cat - Banned for Life
(felis madjewicus)
 
Industry Role:
Join Date: Jul 2006
Location: In Mom & Dad's Basement
Posts: 20,368
If anyone is capable of it, Mudge is the man for the job.
Angry Jew Cat - Banned for Life is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 07:15 AM   #5
Eriic
So Fucking Banned
 
Join Date: Jan 2008
Posts: 2,995
O.K. Then,, Ur, Oh Awe, Yawn..................
Eriic is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 07:28 AM   #6
eroticsexxx
Confirmed User
 
eroticsexxx's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Nassau, Bahamas
Posts: 3,133
:2cents

I posted this because theoretically a tech savvy adult provider can siphon off/monitor/intercept traffic headed to any other major website. OR have someone at an ISP do it for them

The implications could be devastating and ISP's don't really see the need to upgrade to SBGP at present.

Just letting you guys and gals know.
__________________
eroticsexxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 08:01 AM   #7
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
they can have all my bases
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 08:04 AM   #8
Marcus Aurelius
No Refunds Issued.
 
Marcus Aurelius's Avatar
 
Industry Role:
Join Date: Apr 2003
Posts: 14,809
Does this mean that someone could be reading my letters to penthouse forum before they are published? cuz if so...DAMN!
Marcus Aurelius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 08:06 AM   #9
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
Quote:
Originally Posted by eroticsexxx View Post
I posted this because theoretically a tech savvy adult provider can siphon off/monitor/intercept traffic headed to any other major website. OR have someone at an ISP do it for them
No it can't. And something like this has been possible a long time ago. Security hole like this is the same as saying a security hole is that someone can intercept your traffic IF he steals one of the routers along the path in one of the datacenter... ORLY!
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 08:54 AM   #10
sumphatpimp
Confirmed User
 
Join Date: Aug 2002
Posts: 5,235
biggest security risk is the dork between the seat and the keyboard.
always has been, always will be.
and no software or hardware can fix that.
sumphatpimp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:03 AM   #11
TheDoc
Too lazy to set a custom title
 
TheDoc's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
So the security risk is Sys admins? Well we are really screwed then aren't we.

Some Hosting Companies (one that isn't around anymore) use to steal/rip traffic from the sites at the router level. If you don't think some dirty hosts have ripped traffic, emails, member records, ect, then you are naive.
__________________
~TheDoc - ICQ7765825
It's all disambiguation
TheDoc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:11 AM   #12
xmas13
Confirmed User
 
xmas13's Avatar
 
Join Date: Dec 2004
Location: GFY
Posts: 5,176
Technically I can steal virtually anything in a grocery store. It's another ordered sensational article. Wired is a commercial enterprise not a charity. Their mission #1 is making money.

__________________
ICQ 557504926

Last edited by xmas13; 08-27-2008 at 09:12 AM..
xmas13 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:18 AM   #13
xmas13
Confirmed User
 
xmas13's Avatar
 
Join Date: Dec 2004
Location: GFY
Posts: 5,176
Don't surf the web, you will download a virus, may meet a pedophile, have your CC stolen, your intimate life exposed, your ID hijacked. Fuck. What are we all doing here?

Your kids are not safe, you are not either. Cut off the fucking internet.
__________________
ICQ 557504926
xmas13 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:19 AM   #14
xmas13
Confirmed User
 
xmas13's Avatar
 
Join Date: Dec 2004
Location: GFY
Posts: 5,176
The internet affects climate change, next month in Wired.
__________________
ICQ 557504926
xmas13 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:20 AM   #15
xmas13
Confirmed User
 
xmas13's Avatar
 
Join Date: Dec 2004
Location: GFY
Posts: 5,176
I also heard the internet has killed social life and the new Hitler may be a Counter Strike player.
__________________
ICQ 557504926
xmas13 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:28 AM   #16
sumphatpimp
Confirmed User
 
Join Date: Aug 2002
Posts: 5,235
I don't know if this is true or not, but I read somewhere that George Bush had somebody write some spy ware that is installed on just about every computer there is, and it tracks everyone and dumps the info to computers at the CIA.
They even made deals with the anti virus companies to not detect it in there software.
anybody think this is true?
sumphatpimp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:31 AM   #17
sumphatpimp
Confirmed User
 
Join Date: Aug 2002
Posts: 5,235
and John Kerry voted for it before he voted against it.
now he is stuck in Iraq.
sumphatpimp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:39 AM   #18
TheDoc
Too lazy to set a custom title
 
TheDoc's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
Quote:
Originally Posted by sumphatpimp View Post
I don't know if this is true or not, but I read somewhere that George Bush had somebody write some spy ware that is installed on just about every computer there is, and it tracks everyone and dumps the info to computers at the CIA.
They even made deals with the anti virus companies to not detect it in there software.
anybody think this is true?
I would say it isn't true, the advanced levels and customizations that firewalls can take would easily be able to identify that something on the network was sending out information.

It would be a much higher chance that you confirm your windows with Microsoft, they gather the information, and hand it over to the Gov.
__________________
~TheDoc - ICQ7765825
It's all disambiguation
TheDoc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:41 AM   #19
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by sumphatpimp View Post
I don't know if this is true or not, but I read somewhere that George Bush had somebody write some spy ware that is installed on just about every computer there is, and it tracks everyone and dumps the info to computers at the CIA.
They even made deals with the anti virus companies to not detect it in there software.
anybody think this is true?
no its false. Main reason being is in order to actuallly save the info from every computer on earth you would need a hard drive capable of holding it , and a way to get it back out

what they did do though was to route almost all internet traffic through secret computers at backbone level, what they did with this info and what they are/were taking is anyone's guess.
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:48 AM   #20
Due
Confirmed User
 
Due's Avatar
 
Industry Role:
Join Date: Mar 2001
Location: Murrieta, CA
Posts: 3,620
Quote:
Originally Posted by TheDoc View Post
I would say it isn't true, the advanced levels and customizations that firewalls can take would easily be able to identify that something on the network was sending out information.

It would be a much higher chance that you confirm your windows with Microsoft, they gather the information, and hand it over to the Gov.
Actually it is true, I intercept all that traffic through the BGP exploit
__________________
I buy plugs
Skype: Due_Global
/Due
Due is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 09:58 AM   #21
Kimo
...
 
Join Date: Jan 2006
Location: Maryland ICQ:87038677
Posts: 11,542
this is last months news isnt it
__________________
...
Kimo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 10:16 AM   #22
CaptainHowdy
Too lazy to set a custom title
 
Industry Role:
Join Date: Dec 2004
Location: Happy in the dark.
Posts: 93,569
Quote:
Originally Posted by xmas13 View Post
The internet affects climate change, next month in Wired.
...
CaptainHowdy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 10:31 AM   #23
eroticsexxx
Confirmed User
 
eroticsexxx's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Nassau, Bahamas
Posts: 3,133
:2cents

Quote:
Originally Posted by Kimo View Post
this is last months news isnt it
No. THIS was.

And don't get me wrong. I'm not being "chicken little" here.

I'm simply passing on the information to those who can appreciate it - Especially those who may have access to BGP routers in their present job capacity.
__________________
eroticsexxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 10:38 AM   #24
klaze
So Fucking Banned
 
Join Date: May 2008
Location: Adult Marketing Mecca
Posts: 2,167
The internet's biggest security hole is...

PUSSYSERVER!
klaze is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 07:58 PM   #25
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
This sounds like something more sophisticated, but with BGP it's quite easy to cause mischief, either intentionally or accidentally, because routes are not verified to have come from a trusted source (ie: the company that owns them). If your upstreams do not have the appropriate filters in place then you can pretty much broadcast any IP range you like.

Earlier this year a Pakistani ISP advertised/leaked Youtube's routes as if it were its own IP range, which resulted in a shitload of traffic that was supposed to go to Youtube heading in through their own link. The intent was to blackhole (censor) youtube for its customers, but the route was advertised to the big bad internet.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-27-2008, 08:07 PM   #26
pornask
So Fucking Banned
 
Join Date: Aug 2006
Location: 253-233-241
Posts: 6,518
Quote:
Originally Posted by klaze View Post
The internet's biggest security hole is...

PUSSYSERVER!
pornask is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.