![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Nassau, Bahamas
Posts: 3,133
|
![]() Two security researchers have demonstrated a new technique to stealthily intercept internet traffic on a scale previously presumed to be unavailable to anyone outside of intelligence agencies like the National Security Agency.
The tactic exploits the internet routing protocol BGP (Border Gateway Protocol) to let an attacker surreptitiously monitor unencrypted internet traffic anywhere in the world, and even modify it before it reaches its destination. The demonstration is only the latest attack to highlight fundamental security weaknesses in some of the internet's core protocols. Those protocols were largely developed in the 1970s with the assumption that every node on the then-nascent network would be trustworthy. The world was reminded of the quaintness of that assumption in July, when researcher Dan Kaminsky disclosed a serious vulnerability in the DNS system. Experts say the new demonstration targets a potentially larger weakness. "It's a huge issue. It's at least as big an issue as the DNS issue, if not bigger," said Peiter "Mudge" Zatko, noted computer security expert and former member of the L0pht hacking group, who testified to Congress in 1998 that he could bring down the internet in 30 minutes using a similar BGP attack, and disclosed privately to government agents how BGP could also be exploited to eavesdrop. "I went around screaming my head about this about ten or twelve years ago.... We described this to intelligence agencies and to the National Security Council, in detail." The man-in-the-middle attack exploits BGP to fool routers into re-directing data to an eavesdropper's network. Anyone with a BGP router (ISPs, large corporations or anyone with space at a carrier hotel) could intercept data headed to a target IP address or group of addresses. The attack intercepts only traffic headed to target addresses, not from them, and it can't always vacuum in traffic within a network -- say, from one AT&T customer to another. The method conceivably could be used for corporate espionage, nation-state spying or even by intelligence agencies looking to mine internet data without needing the cooperation of ISPs. http://blog.wired.com/27bstroke6/200...ed-the-in.html
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
I am Amazing Content!
Industry Role:
Join Date: Feb 2004
Posts: 39,829
|
you lost me at "Two"...
__________________
AmazingContent.com - providing only the best content and service since 2003 Monetize your content on Veegaz.com - one of Germanies largest VOD sites Got German traffic? We convert it into money for you! Skype: madalton02826 - Email: oltecconsult [at] gmail [dot] com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Too lazy to set a custom title
Join Date: Dec 2006
Posts: 23,400
|
Because we all have access to backbone BGP routing... why I'll just head on over to the datacenter and just walk right on in!
__________________
i like waffles |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
(felis madjewicus)
Industry Role:
Join Date: Jul 2006
Location: In Mom & Dad's Basement
Posts: 20,368
|
If anyone is capable of it, Mudge is the man for the job.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
So Fucking Banned
Join Date: Jan 2008
Posts: 2,995
|
O.K. Then,, Ur, Oh Awe, Yawn..................
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Nassau, Bahamas
Posts: 3,133
|
![]() I posted this because theoretically a tech savvy adult provider can siphon off/monitor/intercept traffic headed to any other major website. OR have someone at an ISP do it for them
The implications could be devastating and ISP's don't really see the need to upgrade to SBGP at present. Just letting you guys and gals know.
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
No Refunds Issued.
Industry Role:
Join Date: Apr 2003
Posts: 14,809
|
Does this mean that someone could be reading my letters to penthouse forum before they are published? cuz if so...DAMN!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
No it can't. And something like this has been possible a long time ago. Security hole like this is the same as saying a security hole is that someone can intercept your traffic IF he steals one of the routers along the path in one of the datacenter... ORLY!
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: Aug 2002
Posts: 5,235
|
biggest security risk is the dork between the seat and the keyboard.
always has been, always will be. and no software or hardware can fix that. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
So the security risk is Sys admins? Well we are really screwed then aren't we.
Some Hosting Companies (one that isn't around anymore) use to steal/rip traffic from the sites at the router level. If you don't think some dirty hosts have ripped traffic, emails, member records, ect, then you are naive.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Join Date: Dec 2004
Location: GFY
Posts: 5,176
|
Technically I can steal virtually anything in a grocery store.
![]() ![]()
__________________
ICQ 557504926 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Dec 2004
Location: GFY
Posts: 5,176
|
Don't surf the web, you will download a virus, may meet a pedophile, have your CC stolen, your intimate life exposed, your ID hijacked. Fuck. What are we all doing here?
Your kids are not safe, you are not either. Cut off the fucking internet. ![]()
__________________
ICQ 557504926 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Join Date: Dec 2004
Location: GFY
Posts: 5,176
|
The internet affects climate change, next month in Wired.
__________________
ICQ 557504926 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Join Date: Dec 2004
Location: GFY
Posts: 5,176
|
I also heard the internet has killed social life and the new Hitler may be a Counter Strike player.
__________________
ICQ 557504926 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Join Date: Aug 2002
Posts: 5,235
|
I don't know if this is true or not, but I read somewhere that George Bush had somebody write some spy ware that is installed on just about every computer there is, and it tracks everyone and dumps the info to computers at the CIA.
They even made deals with the anti virus companies to not detect it in there software. anybody think this is true? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Join Date: Aug 2002
Posts: 5,235
|
and John Kerry voted for it before he voted against it.
now he is stuck in Iraq. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
|
Quote:
It would be a much higher chance that you confirm your windows with Microsoft, they gather the information, and hand it over to the Gov.
__________________
![]() ![]() ![]() It's all disambiguation ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
![]() what they did do though was to route almost all internet traffic through secret computers at backbone level, what they did with this info and what they are/were taking is anyone's guess.
__________________
hatisblack at yahoo.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
Confirmed User
Industry Role:
Join Date: Mar 2001
Location: Murrieta, CA
Posts: 3,620
|
Quote:
![]()
__________________
I buy plugs Skype: Due_Global /Due |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
...
Join Date: Jan 2006
Location: Maryland ICQ:87038677
Posts: 11,542
|
this is last months news isnt it
__________________
... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Too lazy to set a custom title
Industry Role:
Join Date: Dec 2004
Location: Happy in the dark.
Posts: 93,571
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Nassau, Bahamas
Posts: 3,133
|
![]() No. THIS was.
And don't get me wrong. I'm not being "chicken little" here. I'm simply passing on the information to those who can appreciate it - Especially those who may have access to BGP routers in their present job capacity.
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
So Fucking Banned
Join Date: May 2008
Location: Adult Marketing Mecca
Posts: 2,167
|
The internet's biggest security hole is...
PUSSYSERVER! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
This sounds like something more sophisticated, but with BGP it's quite easy to cause mischief, either intentionally or accidentally, because routes are not verified to have come from a trusted source (ie: the company that owns them). If your upstreams do not have the appropriate filters in place then you can pretty much broadcast any IP range you like.
Earlier this year a Pakistani ISP advertised/leaked Youtube's routes as if it were its own IP range, which resulted in a shitload of traffic that was supposed to go to Youtube heading in through their own link. The intent was to blackhole (censor) youtube for its customers, but the route was advertised to the big bad internet. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
So Fucking Banned
Join Date: Aug 2006
Location: 253-233-241
Posts: 6,518
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |