ARTEMIS: Targets BGP Hijacks

Image Credit: BGP Stream. Image is the graphical representation of the in-process BGP redirection attack emanating and under the control of the People’s Republic of China on 2018/12/28.
via Jeff Stone writing at Cyberscoop, comes this fascinatin… Continue reading ARTEMIS: Targets BGP Hijacks

Massive Ad Fraud Scheme Relied on BGP Hijacking

This is a really interesting story of an ad fraud scheme that relied on hijacking the Border Gateway Protocol: Members of 3ve (pronounced "eve") used their large reservoir of trusted IP addresses to conceal a fraud that otherwise would have been easy for advertisers to detect. The scheme employed a thousand servers hosted inside data centers to impersonate real human… Continue reading Massive Ad Fraud Scheme Relied on BGP Hijacking

Bing, Chrome, and Docker API – Hack Naked News #195

A one-liner exploit for X, the danger of searching for Chrome in Bing, exposing your Docker API, you can find sensitive data in the cloud, exploit users by embedded videos in Word documents, dead web apps, hacking BGP routes, a new DHCP vulnerability a… Continue reading Bing, Chrome, and Docker API – Hack Naked News #195

China’s Hacking of the Border Gateway Protocol

This is a long — and somewhat technical — paper by Chris C. Demchak and Yuval Shavitt about China’s repeated hacking of the Internet Border Gateway Protocol (BGP): "China’s Maxim ­ Leave No Access Point Unexploited: The Hidden Story of China Telecom’s BGP Hijacking." BGP hacking is how large intelligence agencies manipulate Internet routing to make certain traffic easier to… Continue reading China’s Hacking of the Border Gateway Protocol

Battleships Over BGP

The Border Gateway Protocol (BGP) is one of the foundations of the internet. It’s how the big routers that shift data around the Internet talk to each other, passing info on where they can send data to. It’s a simple protocol, with each router sending text messages that advertise the routes that they carry. The administrators of these routers create communities, each with an individual code, and this information is passed between routers. Most top-level ISPs don’t spread this data far, but [Ben Cox] realized that his ISP did. and that he could use this as an interesting way to …read more

Continue reading Battleships Over BGP

MyEtherWallet users robbed after successful DNS hijacking attack

Unknown attackers have managed to steal approximately $150,000 in Ethereum from a number of MyEtherWallet (MEW) users, after having successfully redirected them to a phishing site posing as MyEtherWallet.com. The redirection was seamless, and the only … Continue reading MyEtherWallet users robbed after successful DNS hijacking attack