- TalkBack 43 of 43:
- « Previous
- Thread View
- Flat View
- I knew about this months ago
-
Because my machine has been hacked in precisely this way!
Not only my machine but the bios on my router has been hacked in this way. In fact this is how they got in in the first place.
They used a drive by technique to get dns to point to another site. Any downloads were then payloaded with whatever they wanted - bios updates to motherboard, router, graphics cards - indeed any device that has firmware that is updateable is now suspect. Who has done this - I cannot say for sure but it seems to be sourced from Korea/China/Taiwan... All these countries seem to be playing 'games' with each other and using the hardware that we purchased for their DDOS madness. Remember where most hardware is sourced these days - jeez how do we know that 'all' hardware sourced from such regions has not been backdoored. In short we don't.
Welcome to the era of cheap asian hardware - but god you will pay a price...
here is some of my router logs (ignore the time as i have disabled internet time on the router)
trace where the port knock probes come from:
Jan 1 02:12:45 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=222.121.31.67 DST=220.237.239.120 LEN=40 TOS=0x00 PREC=0x00 TTL=102 ID=256 PROTO=TCP SPT=6000 DPT=6588 WINDOW=16384 RES=0x00 SYN URGP=0
Jan 1 02:21:37 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=220.230.143.151 DST=220.237.239.120 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=14295 DF PROTO=TCP SPT=1233 DPT=1433 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 02:21:40 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=220.230.143.151 DST=220.237.239.120 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=14712 DF PROTO=TCP SPT=1233 DPT=1433 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 02:32:32 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=220.139.130.4 DST=220.237.239.120 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=15101 DF PROTO=TCP SPT=37483 DPT=5900 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 02:32:35 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=220.139.130.4 DST=220.237.239.120 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=15206 DF PROTO=TCP SPT=37483 DPT=5900 WINDOW=64240 RES=0x00 SYN URGP=0
Jan 1 02:35:41 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=221.2.234.180 DST=220.237.239.120 LEN=40 TOS=0x00 PREC=0x00 TTL=101 ID=256 PROTO=TCP SPT=6000 DPT=8080 WINDOW=16384 RES=0x00 SYN URGP=0
Jan 1 02:41:43 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=220.202.186.69 DST=220.237.239.120 LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=24141 DF PROTO=TCP SPT=1860 DPT=1433 WINDOW=16384 RES=0x00 SYN URGP=0
china korea taiwan
they are playing games with us!!!
ps: i will pay big money to track down and imprison these sob's as well as big money for *safe* hardware
the whole internet has been ruined by these mongrels, and by the lazy profit driven programing habits of microsoft and co. - Posted by: walkerjian@... Posted on: 03/30/07 You are currently: a Guest | Members login | Terms of Use
What do you think?
SponsoredWhite Papers, Webcasts, and Downloads
- Server Consolidation and Containment With Virtual Infrastructure VMware To meet the constant demand to deploy, maintain and grow a broad array of ... Download Now
- Five Steps to Determine When to Virtualize YourServers VMware Server virtualization isn't just for big companies. Entry-level ... Download Now
- Key Strategies for Federal Agencies - Safe and Cost Effective Migration for Legacy Hardware GovConnection The federal government has mandated that federal agencies reduce energy ... Download Now
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Achieving Cost and Resource Savings with Unified Communications
-
Find out how to maximize your communications investments with Unified Communications.

- Click to download >>
- Save time with automated shipping solutions
-
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
- Visit the UPS Business Essentials Guide
- Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
-
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.

- Learn more about the free, six-month trial offer >>
- New Online Dashboard for IT Leaders
-
Read about top issues IT decision-makers face every day, plus get cost-effective solutions to real-life IT problems.
- Learn more >>
Meet Doc
-
Here to help you with your Document Management Needs
- Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
- To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
-
Produced by
ZDNet and








