I am so fucking done with the internet turning into a trash pile of scams and exploits.
Countering threats from North Korea
41–50 of 172 posts
Re: Countering threats from North Korea
#42Re: Countering threats from North Korea
#43I am so fucking done with the internet turning into a trash pile of scams and exploits.
Who is even routing with North Korea? Seeing how the normal populace there literally doesn't have access to the internet, what on earth is there to be gained?
https://bgpview.io/asn/131279#peers-v4
http://cooks.org.kp/en/ is hosted on that network.
Re: Countering threats from North Korea
#44Earlier quoted context omitted.
Countries have been doing terrible things to people since long before the internet
True but before the internet it was limited to the locality. The internet feels like a public park that gets trashed by folks all across the world and not just by the neighbors. (Just to be clear, I sympathize with your point as well)
Re: Countering threats from North Korea
#45Re: Countering threats from North Korea
#46Earlier quoted context omitted.
A statement from Google.
I'm actually surprised Google would say this is from the DPRK government without also saying it had has been verified by US federal government authorities. Usually they leave it for others to deal with statements at that level.
(Disclaimer: I am head of TAG)
Re: Countering threats from North Korea
#47Couldn't they just hardware mitm the CPU and Ram, not to be prisoner of AES. This way they can dump stages as well.
Honeypots are harder than they look, basically.
Re: Countering threats from North Korea
#48Quoted post unavailable.
Whether that means they didn’t have exploits for other platforms as part of this attack or that we just didn’t succeed in determining them is unknown.
TAG has certainly found and reported exploits in other platforms many times so it is not a matter of not caring.
Source: I am lead of TAG at Google
Re: Countering threats from North Korea
#49Re: Countering threats from North Korea
#50Earlier quoted context omitted.
We see some of this with just normal spear phishing against companies. The "single click" thing is reasonably common, it makes things a bit harder to catch as often the clickthrough will change to whatever is being spoofed in the first place. A homophone ycornbinator.com would serve the malware first time, then next time it would send a permanent redirect. Unique IDs you'll see in things like spam SMS, both to work a…
I am receiving increased SMS spam past week. Is connected to this exploit? Msgs are all different domains with unique ID appended.