Posts

Showing posts with the label Hijack

Google Services- lost in transit or lost in translation?

Image
According to a News report by the Wall Street Journal, some of the web services provided by the internet Giant Google were temporarily unavailable for nearly 2 hours on 12thNovember 2018. The users trying to reach Google Services were rerouted to a sinuous path through operators existing in Russia, China and Nigeria. A Google spokesman wrote that a portion of web traffic was impacted due to incorrect routing of IP addresses, and passage to Google Services was affected. The issue was resolved at 2:35 pm on Monday and services began to operate as expected. However, the root cause of BGP Traffic Hijacking was external to Google and what exactly happened remains obscure. The issue was first noticed by a network monitoring company, ThousandEyes, when they could not connect to Google’s G suite & incorrect routing instructions redirected them to Russian network operator TransTelekom, China Telecom & Nigerian Network provider, MainOne. The issue became crucial when the entire w...

MikroTik Routers vulnerable to cryptocurrency mining campaigns

Image
Over 3,700 Unpatched MikroTik Routers Abused In CryptoJacking Campaigns The vulnerability  CVE-2018-14847  in  MikroTik RouterOS has become eye-candy for cyber maniacs. The ease of exploitation of this vulnerability has resulted in massive abuse of these routers and their network resources in cryptomining. The threat actors exploit the known vulnerability in MikroTik Routers by executing a malicious script to gain administrator privilege on the router. Mikrotik was founded in Latvia in 1995. The brand particularly focuses on designing wireless devices and routers. With the help of a congruent and hidden script, cyber hackers were able to misuse the network resources and bandwidth of MikroTik Router in mining CoinHive Cryptocurrency. CoinHive is a JavaScript cryptocurrency miner for the Monero Block-chain. CoinHive in-browser cryptocurrency mining script thst can be embedded in a browser easily. That is why this cryptocurrency mining script is popular among thre...

Brazilian Banks in a fix: Hackers Exploiting DLink Routers to Redirect Users to Fake Brazilian Banks

Image
Hackers have adopted a clever approach to swindle users of their hard earned money without letting them have a slightest clue. The loopholes in the DLink DSL modem routers have been ingeniously leveraged by cyber miscreants to deceive users. Let us check the process of handling user based queries & requests for web pages and routines over internet after we get acquainted with the following terms: DSL (Digital Subscriber Line): High Speed digital data transfer between servers and systems using telephone lines. DNS Server (Domain Name System ): It is a service on multiple servers  to resolve the browsing URL that the user inputs to IP (Internet Protocol) Addresses where the website is found. Let us now proceed and understand how a web page is displayed when a user inputs a URL Every single URL on the internet has an IP address assigned to it. The IP address points to the computer that hosts the server of the website we are requesting to access. When a user enters a URL (w...