3 ms·
Have all of those IP addresses published as related to the hack been marked as dirty by Spamhaus e.a. before or after the hack - dates shown in the post are 20-
by fpp 12y ago
Have all of those IP addresses published as related to the hack been marked as dirty by Spamhaus e.a. before or after the hack - dates shown in the post are 20-Dec etc - after the hack was published.
- DangerousPie 12y agoThis is a very good point. It looks like all of these were only listed after they became public as part of the attack. So it's not like they were known bad IPs before. As an example, here is the Spamhaus entry for one of the IPs. Notice the references to articles about the Sony hack: http://www.spamhaus.org/sbl/query/SBL242808 http://www.spamhaus.org/sbl/query/SBL242808
- emcrazyone 12y agoEveryone seems too focused on source IP address which any solid IT person can tell you can be hijacked. Even the phone home IPs can be obfuscated but it seems awfully suspicious they all belong to net blocks going to NK if I'm understanding things.
- jamesbrownuhh 12y agoBut according to this, all the phone home addresses are generic open proxies that have been well publicised across the Internet and already abused for quite some time. None of the proxies listed appear to be in NK, and (to date) no evidence that NK IP addresses were on the other end of those proxies at the time. It's a bit like saying "the attackers used malware which made DNS queries via the IP address 8.8.8.8, which has been used by NK in the past" - if anyone were really building a case on that key evidence, they should prepare to be laughed at.
- emcrazyone 12y agoThanks @jamesbrownuhh where did you get that detail about the phone home proxies?