Log in to your IBTimes Account

close
ID
Password
  • Set your IBTimes.com Edition

US, Korean DDoS Attacks originated from United Kingdom



14 July 2009 @ 07:56 pm ET

A Vietnamese security researcher said they discovered the IP address of the master server which was used in attacking the United States and Korean government agency.


US, Korean DDoS Attacks originated from United Kingdom
US, Korean DDoS Attacks originated from United Kingdom (Credit: Bach Khoa Internetwork)
1 of 1

Related Topic

Get stories by e-mail on this topic.

E-mail:

Bach Khoa Internetwork Security (Bkies), a Vietnamese agency, is a member Asian Pacific Computer Emergency Response Team (ACERT) and had been requested by KrCERT (Korean Computer Emergency Response Team) to cooperate in analyzing the malware that was performing DDoS attacks on websites of South Korea and the US.

After the careful evaluation and pattern studies, the agency found a master server which controls 8 command & control servers to make a series of cyber-attack.

"We have fought against C&C servers and have gained control of 2 in 8 of them. After analyzing the logs of these 2 servers, we discovered the IP address of the master server, which is 195.90.118.xxx. This IP is located in UK. The master server is running on Windows 2003 Server Operating System," said Nguyen Minh Duc Senior Security Researcher / Bkis Security Director.

"Bkis has sent the detail of research and the information of the master server in UK to US-CERT and KrCERT."

BKis said that it is now possible to find the hacker behind the US, Korea DDoS attacks but the agency reiterated that it will depend on US and Korean governments.

The Korean authorities confirmed the report as "credible" according to the Korea Times report.

The Government of South Korea law enforcement authorities are now doing its best to coordinate with the British government to investigate the attack.

This article is copyrighted by International Business Times.

    Click!
  • Rate this article:

Comments
1.
Jul 15, 2009 11:58am

The IP is not the real one! it was hack from other computer as disguise, who knows! lol...
2.
Jul 15, 2009 4:04pm

If the origin is not in UK then the security reasecher should analyze well the Logs from the C&C. It should be there ---> "Hidden" Ding!
3.
Jul 15, 2009 5:54pm

whatever!

Post Your Comment

*Name


advertisement
More Tech
Students demonstrated at Tehran University against the government of President Mahmoud Ahmadinejad on Monday, a reformist website reported, more than thr...
Norwegian browser maker Opera urged European Union antitrust regulators on Monday not to rush to close its antitrust case against Microsoft before ensuri...
Apple announced Monday that over 2 billion apps have been downloaded from its App Store since the e-commerce site's launch in July 2008, and the pace "co...

advertisement
Advertisement
POS Magnetic Card Readers

Online distributor for point of sale equipment, TYSSO and Pegasus.

 
IBTimes.com Web
Partners
International Business Times© 2009 The Ibtimes Company. All Rights Reserved. Terms of service | Privacy Policy | Advertising | About Us | Contact Us | Archives