Technology
 
    
  
+Login    +Register    +Find Id / Pw 음성듣기 설치 및 이용방법    Home  l  Archives  l  Learning Times  |  Sitemap  |  Subscription  l  Media Kit  l  PDF
    Home > Newszone > Technology > Technology Digest >
  Nation
  Biz/Finance
  Technology
    Photo News  
    Technology Digest  
    Game  
    Economics Class for Youth  
  Arts & Living
  Sports
  Opinion
  Community
  Special
     
  The Learning Times
     Editorial Listening
     Phone English
     Dear Abby
     Domestic News
     Foreign News
     Screen English
     Live English in Drama
     Discovery Education  
     Ancient Idiom  
     iBT Writing  
     English Writing I
     English Writing II  
     English Grammar
     Grasping Vocab
     iBT Vocab
     Korean Language  
     
     Junior Writing
     Junior Reading
     Junior Reporter
     
 
   07-27-2009 18:11
'DDoS Malware Was Produced in Korea'

By Kim Tong-hyung
Staff Reporter

The powerful Internet attack that crippled South Korean computers earlier this month may have been initiated by local hackers after all, according to a police report issued on Monday.

The National Police Agency's cyber crimes unit said the malicious software used for the recent distributed denial of service (DDoS) attacks were put out by two "Web hard" online storage sites, which manage commercial peer-to-peer transactions of files.

Authorities, including the Korea Communications Commission (KCC) and the National Intelligence Service (NIS), have been struggling to track down the source of the cyber criminals.

However, police investigators say that 21 of the 27 "zombie" computers they examined, which were infected and compromised by the malicious codes, were infected from programs originating from the two online storage sites.

Although the malicious software was distributed from Korean sites, the cyber attackers used four separate servers based overseas to control the programs after they reached computers.

"The DDoS attackers hacked two Korean Web sites, based in Seoul and Busan, and switched the program update files of the sites with their malicious codes," said a police officer.

"Users of these online storage sites unknowingly downloaded the malicious programs, thinking they were updating the programs for the peer-to-peer transactions. We found four foreign servers that we believed were used to issue the attack orders."

A DDoS attack occurs when multiple systems are flooded with traffic that overwhelms their bandwidth or resources. More than 80,000 South Korean computers were affected by the series of DDoS attacks that started on July 7, while the United States and China were also attacked, albeit less ferociously.

The malicious software used in the recent attacks was mostly "botnets," or software robots that run autonomously to initiate the DDoS attacks. The botnets compromise the infected computers and are manipulated by the command and control (C&C) system set up by the hackers.

A total of 432 servers based in 61 countries were used by the hackers for C&C operations in the recent attacks, police officials say. Through the C&C servers, the hackers attempted to steal information from the infected computers and used the devices to spread the malicious codes to other computers, and eventually, programmed the zombies to self-destruct.

According to data provided by German law enforcement authorities, about 98 percent of the 55,500-plus zombie computers that communicated with the C&C server based in Germany were Korean computers, the police agency said.

thkim@koreatimes.co.kr

Reader’s Comments
Notice From KT Website Manager
Bad language will not be tolerated. All comments considered discriminatory against race or sex, or which are considered offensive against certain people, will be eliminated by the manager. Violators will be deprived of their membership.
Please stay on topic.
zbd21   (24.168.132.60)   07-28-2009 09:39
Must be some foreigners in Korea doing this. South Koreans would never do this. (sarcasm for those who don't understand this humor)
boshintang1   (90.14.54.140)   07-28-2009 07:11
This is yet another reason why the Korean government needs to clamp down on Korea's cyber activity. Korea's leftist commies should be punished to the full extent of the law!
STORMBREAK   (216.241.58.82)   07-28-2009 03:38
Or the Chinese either???...wow..wrong conclusion!!
haebyungdae   (118.129.128.235)   07-27-2009 23:52
So it wasnt NK after all? Huh
Managerial regulations
◀ Back ▲Top