Go Back   FormKaos: Board > General Discussion > Vancouver News

Vancouver News What's hot and hip going on in the city of Vancouver

 
 
LinkBack Topic Tools Rate Topic
  #1 (permalink)  
Old Dec 09, 08
Registered User
 
Join Date: Nov 2007
jenai can only hope to improve
China may be spying on BC gov't

Today I thought I'd traceroute to B.C. Government Home - Province of British Columbia to see how well BC Systems has it secured.

I was shocked at what I found.

Right after the hop goes to an internal IP address in the 192.168.2.0 range, I get this address:

121.255.30.241

It resolved to outside of Canada in Hefei, Anhui, China.

I kid you not. gov.bc.ca is pwned by the Chinese through DNS cache poisoning.

I'm frakken appalled. Hopefully my email to the sys admin in Victoria gets through, considering the extensive packet sniffing being done in Hefei.

Oh, I don't know when I'll tell CTV if ever.

This is an internal security matter between me and Victoria.
  #2 (permalink)  
Old Dec 09, 08
ebbomega's Avatar
1up motherfucker
 
Join Date: Oct 2003
ebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to all
Never struck you that it might be that your ISP isn't on the same infrastructure as the BC government web page, and the only plausible route is through China, did it?

If it's hopping to China AFTER your internal network, wouldn't that be on your ISP's side and not on the BC Gov?
  #3 (permalink)  
Old Dec 09, 08
NinjaBoy's Avatar
Full moon Sway
 
Join Date: Nov 2000
NinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to all
Quote:
Originally Posted by jenai View Post
Oh, I don't know when I'll tell CTV if ever.
Speaking as someone who works for that company, I'll let you know straight up we have an impressive team of researchers, consultants, reporters, writers and producers who are dedicated to researching stories...

...and making sure that unfounded crap like this never gets to air.
  #4 (permalink)  
Old Dec 09, 08
EPID3MIK-7's Avatar
DeviantBreaks.com
 
Join Date: Jul 2003
EPID3MIK-7 will become famous soon enoughEPID3MIK-7 will become famous soon enough
ytmnd - you're the man now dog!

Last edited by EPID3MIK-7; Dec 09, 08 at 02:39 PM.
  #5 (permalink)  
Old Dec 09, 08
DONT BE BITTER BE BETTER
 
Join Date: Apr 2001
rawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to all
you have taken something that doesn't make sense and then attached the most unlikely explanation to it, ever.
  #6 (permalink)  
Old Dec 09, 08
Straight Outta Mocash
 
Join Date: Nov 2003
Gusto is just really niceGusto is just really niceGusto is just really niceGusto is just really niceGusto is just really niceGusto is just really niceGusto is just really nice
how you came to this conclusion from running a traceroute to a webserver, i have no idea. wtf.
  #7 (permalink)  
Old Dec 09, 08
NinjaBoy's Avatar
Full moon Sway
 
Join Date: Nov 2000
NinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to all
Stop thinking you are a hacker whenever you run a traceroute...
  #8 (permalink)  
Old Dec 09, 08
bleep
 
Join Date: Aug 2004
b0ld is a jewel in the roughb0ld is a jewel in the roughb0ld is a jewel in the roughb0ld is a jewel in the rough
another typical script kiddie / whitehat .
  #9 (permalink)  
Old Dec 09, 08
G3N3R4L's Avatar
www.deviantbreaks.com
 
Join Date: Dec 2004
G3N3R4L is a jewel in the roughG3N3R4L is a jewel in the roughG3N3R4L is a jewel in the roughG3N3R4L is a jewel in the rough
there's a sys admin in victoria right now laughing his ass off
  #10 (permalink)  
Old Dec 09, 08
Registered User
 
Join Date: Nov 2007
jenai can only hope to improve
yes, CTV would suppress it; it's in the pocket of the powers-that-be.

here is the traceroute that contradicts someone's explanation in the reply to my OP, cos his explanation is based on not bothering to traceroute the IP address.


---
traceroute to 142.32.252.190 (142.32.252.190), 30 hops max, 40 byte packets
1 192.168.1.1 (192.168.1.1) 2.977 ms 2.862 ms 2.906 ms
2 192.168.1.1 (192.168.1.1) 10.062 ms 9.575 ms 11.943 ms
3 rd1bb-ge3-0-0-3.vc.shawcable.net (64.59.159.210) 11.605 ms 23.523 ms 936.175 ms
4 rc2bb-tge0-0-0-0.vc.shawcable.net (66.163.69.141) 22.354 ms 76.469 ms 13.198 ms
5 rc2wh-tge0-7-1-0.vc.shawcable.net (66.163.69.73) 14.015 ms 16.059 ms 12.158 ms
6 pix-gw.gov.bc.ca (206.223.127.6) 14.144 ms 9.435 ms 13.905 ms
7 vanrc002.net.gov.bc.ca (142.30.231.4) 15.925 ms 27.256 ms 13.500 ms
8 vicrc004.net.gov.bc.ca (198.162.64.52) 14.956 ms 20.604 ms 13.867 ms
9 vicrr033.net.gov.bc.ca (142.32.234.36) 18.479 ms 15.770 ms 16.159 ms
10 vicgw013.net.gov.bc.ca (142.32.34.37) 17.967 ms 21.681 ms 21.884 ms
11 192.168.2.6 (192.168.2.6) 16.032 ms 16.647 ms 15.970 ms
12 121.255.30.241 (121.255.30.241) 15.440 ms 36.141 ms 16.961 ms
13 * * *

right after hop 10 it's gone off to an IP registered in China, but probably somewhere else in Victoria, due to the narrow standard deviance.
  #11 (permalink)  
Old Dec 09, 08
Registered User
 
Join Date: Nov 2007
jenai can only hope to improve
Quote:
Originally Posted by G3N3R4L View Post
there's a sys admin in victoria right now laughing his ass off
actually according to his voice mail, he is on holiday pay c/o of your tax dollars until January 15. He probably took the 6 week leave started Dec. 4
  #12 (permalink)  
Old Dec 09, 08
Straight Outta Mocash
 
Join Date: Nov 2003
Gusto is just really niceGusto is just really niceGusto is just really niceGusto is just really niceGusto is just really niceGusto is just really niceGusto is just really nice
ISP: ANHUI PROVINCIAL EDUCATION DEPARTMENT

maybe they're training spies lol.
  #13 (permalink)  
Old Dec 09, 08
DONT BE BITTER BE BETTER
 
Join Date: Apr 2001
rawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to all
LETS PLAY INTERNET 101

Quote:
Originally Posted by jenai View Post
yes, CTV would suppress it; it's in the pocket of the powers-that-be.

here is the traceroute that contradicts someone's explanation in the reply to my OP, cos his explanation is based on not bothering to traceroute the IP address.
LOL RITE

Quote:

---
traceroute to 142.32.252.190 (142.32.252.190), 30 hops max, 40 byte packets
1 192.168.1.1 (192.168.1.1) 2.977 ms 2.862 ms 2.906 ms
2 192.168.1.1 (192.168.1.1) 10.062 ms 9.575 ms 11.943 ms
3 rd1bb-ge3-0-0-3.vc.shawcable.net (64.59.159.210) 11.605 ms 23.523 ms 936.175 ms
4 rc2bb-tge0-0-0-0.vc.shawcable.net (66.163.69.141) 22.354 ms 76.469 ms 13.198 ms
5 rc2wh-tge0-7-1-0.vc.shawcable.net (66.163.69.73) 14.015 ms 16.059 ms 12.158 ms
6 pix-gw.gov.bc.ca (206.223.127.6) 14.144 ms 9.435 ms 13.905 ms
7 vanrc002.net.gov.bc.ca (142.30.231.4) 15.925 ms 27.256 ms 13.500 ms
8 vicrc004.net.gov.bc.ca (198.162.64.52) 14.956 ms 20.604 ms 13.867 ms
9 vicrr033.net.gov.bc.ca (142.32.234.36) 18.479 ms 15.770 ms 16.159 ms
10 vicgw013.net.gov.bc.ca (142.32.34.37) 17.967 ms 21.681 ms 21.884 ms
EVERYTHINGS FINE UP UNTIL HERE

Quote:
11 192.168.2.6 (192.168.2.6) 16.032 ms 16.647 ms 15.970 ms
THIS IS AN INTERNAL ADDRESS, WHICH MEANS YOU HAVE SOMETHING INTERNAL ON YOUR NETWORK REPLYING TO THIS AND FORWARDING YOU ON TO:

Quote:
12 121.255.30.241 (121.255.30.241) 15.440 ms 36.141 ms 16.961 ms
13 * * *

SO IN CLOSING, YOUR SHIT SUCKS AND THIS HAS NOTHING TO DO WITH THE BC GOVERNMENT OR THEIR ROUTING
  #14 (permalink)  
Old Dec 09, 08
green bastard
 
Join Date: Mar 2004
DefJef has a spectacular aura aboutDefJef has a spectacular aura aboutDefJef has a spectacular aura about
I wish I had the kinda free time that Jenai has so I could make tinfoil hats all day and worry about random traceroutes and anything else that's not important and totally out of my control.
  #15 (permalink)  
Old Dec 09, 08
NinjaBoy's Avatar
Full moon Sway
 
Join Date: Nov 2000
NinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to all
Quote:
Originally Posted by jenai View Post
yes, CTV would suppress it; it's in the pocket of the powers-that-be.
A local TV evening news is put together over the course of six hours or so...

The news director, sends his reporters to cover what he feels take priority in the news. They come back, put it together. He approves it. He doesn't contact anyone else for approval.

It goes to air.

In order for your theory, the news director (and assistant news director) has to be in the governments pocket. Although, I'm not sure which government you are accusing of controlling them, the chinese or the BC...

So there's two people that they have to buy off. Then add in all the other stations in Vancouver... we're at six. Oh, for the hell of it lets add the major cities as well. That's probably about fifteen for the sake of arguement...

30 people, who are reporters for a living, being bought out by the government and turning down the opportunity to report the biggest story of their life...

Wow... a bit of a stretch...

Oh, lets also not forget the fact that there are about a hundred stations in each province...

So now we're at 200 people in this province, or 2000 people across Canada....

You're trying to convince me that out of 2000 reporters nobody would report this?
  #16 (permalink)  
Old Dec 09, 08
sup?
 
Join Date: Aug 2005
tiedye is a name known to alltiedye is a name known to alltiedye is a name known to alltiedye is a name known to alltiedye is a name known to alltiedye is a name known to alltiedye is a name known to alltiedye is a name known to alltiedye is a name known to alltiedye is a name known to all
Quote:
Originally Posted by jenai View Post
This is an internal security matter between me and Victoria.
This is mint!
  #17 (permalink)  
Old Dec 09, 08
Registered User
 
Join Date: Nov 2007
jenai can only hope to improve
oh, on an OT note I lost my mobile 15 minutes ago near Church's, probably in the parking lot south of the building.

or, it could be stuck under the car seat of the roomie's. hmm time to SMS it.

i wonder where my stereo bluetooth receiver is...
  #18 (permalink)  
Old Dec 09, 08
NinjaBoy's Avatar
Full moon Sway
 
Join Date: Nov 2000
NinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to allNinjaBoy is a name known to all
Church/Russian conspiracy obviously.

Last edited by NinjaBoy; Dec 09, 08 at 04:51 PM. Reason: Had to ad the "/Russian" part...
  #19 (permalink)  
Old Dec 09, 08
Celebrate or Suffer
 
Join Date: Nov 2001
SEAN! is a glorious beacon of lightSEAN! is a glorious beacon of lightSEAN! is a glorious beacon of lightSEAN! is a glorious beacon of lightSEAN! is a glorious beacon of lightSEAN! is a glorious beacon of lightSEAN! is a glorious beacon of light
Quote:
Originally Posted by jenai View Post
oh, on an OT note I lost my mobile 15 minutes ago near Church's, probably in the parking lot south of the building.

or, it could be stuck under the car seat of the roomie's. hmm time to SMS it.

i wonder where my stereo bluetooth receiver is...
there are people who are willing to live with you?
  #20 (permalink)  
Old Dec 09, 08
Registered User
 
Join Date: Nov 2007
jenai can only hope to improve
Quote:
Originally Posted by rawb View Post
LETS PLAY INTERNET 101



LOL RITE



EVERYTHINGS FINE UP UNTIL HERE



THIS IS AN INTERNAL ADDRESS, WHICH MEANS YOU HAVE SOMETHING INTERNAL ON YOUR NETWORK REPLYING TO THIS AND FORWARDING YOU ON TO:




SO IN CLOSING, YOUR SHIT SUCKS AND THIS HAS NOTHING TO DO WITH THE BC GOVERNMENT OR THEIR ROUTING

The internal address is outside the gateway in Victoria, which means it's within that area. The IP address may be administered by what APNIC says it is, but the DNS cache poisoner is in Victoria, because the ping response times are under 50 mS.

192.168.2.6 indicates that the GW in hop 10 is compromised.
  #21 (permalink)  
Old Dec 09, 08
DONT BE BITTER BE BETTER
 
Join Date: Apr 2001
rawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to all
Quote:
Originally Posted by jenai View Post
The internal address is outside the gateway in Victoria, which means it's within that area. The IP address may be administered by what APNIC says it is, but the DNS cache poisoner is in Victoria, because the ping response times are under 50 mS.

192.168.2.6 indicates that the GW in hop 10 is compromised.
I AM REALLY GOING TO LOVE HOW YOU ARE GOING TO EXPLAIN HOW YOU ARE GETTING TRACEROUTE REPLIES FROM AN INTERNAL IP IN VICTORIA.
  #22 (permalink)  
Old Dec 09, 08
ebbomega's Avatar
1up motherfucker
 
Join Date: Oct 2003
ebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to all
Quote:
Originally Posted by b0ld View Post
another typical script kiddie / whitehat .
script kiddies and whitehats are two completely different things.

Whitehats are actually hackers.
  #23 (permalink)  
Old Dec 09, 08
Thread referee
 
Join Date: Jan 2002
lildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of light
isn't whitehat legit practices and blackhat shady practices, with greyhat being in the middle?

wait... anyways..... jenai you are a fucking idiot, get some help.
  #24 (permalink)  
Old Dec 09, 08
ebbomega's Avatar
1up motherfucker
 
Join Date: Oct 2003
ebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to all
Quote:
Originally Posted by jenai View Post
The internal address is outside the gateway in Victoria, which means it's within that area. The IP address may be administered by what APNIC says it is, but the DNS cache poisoner is in Victoria, because the ping response times are under 50 mS.

192.168.2.6 indicates that the GW in hop 10 is compromised.
You don't understand.

The only way you'll be able to talk to a 192.168.x.x address is if it is in YOUR LAN. If you were to ping such an address (essentially what tracert does) then your ISP would recognize it as a private IP and wouldn't route it at all.

What is most likely your problem is that your own computer (or router) is compromised and is bouncing traffic that hits the next hop on tracert to china. But if this was happening on the victoria end, it would NOT be showing a 192.168.x.x address. At all.

Sorry, you're the one that's being spied on by China, not the government.
  #25 (permalink)  
Old Dec 09, 08
ebbomega's Avatar
1up motherfucker
 
Join Date: Oct 2003
ebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to allebbomega is a name known to all
Quote:
Originally Posted by lildonkey View Post
isn't whitehat legit practices and blackhat shady practices, with greyhat being in the middle
Yup. Script kiddies, on the other hand, are just a form of cracker that doesn't really care so much about how things work but instead focuses on amassing as many exploits as possible and using them to compromise people's systems.

I've never heard of a whitehat script kiddie.
 

Topic Tools
Rate This Topic
Rate This Topic:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump

Similar Topics
Topic Topic Starter Forum Replies Last Post
China is Disturbed Neotribe Coffee Lounge 6 Apr 19, 06 09:38 AM
Globe and Mail, Oct. 23rd: China Rising DJ Ponz Coffee Lounge 4 Oct 25, 04 05:04 AM
HU'S ON FIRST - Starring George Bush Jr. MC Hammered Coffee Lounge 6 Nov 30, 02 07:43 PM
China going too far? Google.com ban Ć’ORM Punching Bag 11 Sep 07, 02 02:51 PM


All times are GMT -7. The time now is 06:54 AM.


Forum software by vBulletin
2000-2018 FNK.CA