Saturday, November 30, 2013

Manpower Ministry finds another duplicate of website, second one in two days

Babe 
This person is a US based hosted hacker.
Yesterday is a Singapore based hosted hacker.


Do a nslookup www.mom.gov.sg show the following which should be the right DNS record to the official website – with URL different from the forged website and also notice is a IPv6 address unlike the forged address which is a IPv4 address.

Non-authoritative answer:
Name :- www.mom.gov.sg
IP address :- 2406:3000:2a:8::66
                203.117.191.66

Do a nslookup www.movgov.sg show the following which should be the duplicate DNS record to the forged website – with a different URL and a different IP address - by saving the real MOM webpage as html web page - can forged like the real one.

Non-authoritative answer:

Name :- movgov.sg
IP address :- 69.162.82.250
Aliases :- www.movgov.sg

Attached below is the trace route for this forged website.

 2    13 ms     9 ms     9 ms  bb116-15-49-1.singnet.com.sg [116.15.49.1]
  3    10 ms     8 ms     9 ms  ge-3-0-0-3489.sapporo.singnet.com.sg [202.166.124.165]
  4    10 ms    10 ms    39 ms  xe-9-0-0-3900.qt-ar04.singnet.com.sg [202.166.120.45]
  5    10 ms    10 ms    10 ms  xe-11-1-2.qt-cr03.singnet.com.sg [202.166.126.209]
  6    11 ms    12 ms    10 ms  ae6-0.singha.singnet.com.sg [202.166.120.186]
  7    10 ms    10 ms    11 ms  ae5-0.beck.singnet.com.sg [202.166.126.41]
  8    10 ms    10 ms    10 ms  203.208.190.57
  9    10 ms    10 ms    10 ms  ge-2-0-0-0.nycec-cr1.ix.singtel.com [203.208.151.217]
 10   181 ms   205 ms   200 ms  so-4-2-2-0.toknf-cr3.ix.singtel.com [203.208.173.106]
 11   191 ms   205 ms   192 ms  so-3-1-1-0.hkgcw-cr3.ix.singtel.com [203.208.171.38]
 12   209 ms   187 ms   187 ms  ge-11-2-0.mpr2.pao1.us.above.net [64.125.12.205]
 13   214 ms   184 ms   190 ms  xe-2-2-0.cr2.sjc2.us.above.net [64.125.31.70]
 14   207 ms   210 ms   219 ms  ae1.cr2.lax112.us.above.net [64.125.31.234]
 15   242 ms   246 ms   252 ms  ae4.cr2.iah1.us.above.net [64.125.25.54]
 16   233 ms   236 ms   235 ms  ae1.cr2.dfw2.us.above.net [64.125.21.137]
 17   244 ms   228 ms   229 ms  xe-0-2-0.mpr1.dfw1.us.above.net [64.125.27.213]
 18   242 ms   259 ms   241 ms  64.125.188.182.t00822-03.above.net [64.125.188.182]
 19   232 ms   231 ms   232 ms  te6-1.bdr2.core1.dllstx3.dallas-idc.com [208.115.192.58]
 20   232 ms   244 ms   217 ms  ge0-1.vl138.cr02-76.dllstx3.dallas-idc.com [208.115.251.146]
 21   232 ms   227 ms   239 ms  domains.freetzi.hosting.free [69.162.82.250]

Trace complete.

Soccerbetting2  
How did you arrive at the conclusion that the hacker is US based not Australia based not New Zealand based etc ? Maybe you can shared your expertise here ?

Babe  
No need. Wait till the hackers got caught.

Soccerbetting2  
You so confident that the hacker is from US based ? OK , trust your expertise knowledge .

Babe  
I say is US based hosted hacker.

Soccerbetting2  

OK . I have stated that it is US based from my first post and also US based from my second post also .
Maybe my second posting is posted at first as stated as US but I did corrected and edited that in less than 30 seconds starting from my second posting of it to be "US based" before you replied.

And "US based" is no difference in meaning as from US based hosted hacker .

Hope this clarified out .

Babe  

"US based" & "US based hosted hacker" - is alot of difference technically.
Anyway, no need to dwell into detail & give things away. Let the authorities handle.

Lee Liat Kuan  
Babe, do you know or just guessing?

Babe  
When the hackers got caught, you will know lor.

No comments:

Post a Comment