Skip to content
Insecure Lab

Insecure Lab

Hacker News

  • Insecure Lab
  • Contact Us

AT&T Facebook Traffic Takes a Loop Through China & South Korea

Network Forensics Network Hacking News / Stories Privacy Attacks
23-March-201127-March-2011Prasanna Sherekar

Traffic destined for Facebook from AT&T’s servers took a strange loop though China and South Korea on Tuesday, according to a security researcher.Facebook Route

As Barrett Lyon wrote on his blog, typically AT&T customers’ data would have routed over the AT&T network directly to Facebook’s network provider but due to a routing mistake, their private data went first to Chinanet then via Chinanet to SK Broadband in South Korea, then to Facebook. This means that anything you looked at via Facebook without encryption was exposed to anyone operating Chinanet, which has a very suspect Modus operandi.

Route to Facebook from AT&T on 22nd March 2011 :

route-server>show ip bgp 69.171.224.13 (Facebook’s www IP address)
BGP routing table entry for 69.171.224.0/20, version 32605349
Paths: (18 available, best #6, table Default-IP-Routing-Table)
Not advertised to any peer
7018 4134 9318 32934 32934 32934

The AS path (routing path) translates to this:
1. AT&T (AS7018)
2. Chinanet (Data in China AS4134)
3. SK Broadband (Data in South Korea AS9318)
4. Facebook (Data back to US 32934)

What could have happened with your data? Most likely absolutely nothing. Yet, China is well known for it’s harmful networking practices by limiting network functionality and spying on its users, and when your data is flowing over their network, your data could be treated as any Chinese citizens’. Does that include capturing your session ID information, personal information, emails, photos, chat conversations, mappings to your friends and family, etc.? One could only speculate, however it’s possible.

This happens all the time — the Internet is just not a trusted network.

One way to prevent this from happening to your account: Enable HTTPS.

In January, Facebook rolled out the HTTPS feature to all browsing done on the site, but it’s opt-in an not automatic setting. Previously, Facebook used HTTPS only when you entered in your password.

To enable this security feature, go to – Account Settings >> Account Security
Click “change”. Check mark “Browse Facebook on a secure connection (https) whenever possible”.

Facebook Account Security

Tagged FacebookFacebook Account SecurityFacebook PrivacyFacebook TracerouteFacebook Traffic RouteNewsRouting ErrorStoriesTraceroute

Post navigation

MHTML vulnerability under active exploitation
MySQL and Sun websites hacked using SQL injection

Related Posts

DDOSIM – Layer 7 DDoS Simulator

15-November-201019-November-2010Prasanna Sherekar

TJX Maxx Hacker Jailed for 30 years

11-January-200922-February-2009Prasanna Sherekar

Researcher cracks Mac in 10 seconds at PWN2OWN, wins $5k

26-March-200930-July-2009Prasanna Sherekar

Categories

  • Android Hacking
  • Antivirus / Firewall
  • Application Security
  • Bug
  • Conference
  • Contest
  • Cryptography
  • Database Hacking
  • DoS Attacks
  • EMail Hacking
  • Exploits
  • Facebook Hacking
  • Google Hacking
  • Hackers
  • Hacking Tips Tricks
  • Hacking Tools
  • Information Gathering
  • Input Validation Attacks
  • Intrusion Detection
  • IOS Hacking
  • Malware / Rootkit
  • Mobile Hacking
  • Network Forensics
  • Network Hacking
  • News / Stories
  • Password Hacking
  • Penetration Testing
  • Privacy Attacks
  • Security Tools
  • Social Engineering Attacks
  • Twitter Hacking
  • Uncategorized
  • Videos
  • Viruses
  • Vulnerabilities
  • Website Hacking
  • WhatsApp Hacking
  • White Papers
  • Windows Hacking
  • Windows Tweaks
  • Wireless Hacking
www.insecure.in | © 2023  Insecure Lab, India.