Close

Results 1 to 4 of 4
  1. #1
    DF VIP Member
    greens117's Avatar
    Join Date
    Oct 2007
    Location
    United Kingdom
    Posts
    4,458
    Thanks
    1,108
    Thanked:        250
    Karma Level
    467

    Default Internet slows down after DNS attack on Spamhaus

    Internet slows down after DNS attack on Spamhaus

    Hundreds of thousands of Britons are unsuspectingly taking part in one of the internet's biggest-ever cyber-attacks

    Spamhaus has been under attack since adding a Dutch hosting organisation called Cyberbunker to its list of unwelcome internet sites.
    Photograph: Piotr Pawinski/Alamy


    Charles Arthur, technology editor

    Hundreds of thousands of Britons are unsuspecting participants in one of the internet's biggest cyber-attacks ever – because their broadband router has been subverted.

    Spamhaus, which operates a filtering service used to weed out spam emails, has been under attack since 18 March after adding a Dutch hosting organisation called Cyberbunker to its list of unwelcome internet sites. The service has "made plenty of enemies", said one expert, and the cyber-attack appeared to be retaliation.

    A collateral effect of the attack is that internet users accustomed to high-speed connections may have seen those slow down, said James Blessing, a member of the UK Internet Service Providers' Association (ISPA) council.

    "It varies depending on where you are and what site you're trying to get to," he said. "Those who are used to it being really quick will notice." Some people accessing the online streaming site Netflix reported a slowdown.

    Spamhaus offers a checking service for companies and organisations, listing internet addresses it thinks generate spam, or which host content linked to spam, such as sites selling pills touted in junk email. Use of the service is optional, but thousands of organisations use it millions of times a day in deciding whether to accept incoming email from the internet.

    Cyberbunker offers hosting for any sort of content as long, it says, as it is not child pornography or linked to terrorism. But in mid-March Spamhaus added its internet addresses to its blacklist.

    In retaliation, the hosting company and a number of eastern European gangs apparently enlisted hackers who have in turn put together huge "botnets" of computers, and also exploited home and business broadband routers, to try to knock out the Spamhaus system.

    "Spamhaus has made plenty of enemies over the years. Spammers aren't always the most lovable of individuals, and Spamhaus has been threatened, sued and [attacked] regularly," noted Matthew Prince of Cloudflare, a hosting company that helped the London business survive the attack by diverting the traffic.

    Rather than aiming floods of traffic directly at Spamhaus's servers – a familiar tactic that is easily averted –the hackers exploited the internet's domain name system (DNS) servers, which accept a human-readable address for a website (such as guardian.co.uk) and spit back a machine-readable one (77.91.248.30). The hackers "spoofed" requests for lookups to the DNS servers so they seemed to come from Spamhaus; the servers responded with huge floods of responses, all aimed back at Spamhaus.

    Some of those requests will have been coming from UK users without their knowledge, said Blessing. "If somebody has a badly configured broadband modem or router, anybody in the outside world can use it to redirect traffic and attack the target – in this case, Spamhaus."

    Many routers in the UK provided by ISPs have settings enabled which let them be controlled remotely for servicing. That, together with so-called "open DNS" systems online which are known to be insecure helped the hackers to create a flood of traffic.

    "British modems are certainly being used for this," said Blessing, who said that the London Internet Exchange —which routes traffic in and out of the UK — had been helping to block nuisance traffic aimed at Spamhaus.

    The use of the DNS attacks has experts worried. "The No 1 rule of the internet is that it has to work," Dan Kaminsky, a security researcher who pointed out the inherent vulnerabilities of the DNS years ago, told AP.

    "You can't stop a DNS flood by shutting down those [DNS] servers because those machines have to be open and public by default. The only way to deal with this problem is to find the people doing it and arrest them."
    Source
    http://m.guardian.co.uk/technology/2...-down-internet
    I STINK GET OVER IT !

  2. #2
    DF VIP Member Over Carl's Avatar
    Join Date
    Apr 2006
    Location
    London
    Posts
    13,125
    Thanks
    3,975
    Thanked:        1,690
    Karma Level
    1252

    Default Re: Internet slows down after DNS attack on Spamhaus

    While I've heard this news and it appears to be genuine, I think there is something incorrect here.

    It states someone could easily remotely access a router left on default configuration which is true. It doesn't make it clear but the only way of implementing the specifed attach at router level I can think of is to change the specified dns servers to rogue servers under the control of the hackers.

    I'm pretty sceptical that they would take the time to do this, although I suppose it's not totally unfeasible they've made scripts to look for common routers and try to automatically login and change settings. Problem with that approach is text boxes can change/move with things like configuration, firmware updates or customisation of firmwares for ISP's which would massively complicate any attempts to do this.

    Thanks to Over Carl

    ant3b (28th March 2013)  


  3. #3
    DF Probation Goldberg's Avatar
    Join Date
    Jun 2001
    Location
    Landaaaan!
    Posts
    14,453
    Thanks
    1,325
    Thanked:        1,547
    Karma Level
    1153

    Default Re: Internet slows down after DNS attack on Spamhaus

    This was forwarded around work recently. Wonder what you could do with this:

    http://internetcensus2012.bitbucket.org/paper.html
    We all make mistakes sometimes

  4. #4
    DF VIP Member blacksheep's Avatar
    Join Date
    Jun 2006
    Location
    Manchester
    Posts
    3,877
    Thanks
    87
    Thanked:        265
    Karma Level
    546

    Default Re: Internet slows down after DNS attack on Spamhaus

    Quote Originally Posted by Over carl View Post
    While I've heard this news and it appears to be genuine, I think there is something incorrect here.

    It states someone could easily remotely access a router left on default configuration which is true. It doesn't make it clear but the only way of implementing the specifed attach at router level I can think of is to change the specified dns servers to rogue servers under the control of the hackers.

    I'm pretty sceptical that they would take the time to do this, although I suppose it's not totally unfeasible they've made scripts to look for common routers and try to automatically login and change settings. Problem with that approach is text boxes can change/move with things like configuration, firmware updates or customisation of firmwares for ISP's which would massively complicate any attempts to do this.

    They won't be using the router web configuration page, they'll ssh to the router and update a config file.

    Thanks to blacksheep

    Over Carl (30th March 2013)  


Similar Threads

  1. internet blocked
    By sbaxter9 in forum Internet Connections & VPNs
    Replies: 10
    Last Post: 9th March 2004, 10:31 PM
  2. Zone alarm slows browsing
    By Aware in forum PC Problems
    Replies: 10
    Last Post: 18th September 2002, 10:42 AM
  3. definitive internet
    By shadygeezer in forum The Comedy Club
    Replies: 1
    Last Post: 12th September 2002, 06:12 PM
  4. Zen Internet
    By collettski in forum Internet Connections & VPNs
    Replies: 0
    Last Post: 11th September 2002, 02:31 PM
  5. Network Internet Sharing Help
    By Dark Angel in forum Internet Connections & VPNs
    Replies: 7
    Last Post: 4th September 2002, 01:20 PM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •