Hundreds of thousands of Britons are unsuspecting participants in one of the internet's biggest cyber-attacks ever – because their broadband router has been subverted.
Spamhaus, which operates a filtering service used to weed out spam emails, has been under attack since 18 March after adding a Dutch hosting organisation called Cyberbunker to its list of unwelcome internet sites. The service has "made plenty of enemies", said one expert, and the cyber-attack appeared to be retaliation. A collateral effect of the attack is that internet users accustomed to high-speed connections may have seen those slow down, said James Blessing, a member of the UK Internet Service Providers' Association (ISPA) council. "It varies depending on where you are and what site you're trying to get to," he said. "Those who are used to it being really quick will notice." Some people accessing the online streaming site Netflix reported a slowdown.
Spamhaus offers a checking service for companies and organisations, listing internet addresses it thinks generate spam, or which host content linked to spam, such as sites selling pills touted in junk email. Use of the service is optional, but thousands of organisations use it millions of times a day in deciding whether to accept incoming email from the internet. Cyberbunker offers hosting for any sort of content as long, it says, as it is not child pornography or linked to terrorism. But in mid-March Spamhaus added its internet addresses to its blacklist.
In retaliation, the hosting company and a number of eastern European gangs apparently enlisted hackers who have in turn put together huge "botnets" of computers, and also exploited home and business broadband routers, to try to knock out the Spamhaus system.
"Spamhaus has made plenty of enemies over the years. Spammers aren't always the most lovable of individuals, and Spamhaus has been threatened, sued and [attacked] regularly," noted Matthew Prince of Cloudflare, a hosting company that helped the London business survive the attack by diverting the traffic.
Rather than aiming floods of traffic directly at Spamhaus's servers – a familiar tactic that is easily averted – the hackers exploited the internet's domain name system (DNS) servers, which accept a human-readable address for a website (such as guardian.co.uk) and spit back a machine-readable one (77.91.248.30). The hackers "spoofed" requests for lookups to the DNS servers so they seemed to come from Spamhaus; the servers responded with huge floods of responses, all aimed back at Spamhaus.
Some of those requests will have been coming from UK users without their knowledge, said Blessing. "If somebody has a badly configured broadband modem or router, anybody in the outside world can use it to redirect traffic and attack the target – in this case, Spamhaus."
Many routers in the UK provided by ISPs have settings enabled which let them be controlled remotely for servicing. That, together with so-called "open DNS" systems online which are known to be insecure helped the hackers to create a flood of traffic.
"British modems are certainly being used for this," said Blessing, who said that the London Internet Exchange — which routes traffic in and out of the UK — had been helping to block nuisance traffic aimed at Spamhaus.
The use of the DNS attacks has experts worried. "The No 1 rule of the internet is that it has to work," Dan Kaminsky, a security researcher who pointed out the inherent vulnerabilities of the DNS years ago, told AP.
"You can't stop a DNS flood by shutting down those [DNS] servers because those machines have to be open and public by default. The only way to deal with this problem is to find the people doing it and arrest them."
Search This Site
Thursday, March 28, 2013
Subscribe to:
Post Comments (Atom)
News Archive
-
►
2022
(3)
- ► September 2022 (1)
- ► August 2022 (1)
- ► April 2022 (1)
-
►
2021
(12)
- ► October 2021 (1)
- ► April 2021 (1)
- ► March 2021 (1)
-
►
2020
(252)
- ► December 2020 (8)
- ► November 2020 (5)
- ► October 2020 (12)
- ► September 2020 (5)
- ► August 2020 (1)
- ► April 2020 (29)
- ► March 2020 (52)
- ► February 2020 (26)
- ► January 2020 (79)
-
►
2019
(694)
- ► December 2019 (42)
- ► November 2019 (59)
- ► October 2019 (116)
- ► September 2019 (32)
- ► August 2019 (32)
- ► April 2019 (77)
- ► March 2019 (105)
- ► February 2019 (73)
- ► January 2019 (71)
-
►
2018
(361)
- ► December 2018 (103)
- ► November 2018 (96)
- ► October 2018 (149)
- ► August 2018 (11)
- ► February 2018 (2)
-
►
2017
(11)
- ► April 2017 (7)
- ► January 2017 (4)
-
►
2016
(605)
- ► August 2016 (6)
- ► April 2016 (132)
- ► March 2016 (72)
- ► February 2016 (154)
- ► January 2016 (42)
-
►
2015
(1356)
- ► December 2015 (76)
- ► November 2015 (94)
- ► October 2015 (86)
- ► September 2015 (142)
- ► August 2015 (42)
- ► April 2015 (92)
- ► March 2015 (233)
- ► February 2015 (94)
- ► January 2015 (42)
-
►
2014
(1256)
- ► December 2014 (54)
- ► November 2014 (52)
- ► October 2014 (83)
- ► September 2014 (102)
- ► August 2014 (120)
- ► April 2014 (128)
- ► March 2014 (259)
- ► February 2014 (201)
- ► January 2014 (119)
-
▼
2013
(2600)
- ► December 2013 (195)
- ► November 2013 (59)
- ► October 2013 (172)
- ► September 2013 (407)
- ► August 2013 (219)
- ► April 2013 (217)
-
▼
March 2013
(473)
- CBDT: Delve deep into info exchange
- The bad business of taxing agentsMake 'doing busin...
- 2000 CRORE IT DEMAND ON NOKIA
- Value education--Fourth Dimension Editorial
- Due Dates for March 13
- IT : When Legislature amends provisions of Act wit...
- CL : Where film production/distribution associatio...
- CL : Where majority shares of appellant-company we...
- IT : In order to assess individuals to be forming ...
- IT: Where less than 50 per cent funds of assessee ...
- s IT : Where assessee was engaged in business of d...
- IT : To claim deduction of interest paid on borrow...
- Appointment Of Chartered Accountants For Internal ...
- Vacancy for CA/ CS in The Clearing Corporation of ...
- Vacancy for /ICWA/CA-Inter/CA in Accenture
- Vacancy for CA Inter / ICWA Inter in Ministry of H...
- President should automatically pardon convicts bel...
- Service Tax on AC restaurants Food for Thought
- Income-tax departmentto issue draft order on Rs 15...
- REQUIRED PARTNER
- Cellular company providing services in the form of...
- FOR CAs MOTOR INSURANCE SCHEME
- ICAI HEALTH INSURANCE SCHEME
- INSURANCE PROTECTION FOR CA FIRMS
- ST : I. Tax paid on freight for dutiable transport...
- CBDT streamlines taxation rules for IT sector
- AAGHAAZ- CPT starts 7th April,2013,,Last Date Of R...
- SOME USEFUL AUDIT EXCEPTION / ANALYTICAL REPORTS G...
- IFRS-GOING CONCERN-AUSTRALIAN COMPANY-AICPA
- How to identify development centres engaged in con...
- CA Firm looking for full time partner
- Accounts Manager Job
- CL : Where company's admitted liability was in exc...
- Public speech training/personality development pro...
- IT : Court should resort to section 260A after bei...
- INTERNET UNDER ATTACK
- IT : Speculation losses carried forward from previ...
- IT : Questions of identity and creditworthiness of...
- 2000 CRORE IT DEMAND ON NOKIA
- IT : No infirmity in the action of the TPO in usin...
- DEBTS RECOVERY TRIBUNAL (PROCEDURE FOR INVESTIGATI...
- Another wake-up call - No place for India in IASB'...
- Vacancy for CA/ ICWA in HSBC
- CL : IT authority has no power to intervene on any...
- Un-necessary litigation by revenue to disallow ele...
- Vacancy for CA/ ICWA in Gujarat Energy Transmissio...
- Seminar on Bank Audit on 28th March 2013
- SEBI (SAST) (AMENDMENT) REGULATIONS, 2013
- Vacancy for CA in Aditya Birla Nuvo Ltd
- Extension of Banking Hours on Saturday, 30th March...
- For those who want Bank Branch Audit
- Vacancy for CA in Essel Mining and Industries Limited
- Exposure Draft Financial Instruments: Expected Cre...
- Postponement of Examination scheduled on 4th & 5th...
- Happy Holi Get Rs.1000 cash back on all your recha...
- SECTION 143 OF THE INCOME-TAX ACT, 1961 - ASSESSME...
- Looking for Associates- Equity Research (2-3Yrs)- ...
- COMPANIES DIRECTORS IDENTIFICATION NUMBER (AMENDME...
- Public Notice regarding Launching of E-Payment fac...
- Amnesty Scheme - Settle your ST issues without any...
- CBI court sentences additional income tax commissi...
- Guj I-T official in CBI net for graft New Delhi:
- S. 269SS not violated if Assessee borrows in cash ...
- Appointment of Consulting Auditors for Muncipal Co...
- BANK WISE LIST FOR 2012-13 BRANCH AUDITORS -RBI
- Rural Electrification Corporation Ltd. (REC) invit...
- Opening for CA at Bizancial Consulting Pvt. Ltd.
- ICAI BANK AUDIT EXPERT PANEL
- SMALL SAVINGS INTEREST REDUCED
- Work in Ambedkar Nagar
- ITAT: ALP between AE and non AE Transcation
- CONDUCTING STATUTORY BR. AUDIT IN CBS ENVIRONMENT...
- Instruction No. 3/2011, dated 9-2-2011, would appl...
- SEBI relies on robotic systems to handle Sahara f...
- 30k officers of central excise, customs to go on 3...
- Manager - Finance Foggers India Pvt Ltd
- Banks will open Clearing operations on March 29, 3...
- CONDUCTING STATUTORY BR. AUDIT IN CBS ENVIRONMENT…...
- GE failed to adequately warn about dangers of its ...
- Two months after Infosys, India’s most celebrated ...
- CONDUCTING STATUTORY BR. AUDIT IN CBS ENVIRONMENT…...
- Electronic version of New ST 3 expected to be avai...
- Building a complex human organ in the lab is no lo...
- What Harvard Looks for in a Student
- Walkin Interview for CA in J.Kumar Infraprojects Ltd.
- CA vacancy in ALBA Asia Pvt. Ltd.
- CA vacancy in Samruddha Group
- CA vacancy in VENKAT INTERNATIONAL PUBLIC SCHOOL
- CA/CMA vacancy in Thiess Minecs India Pvt Ltd
- CA / ICWA vacancy in Davi Engineering Pvt. Ltd.
- CA Vacancy in Sikka Group
- CA (Inter) vacancy in PNC Infratech Limited
- Vacancy for CA inter/ Icwa Inter/ Inter CS in GIC ...
- ST : Credit of input service cannot be denied mere...
- Vacancy for CA/ICWA in NBCFDC
- ST : Chartered Accountant's service, business supp...
- Vacancy for position 15 months CS Management Training
- The Criminal Law (Amendment) Bill 2013
- Vacancy for CA/ICWA in Novartis Healthcare Private...
- COMPANIES (ACCEPTANCE OF DEPOSITS AMENDMENT) RULES...
- ► February 2013 (241)
- ► January 2013 (219)
-
►
2012
(2695)
- ► December 2012 (213)
- ► November 2012 (168)
- ► October 2012 (253)
- ► September 2012 (173)
- ► August 2012 (278)
- ► April 2012 (256)
- ► March 2012 (310)
- ► February 2012 (289)
- ► January 2012 (184)
-
►
2011
(1842)
- ► December 2011 (228)
- ► November 2011 (316)
- ► October 2011 (188)
- ► September 2011 (167)
- ► August 2011 (138)
- ► April 2011 (194)
- ► March 2011 (151)
- ► February 2011 (22)
- ► January 2011 (17)
-
►
2010
(14)
- ► December 2010 (14)
No comments:
Post a Comment