Showing posts with label servers. Show all posts
Showing posts with label servers. Show all posts

Wednesday, August 19, 2009

Windows WINS server attack coming from China

Yesterday, John Fontana reported that the vulnerability in the WINS service on Windows server was being exploited, and now researchers have found that the attacks are coming from China, despite some troubles with the undersea cables linking China to other parts of the world.

Attacks on the WINS service vulnerability in Windows Server are coming from China, but so far are not widespread, according to the Internet Storm Center.

The ISC, which is run by the SANS Institute, says they have only been able to collect limited information on the attacks, but confirmed that they are coming from IP addresses inside China.

The WINS service vulnerability was revealed last week when Microsoft issued patch MS09-039 as part of its regular Patch Tuesday release cycle

The vulnerability was rated as "critical."

Bojan Zdrnja, who is the current Handler on duty at the ISC, said in an email response that the ISC has received "several confirmations that the attacks appear to be real, and targeted against WINS servers that have not been patched with the MS09-039 patch."

He said ISC data shows that there is scanning going on, but so far there is no evidence of a widespread attack.

Friday, July 17, 2009

Investigation Into Cyberattacks is of Global concern

UK authorities have launched an investigation into the recent cyberattacks that crippled Web sites in the U.S. and South Korea, as the trail to find the perpetrators stretches around the world.

On Tuesday, the Vietnamese security vendor Bach Khoa Internetwork Security (Bkis) said it had identified a master command-and-control server used to coordinate the denial-of-service attacks, which took down major U.S. and South Korean government Web sites.

Command and Control
A command-and-control server is used to distribute instructions to zombie PCs, which form a botnet that can be used to bombard Web sites with traffic, rendering the sites useless. The server was on an IP (Internet Protocol) address used by Global Digital Broadcast, an IP TV technology company based in Brighton, England, according to Bkis.

BKIS Gain Control
That master server distributed instructions to eight other command-and-control servers used in the attacks. Bkis, which managed to gain control of two of the eight servers, said that 166,908 hacked computers in 74 countries were used in the attacks and were programmed to seek out and download new instructions every three minutes, from designated random sites.

Master Server in Miami
But the master server isn't in the U.K.; it's in Miami, according to Tim Wray, one of the owners of Digital Global Broadcast, who spoke to IDG News Service on Tuesday evening, London time.
The server belongs to Digital Latin America (DLA), which is one of Digital Global Broadcast's partners. DLA encodes Latin American programming for distribution over IP TV-compatible devices, such as set-top boxes.

VPN Distribution
New programs are taken from satellite and encoded into the proper format, then sent over VPN (Virtual Private Network) to the U.K., where Digital Global Broadcast distributes the content, Wray said. The VPN connection made it appear the master server belonged to Digital Global Broadcast when it actually is in DLA's Miami data center.

Engineers from Digital Global Broadcast quickly discounted that the attacks originated with the North Korean government, which South Korean authorities have suggested may be responsible.

Digital Global Broadcast
Digital Global Broadcast was notified of a problem by its hosting provider, C4L, Wray said. His company has also been contacted by the U.K.'s Serious Organised Crime Agency (SOCA). A SOCA official said she could not confirm or deny an investigation.

Amaya Ariztoy, general counsel for DLA, said the company examined the server in question today and found "viruses" on it. "We are conducting an investigation internally," Ariztoy said.

Forensic Analysis
Investigators will need to seize that master server for forensic analysis. It's often a race against the hackers, since if the server is still under their control, critical data could be erased that would help an investigation.

"It's a tedious process and you want to do it as quickly as possible," said Jose Nazario, manager of security research for Arbor Networks.

Data Log Files
Data such as log files, audit trails and uploaded files will be sought by investigators, Nazario said. "The holy grail you are looking for are pieces of forensics that reveal where the attacker connected from and when," he said.

MyDoom modified
To conduct the attacks, the hackers modified a relatively old piece of malware called MyDoom, which first appeared in January 2004. MyDoom has e-mail worm characteristics and can also download other malware to a PC and be programmed to conduct denial-of-service attacks against Web sites.

Variant analysis
Analysis of the MyDoom variant used in the attacks isn't that impressive. "I still think the code is pretty sloppy, which I hope means they [the hackers] leave a good evidence trail," Nazario said.

It could also be that the perpetrator is either very confident that they will not be found, is trying to hide in the pseudo amateur world of the cyber geeks and vandals. Someone who is not concerned or is immune from discovery and persecution.

A virtual self destructive personality that is implementing, what they believe to be a damaging but non fatal 'suicide' mission, allegedly.

Wednesday, May 6, 2009

The Internet: How easily could it be shut down?

How easy is it to SHUTDOWN the Internet?

The experts and geeks alike will tell you that it is impossible! "Almost, certainly not." They would say in their clearly doubtful manner.

Why not?, you ask. Well, much of the infrastructure, the servers, cabling, satellites, and the internet service providers (ISPs) that run them, is in private hands. A single government might be able to command ISPs in their territory to shut down, but people could still receive data through satellite links controlled by other companies not answerable to that government. Hmm! OK so far.

To extend that shutdown across national borders is barely conceivable. "One very powerful government could have strong effects on their own country, but it would be very difficult to do this on a worldwide basis," says Milton Mueller, and he should know, he represents the international Internet Governance Project.

Who would 'want' to shut down the internet? Even the biggest cyber-attacks cause much less economic damage than closing the internet would. What's more, the experts say, malicious attempts to disable the internet are testimony to the difficulty of the task: the biggest attack in history came in February 2007, and you probably didn't even notice.

This attack attempted to overwhelm the 13 "root name servers" that carry the directory of all the internet addresses in use worldwide - data vital to the smooth running of the net. Two servers, both in the US, were affected, but with 11 others untouched, the attack failed.

ICANN has now begun to implement a further safeguard system, known as Anycast, by which each of the internet's 13 root name servers also acts as a duplicate, or mirror, for some of the others. "A root server in California can be mirrored in Taiwan or the Middle East," Mueller says. "By playing tricks with the addressing, we effectively have hundreds of these root servers."

If cyber-assaults get nowhere in shutting down the net, physical attacks on the infrastructure are unlikely to fare any better. You would have to physically plant bombs to destroy undersea cables, before launching missile attacks on the root name servers that are spread around the planet. "Then the internet will be the least of your worries," says Mueller. "We're talking about full-fledged international war."

There is another question that puzzles me. Why would the cyber-criminals and hackers want to shut down the web? It is the source of all their revenue, thrills and raison d'etre. I believe that the 'manipulation' and 'control' of the internet is a more probably target and that again is only partly possible with or without government funding, allegedly.