CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer
image Guest Writer: Update on DDoS – mid 2007 image
Anti-Terror
Its been an interesting last few months with respect to distributed denial of service (“DDoS”) attacks. Some noteworthy events:

1) Spread of DDoS to include Cyber-censorship and cyber-terrorism/war

In May 2007 either the biggest instance of cyber-terrorism, or the first instance of cyber-war occurred. The Estonian government moved a Russian World War 2 statue, amid huge protest from Russia and Russians within Estonia. Shortly afterwards, Estonian government websites, Estonian banks, and Estonian VoIP infrastructure were taken offline for a couple of weeks from DDoS attacks. The only way Estonia could get their sites back up was to block all traffic outside Estonia. Your readers may have read the headlines so no point re-hashing old info, but what didn’t make the news is that there were chat rooms in Russia promoting the download of software to have your laptop ‘join the attacking force against Estonia’ - first instance of volunteer DDoS recruitment that I've heard of.

Around the same time as the attacks on Estonia were taking place, DDoS attacks on Russian online media / opposition political party websites started, and continue to this day. Putin is pretty well known to not be an advocate of free speech, and this is a logical extension of his policy of shutting down independent physical newspaper operations. It has also started to spread outside of Russia – the Daily Telegraph of the UK ran an anti-Putin report a month ago and was taken offline from a DDoS attack until they found Prolexic. This cyber-censorship trend will likely be copied by other regimes in the future (would think Venezuela for one).

DDoS is particularly suited to either of these activities; the target can be attacked immediately with an available botnet, and as tracking down the command and control server becomes harder, the attackers more easily maintain their anonymity. The Russian government was accused of aiding the Estonian attack but denied any knowledge, saying that attacking IPs within the Kremlin were spoofed.

2) Interesting visitor stats

If you type 'ddos' into google, we tend to come up first under the sponsored links (nothing exciting there as we pay for the privilege). We've been tracking who comes to our sites for a few months now, for marketing effectiveness purposes.

We believe that a percentage of our hits come from potential attackers wanting to learn how to create a DDoS attack. We believe this more strongly when there is a large percent of 'bounced' visits - people spending less than a minute on our site. One plausible explanation is that the visitor realizes that we're DDoS defense vs DDoS offense, and moves on. Since we've began tracking it, we've had a huge number of hits from China (where DDoS has become a well-known business - whether botnets for hire or scripts for sale to create-your-own-botnet). As penalties for attacking intra-China vs externally to China are vastly different (execution for an intra-China attack vs a letter then maybe a small fine for attacking a foreign country), our feeling is that many of the Chinese hits are of a 'how to DDoS' variety.

We noticed a 100% increase in visits from Russia in February this year - 2 months before the cyber-censorship/terrorism attacks detailed above.

Between May and June 2007, the majority of our website visits are either coming from China or from three cities: Rabat Morocco, Riyadh Saudi Arabia, and Istanbul Turkey. May 2007 in comparison to Dec 2006 visitor stats to Prolexic's website are:

Rabat - 3900% increase in hits
Riyadh - 2700% increase in hits
Istanbul - 900% increase in hits

Morocco and Saudi Arabia are known recruitment areas for al-Qaeda. I don't know what Turkey might mean, except that when we helped the FBI put a Russian DDoS extortionist in jail a few years back, we were told that the rest of the group fled to Turkey, and we have seen attacks out of Turkey since.

Of course, all of the above could have some other explanation, and we don't have enough correlated data to be statistically significant (i.e. Russian visits > Russian based DDoS attacks). However, we may also be heading for some interesting times in the realm of DDoS. We’ve approached some law enforcement agents but haven’t really heard much back – if you have law enforcement contacts that would be interested, I’d be happy to give them more details.

Kind regards

Keith Laslop
President
www.prolexic.com
Posted on Friday, 10 August 2007 @ 02:40:13 UTC by Paul (2057 reads)
[ Trackback ]
image

"Guest Writer: Update on DDoS – mid 2007" | Login/Create an Account | 3 comments | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Update on DDoS – mid 2007 (Score: 1)
by PAN_IRISH  on Sunday, 12 August 2007 @ 02:42:52 UTC
(User Info | Send a Message)
how do you spoof an I.P NUMBER inside the KREMLIN?


The Russian government was accused of aiding the Estonian attack but denied any knowledge, saying that attacking IPs within the Kremlin were spoofed.
..



Re: Update on DDoS – mid 2007 (Score: 1)
by xpatjock (luxortech@europe.com)  on Monday, 13 August 2007 @ 08:18:51 UTC
(User Info | Send a Message)
Unfortunately the DDoS attacks are just one side of the story. Any article in the western press ( electronic issues) which is critical in the slightest of Russian policy and Putin in particular, results in any discussion forums linked to the article being swamped with responses from concerned Russians slagging off the article, its author etc in terms that sometimes are not far removed from those used in Soviet times. Any attempt to reason with the poster is useless as I know from trying to have a reasoned discussion on the New Statesman website (A left wing news journal) following an article on Poland and the Baltic states attitude to Russia.)
I wouldn't be surprised if even the New Statesman faces a DDoS soon

What is annoying is that if western hackers were to post calls for other hackers to join the attack on country xxxx then there would be uproar, but in the case of Estonia, the Kremln just ignores it all.


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· Google Search Engine
· W3 Consortium
· More about Anti-Terror
· News by Paul


Most read story about Anti-Terror:
SpyFalcon, a nightmare rebranded

block bottom
Article Rating
spacer
Average Score: 4.66
Votes: 9


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer