Domain: merit.edu
Stories and comments across the archive that link to merit.edu.
Stories · 19
-
Comcast Accused of Congestion By Choice
An anonymous reader writes "A kind soul known as Backdoor Santa has posted graphs purportedly showing traffic through TATA, one of Comcast's transit providers. The graphs of throughput for a day and month, respectively, show that Comcast chooses to run congested links rather than buy more capacity. Keeping their links full may ensure that content providers must pay to colocate within Comcast's network. The graphs also show a traffic ratio far from 1:1, which has implications for the validity of its arguments with Level (3) last month." -
Peering Disputes Migrate To IPv6
1sockchuck writes "As more networks prepare for the transition to IPv6, we're seeing the first peering disputes (sometimes known as 'Internet partitions') involving IPv6 connectivity. The dispute involves Cogent, which has previously been involved in high-profile IPv4 peering spats with Sprint, Level 3 and Telia. Hurricane Electric, which has been an early adopter on IPv6, says Cogent won't peer with it over IPv6. Hurricane has extended an olive branch by baking a cake bearing a message of outreach for Cogent." -
One Broken Router Takes Out Half the Internet?
Silent Stephus writes "I work for a smallish hosting provider, and this morning we experienced a networking event with one of our upstreams. What is interesting about this, is it's being caused by a mis-configured router in Europe — and it appears to be affecting a significant portion of the transit providers across the Internet. In other words, a single mis-configured router is apparently able to cause a DOS for a huge chunk of the Net. And people don't believe me when I tell them all this new-fangled technology is held together by duct-tape and baling wire!" -
Network Solutions Under Large-Scale DDoS Attack
netizen writes "CircleID is reporting a large-scale DDoS attack affecting all of Network Solutions' name servers for the past 48 hours, potentially affecting millions of websites and emails around the world hosting their domain names on the company's servers. The NANOG mailing list indicates that it is due to a very large-scale UDP/53 DDoS which Network Solutions has also confirmed: 'There is a spike in DNS query volumes that is causing latency for the delay in web sites resolving. This is a result of a DDOS attack. We are taking measures to mitigate the attack and speed up queries."" -
Satellite IDs Ships That Cut Cables
1sockchuck writes "Undersea telecom cable operator Reliance Globalcom was able to use satellite images to identify two ships that dropped anchor in the wrong place, damaging submarine cables and knocking Middle East nations offline in early February. The company used satellite images to study the movements of the two ships, and shared the information with officials in Dubai, who impounded the two vessels. The NANOG list has a discussion of where Reliance might have obtained satellite images to provide that level of detail. Google News links more coverage of the developments." -
Cisco Warns of Stolen Web Site Passwords
An anonymous reader writes "Cisco warned customers today that someone had broken in and stolen an untold number of passwords and usernames that its customers and employees use to login at Cisco.com, according stories at News.com and Washingtonpost.com. Cisco says the problem is unrelated to flaws in its hardware, but both stories note that Cisco's latest troubles are likely fallout from their legal battles with researcher Mike Lynn, who last week revealed major flaws in Cisco routers. There is also a growing thread at Nanog where network admins are complaining of not being able to get new passwords." -
MelbourneIT Lapse Permitted Panix Hijack
McSpew writes "Netcraft reports MelbourneIT's CTO, Bruce Tonkin, has admitted the Panix domain hijacking occurred because of a loophole in MIT's domain transfer process. He doesn't go into detail about what that loophole was, or how it was closed. As a Panix user, I'd like more detail, and I'd like to know what can be done to stop this sort of nonsense happening to other domains." -
Faster Updates for DNS Root Servers Arrive
Tee Emm writes "VeriSign's DNS Rapid Update notice period (as announced on NANOG mailing list) expires today. Beginning September 9, 2004 the SOA records of the .com and .net zones will be updated every 5 minutes instead of twice a day. The format of the serial number is also changing from the current YYYYMMDDNN to a new one that depicts the UTC time." We first mentioned this back in July, but it's finally launching now. -
Verisign Speeds Up DNS Updates
Changeling writes "According to Matt Larson, a representative of VeriSign Naming and Directory Services, on September 8, 2004 Verisign will be switching from performing 2 updates per day of the .com and .net zones to performing updates every few seconds. According to Matt, 'After the rapid DNS update is implemented, the elapsed time from registrars' add or change operations to the visibility of those adds or changes in all 13 .com/.net authoritative name servers is expected to average less than five minutes." Full story can be found here." -
Court Says Customers May Take IPs Away From ISP
Jeremy Kister writes "According to a post on the North American Network Operators Group mailing-list, The State of New Jersey has issued a temporary restraining order, allowing a former customer of Net Access Corporation (NAC) to take non-portable IP Address space (issued from ARIN), away from NAC." The post argues: "This is a matter is of great importance to the entire Internet community. This type of precedent is very dangerous. If this ruling is upheld it has the potential to disrupt routing throughout the Internet, and change practices of business for any Internet Service Provider." -
Verisign's SiteFinder - An Engineer's View
ixs writes "CircleID has an interesting article by David Monosov about Verisign's plans to reintroduce Sitefinder. The article presents the thesis that the Internet engineering community is partly to blame for Verisign's ability to mess with the .com and .net root zones. According to the author we spend too much time with our systems and not enough with politics. The writeup was previously posted to NANOG and received a favorable response from Paul Vixie." -
Verisign Plans DNS Changes
NetWizard writes "According to a recent NANOG post and an InfoWorld story, 'Verisign will change the serial number format and "minimum" value in the .com and .net zones' SOA records on or shortly after 9 February 2004'. They seemed to have learned their lesson, from the post: 'There should be no end-user impact resulting from these changes (though it's conceivable that some people have processes that rely on the semantics of the .com/.net serial number.) But because these zones are widely used and closely watched, we want to let the Internet community know about the changes in advance.)'" -
BIND Patches Make Bad Situation Worse
An anonymous reader writes "After .COM and .NET started using a wildcard, the internet community busily started creating patches to various pieces of software to circumvent this. It was said that this was a grave problem to the internet. Several official BIND patches were announced over the next few days. However, it turns out they weren't necessarily too well thought through. Usage of the patch unexpectedly broke at least 7 Top Level Domains, ISC announced 3 weeks later, after users started having problems. The .NAME registry has sent a formal letter to ICANN's Security and Stability Advisory Comittee to warn against using the BIND patch, which they will look into in their next meeting. The intention may have been good, but... Stability? Anyone?" -
Osirusoft Blacklists The World
ariehk writes "As of today, Osirusoft, distributer of the SPEWS and open relay blocklists, among others, is no longer operational. Servers using these lists (including the FTC) are currently rejecting ALL email. This shutdown seems to be in response to a several-week-long DDoS attack on Osirusoft, SPEWS and others, resulting in both sites being down. This has caused much discussion on n.a.n-a.e, including the suggestion that the attack is somehow related to the SoBig worm. The spammers must be hurting if they can devote these kinds of resources to attacking blocklists." Read on below a related submission.NSXDavid writes "Earlier today our site mysteriously ended up on Joe Jared's Osirusoft SPAM blacklist which is used by lots of antispam software (like SpamAssassin and sendmail). Since he is currently under a serious DDoS attack, there was no way to appeal this decision. We contacted Mr. Jared by phone who informed us that 'everyone needs to stop using Osirusoft and that he's going to be shutting the service down.' Then he says he's going to blacklist 'the world' (aka, ban *.*.*.*) to get his point across. Later on this evening, he apparently went ahead and did just that. Succumbing to lawsuits and DDoS, a once great blacklist is dead. SpamAssassin is removing it from their config in the next release (rc3) and email admins around the globe are reconfiguring their mail servers."
-
W2K and MAC OS9 Flood Root Nameservers?
wizzy writes "Irelands toplevel domain registry has a notice on Microsoft and Apple DHCP clients sending dynamic DNS updates per RFC2136. The problem is they are not sufficiently careful about where they send it if they are in RFC1918 space - usually used for behind-firewall addressing, which is where they usually are.. This is resulting in bogus updates being sent at the rate of nearly one million an hour to root nameservers, only to be rejected - as reported on the NANOG mailing list." -
Telco Networks Open to Attack?
Cally writes: "This post to NANOG summarises Dave Henderson's paper (.ppt: HTML in Google cache, grep for 'Now Really Public') from the Internetwork Interoperability Test Coordination Committee, about the state of security in the public switched (telephone) network: wide open and "very fragile with a tremendous number of vulnerabilities". Apparently, there's $12b in fraud per year, growing interest from blackhat groups, and more, better, intruder tools. We often hear talk of "information warfare attacks that could result in the draining of bank reserves and the cutting off of power sources" from budget-and-PR hungry, but clue-light, politicians and wonks these days. When an experienced engineer uses such language, it's more worrying." We've also had submissions of this AP article speculating about viruses hitting mobile phones. -
C&W De-Peers PSInet
-
Slashback: Apple, Lawyers, Backbones
More below on improving OS X security, AOL GPL SNAFUs, Mandrake's reputed layoffs (short answer: No.), Big Daddy's control over gaming in Connecticut, and more. All below in tonight's episode of Slashback.We are from France! And we're doing fine ... PovRayMan writes "Mandrakesoft has denied rumors of it's recent layoffs and management change due to "financial liquidity." The article mentions how the former CEO, Henri Poole, agreed on the management change. The article even goes out to say that their "prospects never looked so good" with the recent release of Mandrake 8. Either way, I'm downloading Mandrake 8 iso's right now and look forward to playing with it."
Like Alar for the other kind of apple. Lots of people were interested in the possible security flaws in OS X; thanks to Alex Salkever of BusinessWeek, we have word from Apple SE Manager Jeff Gagne, who writes: "We have just posted a Mac OS security web page for people looking for information concerning security updates, security notifications, etc. involving Mac OS X. Please visit the following url for more information: http://www.apple.com/support/security/security.html."
Follow the bouncing lawyers, with a mallet and a browser. Mike Haisley of AOL watchdog Observers.net writes with an update to yesterday's AOL And The GPL story: "It seems that America Online has their legal team working overtime on this one, site was pulled, and back up, and we were just given notice that it's going down again." Here is the Emergency Mirror.
Go forth and legislate no more. mikey573, pointing to a Hartford Courant Article, writes: "It's nice to see that Connecticut governor John Rowland is protecting gamers' rights by vetoing a bill that would have limited access to arcade point-and-shoot games: "Asserting that government should not act as 'Big Daddy,' Gov. John G. Rowland said Thursday that he will veto a bill barring children under 18 from playing 'point-and-shoot' video games in public places." I'm going to play Duck Hunt now in celebration! My only concern is the Connecticut legislature got as far as passing the bill in the first place." Well said.
Erratus, errata, erratum. Jamie would like to make several corrections to Monday's story about Macromedia being blackholed:
(1) I really shouldn't have singled out Above.net in the headline. They're just one backbone that uses the MAPS RBL to block non-mail traffic from their subscribers. In fact, Teleglobe.net was the backbone that blocked web access from one of our submittors.
And (B), Paul Vixie, the co-founder of MAPS, is no longer the CTO of Above.net.
-
The Author of Ping is Reported Dead
Wedman writes: "This is in the Nanog Archive, dated 2000-11-21: 'Mike Muuss, the author of the PING program used on networks everywhere, died last night in a traffic accident on US route 95 in Maryland. He was an alumnus of Johns Hopkins." Seems appropriate on Thanksgiving to thank a man who created something that we all rely on every day.