SDF Punted, Due to DDOS
bullshizzle writes "The longest running Public Access UNIX System (SDF, running BSD) est. 1989 had their services terminated abruptly by NWLink because of a DDoS attack. Termination was carried out immediately without prior notification, which violates their contract (page1, page2). Complaints can be filed to the Washington State Attorney General's Office by filling out this simple form conveniently located online. You can follow the story at lonestar.org." While still bad, I've been corrected - SDF was *not* the longest running public access Unix - ArborNet (Located right here in my town) has been around for at least a number more years.
This wasn't a case of the attackers being hosted by SDF. They were attacked from the outside by some third party, and their provider unplugged them as a result.
This is similar to: if I wanted to shut down a local unpopular political organization's bookstore, so I picketed and made noise and made things unpleasant out in front of the bookstore, and the result was that the bookstore's lease was revoked by the owner of the building.
Now, due to a couple of kiddies that wanted to prove their `skills', SDF has to go offline, leaving thousands of users unable to access their email and contact friends, and several more thousands unable to access Web and Gopher resources hosted on SDF... giving commercial providers like AOL just one more argument in their favour. They can afford lawyers to take care of shit like this... we can only depend on community leverage. I hope it will be plentyful. Damn. I wanna play netris on sdf....
As long as its in the best interests of the bandwidth providers (who get mega cash for all these GBs) this kind of crap will never stop.
And guess what, its EASY to stop! Simply require the netork borders to perform filtering on packets crossing the border. If your cable modem is spewing out packets addressed from China, and you're in Florida, SOMETHING IS WRONG. These packets should have never gotten into the internet in the first place.
Suddenly, when spoofing is no longer possible, DoS doesn't seem like such a great idea. Even with botnets and crap for DDoS usage, if you can be tracked back from a single trojaned box, you'd have to be stupid to try.
If I have been able to see further than others, it is because I bought a pair of binoculars.
PEOPLE .. Please stop threatening NWLINK. Yes, they could have handled this situation better, but the point is they didn't and that isn't going to change. We need to look toward the future now. If any host can be shutdown like this, then no hosts are safe. I think the thread here should go to POSITIVE WAYS to do successful tracebacks so that DDoSing will stop for everyone. I don't want to see SDF become the scapegoat for this, it really doesn't solve anything for the long term. I've talked with the CEO of NWLINK and he is a nice guy, but he has his hands full as it is. Lets not look back and think of the future.
Stephen Jones
Caretaker
SDF Public Access UNIX System