Posted by
CmdrTaco
on from the no-surprise-there dept.
quakeslut writes "It's Feb. 1st everyone... and all of you who have been reading Slashdot know that today MyDoom.A begins it's attack... according to Reuters, SCO has already been hit hard. Stay tuned for Tuesday when MyDoom.B hits Microsoft..."
Re:Why today...
by
Pharmboy
·
· Score: 5, Interesting
Sunday isn't even a business day? How much money will they not lose?
There is one basic flaw in your assumption. Granted, for many businesses, this would hold true, but not SCO. Being attacked on Sunday is just as detrimental as being attacked on Wednesday, as it appears they make just as much money when no one is there as they do when the place is fully staffed: nothing.
I am sure they will spin this around and demonstrate how this hurt them terribly, costing them tens, if not hundreds of dollars in potential sales;) Then again, they will blame the Linux community for this, even though its soley from a bunch of owned Windows boxes. This is akin to blaming Smith and Wesson for injuries to the neighbors when you fire your gun in random directions.
-- Tequila: It's not just for breakfast anymore!
Re:Why today...
by
87C751
·
· Score: 5, Insightful
This is akin to blaming Smith and Wesson for injuries to the neighbors when you fire your gun in random directions.
Nit: It's more akin to blaming Smith & Wesson when mayhem results from you firing your Glock in random directions.
-- Mail? Put "slashdot" in the subject to pass the spam filters.
Re:Why today...
by
SpaceLifeForm
·
· Score: 4, Informative
SCO obviously does not care about being forewarned,
and wants to milk this for all they can.
From the article:
"While we expect this attack to continue throughout the next few weeks, we have a series of contingency plans to deal with this problem and we will begin communicating those plans on Monday morning," Jeff Carlon, worldwide director of Information Technology infrastructure, The SCO Group, said in the statement.
NOTE TO SCO: You don't have to communicate any
series of contingency plans to anyone except
your own IT staff (if you have any left).
Any press releases from SCO will be
obvious FUD and will not mean a damn thing.
-- You are being MICROattacked, from various angles, in a SOFT manner.
Re:Why today...
by
pherris
·
· Score: 4, Interesting
Speaking of FUD... Is there a way to tell if it's actually DoS'd, or if they shut it down themselves??
www.sco.com has been pulled from their dns records. Their whois info shows four dns servers: ns.calderasystems.com, ns2.calderasystems.com, c7ns1.center7.com and nsca.sco.com. IFAIK ns.sco.com, ns1.sco.com and ns2.sco.com use to be their DNSs of record. I ran a quick check of www.sco.com on all seven servers and found it had been removed. Since their is no ip number for that name sco never sees the http request.
I personally would've changed it to lo (127.0.0.1) so at least other dns servers would cache the first request (and serve out copies without checking) thus taking avoiding a lot of those hits to their dns servers everytime MYDOOM makes it's request. Even with their current setup they should avoid most of the force of MYDOOM (unless it attacks a range of active names and/or numbers).
The better solution if they want to keep their web server alive is to channel all requests to another web server with a thin pipe (say a T1) right off a backbone that reads the http client header, discards the MYDOOM requests (also with some real ones) and forwards everyone else to their real http server (say www2.sco.com). This could greatly minimize MYDOOM's damage, changing the a hurricane into a rain shower.
On the other hand doing it their way allows them to more easily cry "poor [sco]", claim this attack completely shut them down, have a record of exactly how many attacks they're getting and claim they lost business (like they had any anyways). This whole attack has "script kiddie" written all over it. If the author lives in the US there's a fair chance they'll catch him, and then he's SOL. In my opinion MYDOOM discredits the gnu/linux community. sco sucks but this isn't the way. An opinion shared by most in our community.
-- "And a voice was screaming: 'Holy Jesus! What are these goddamn animals?'" - HST
Re:Why today...
by
Reziac
·
· Score: 4, Interesting
Thanks for the info, saved in my evergrowing "SCOpera" files:)
I looked at MyDoom's innards, and it struck me as odd, not typical script-kiddie material at all. I got the sense it was the work of someone whose programming work had *not* previously included this sort of thing. So I'm inclined to agree with the speculation that it's primarily a spammer's zombie-generating tool, built by contract with some starving professional coder, and that the SCO and M$ DoS components are red herrings.
As you say, SC0-baiting is great fun, but illegal attacks do nothing for the case against them (tho they seem to be using it to further their own case *against* themselves, judging by the "time travel" element that Groklaw pointed out) and just make us look bad. SCO is perfectly capable of cutting their own throats without "help".
-- ~REZ~
#43301. Who'd fake being me anyway?
How stupid do you have to be?
by
Matrix9180
·
· Score: 5, Interesting
SCO had plenty of time to prepare for this. They were well aware it was coming. I personally believe it's a publicity stunt. (which probably wouldn't surprise anybody around here).
-- 120chars for a sig is teh suck
Re:How stupid do you have to be?
by
ardiri
·
· Score: 4, Insightful
> SCO had plenty of time to prepare for this
makes you wonder if they had anything to do with the virus itself? if someone was going to make a blatent attempt at SCO - why not make it a surprise. publicity stunt it may be, all being run on feb 1 (sunday, non business day) - its obviously worked. news all over the world has picked this up.
Re:How stupid do you have to be?
by
SkArcher
·
· Score: 4, Interesting
Analysis shows that all other sites on that router ring are working properly, that the net is no slower than usual and that You can still download SCO Linux from their site.
SCO Linux includes all the SCO disputed IP under the GPL, so download it now and burn to CD - keep it on a shelf and if anyone tries to claim money show that SCO have given you a license to use the code under the GPL.
--
An infinite number of monkeys will eventually come up with the complete works of/.
Re:How stupid do you have to be?
by
mindriot
·
· Score: 4, Interesting
It might well be a publicity stunt; but it's not like they're completely unprepared, at least according to netcraft:
We had expected that SCO might take www.sco.com out of the DNS in the run up to the MyDoom DDoS payload in order to keep the denial of service http traffic off the Internet. So far, though, www.sco.com still resolves and receives http requests, though closing the connection without sending a response.
That said, the sco.com hostmaster is reserving his options, with the TTL set to just 60 seconds at time of writing.
Re:How stupid do you have to be?
by
SkArcher
·
· Score: 4, Informative
An infinite number of monkeys will eventually come up with the complete works of/.
Well actually...
by
Chicane-UK
·
· Score: 5, Informative
If you query their DNS servers, you'll see that they have removed the A records to their site.
So the traffic just won't get to them anyway..
-- "Hey! Unless this is a nude love-in, get the hell off my property!!"
Re:Well actually...
by
anticypher
·
· Score: 5, Informative
Not yet. I just checked all 4 of their name servers:
AUTHORITY SECTION: sco.com. 6H IN NS ns.calderasystems.com. sco.com. 6H IN NS ns2.calderasystems.com. sco.com. 6H IN NS nsca.sco.com. sco.com. 6H IN NS c7ns1.center7.com.
and all of them return www.sco.com. 1M IN A 216.250.128.12
So their name servers are still up and running, and pointing to a valid address. Reasonably, they have a 1 minute TTL, which will give them a quick response if they do decide to point it at 127.0.0.1 or 66.35.250.150.
the AC
the slashdot crud filter doesn't like double semi-colons in posts
-- Hemos is like...sci-fi fans;he thinks technology is cool, but he hasn't bothered to understand the science it's based on
The DoS attack will start at 16:09:18 UTC (08:09:18 PST) on February 1, 2004. The worm checks the local system time and date to determine if it should initiate the DoS attack
I'm typing this and the time is currently 14:30UTC.
For those who are interested, it does appear to work in wine, before the news of it reached slashdot, I ran a copy of it in controlled conditions under Wine to see what it would do. It appears to be mainly a spam relay with SCO DOS'ing added as an afterthought.
I wish it wouldn't happen. This virus is painting the Linux community as a bunch of petulant adolescents - regardless of who's doing it.
I'm trying to remember who in the Linux community was quoted in the Wall Street Journal as saying "Let's take the high road." We should do just that. We all know that SCO doesn't have a leg to stand on. Let's let them sink themsleves.
What I want to know is how many people infected their computers on purpose and how man just didin't remove the virus after they found it? Most prople won't do a criminal act will but ignoring somebody elses?
-- "A good friend will bail you out of jail. A true friend will be sitting next to you saying, 'damn....that was fun!'"
Course it's not funny they will just say "The terrorist group "Linux Community" has claimed responsibility for the attacks" and declare us part of the axis of weasel like they did the other day on CNN.
Helps SCO and Microsoft
by
Mysteray
·
· Score: 4, Insightful
Does anyone believe that this will do anything except help SCO? It associates their enemies (IBM, Linux), with worm/virus creators and spammers. If this sort of thing keeps up, the US Legislative and Executive branches will actively take the side of SCO and MS against Linux and it's "hackers".
What do they need a website for anyway? Their only business is lawsuits and press releases.
Re:Helps SCO and Microsoft
by
dreamchaser
·
· Score: 4, Insightful
YOU might not assume those things, but Joe Public will. It's all about perception. And if they catch the perp and he DOES turn out to be a linux zealot, it will taint the whole community.
Just because YOU have some sense and intelligence doesn't mean the press or the public does.
Netcraft stats
by
mnordstr
·
· Score: 4, Informative
Funny, when I go to SCO's site...
by
Glock27
·
· Score: 4, Funny
all I get is "Document contains no data".
Just like the IBM lawsuit...;-)
I don't advocate virus attacks to further the OSS community's aims...all Linux software authors and organizations ought to be suing SCO instead. That kind of attack will cost them real money and time, and won't generate any sympathy from anyone (who's sane anyhow).
-- Galileo: "The Earth revolves around the Sun!"
Score: -1 100% Flamebait
Re:What's the difference?
by
sbennett
·
· Score: 5, Funny
What's the difference between writing a virus that targets sco.com and posting a link to sco.com in a slashdot story?
Who needs a web site when you have earned a Distributed Lack of Purchasing attack?
--
Friends don't help friends install M$ junk.
M$ might not be hit so hard..
by
Anonymous Coward
·
· Score: 4, Interesting
According to heise.de(in English) MyDoom.B is not nearly as widespread as the A-version. According to the article the A-version just had a good start, because it was distributed through an IRC-Botnet. So we will probably not see microsoft.com going down.
How did this virus spread so easily?
by
galaga79
·
· Score: 4, Interesting
What I don't get is how this virus spread so far, considering how hard it must to be get infected by it. You'd have to go out of your way to get infected since the spreads its self as zip compressed attachment.
I can understand how past viri have spread so quickly taking advantages of exploits in Outlook and Windows RPC etc, but this doesn't seem to use any exploits what so ever.
Is it just a lot of stupid users or I am missing something?
Re:How did this virus spread so easily?
by
unborn
·
· Score: 4, Insightful
An infection where the user knowledgeably accepts a substance ( even if considered harmless at the moment of acceptance ) should be called "a poison", not "a virus".
If you are given a drink that will kill you, but you drink it without knowing - that's a poison. If someone sneezes a few feets away and an airplane passes by you at the same exact moment of the other person sneezing and you can't hear the sneeze, and you get infected - then it's a virus.
Hence, opening an executable is subjecting yourself to the possibility of poisoning. Reading your email while a flaw is exploited in your email client is a virus.
Re:How did this virus spread so easily?
by
Lumpy
·
· Score: 4, Informative
a lot of stupid users? yes and no. For the past 4 versions of Windows Microsoft has refused to remove a huge security hole called file extension hiding. They knew it was a gigantic hole when they added it, and many MANY times industry experts have pleaded to them to remove it. Microsoft refuses.
Microsoft did not spread the virus but they created the tools to ensure it's spread by the non-technical.
and people ask about the "cost" of linux, how about the extreme cost of continuing to use Microsoft products...
-- Do not look at laser with remaining good eye.
Re:How did this virus spread so easily?
by
gdav
·
· Score: 5, Funny
The users that I support would double-click on a landmine to see what it did.
Re:How did this virus spread so easily?
by
glesga_kiss
·
· Score: 5, Insightful
For the past 4 versions of Windows Microsoft has refused to remove a huge security hole called file extension hiding.
Bollocks. The people commonly infected with viruses wouldn't even know what a file extension was, let alone the difference between an exe and a txt file.
"The one with the W is a word file, the portrait is a graphic file etc". Give a file "virus.exe" the same icon graphic as a word file, and most users wouldn't know the difference.
On the other hand, if you don't hide the extension, then each of us here would be constantly dealing with dumb users who have renamed "Document1.doc" to "Report" (no extension). For 99% of users, hiding extensions is a good idea.
Re:How did this virus spread so easily?
by
Phil+Wherry
·
· Score: 4, Interesting
What I find particularly fascinating about all of this is the fact that this is being treated primarily as a user education issue. While it's true that a savvy user can dodge this attack completely by simply not opening the attachment in question, one might still rightly ask, "Why is it that users have to be security-savvy in order to effectively use their computers?" Many of the security problems that we see are, in fact, caused by architectural flaws.
The lack of distinction between executable files and data is the first problem. Windows differentiates between data files and programs through file naming convention; the mere construction of a filename is sufficient to get the operating system to attempt to run it if the user should happen to click on it within the GUI.
Other operating systems don't do this. Unix systems have an attribute separate from the filename that indicates that the file is executable code. This attribute (a permission bit, actually) must be set in order for the code to execute in response to a click from within the GUI (or, for that matter, in response to actions in the command-line interface). Had this worm been effective on a Unix system, it would have required that the user save the attachment as a file, modify the executable permissions for the file, then invoke the application. Most other non-Unix systems with which I've worked are similar; you have to either explicitly communicate to the operating system "run this file as a program" or somehow bless the file in order to turn it into an application.
Once the application is running, we discover the next major architectural flaw: it's possible for most users of Windows to modify the behavior of the operating system itself without realizing it. Most modern operating systems require a user to be in some sort of a privileged mode in order to install applications or otherwise change the behavior of the system. The "su" command (or, better yet, the "sudo" command) in Unix allows one to assume "superuser" privileges for this purpose. In Windows, you have to be logged in as a user with administrative rights to the computer, but there's no simple way to assume and release privileges for the purpose of installing an application. So most users (outside the most restrictive of corporate environments) use their Windows environments from a login with full administrative privileges. This is the equivalent of running one's Unix environment while logged in as "root," a practice regarded as reckless and incompetent. Unfortunately, it's very hard to get work done in Windows any other way.
As a result, malware like the MyDoom worm can take advantage of these administrative privileges in order to make itself harder to remove. It's quite common for such applications to add themselves to the list of things that run when the computer is started up. One variant of the MyDoom worm even goes so far as to damage a network configuration file in order to make it difficult for antivirus software to download updated signature files. These attacks work only because the worm is easily able to gain administrative rights to the computer. There's certainly plenty of mischief that can be perpetrated as an ordinary user, but it's quite a bit easier to prevent when the OS is off-limits. And, when bad things do happen, it's vastly easier to clean up the damage when the integrity of the operating system itself isn't in question.
So, the next time you hear the claim that a security problem is caused by a user acting stupid, consider this: is it really the case that the user is stupid, or is the real stupidity the set of architectural decisions that enable the user to make mistakes?
DDoS attack time table + analysis of DoS in Mydoom
by
Anonymous Coward
·
· Score: 5, Informative
There was a story posted "Refuting tall-tales and stories about the Mydoom worms" which can be found at: http://www.math.org.il/mydoom-facts.txt
It contains the Time Table for the attack along with reverse engineering analysis of the DoS component in Mydoom.
You might also want to check: http://www.math.org.il/newworm-digest1.txt
Which contains an analysis and reverse engineering bits for Mydoom.A>
Re:Finally!
by
Anonymous Coward
·
· Score: 5, Insightful
This virus is painting the Linux community as a bunch of petulant adolescents - regardless of who's doing it.
No, it's not. The media (and SCO, et al for obvious reasons) is painting the F/OSS community as adolescents
What I want to know is how many people infected their computers on purpose and how man just didin't remove the virus after they found it? Most prople won't do a criminal act will but ignoring somebody elses?
Actually, as a private computer techie, I've been removing MyDoom from my client's computers for the past couple of days. It really is amazing how fast it's spread...
As a Linux geek I must admit to a small snicker at SCO's misfortune here, but it is definately not the right way to go about solving the SCO problem. All publicity is *NOT* good publicity, and the last thing we need is the world to think "Linux == Geeks spreading virii". I've been taking pains to point out the spam connection with the MyDoom virus, and I think that's the angle we should persue here. I can only hope that the next looser who DOSes SCO gives us as easy an "its not us" angle.
-- "Mission Accomplished" -- George W. Bush May 1, 2003
What they didn't include in the article
by
marsu_k
·
· Score: 5, Insightful
Curiously, this article seems to imply that there was a political agenda behind DDoSing SCO - but to quote Mikko Hypponen of F-secure a bit more:
"It's also possible the attack against SCO is just a smokescreen to misdirect attention away from the backdoor component in the virus - which is most likely included in order to facilitate sending of spam email messages."
Similiar, albeit longer, quote from him asserting that indeed spammers were behind this worm was in the local newspaper on Friday, but it's in Finnish and I'm too lazy to translate it. But the above quote can be found here.
"I wish it wouldn't happen. This virus is painting the Linux community as a bunch of petulant adolescents"
In case anyone still thinks this virus is related to linux people, let's put it as bluntly as we can:
Spammers have created yet another virus to send their emails, not caring about the cost to you, your computer, the law, or the internet in general
If you believed the spammer lies about how you've opted in to something, or how this is their freedom of speech, or how you can just press delete, then this should be the evidence you need: spammers are prepared to take down the entire internet for their own personal gain.
If anybody has bought anything advertised by email, or is considering doing so, or knows anybody who buys from email advertisements, then please be aware: you are supporting the criminals who are deliberately and maliciously attacking your computer, and the computers of your friends. Their programs are constantly bombarding your computer, where any mistake you make could lead to your computer becoming unusable by you, and being used to send illegal emails in vast quantities to the computers of others.
If any newspaper editor is reading this, and thinks "it's attacking SCO, it must be programmed by a Linux advocate", wake up and smell the misdirection. The DDOS in this virus was added as an afterthought. "Virus creation wizard step 6: you are nearly finished creating your virus. now type the name of a website you want it to attack"
Yes, it's a classic trick, and it's worked for thousands of years. I'ts worked for politicians and armies. It's worked for the con-artist and the cult leader. What is this trick? Miss-direction. If you think that this virus has anything at all to do with the open source community or SCO then your not keeping your eye on the ball sparky!
1. This virus makes a machine an open relay. Considering recent legislation and other anti-spam techniques I smell spammer bovine feces here.
3. The open source community is coming up with various anti-spam measures. Don't you think the spammers would love painting their enemy as petulant child - as they have proven themselves to be?
MyDOOM isn't the open source community pissing on on SCO, it's spammers pissing on all of us.
-- "Science is about ego as much as it is about discovery and truth " - I said it, so sue me.
SCO website just a symbol...
by
bangular
·
· Score: 5, Insightful
Realistically, who the hell even goes to the SCO website. They've got so few new potential customers anyway (I would put the number at zero). Current UnixWare users doubtfully visit their website very much anyway.
Their website being down is more of a symbol. A symbol to them of "Look at what they are doing to us". It's obviously not very important to them anyway seeing as how in the past they've taken it down for hours to days at a time for "server upgrades". If it were that critical to them, they wouldn't have had downtime. But it was cheaper to take it down and do what they needed to do to spend the money to keep it up during upgrades.
Anyway, SCO can eat apple sauce out of my ass with a spoon.
I think a lot of folks have mixed feelings on this on.
-- "It is a greater offense to steal men's labor, than their clothes"
Re:Is it Down or is it 'down'?
by
Megane
·
· Score: 4, Informative
(thanks for the tip of trying linuxupdate.sco.com)
traceroute to www.sco.com (216.250.128.12), 30 hops max, 40 byte packets
. ..
4 bb1-p5-2.rcsntx.sbcglobal.net (151.164.243.13) 20.902 ms 22.986 ms 20.92 ms
5 bb2-p6-0.rcsntx.swbell.net (151.164.191.122) 20.957 ms 20.977 ms 20.878 ms
6 ex1-p11-0.eqdltx.sbcglobal.net (151.164.191.229) 24.012 ms 22.046 ms 20.96 ms
7 asn2828-xo-eqdltx.sbcglobal.net (151.164.248.14) 23.907 ms 23.2 ms 23.912 ms
8 p5-2-0-3.rar1.dallas-tx.us.xo.net (65.106.4.197) 23.96 ms 22.868 ms 23.999 ms
9 p0-0-0-1.rar2.dallas-tx.us.xo.net (65.106.1.42) 24.063 ms 22.648 ms 23.905 ms
10 p1-0-0.rar2.denver-co.us.xo.net (65.106.0.41) 38.954 ms 37.252 ms 47.928 ms
11 p0-0-0-2.rar1.denver-co.us.xo.net (65.106.1.81) 38.88 ms 37.841 ms 38.944 ms
12 p4-0-0.mar1.saltlake-ut.us.xo.net (65.106.6.74) 50.949 ms 49.296 ms 50.948 ms
13 p0-0.chr1.saltlake-ut.us.xo.net (207.88.83.42) 50.886 ms 49.851 ms 50.774 ms
14 205.158.14.114.ptr.us.xo.net (205.158.14.114) 53.912 ms 52.526 ms 51.004 ms
15 * * *
traceroute to linuxupdate.sco.com (216.250.128.241), 30 hops max, 40 byte packets
. ..
4 bb1-p5-2.rcsntx.sbcglobal.net (151.164.243.13) 20.947 ms 20.046 ms 20.905 ms
5 bb2-p6-0.rcsntx.swbell.net (151.164.191.122) 20.919 ms 29.145 ms 20.855 ms
6 ex1-p11-0.eqdltx.sbcglobal.net (151.164.191.229) 20.951 ms 22.991 ms 23.963 ms
7 asn2828-xo-eqdltx.sbcglobal.net (151.164.248.14) 23.945 ms 22.989 ms 23.894 ms
8 p5-1-0-3.rar1.dallas-tx.us.xo.net (65.106.4.193) 23.955 ms 25.426 ms 24.013 ms
9 p0-0-0-1.rar2.dallas-tx.us.xo.net (65.106.1.42) 26.979 ms 62.002 ms 27.099 ms
10 p1-0-0.rar2.denver-co.us.xo.net (65.106.0.41) 38.821 ms 37.981 ms 38.89 ms
11 p0-0-0-2.rar1.denver-co.us.xo.net (65.106.1.81) 38.789 ms 38.094 ms 38.888 ms
12 p4-0-0.mar1.saltlake-ut.us.xo.net (65.106.6.74) 51.054 ms 50.024 ms 50.811 ms
13 p0-0.chr1.saltlake-ut.us.xo.net (207.88.83.42) 51.001 ms 49.886 ms 50.934 ms
14 205.158.14.114.ptr.us.xo.net (205.158.14.114) 53.903 ms 53.136 ms 53.841 ms
15 c7pub-216-250-136-254.center7.com (216.250.136.254) 50.937 ms 51.759 ms 50.787 ms
16 linuxupdate.sco.com (216.250.128.241) 51.004 ms 52.438 ms 50.988 ms
traceroute to ftp.calderasystems.com (216.250.128.13), 30 hops max, 40 byte packets
. ..
4 bb1-p5-2.rcsntx.sbcglobal.net (151.164.243.13) 20.892 ms 20.06 ms 23.887 ms
5 bb2-p6-0.rcsntx.swbell.net (151.164.191.122) 21.051 ms 19.935 ms 21.034 ms
6 ex1-p11-0.eqdltx.sbcglobal.net (151.164.191.229) 23.82 ms 23.095 ms 23.868 ms
7 asn2828-xo-eqdltx.sbcglobal.net (151.164.248.14) 23.987 ms 23.063 ms 20.829 ms
8 p5-2-0-3.rar1.dallas-tx.us.xo.net (65.106.4.197) 23.989 ms 22.84 ms 23.934 ms
9 p0-0-0-1.rar2.dallas-tx.us.xo.net (65.106.1.42) 24.086 ms 25.935 ms 23.877 ms
10 p1-0-0.rar2.denver-co.us.xo.net (65.106.0.41) 38.916 ms 38.112 ms 38.925 ms
11 p0-0-0-2.rar1.denver-co.us.xo.net (65.106.1.81) 38.603 ms 38.096 ms 38.94 ms
12 p4-0-0.mar1.saltlake-ut.us.xo.net (65.106.6.74) 50.947 ms 49.871 ms 50.914 ms
13 p0-0.chr1.saltlake-ut.us.xo.net (207.88.83.42) 50.944 ms 49.782 ms 51.008 ms
14 205.158.14.114.ptr.us.xo.net (205.158.14.114) 50.836 ms 53.072 ms 53.935 ms
15 * * *
So either they're being merely slashdotted or they "accidentally on purpose" kicked www.sco.com's router power plug out of the wall. According to ARIN, they're all on the same/20 network, so they're probably not on a different final link from XO. They're certainly not being DoS'ed for bandwidth.
Telling people not to voice their opionions because of fear of what other people might think of you is an asinine way to excersice your right to free speech.
Yes, free speech is something we believe in at slashdot as well. We can and should make jokes. Why? Because we always make jokes about things! I would make a joke right now, but (1) I'm not that funny, and (2) I'm just too shocked that I am being told in a +5 comment not to say something.
Let the media report what they will. The fact is, some part of the community that you posted to can find humour in this. We are for sure a community that finds humour in everything.
Actually, now that I read your comment again, I am not sure you are serious. Perhaps it was just a joke and our mods have modded you insightfull?
I WANT TO "SWITCH" BACK!
by
andrewleung
·
· Score: 4, Funny
i want to be part of DDOS attack!
dammit! why are mac users always left out of the fun?! >_
The virus is spread by UNIX
by
Anonymous Coward
·
· Score: 4, Interesting
Some guy on winnetmag obviously thinks they should be offline, they must have brought it upon themselves, as he seems to think the virus is the fault of UNIX. he says that "A new email virus called MyDoom is spreading rapidly across the Internet through UNIX mail servers, bringing with it a dangerous attachment that, when opened, can give attackers access to users' computers through an electronic backdoor."
Unfortunately, this is really the media's fault. There were several high profile articles that quoted posts modded +5, Funny on Slashdot's original article about MyDoom and cited them as the voice of the Open Source community, taking glee at this new virus. It was essentially cited as evidence that the "nefarious" Open Source community was somehow behind this virus or honestly approved of it. Basically these people don't understand how Slashdot works, that we find humor in even the most macabre topics, and that one person's comment doesn't mean anything more than that one random person thought something. As another poster said, it's like quoting a guy in a bar in LA and saying "people in LA think this...".
Anyway, I know and you know how to spot a troll/humorous post/etc. on Slashdot. And we know that people's opinions go all over the map on many issues discussed on Slashdot. Joe Reporter doesn't get this and there is a real risk of them printing more smear-stories about a community that like-it-or-not you will be perceived as part of by virtue of posting here. It's reasonable for us to try not to make that community look bad - not saying not to speak your mind, but to keep in mind that in a high profile story like this, even though you may be Joe Nobody, your words could be used against you and lots of other people.
Re:MS Business Model
by
victorvodka
·
· Score: 4, Funny
well, a DDOS attack on MSN wouldn't look so good. all those subscribers in redneckistan with suddenly no homepage to click on. "Ethel Sue! The Inter-o-net ain't workin'" "Billy John, I done told you we should have went and got ourselves that there newfangled Verimazon Dee Ass El!"
--
The flag just makes more sense than the constitution. - Judas Gutenberg
Re:Slashdotted Reuters?
by
hankaholic
·
· Score: 4, Informative
Did you read the paragraph preceding the one you cite from the article? It reflects my own initial thoughts on reading your post, and doesn't attempt to blame the OS for what really is a network problem:
If ISPs would begin adopting the practice of preventing the escape of fraudulently addressed packets from within their controlled networks, this potent attack, and its many cousins, would die overnight.
This seems much wiser a suggestion than the anti-MS paragraph which you chose to cite. Who better to set actual network policy than those responsible for managing those networks?
Microsoft including a raw socket API is about as evil as Microsoft supporting the creation of outgoing connections to any arbitrary mail servers -- sure, it's open to abuse (DDoS, spam, etc.), but removing the sort of API that traceroute and ping tools would use to perform useful work is not a security fix. It closer to asking Home Depot not to sell hammers because they can be used as weapons.
Further, having MS remove the raw socket API would lead those with cruel intentions to use non-Windows machines exclusively to do their evil deeds. Consider that the mind which concludes that the raw socket API must be removed because of the unpleasant actions of a few people probably isn't far from thinking that operating systems which are engineered in an open and flexible environment can be used for subversion as well. Suddenly those using "subversive" non-MS operating systems which haven't removed raw packet interfaces are a little more suspect in the public eye.
If ISPs would only permit traffic with sane source IP addresses to leave their networks, then the only effect sending such packets out would have would be to waste traffic between the would-be tricksters and their ISP's router(s).
-- Somebody get that guy an ambulance!
www A 127.0.0.1
by
Stephen+Samuel
·
· Score: 4, Insightful
Given that they knew this was coming, and knew that they didn't have the bandwidth/CPU to handle the masssive overload, why didn't SCO Just set the A record for their website to 127.0.0.1 for a couple of days?? Either that or 192.168.42.42... With the former, a virus infected machine would simply attack itself. With the later, it would try to contact a well known address which would allow sysadmins to find any infected machine (and remove the virus) by simply looking for references to the address.
-- Free Software: Like love, it grows best when given away.
I Feel Bad For Him...
by
Greyfox
·
· Score: 4, Funny
I think we should all send him a present! For example, these guys will ship a big ol' batch of live crickets. For $58, we could ship ol' Darl 5000 crickets and I know that would cheer him up!
--
I'm trying to teach myself to set people on fire with my mind... Is it hot in here?
Re:Lawyer think...
by
LinuxGeek
·
· Score: 4, Informative
Correction to make on my previous post. I had already done a dig and nslookup, but on sco.com and not www.sco.com.
[root]# host www.sco.com Host www.sco.com not found: 3(NXDOMAIN)
SCO has updated their dns servers and axed the record for www.sco.com. NXDOMAIN means no such domain. Wonder why SCO didn't announce that they themselves took www.sco.com completely offline.
Hopefully the media will know about this when SCO complains about the DDOS attack. Now I know why the rest of their services are fairly intact and responding.
--
Kindness is the language which the deaf can hear and the blind can see. - Mark Twain
But wait!!! I can prove it's not the virus.
by
dtfinch
·
· Score: 5, Informative
www.sco.com no longer resolves. They removed it from their name server yesterday. Only sco.com without the www resolves to an ip address. The attack should be almost completely averted by now because of this, but sco.com is still down.
The only possible cause I see for them to still be offline is if they took it offline themselves, or there's been another attack that they've failed to mention to the press, but it's unlikely that they'd turn down any opportunity to slam us if that were the case. Check it yourselves. The worm specifically attacks the domain www.sco.com, which no longer exists, and the dns entry expired yesterday. All that worm traffic should be going to oblivion by now, because Windows doesn't reuse expired dns records when requery attempts fail.
Re:Lawyer think...
by
LinuxGeek
·
· Score: 4, Insightful
My point is that sevaeral SCO folks ( and Darl specifically) are blaming the actual traffic flood, even todays PR release.
LINDON, Utah, Feb. 1/PRNewswire-FirstCall/ -- The SCO Group, Inc. (Nasdaq: SCOX), the owner of the UNIX(R) operating system and a leading provider of UNIX-based solutions, has confirmed that a large scale, Denial of Service attack has started that has made the company's Web site, www.sco.com, completely unavailable. Internet traffic began building momentum on Saturday evening and by midnight Eastern Time the SCO Web site was flooded with requests beyond its capacity. The company expects these attacks to continue through Feb. 12.
SCO has made their website completely unavailable by removing the www.sco.com name record, not a flood of packets. They have mentioned nothing about packet filtering at the router level or any alternative method of keeping their main site online. When the attacks start flooding Microsoft, do you think they will just take their main site down or look at a solution that keeps them up?
I'm only pointing out that SCO is not being honest about the reason for their web sites complete unavailablity. They could still be online with several alternative options that they aren't exploring and want to act like they have no choice in the matter. It looks like they are taking the 'poor me' attitude when things could have been made much better with a little effort.
Maybe their site isn't as important to the operation of their new business model. It may be an even bigger asset to them as a publicity tool while it is down ( due to their lack of name record). When I see them admit that they took it down themselves, then they will have a bit more credibility. With no name record, thus no actual attack on their site, they can't know when the attack would have ended or how severe the flood would have been. They can't really track the attack via DNS lookup operations because that can't give an accurate picture of the potential flood, only the number of participating machines.
They've removed the means to gather statistics about the attack and devise means to counter a defense. The opposite of what I would expect of Microsoft, IBM, Symantec, RedHat, Slashdot or thousands of other sites on the internet.
--
Kindness is the language which the deaf can hear and the blind can see. - Mark Twain
and just to be sure they get DoS'ed, you post a link to their website on slashdot.
Sunday isn't even a business day? How much money will they not lose?
Jonathanjk.com
SCO had plenty of time to prepare for this. They were well aware it was coming. I personally believe it's a publicity stunt. (which probably wouldn't surprise anybody around here).
120chars for a sig is teh suck
If you query their DNS servers, you'll see that they have removed the A records to their site.
So the traffic just won't get to them anyway..
"Hey! Unless this is a nude love-in, get the hell off my property!!"
Until Saturday when MyDoom.S hits Slashdot..
This is not helping. Why would you even want to do this??
Please stop as you're injuring the community you're trying to help.
GJC
Gregory Casamento
## Chief Maintainer for GNUstep
From this page:
The DoS attack will start at 16:09:18 UTC (08:09:18 PST) on February 1, 2004. The worm checks the local system time and date to determine if it should initiate the DoS attack
I'm typing this and the time is currently 14:30UTC.
For those who are interested, it does appear to work in wine, before the news of it reached slashdot, I ran a copy of it in controlled conditions under Wine to see what it would do. It appears to be mainly a spam relay with SCO DOS'ing added as an afterthought.
I'm trying to remember who in the Linux community was quoted in the Wall Street Journal as saying "Let's take the high road." We should do just that. We all know that SCO doesn't have a leg to stand on. Let's let them sink themsleves.
There is no spoon or sig.
What I want to know is how many people infected their computers on purpose and how man just didin't remove the virus after they found it? Most prople won't do a criminal act will but ignoring somebody elses?
"A good friend will bail you out of jail. A true friend will be sitting next to you saying, 'damn....that was fun!'"
The server, the server, the server is on fire!
We dont need no SCO let the #*($&# burn!
Course it's not funny they will just say "The terrorist group "Linux Community" has claimed responsibility for the attacks" and declare us part of the axis of weasel like they did the other day on CNN.
Does anyone believe that this will do anything except help SCO? It associates their enemies (IBM, Linux), with worm/virus creators and spammers. If this sort of thing keeps up, the US Legislative and Executive branches will actively take the side of SCO and MS against Linux and it's "hackers".
What do they need a website for anyway? Their only business is lawsuits and press releases.
Some news about the SCO dns:a y_morning_and_wwwscocom_is_still_in_the_dns.html
o .com
http://news.netcraft.com/archives/2004/02/01/sund
And graphs showing the results:
http://uptime.netcraft.com/perf/graph?site=www.sc
Just like the IBM lawsuit... ;-)
I don't advocate virus attacks to further the OSS community's aims...all Linux software authors and organizations ought to be suing SCO instead. That kind of attack will cost them real money and time, and won't generate any sympathy from anyone (who's sane anyhow).
Galileo: "The Earth revolves around the Sun!"
Score: -1 100% Flamebait
What's the difference between writing a virus that targets sco.com and posting a link to sco.com in a slashdot story?
Simple. The virus is less effective.
Friends don't help friends install M$ junk.
According to heise.de(in English) MyDoom.B is not nearly as widespread as the A-version. According to the article the A-version just had a good start, because it was distributed through an IRC-Botnet. So we will probably not see microsoft.com going down.
What I don't get is how this virus spread so far, considering how hard it must to be get infected by it. You'd have to go out of your way to get infected since the spreads its self as zip compressed attachment.
I can understand how past viri have spread so quickly taking advantages of exploits in Outlook and Windows RPC etc, but this doesn't seem to use any exploits what so ever.
Is it just a lot of stupid users or I am missing something?
aus.music.scrapbook
There was a story posted "Refuting tall-tales and stories about the Mydoom worms" which can be found at:
t
http://www.math.org.il/mydoom-facts.txt
It contains the Time Table for the attack along with reverse engineering analysis of the DoS component in Mydoom.
You might also want to check:
http://www.math.org.il/newworm-digest1.tx
Which contains an analysis and reverse engineering bits for Mydoom.A>
This virus is painting the Linux community as a bunch of petulant adolescents - regardless of who's doing it.
No, it's not. The media (and SCO, et al for obvious reasons) is painting the F/OSS community as adolescents
As a Linux geek I must admit to a small snicker at SCO's misfortune here, but it is definately not the right way to go about solving the SCO problem. All publicity is *NOT* good publicity, and the last thing we need is the world to think "Linux == Geeks spreading virii". I've been taking pains to point out the spam connection with the MyDoom virus, and I think that's the angle we should persue here. I can only hope that the next looser who DOSes SCO gives us as easy an "its not us" angle.
"Mission Accomplished" -- George W. Bush May 1, 2003
Curiously, this article seems to imply that there was a political agenda behind DDoSing SCO - but to quote Mikko Hypponen of F-secure a bit more:
"It's also possible the attack against SCO is just a smokescreen to misdirect attention away from the backdoor component in the virus - which is most likely included in order to facilitate sending of spam email messages."
Similiar, albeit longer, quote from him asserting that indeed spammers were behind this worm was in the local newspaper on Friday, but it's in Finnish and I'm too lazy to translate it. But the above quote can be found here.
"I wish it wouldn't happen. This virus is painting the Linux community as a bunch of petulant adolescents"
In case anyone still thinks this virus is related to linux people, let's put it as bluntly as we can:
Spammers have created yet another virus to send their emails, not caring about the cost to you, your computer, the law, or the internet in general
If you believed the spammer lies about how you've opted in to something, or how this is their freedom of speech, or how you can just press delete, then this should be the evidence you need: spammers are prepared to take down the entire internet for their own personal gain.
If anybody has bought anything advertised by email, or is considering doing so, or knows anybody who buys from email advertisements, then please be aware: you are supporting the criminals who are deliberately and maliciously attacking your computer, and the computers of your friends. Their programs are constantly bombarding your computer, where any mistake you make could lead to your computer becoming unusable by you, and being used to send illegal emails in vast quantities to the computers of others.
If any newspaper editor is reading this, and thinks "it's attacking SCO, it must be programmed by a Linux advocate", wake up and smell the misdirection. The DDOS in this virus was added as an afterthought. "Virus creation wizard step 6: you are nearly finished creating your virus. now type the name of a website you want it to attack"
1. This virus makes a machine an open relay. Considering recent legislation and other anti-spam techniques I smell spammer bovine feces here.
2. More and more spammers used high jacked machines for DNS, web service as well as relaying their crap. spammers Check out the nanae news group for more examples
3. The open source community is coming up with various anti-spam measures. Don't you think the spammers would love painting their enemy as petulant child - as they have proven themselves to be?
MyDOOM isn't the open source community pissing on on SCO, it's spammers pissing on all of us.
AngryPeopleRule
"Science is about ego as much as it is about discovery and truth " - I said it, so sue me.
Realistically, who the hell even goes to the SCO website. They've got so few new potential customers anyway (I would put the number at zero). Current UnixWare users doubtfully visit their website very much anyway.
Their website being down is more of a symbol. A symbol to them of "Look at what they are doing to us". It's obviously not very important to them anyway seeing as how in the past they've taken it down for hours to days at a time for "server upgrades". If it were that critical to them, they wouldn't have had downtime. But it was cheaper to take it down and do what they needed to do to spend the money to keep it up during upgrades.
Anyway, SCO can eat apple sauce out of my ass with a spoon.
I think a lot of folks have mixed feelings on this on.
"It is a greater offense to steal men's labor, than their clothes"
traceroute to www.sco.com (216.250.128.12), 30 hops max, 40 byte packets .
.
.
. .
4 bb1-p5-2.rcsntx.sbcglobal.net (151.164.243.13) 20.902 ms 22.986 ms 20.92 ms
5 bb2-p6-0.rcsntx.swbell.net (151.164.191.122) 20.957 ms 20.977 ms 20.878 ms
6 ex1-p11-0.eqdltx.sbcglobal.net (151.164.191.229) 24.012 ms 22.046 ms 20.96 ms
7 asn2828-xo-eqdltx.sbcglobal.net (151.164.248.14) 23.907 ms 23.2 ms 23.912 ms
8 p5-2-0-3.rar1.dallas-tx.us.xo.net (65.106.4.197) 23.96 ms 22.868 ms 23.999 ms
9 p0-0-0-1.rar2.dallas-tx.us.xo.net (65.106.1.42) 24.063 ms 22.648 ms 23.905 ms
10 p1-0-0.rar2.denver-co.us.xo.net (65.106.0.41) 38.954 ms 37.252 ms 47.928 ms
11 p0-0-0-2.rar1.denver-co.us.xo.net (65.106.1.81) 38.88 ms 37.841 ms 38.944 ms
12 p4-0-0.mar1.saltlake-ut.us.xo.net (65.106.6.74) 50.949 ms 49.296 ms 50.948 ms
13 p0-0.chr1.saltlake-ut.us.xo.net (207.88.83.42) 50.886 ms 49.851 ms 50.774 ms
14 205.158.14.114.ptr.us.xo.net (205.158.14.114) 53.912 ms 52.526 ms 51.004 ms
15 * * *
traceroute to linuxupdate.sco.com (216.250.128.241), 30 hops max, 40 byte packets
. .
4 bb1-p5-2.rcsntx.sbcglobal.net (151.164.243.13) 20.947 ms 20.046 ms 20.905 ms
5 bb2-p6-0.rcsntx.swbell.net (151.164.191.122) 20.919 ms 29.145 ms 20.855 ms
6 ex1-p11-0.eqdltx.sbcglobal.net (151.164.191.229) 20.951 ms 22.991 ms 23.963 ms
7 asn2828-xo-eqdltx.sbcglobal.net (151.164.248.14) 23.945 ms 22.989 ms 23.894 ms
8 p5-1-0-3.rar1.dallas-tx.us.xo.net (65.106.4.193) 23.955 ms 25.426 ms 24.013 ms
9 p0-0-0-1.rar2.dallas-tx.us.xo.net (65.106.1.42) 26.979 ms 62.002 ms 27.099 ms
10 p1-0-0.rar2.denver-co.us.xo.net (65.106.0.41) 38.821 ms 37.981 ms 38.89 ms
11 p0-0-0-2.rar1.denver-co.us.xo.net (65.106.1.81) 38.789 ms 38.094 ms 38.888 ms
12 p4-0-0.mar1.saltlake-ut.us.xo.net (65.106.6.74) 51.054 ms 50.024 ms 50.811 ms
13 p0-0.chr1.saltlake-ut.us.xo.net (207.88.83.42) 51.001 ms 49.886 ms 50.934 ms
14 205.158.14.114.ptr.us.xo.net (205.158.14.114) 53.903 ms 53.136 ms 53.841 ms
15 c7pub-216-250-136-254.center7.com (216.250.136.254) 50.937 ms 51.759 ms 50.787 ms
16 linuxupdate.sco.com (216.250.128.241) 51.004 ms 52.438 ms 50.988 ms
traceroute to ftp.calderasystems.com (216.250.128.13), 30 hops max, 40 byte packets
. .
4 bb1-p5-2.rcsntx.sbcglobal.net (151.164.243.13) 20.892 ms 20.06 ms 23.887 ms
5 bb2-p6-0.rcsntx.swbell.net (151.164.191.122) 21.051 ms 19.935 ms 21.034 ms
6 ex1-p11-0.eqdltx.sbcglobal.net (151.164.191.229) 23.82 ms 23.095 ms 23.868 ms
7 asn2828-xo-eqdltx.sbcglobal.net (151.164.248.14) 23.987 ms 23.063 ms 20.829 ms
8 p5-2-0-3.rar1.dallas-tx.us.xo.net (65.106.4.197) 23.989 ms 22.84 ms 23.934 ms
9 p0-0-0-1.rar2.dallas-tx.us.xo.net (65.106.1.42) 24.086 ms 25.935 ms 23.877 ms
10 p1-0-0.rar2.denver-co.us.xo.net (65.106.0.41) 38.916 ms 38.112 ms 38.925 ms
11 p0-0-0-2.rar1.denver-co.us.xo.net (65.106.1.81) 38.603 ms 38.096 ms 38.94 ms
12 p4-0-0.mar1.saltlake-ut.us.xo.net (65.106.6.74) 50.947 ms 49.871 ms 50.914 ms
13 p0-0.chr1.saltlake-ut.us.xo.net (207.88.83.42) 50.944 ms 49.782 ms 51.008 ms
14 205.158.14.114.ptr.us.xo.net (205.158.14.114) 50.836 ms 53.072 ms 53.935 ms
15 * * *
So either they're being merely slashdotted or they "accidentally on purpose" kicked www.sco.com's router power plug out of the wall. According to ARIN, they're all on the same /20 network, so they're probably not on a different final link from XO. They're certainly not being DoS'ed for bandwidth.
#naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
Is this a troll?
Telling people not to voice their opionions because of fear of what other people might think of you is an asinine way to excersice your right to free speech.
Yes, free speech is something we believe in at slashdot as well. We can and should make jokes. Why? Because we always make jokes about things! I would make a joke right now, but (1) I'm not that funny, and (2) I'm just too shocked that I am being told in a +5 comment not to say something.
Let the media report what they will. The fact is, some part of the community that you posted to can find humour in this. We are for sure a community that finds humour in everything.
Actually, now that I read your comment again, I am not sure you are serious. Perhaps it was just a joke and our mods have modded you insightfull?
i want to be part of DDOS attack!
dammit! why are mac users always left out of the fun?! >_
Some guy on winnetmag obviously thinks they should be offline, they must have brought it upon themselves, as he seems to think the virus is the fault of UNIX. he says that "A new email virus called MyDoom is spreading rapidly across the Internet through UNIX mail servers, bringing with it a dangerous attachment that, when opened, can give attackers access to users' computers through an electronic backdoor."
sheesh where do they get these people
Anyway, I know and you know how to spot a troll/humorous post/etc. on Slashdot. And we know that people's opinions go all over the map on many issues discussed on Slashdot. Joe Reporter doesn't get this and there is a real risk of them printing more smear-stories about a community that like-it-or-not you will be perceived as part of by virtue of posting here. It's reasonable for us to try not to make that community look bad - not saying not to speak your mind, but to keep in mind that in a high profile story like this, even though you may be Joe Nobody, your words could be used against you and lots of other people.
well, a DDOS attack on MSN wouldn't look so good. all those subscribers in redneckistan with suddenly no homepage to click on. "Ethel Sue! The Inter-o-net ain't workin'" "Billy John, I done told you we should have went and got ourselves that there newfangled Verimazon Dee Ass El!"
The flag just makes more sense than the constitution. - Judas Gutenberg
This seems much wiser a suggestion than the anti-MS paragraph which you chose to cite. Who better to set actual network policy than those responsible for managing those networks?
Microsoft including a raw socket API is about as evil as Microsoft supporting the creation of outgoing connections to any arbitrary mail servers -- sure, it's open to abuse (DDoS, spam, etc.), but removing the sort of API that traceroute and ping tools would use to perform useful work is not a security fix. It closer to asking Home Depot not to sell hammers because they can be used as weapons.
Further, having MS remove the raw socket API would lead those with cruel intentions to use non-Windows machines exclusively to do their evil deeds. Consider that the mind which concludes that the raw socket API must be removed because of the unpleasant actions of a few people probably isn't far from thinking that operating systems which are engineered in an open and flexible environment can be used for subversion as well. Suddenly those using "subversive" non-MS operating systems which haven't removed raw packet interfaces are a little more suspect in the public eye.
If ISPs would only permit traffic with sane source IP addresses to leave their networks, then the only effect sending such packets out would have would be to waste traffic between the would-be tricksters and their ISP's router(s).
Somebody get that guy an ambulance!
Given that they knew this was coming, and knew that they didn't have the bandwidth/CPU to handle the masssive overload, why didn't SCO Just set the A record for their website to 127.0.0.1 for a couple of days?? Either that or 192.168.42.42... With the former, a virus infected machine would simply attack itself. With the later, it would try to contact a well known address which would allow sysadmins to find any infected machine (and remove the virus) by simply looking for references to the address.
Free Software: Like love, it grows best when given away.
I think we should all send him a present! For example, these guys will ship a big ol' batch of live crickets. For $58, we could ship ol' Darl 5000 crickets and I know that would cheer him up!
I'm trying to teach myself to set people on fire with my mind... Is it hot in here?
Correction to make on my previous post. I had already done a dig and nslookup, but on sco.com and not www.sco.com.
;; global options: printcmd
;; Got answer:
;; -HEADER- opcode: QUERY, status: NXDOMAIN, id: 14794
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
[root]# host www.sco.com
Host www.sco.com not found: 3(NXDOMAIN)
[root]# dig www.sco.com
; > DiG 9.2.1rc1 > www.sco.com
SCO has updated their dns servers and axed the record for www.sco.com. NXDOMAIN means no such domain. Wonder why SCO didn't announce that they themselves took www.sco.com completely offline.
Hopefully the media will know about this when SCO complains about the DDOS attack. Now I know why the rest of their services are fairly intact and responding.
Kindness is the language which the deaf can hear and the blind can see. - Mark Twain
www.sco.com no longer resolves. They removed it from their name server yesterday. Only sco.com without the www resolves to an ip address. The attack should be almost completely averted by now because of this, but sco.com is still down.
The only possible cause I see for them to still be offline is if they took it offline themselves, or there's been another attack that they've failed to mention to the press, but it's unlikely that they'd turn down any opportunity to slam us if that were the case. Check it yourselves. The worm specifically attacks the domain www.sco.com, which no longer exists, and the dns entry expired yesterday. All that worm traffic should be going to oblivion by now, because Windows doesn't reuse expired dns records when requery attempts fail.
> www.sco.com
Server: ns.calderasystems.com
Address: 216.250.130.1
*** ns.calderasystems.com can't find www.sco.com: Non-existent domain
> sco.com
Server: ns.calderasystems.com
Address: 216.250.130.1
Non-authoritative answer:
Name: sco.com
Address: 216.250.128.12
SCO has made their website completely unavailable by removing the www.sco.com name record, not a flood of packets. They have mentioned nothing about packet filtering at the router level or any alternative method of keeping their main site online. When the attacks start flooding Microsoft, do you think they will just take their main site down or look at a solution that keeps them up?
I'm only pointing out that SCO is not being honest about the reason for their web sites complete unavailablity. They could still be online with several alternative options that they aren't exploring and want to act like they have no choice in the matter. It looks like they are taking the 'poor me' attitude when things could have been made much better with a little effort.
Maybe their site isn't as important to the operation of their new business model. It may be an even bigger asset to them as a publicity tool while it is down ( due to their lack of name record). When I see them admit that they took it down themselves, then they will have a bit more credibility. With no name record, thus no actual attack on their site, they can't know when the attack would have ended or how severe the flood would have been. They can't really track the attack via DNS lookup operations because that can't give an accurate picture of the potential flood, only the number of participating machines.
They've removed the means to gather statistics about the attack and devise means to counter a defense. The opposite of what I would expect of Microsoft, IBM, Symantec, RedHat, Slashdot or thousands of other sites on the internet.
Kindness is the language which the deaf can hear and the blind can see. - Mark Twain