Slashdot Mirror


TimeWarner DNS Hijacking

Exstatica writes "It looks like TimeWarner is taking vigilante action on the botnet problem. They've hijacked DNS for a few IRC servers, the latest being irc.mzima.net and irc.nac.net — both part of EFNet. (irc.vel.net was hijacked earlier but has been restored.) Using ns1.sd.cox.net, the lookup returns an IP for what looks to be a script that forces the user into a channel and issues a set of commands to clean the drones. There have been different reports of other IRC networks being hijacked and other DNS servers involved. Is this the right way to handle the botnet problem? Is hijacking DNS legal?" Botnets are starting to move off of IRC for command and control, anyway.
Update: 07/24 00:01 GMT by KD : Updated and added more links; thanks to Drew Matthews at vel.net. 07/24 11:52 GMT by KD : Daniel Haskell wrote in to say that ircd.nac.net is seeing cox.net connections again, and that they are in discussion with the EFF over the matter.

11 of 339 comments (clear)

  1. In other news by MonGuSE · · Score: 1, Funny

    In other news Redhat has begun using arp poisoning and TLD hijacking to remove the Malicious and insecure Microsoft Windows installs. After all windows installs are purged there is expected to never ever be a future threat and heavy handed tactics will never be used again. Sometimes the cure is worse than the ailment.

  2. This is a DNS hijacking. by woodchip · · Score: 5, Funny

    OK DNS Server resolve me to .cu and no body gets hurt.

  3. The Right Way? by Kozar_The_Malignant · · Score: 5, Funny

    >Is this the right way to handle the botnet problem?

    No. The right way involves castration with rusty linoleum knives, Turkish prisons, and rabid wolverines. If that doesn't work, we should quit being nice and get nasty with these folks. Seriously, this problem will not go away until people start doing some hard time, preferably with a cell mate who does not need Erct|le Member Help!

    --
    Some mornings it's hardly worth chewing through the restraints to get out of bed.
  4. Re:Fair game by Vegeta99 · · Score: 2, Funny

    Except for Eris, of course.

  5. Re:IRC networks must police themselves by Assassin+bug · · Score: 4, Funny

    Do do do do, dah dah dah dah, is all I have to say to you.

  6. Re:The criminal code calls it "Theft of Services" by wik · · Score: 3, Funny

    Hey, not so fast!

    PA recently became the 50th state in the union to put their laws online.

    --
    / \
    \ / ASCII ribbon campaign for peace
    x
    / \
  7. Re:About time by davecarlotub · · Score: 2, Funny

    I, for one, do *NOT* trust the police, however I welcome our new botnet-breaking overlords.

  8. Re:Alternative DNS? by Anonymous Coward · · Score: 1, Funny

    Pfff. pansy.
    I'll stick to memorizing the IP addresses of all the sites I like, thank you.

  9. Re:New Update since i submited this yesterday by Anonymous Coward · · Score: 0, Funny

    -100 for lame referential cross-linking to wiktionary to support your dirty spelling pedantry...

    A**hole....

  10. Re:New Update since i submited this yesterday by Skrynesaver · · Score: 5, Funny
    Realistically anyone attempting to prosecute Cox for exploiting a backdoor in a botnet is going to have a hard time keeping their client out of jail.

    I look forward to Cox meeting their lawyers.
    Evil_lawyer_dude: You have exploited a vulnerability in my clients software
    Cox Communications: Ooops, so we have, would you care to name your client
    Evil_lawter_dude: I don't have to
    Cox Communications: Well, without evidence of harm done to your client we can't be held liable for anything
    Evil_lawyer_dude: My client has been unable to carry on his business using the resources of your customers
    Cox Communications: Yes, and we have a list of customers who would be part of a counter suit, no go away or we will taunt you some more.

    --
    "Linux is for noobs"-The new MS fud strategy
  11. This is bad....*how*? by IonOtter · · Score: 2, Funny

    TWC: "Sir, you have an IRC bot on your machine that's making DDoS attacks."

    Majority Computer User: "'IRC'? I'm seeing who??? Who am I seeing and when? Why am I seeing them? What're you talking about?!? Am I being charged for this?!? OMG, did Billy download music or movies or something?!? Oh Jesus Christ I'm going to kill that brat! Oh God, did you report me?!? I'm going to jail, aren't I?!?"

    TWC: (sweatdrop)

    So. Explain to me how castrating bots without disturbing or distressing the vast and overwhelming majority of computer users is a bad thing?

    --
    [End Of Line]