Slashdot Mirror


TimeWarner DNS Hijacking

Exstatica writes "It looks like TimeWarner is taking vigilante action on the botnet problem. They've hijacked DNS for a few IRC servers, the latest being irc.mzima.net and irc.nac.net — both part of EFNet. (irc.vel.net was hijacked earlier but has been restored.) Using ns1.sd.cox.net, the lookup returns an IP for what looks to be a script that forces the user into a channel and issues a set of commands to clean the drones. There have been different reports of other IRC networks being hijacked and other DNS servers involved. Is this the right way to handle the botnet problem? Is hijacking DNS legal?" Botnets are starting to move off of IRC for command and control, anyway.
Update: 07/24 00:01 GMT by KD : Updated and added more links; thanks to Drew Matthews at vel.net. 07/24 11:52 GMT by KD : Daniel Haskell wrote in to say that ircd.nac.net is seeing cox.net connections again, and that they are in discussion with the EFF over the matter.

64 of 339 comments (clear)

  1. New Update since i submited this yesterday by Exstatica · · Score: 5, Informative

    Since submitting this article yesterday there have been some new developments. There was a large debate on Nanog about what has been happening and eventually was published to wired. The full description of everything that has happened and how it happened can be found on my site at http://www.exstatica.net/hijacked/ as for irc.vel.net we have been returned our dns, but irc.mzima.net appears to still be hijacked.

    1. Re:New Update since i submited this yesterday by TheRealMindChild · · Score: 4, Insightful

      That sounds like dirty lawyer logic.

      Next you'll argue that reverse engineering a virus is a violation of the DMCA.

      Ill be the first to say it. Who the fuck cares. The problem is being delt with.

      --

      "When life gives you lemons, don't make lemonade. Make life take the lemons back!" -- Cave Johnson
    2. Re:New Update since i submited this yesterday by Anonymous Coward · · Score: 4, Interesting

      This is in no way a new practice -- Time Warner has been doing this for well over two years. In the past script kiddies who have been caught hosting botnet servers on *.res.rr.com machines had their DNS's redirected to a single server in which all registered IRC users would be directed to #badbotbad, with the topic as .remove. It did, and still does, little to stop the botnet problem since the methods TW uses to sniff out the botnet servers are very specific to IRC protocol. That, and the server would only remove a standard kiddie rxbot with unchanged commands. --Manix

    3. Re:New Update since i submited this yesterday by Lawn+Jocke · · Score: 2, Insightful

      Next you'll argue that reverse engineering a virus is a violation of the DMCA.

      Bit exaggerated use of a slippery slope metaphor. IANAL but to my understanding, their actions were closer to breaking into somebody's house to steal back your remote control. Not to justify their actions- just clarifying.

      Ill be the first to say it. Who the fuck cares. The problem is being delt with.

      I'll be the first to ask: If you don't give a hoot about this issue, what are you doing in this topic, let alone in the /. community?

      --
      Maybe if this sig is witty or clever enough, someone will love me...
    4. Re:New Update since i submited this yesterday by Paradise+Pete · · Score: 3, Insightful
      Ill be the first to say it. Who the fuck cares. The problem is being delt with.

      Vigilante justice - the mark of the civilized man. String 'em up first, ask questions later. Your logic has been used to justify uncountable wrongs.

    5. Re:New Update since i submited this yesterday by geminidomino · · Score: 4, Insightful

      Ill be the first to say it. Who the fuck cares. The problem is being delt with.


      Vigilante justice - the mark of the civilized man. String 'em up first, ask questions later. Your logic has been used to justify uncountable wrongs.

      In all fairness, so has the so-called "Rule of Law."
    6. Re:New Update since i submited this yesterday by Anonymous Coward · · Score: 2, Informative

      Time Warner was not the one doing "#badbotbad" -- AOL was/is. Additionally, it forced all bots into that channel *in addition* to the preprogrammed channel(s). They "null route" on the ATDN usually, but from time to time they would "next hop" the traffic to standalone server running a modified ircd.

      The "#badbotbad" topic was rotated frequently amongst the most common bots/variants. The specific channels had their topics set according to the most common bot using that channel at the time.

      Finally, a nickserv was established to preregister certain nicks and masks to deter "real" bot herder/owners from signing on to take back control. A script then slammed in to the server with the registered nick(s) sending the appropriate kill commands.

      Sometimes it worked, and sometimes it didn't.

    7. Re:New Update since i submited this yesterday by Skrynesaver · · Score: 5, Funny
      Realistically anyone attempting to prosecute Cox for exploiting a backdoor in a botnet is going to have a hard time keeping their client out of jail.

      I look forward to Cox meeting their lawyers.
      Evil_lawyer_dude: You have exploited a vulnerability in my clients software
      Cox Communications: Ooops, so we have, would you care to name your client
      Evil_lawter_dude: I don't have to
      Cox Communications: Well, without evidence of harm done to your client we can't be held liable for anything
      Evil_lawyer_dude: My client has been unable to carry on his business using the resources of your customers
      Cox Communications: Yes, and we have a list of customers who would be part of a counter suit, no go away or we will taunt you some more.

      --
      "Linux is for noobs"-The new MS fud strategy
    8. Re:New Update since i submited this yesterday by empaler · · Score: 3, Insightful

      Yeah, because his entire post hinged on that one spelling error that he corrected in a concise and non-derogatory manner that TheRealMindChild might actually benefit from reading.

      Kudos for calling him an asshole - with fucking stars.

    9. Re:New Update since i submited this yesterday by Propaganda13 · · Score: 2, Interesting

      Smart people care. Where do you draw the line? If your computer was infected with a bot, would you want your ISP to A) notify you and give you tools to clean your computer B) Reformat your computer

      Both options deal with the problem.

      I'm surprised that bots aren't boobytrapped against this sort of action, but as the summary states using IRC for bots is yesterday's news.

    10. Re:New Update since i submited this yesterday by Cederic · · Score: 4, Insightful


      The author of the software is irrelevant. It's my PC, if a company hacks into it and changes it then they're breaking the law.

      That they're using previously installed malware to do so is completely irrelevant to this.

      Can they even demonstrate that I don't know of the existance of that malware? Maybe I installed it myself, maybe I'm monitoring it.

      It's illegal, and they should be prosecuted.

    11. Re:New Update since i submited this yesterday by Anonymous Coward · · Score: 2, Informative

      While I agree that ISPs should be doing something against botnet and trojan problems, this is not the way to go for several reasons.
      First of all, redirecting traffic or manipulating dns replies for sites/domains/servers you do not own is a legal no-go for ISPs and ICPs of any kind. It opens up the possibility of man-in-the-middle attacks and also very much is against the idea of the Internet itself.

      Second, timewarner did not only redirect connections to EFnet, they also didn't bother to contact neither their users nor EFnet about this. EFnet had to deal with all those complaints - which they could not handle as it wasn't their fault.

      Third, timewarner chose a concept that is bound to fail. One cannot just redirect IRC traffic for a random IRC server. While there's botnets that use standard ports ofc, most botnets either use private irc servers (installed on cracked machines) and/or non-standard ports. And as the OG said, they are moving to other ways of communication. As for EFnet, TW should have told the staff that they suspected a botnet and give details. This would have been way more efficient and not just annoy all affected (and possibly not even infected) users.

      Fourth, as I've seen details about timewarner's actions, they're trying to run different uninstall commands on the possibly infected machines. They'd either need to exactly know which command it'd take or test all of them while risking that the infected machine will detect this overtake procedure and go into a "safe mode" or disconnect again.

      If I went to summarize this up: The idea isn't that bad, but it's bound to fail as botnets and IRC do not work the way they think.

      PS: I'm not an EFnet representee, but I'm part of an organization that works on disabling botnets together with other people from various irc networks. I do not understand why timewarner did not even bother try to contact us - even though I had contact to their abuse desk long time ago.

    12. Re:New Update since i submited this yesterday by Curien · · Score: 2, Informative

      Can they even demonstrate that I don't know of the existance of that malware? Maybe I installed it myself, maybe I'm monitoring it.

      Then you violated your TOS and were on their network illegally.

      It's your PC, but it's THEIR network. They have the right to defend their network and the obligation to protect other people using it. I'd even bet their TOS authorizes this kind of behavior.

      --
      It's always a long day... 86400 doesn't fit into a short.
    13. Re:New Update since i submited this yesterday by plague3106 · · Score: 2, Interesting

      They have the right and the power to prevent me connecting to their network. They do not have the right or authority to invasively damage my computer.

      Please explain how shutting down a bot on your computer is damaging it.

    14. Re:New Update since i submited this yesterday by Fastolfe · · Score: 2, Insightful

      I'm part of an organization that works on disabling botnets together with other people from various irc networks. I do not understand why timewarner did not even bother try to contact us - even though I had contact to their abuse desk long time ago.

      Perhaps they're simply unaware that you exist? I'm sure the people staffing abuse@ are a bit separated from the people making these types of decisions.

    15. Re:New Update since i submited this yesterday by MrPeach · · Score: 2, Insightful

      While I agree in principle, I believe a more prudent approach is:

      1) ISP detects your computer is being used for SPAM/DOS/some other hijacked purpose (and NOT just user behavior problems)
      2) ISP restricts you to a walled garden where your infected machine cannot access the internet - and you are informed as to the cause and action needed from you before access can be restored
      3) you call ISP whining about your internet connection (or skip to step 5)
      4) ISP repeats the information from the walled garden
      5) you clean up your shit, the ISP confirms this and you are allowed back on the internet

      No need for abusive actions against the user. Just put them in internet jail and if they care to get their internet back they need to fix the problem. If the ISP is feeling particularly generous, they can make the tools needed for the cleanup available within the walled garden, otherwise you'll have to call the Geek Squad or something.

      This type of hijacking is 1) not needed, 2) ineffectual against most problems, & 3) non-functional against people like me who use an alternative DNS (openDNS).

  2. This is a DNS hijacking. by woodchip · · Score: 5, Funny

    OK DNS Server resolve me to .cu and no body gets hurt.

  3. The criminal code calls it "Theft of Services" by cenonce · · Score: 5, Interesting

    In Pennsylvania, it sounds like it might fall under Theft of, or Diversion of Services.

    1. Re:The criminal code calls it "Theft of Services" by wik · · Score: 3, Funny

      Hey, not so fast!

      PA recently became the 50th state in the union to put their laws online.

      --
      / \
      \ / ASCII ribbon campaign for peace
      x
      / \
  4. Yes, it is the right way by Anonymous Coward · · Score: 2, Interesting

    Politicians are more concerned with pampering the amok-running entertainment industry, providers are more concerned with keeping their pink contract customers, users are more concerned with getting cheap viagra and don't care about the number of botnets their computers are part of and law enforcement is chasing whoever is tagged with the kiddieporn or terrorism flag.

    If admins don't take it into their own hands, nobody is going to do anything.

  5. IRC networks must police themselves by Anonymous Coward · · Score: 2, Interesting

    Police thyself, or others will do the policing for you.

    1. Re:IRC networks must police themselves by Assassin+bug · · Score: 4, Funny

      Do do do do, dah dah dah dah, is all I have to say to you.

  6. TimeWarner != Cox by OverlordQ · · Score: 2, Informative

    While Cox used to use Time Warner's RoadRunner for their cable internet service, Cox's Internet offerings are In-House now.

    --
    Your hair look like poop, Bob! - Wanker.
  7. Is there an easier and more effective way?? by grapeape · · Score: 4, Interesting

    If Time Warner was really concerned about it wouldnt it be easier and more effective to use their virtual truck (TW Self help) application to redirect the users browser start page to a list of instructions, tools and a support number to clean up their system? I have seen several instances were they redirect users to a "disabled due to non-payment" type pages...would a "Hey idiot your computer is infected" page be that difficult?

    1. Re:Is there an easier and more effective way?? by sqlrob · · Score: 4, Interesting

      Knowing them, yes, and probably not a good idea.

      A while back, I got a "your computer is infected" notice from them. I checked all my computers, the Windows ones with tools that weren't even available to the public at the time, and zero, zip, nada. Everything was clean, sniffs showed nothing out of place.

      Finally talked with someone with a clue, and they classified my SpamAssassin install as a DOS on their name servers because they were caching the negative responses from the various blacklists.

  8. About time by beefcake1942 · · Score: 2, Insightful

    Frankly, I think it's about time somebody started ACTING on the problems we face online. Botnets are a huge global issue, and we simply must do all that we can to stop them. Although I suppose this probably could be considered illegal (remotely installing software on somebody's PC without their authorisation breaks pretty much every anti-hacking law in the land), how else can we tackle these issues? Zombie PCs aren't going away any time soon, so more needs to be done. The only problem is as the OP originally stated - botnet control is moving away from IRC networks anyway, so this may also be a case of too little too late. What other methods can be used to help curb the botnet problem?

    1. Re:About time by CrazedWalrus · · Score: 4, Insightful

      I think this action is right-on. The parts of the equation missing are trust and accountability.

      We don't trust vigilantes, not because we don't agree with them, but because we don't trust them to always act in the greater good. Their future actions and motivations are unknowns. Since their identities may even be secret, there's no way to hold them accountable.

      Why are we ok with the police taking the same actions as a vigilante would take? Because of trust earned through accountability. To retask a familiar saying: "Put all your eggs in one basket and then watch that basket". That basket is the police, and we've put all our eggs in it. That means the public at large can watch the police, who are well-known and generally easy to spot. It means that internal controls can be set up, and rules of engagement can be put in place. We trust the police as much as we do because we know that, ultimately, they're under the control of the general public, who can exert pressure on them when they act badly. This is why we tend to put more trust in organizations, rather than individuals. Organizations are easier to censure.

      Understanding that, it's easy to see what the course of action needs to be. As much as we here at /. tend to have a love/hate relationship with authorities, I think one needs to be set up specifically to deal with these problems. They need to be given what power is necessary to deal with the problems like spam, trojans, botnets, whatever, but at the same time, they need to be directly accountable to the public in a similar manner to police forces. Legitimize the vigilante action by coupling it with accountability.

      I don't really know the specifics of setting up something like this, but I think using the police as a model would be the way to go. Rules and procedures, all the requisite bureaucracy, but also the ability to launch tactical "busts", "cyber" or otherwise. They'd need all the same approvals, warrants, etc. They'd have branches in all concerned countries, and would work through the legal systems in their home countries. In some countries, they might be a part of the police force, since much of the administrivia would be similar. Ultimately, I'd think CERT or something like it would be a good headquarters or parent organization for such a group.

      The point is that we've already worked this out in the "Real World". Applying it to The Internet shouldn't be a patent-worthy exercise. While I wish we didn't need government involvement, much of the authority required is the type of authority that only government can legitimately grant, such as the ability to seize equipment.

      I aplogize that this isn't as eloquently described as I'd have liked, but I think the general idea is there. You may now procede to flame me for advocating the Policing of the Intertubes but ultimately, I think that's where we're headed.

    2. Re:About time by davecarlotub · · Score: 2, Funny

      I, for one, do *NOT* trust the police, however I welcome our new botnet-breaking overlords.

  9. Another vote for OpenDNS! by sillivalley · · Score: 4, Insightful

    So we can expect the next generation of malware to alter systems to use OpenDNS?

    Might make some systems a little more useful!

  10. About Time Someone Tried Something by Anonymous Coward · · Score: 2, Insightful

    Let's face it, the company with the most responsibility in the Botnet mess, Microsoft, has been sitting on their hands when it comes to dealing with the issue. Well, until they figured out they could make a buck at it.

    Botnets are used by organized crime for spam, stock scams and a host of other illegal activities. It's time someone did something...if only for the political effect.

  11. The Right Way? by Kozar_The_Malignant · · Score: 5, Funny

    >Is this the right way to handle the botnet problem?

    No. The right way involves castration with rusty linoleum knives, Turkish prisons, and rabid wolverines. If that doesn't work, we should quit being nice and get nasty with these folks. Seriously, this problem will not go away until people start doing some hard time, preferably with a cell mate who does not need Erct|le Member Help!

    --
    Some mornings it's hardly worth chewing through the restraints to get out of bed.
  12. This will NOT raise awareness or work in any way. by twitter · · Score: 5, Interesting

    Wired found someone who approves of breaking the internet:

    Frankly, redirecting requests to malware sites, or IRC communication channels, to cleaner-sites sounds like a practical short term tactic to me. And if it raises awareness around the seriousness of the bot problem I'm all for it.

    Right, because the kind of people who might actually use IRC know nothing about botnets and the kind of Windoze users who are part of the botnet care about IRC. This is just another attack on the free software community as outlined in the Haloween Documents.

    Once again, the ISP has punished the good guys for problems crated by the bad guys. The root cause of the botnet is Windoze. Fixing it and raising awareness is as simple as cutting the problem computers off your network and telling their owners why. This is as it should be and pretending otherwise props up third rate software and threatens the stability of the net.

    --

    Friends don't help friends install M$ junk.

  13. Their DNS Server... by flyingfsck · · Score: 4, Insightful

    If I wish to black hole something on my DNS, it is my prerogative to do so. If someone else is using my server for free and complains about the shitty service, then I'll gladly refund his money...

    --
    Excuse me, but please get off my Pennisetum Clandestinum, eh!
    1. Re:Their DNS Server... by DarkOx · · Score: 2, Interesting

      Yes, but arguably DNS is a services you expect your ISP to provide. I know I do. I rather like my ISPs DNS server, its fast and near to me in terms of hops. Its a great forward DNS server for the DNS server on my personal network.

      I expect my ISP to provide me with correct DNS loopup results. If they don't then they would not be providing me with part of the service I understand I am paying them for. They would hear from me about it pretty quickly and more then likely loose my business over it. There are after all lots of ISPs out there.

      --
      Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
  14. It's not like the police are doing anything.. by QuantumG · · Score: 4, Interesting

    Uhhhh.. see, I'm kinda of the opinion that vigilante action is only bad if there are proper channels. There are none.

    --
    How we know is more important than what we know.
  15. Re:This will NOT raise awareness or work in any wa by thegrassyknowl · · Score: 5, Insightful

    Once again, the ISP has punished the good guys for problems crated by the bad guys. The root cause of the botnet is Windoze. Fixing it and raising awareness is as simple as cutting the problem computers off your network and telling their owners why. This is as it should be and pretending otherwise props up third rate software and threatens the stability of the net.

    I wish I hadn't run out of mod points; this is gold.

    That's a pretty cut and dried way of reducing the number of bots. Cutting the user off forces them to understand what is wrong and why they're cut off. If you just give them information most will just click past it and continue on their merry way. Users don't want information. They want the pr0nz as quick as possible. Didn't you know that?

    I can think of one case where a (now ex) friend of mine would email To: every single person in her work address book with SPAM for her work. I started out telling her to use the Bcc: field at least and pointed her to a web page describing why you'd want to do that. she replied "I don't want to read all that technical garbage" then carried on the same. Then I asked her to remove me from her list. She replied "I am going to send you this stuff because I know you want it" (it really was SPAM for her work, it wasn't even jokes or chain mail). There ended our friendship as I reported them to their ISP. They were warned by their ISP and still continued doing what they did. They lost hosting pretty quick after that.

    People don't want to learn. They are, by and large, idiots. Heavy handed measures are the only way to force them to realise that fact.

    --
    I drink to make other people interesting!
  16. What??? by bogie · · Score: 5, Interesting

    You mean you actually talked to someone in tech support who not only knew what a packet was but also looked up what was happening on their end at a technical level? How many drones did you have to speak to telling you to A)reboot or B)reinstall your machine? Did you use chicken blood or ox blood to perform this magic?

    --
    If you wanna get rich, you know that payback is a bitch
    1. Re:What??? by Martin+Blank · · Score: 3, Informative

      Actually, if you can get past the first level of drones (and sometimes the second level, depending on the company), you'll talk to people who know not only what a packet is, but also can do actual troubleshooting on the modem connection and make some sense of it. I've experienced this with Comcast, Adelphia, and Time-Warner (it was completely absent, so far as I could tell, from MediaOne when they were around); in one case, I got a very thorough explanation of the problem as it related to head-end equipment and what needed to be done to fix it from the tech as she was entering it into the work order.

      The problem, of course, is that almost all users that call in don't need more than scripted hand-holding, and those of us that know what we're talking about call in and hit that wall, through which it can be very difficult to find an open window through which to crawl to find a knowledgeable person.

      --
      You can never go home again... but I guess you can shop there.
    2. Re:What??? by DigiShaman · · Score: 3, Informative

      Remember, the job of a TSR and CSR is among the jobs with the highest turn-over rate.

      The people that apply (and get) these jobs fall in two main categories. The first being entry level. The second being highly skilled IT professionals who got laid off and need something to pay the bills until the find a better job. As such, you will get a nice mix of idiots and very brilliant staff manning the phone queue.

      --
      Life is not for the lazy.
  17. In the long run, not a great idea by BertieBaggio · · Score: 4, Insightful

    I have mod points, but I'd like to collectively reply to a few of the comments I see here. for those of you that are commending this act of vigilantism, stop and think - is this the most effective way to tackle the problem? The way I see it is that being a vigilante is akin to being involved in a constant game of whack-a-mole. The only problem is that when you start taking down bots (or even whole botnets), the people running them begin to realise that their current generation of malware isn't effective enough, and create something that is harder to detect. As the summary notes, we've already seen them trying to improve their resources. There was another post I saw on here that put it more eloquently, essentially saying: vigilantism only helps the bad guys work out where they need to improve.

    So how about instead of trying to fight a brushfire with an extinguisher, we get to the root of the problem and start educating users. Yes, that takes effort. I can't begin to count the hours I've spent trying to explain to folk why using an alternative browser (or OS or whatever) is a good idea, and what they should look for in a reputable site, and so on and so on ad nauseum. It's a slow process, but the more people that are aware of the risks - and more importantly, the reasons for the risks - the less there potential 'marks' there are for all the script kiddeez, rooters and organised criminals out there.

    And for us on /. - less requests to fix the family computer when we visit at Christmas.

    --
    If all you have is a grenade, pretty soon every problem looks like a foxhole -- MightyYar
    1. Re:In the long run, not a great idea by BertieBaggio · · Score: 2, Interesting

      When I first read your post I thought you were trying to make a dry joke, but I figure from your other posts that you are serious. If you really want a dedicated police force for this sort of thing why not show local politicians that it is feasible, important, and not a waste of money (the last one is the most important). If you can give them an example ("Here is a guy I tracked down in 5 hours. He controls 10,000 bots he can do $50,000 worth of damage an hour. He has probably misappropriated 1000 identities. Etc.") and pitch it to them at an angle that shows it as a way for them to win brownie points with their superiors/voters/whoever they might just do something about it.

      Once there is something like that at a local level you have what is known as a 'test case' or 'pilot project'. If it works other people will jump on the bandwagon.

      This vigilantism shows us that it is possible to track down who is controlling the networks (or at the very least pin them to an IP address), but like I say, taking down bots here and there is futile and will only encourage them to evolve.

      --
      If all you have is a grenade, pretty soon every problem looks like a foxhole -- MightyYar
  18. Not perfect, but by davmoo · · Score: 3, Interesting

    This isn't the perfect or ideal way to do things. But its about damned time the ISPs did something.

    There is simply **NO** excuse for a bot to be running on any ISP for more than the time it takes to detect it pumping out massive volumes of email. My solution, as I've stated several times, would be to disconnect the offending computer, and then fire them off a snailmail letter stating that they will not be permitted back until their computer is disinfected. But since that would cost them customers, no one will do that.

    --
    I want a new quote. One that won't spill. One that don't cost too much. Or come in a pill.
  19. Re:No "awareness" needed by QuantumG · · Score: 2, Insightful

    No, no, and no.

    The problem is the assholes who take over people's computers to send spam and flood web sites.

    The solution is a well funded police force to hunt them down.

    --
    How we know is more important than what we know.
  20. Re:Fair game by Vegeta99 · · Score: 2, Funny

    Except for Eris, of course.

  21. This has been going on for TWO years by Pap22 · · Score: 2, Informative

    http://secureme.blogspot.com/2005_06_01_archive.ht ml/

    Scroll down to the very bottom of that page. Notice the date.

  22. Tortious Interference by Spazmania · · Score: 2, Interesting

    Is hijacking DNS legal?

    "Tortious interference," is part of english common law roughly defined as the causing of harm by disrupting something that belongs to someone else. The original example was a guy who repeatedly drove ducks away from his neighbors' pond by firing a gun in the air on his own property.

    So no, its not legal. But if you want to pursue it in court, you have only one of the weaker common-law torts to rely on.

    --
    Moderating "-1, Disagree" is simple censorship. Have the guts to post your opinion.
  23. No, probably not by Sycraft-fu · · Score: 5, Interesting

    Since it sounds like they were doing it with their DNS servers. While it would be illegal for me to break in to your DNS server and modify it, it is not illegal for me to modify my DNS server, even if you use it. If you dislike it, you can use another service, but unless I have a contract with you there's nothing wrong with it (legally). You can argue it is a bad idea, but changing their equipment on their network is well within their rights.

    1. Re:No, probably not by stonecypher · · Score: 2, Informative

      The law doesn't seem to agree with you. From the thing you didn't read: (b) Diversion of services.--A person is guilty of theft if, having control over the disposition of services of others to which he is not entitled, he knowingly diverts such services to his own benefit or to the benefit of another not entitled thereto. Whether that benefit is monetary doesn't seem to matter.

      It turns out that when you're a telecommunications provider, there are a whole bunch of laws to the effect of "you can't divert or compromise the telecommunications you're selling."

      --
      StoneCypher is Full of BS
    2. Re:No, probably not by Mjec · · Score: 2, Insightful

      (b) Diversion of services.--A person is guilty of theft if, having control over the disposition of services of others to which he is not entitled...

      (Emphasis added).

      Yeah, they're entitled to do whatever they want with their DNS servers. You're the one asking them for information. Now, if they were obtaining a financial benefit then it may be obtaining money by deception, or fraud, because they're providing you with false information. It may be a breach of contract, though you'll find it hard to prove that they owe you anything at all. So yeah, there's really nothing wrong per se with what they're doing.

      --
      "But everyone should know everything." -markab
  24. Alternative DNS? by SaDan · · Score: 2, Insightful

    208.67.222.222
    208.67.220.220

    I don't work for OpenDNS, but they've got some nice DNS servers out there for use. http://www.opendns.com/

    Kind of sad, the first thing I thought about when I started reading about this was, "Wow... Who'd a thought you needed TOR to get proper DNS resolution?"

    1. Re:Alternative DNS? by dissy · · Score: 5, Insightful

      I thought OpenDNS was the greatest thing, until I noticed if you type in a URL that isn't valid it doesn't deliver the standard "non-existent domain" return, but instead gives you an OpenDNS search results page. Bleh. I'll stick with running Bind on my own server, thank you. Actually, if you signup for a free account, and add your IP(s) in their dashboard webapp, you can configure all sorts of things, including to return NXDOMAIN on resolution failure.

      I too agree that breaking NXDOMAIN is a bad thing, but OpenDNS at least does let you change this yourself. It just has the wrong default, so to speak.

      I strongly urge you to signup for a free account, and look over their settings available, before you judge.

      -- Jon
  25. Re:crackz.ws dns by Technician · · Score: 2, Informative

    it redirects to a "Scam Blocked" page...

    If you don't like the Cox DNS results, feel free to put another DNS server in your router or computer. Switch from dynamic DNS to static DNS and use some of the public DNS servers.

    Here is a good place to start..
    http://www.opennic.unrated.net/public_servers.html

    --
    The truth shall set you free!
  26. Re:No "awareness" needed by ScrewMaster · · Score: 4, Insightful

    I think a well-funded spec-ops team would do even more. Make these guys disappear. I mean, hell, if we're gonna live in a police state, we might as well enjoy a few of the fringe benefits.

    --
    The higher the technology, the sharper that two-edged sword.
  27. Hijacking, and San Diego Cox Communications by CherniyVolk · · Score: 4, Interesting


    First, as a person who owns and operates many networks, I would be rather annoyed that someone has hijacked one of my domains, for any purpose.

    To me, a domain name is the equivalent to a land deed, it's a peace of virtual real-estate. It's a representation and label identifying a group of IP addresses which may or may not be associated to a physical device or service. If I have a problem with some other network, I attempt to contact the powers-that-be of the offending network; in good faith, that they would be cooperative.

    Now, I assume many offensive networks out there might not cooperate, or might think that what their network is doing is either legal, moral, or of no harm. Well... I do admit, I block all of APNIC to my mail servers, though, I do not service "customers" either. If I did, I would assume my customer demographic might include a need or desire for correspondence with those in APNIC, and permit the traffic. While I might, on case by case scenerios, filter a range of IPs known for SPAM or whatever, things I certainly wouldn't do is hi-jack a domain, and most disturbingly, attempt to execute code on a clients machine without direct consent for each instance, each time. Basically, what you're doing then is intentionally deceiving a computer system, breaking standards, breaking and entering said computer system, and influencing change which permanently alters HOW that computer operates. And, knowing the practices and the broad generalized sweeping tactics of Cox Communications (for example), I must say I do NOT trust what they MIGHT consider as "malicious" code to delete off my computer "at their whim".

    If this becomes "legal", then what's to stop Cox Communications (for example), from considering my MP3s as "malicious or of questionable origin" and on behalf of RIAA, delete my mp3s? How are they going to know?

    Now, on to San Diego Cox Communications. While I agree that if you are on someones network, you do what they say. However, as already implied above, if my intention is to provide "Internet Service", then I DO inherently forfeit some of that overall power. And Cox Cable, blocking incoming and outgoing ports is really not within their moral obligation to do so. Nothing illegal about them doing it, no doubt some here might agree with them. But, if I'm going to sell someone "Internet Service", as I have in the past, they get "Internet Service" in full. I don't want a parent above me, and most certainly, I should be allowed unaltered Internet Service from Cox Communications on request against the default safegaurds in-place for the sake of the laymen.

    But, Cox Communications does NOT permit one to exercise all of the technologies available. They notoriously block ports, and muck with the traffic. Why? Who knows, and I don't mean to be elitist, but their explanations of some Windows worm really doesn't apply to my Linux box. Besides, if I was running Windows, I still wouldn't appreciate all the port blocking and crap. I'll handle that myself.

    As a result, I refuse to use Cox Cable or Time Warners Road Runner services. (Aside from the fact I'm banned from San Diego Cox Cable's network for running VPN clouds on their network, among other things like DoS'ing everyone on my subnet to boost my download speeds...), I warmly welcome other high-speed services that do NOT play parenthood. Sadly, one practically has to purchase a "Business" line instead of a "Home" connection. So, that's in fact what I have so if I want to launch my own webserver/mailserver, SQL Server or whatever, it's simply a matter of just configuring and launching the daemon.

    In short, I feel hi-jacking is wrong. And I feel that people should not use Cox Cable as they are the "AOL" of today anyways. Such actions are so typical of Cox Cable... it's truelly ridiculous.

  28. Killing Fly with a Bazooka by madsheep · · Score: 4, Interesting

    Well as some have pointed out you can use other DNS servers. However, many people don't have the time/knowledge/or need to mess with this and they really shouldn't have to. Messing with DNS for these purposes is a questionable activity. However, especially in the case of EFNet servers, I find this especially strange. EFNet does have some botnets that end up with them, but they are very few and far between.. and small in nature. These things are taken down pretty rapidly on EFNet and that's part of the reason they're not used frequently. DALnet -- a whole other story. There's tons of active botnets there now. EFNet is definitely much smaller in scale n terms of the number, the size, and the lifespan. This is pretty sad. Redirecting a hacked server being used by an IRCD is one thing. Doing it selective IRCDs on a huge *legit* network.. that's a whole other story.

  29. It's not so much about DNS by ShaunC · · Score: 2, Insightful

    Since it sounds like they were doing it with their DNS servers.
    NO!! This goes far beyond DNS and is extremely irresponsible!!

    A DNS response to a widespread bot infection, a worm attack, or other overwhelming threat would be to claim SOA for the offending domain on your network, and resolve the entire domain to 127.0.0.1. Even that's sketchy, but it's what we might call the internet equivalent of Generally Accepted Accounting Principles. I've seen registrars themselves nullroute a domain and in general there's not much objection, because extreme action is only taken in extreme circumstances. That isn't what happened here at all.

    What happened here is that multiple ISPs rerouted legitimate connection attempts to legitimate network servers to their own, pseudo-C&C servers. Through the hijacked connections, they issued commands (in the /topic and directly in the channel) that may alter or remove software installed on the client PC. Now, maybe the client wanted to have SpamBotFoo installed on their computer, and maybe they didn't, but at what point did they give their ISP permission to remove SpamBotFoo from their computer? Since when is it suddenly okay for an ISP to intercept outbound connections from a customer's PC, reroute those communications to a destination of their choice, and knowingly issue commands to software installed on their customer's PC that would alter the contents of said PC, or worse, remove software from it?

    It would certainly not be legal for me, as Joe Blow, to intercept your packets (for any purpose, good or evil), nor would it be legal for me, as Joe Blow, to use those intercepted packets to attempt to "uninstall" software from your computer, regardless of what that software is. Why, then, is it okay for ISPs to do the same?
    --
    Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
    1. Re:It's not so much about DNS by SanityInAnarchy · · Score: 2

      A DNS response to a widespread bot infection, a worm attack, or other overwhelming threat would be to claim SOA for the offending domain on your network, and resolve the entire domain to 127.0.0.1. Even that's sketchy

      Indeed. It goes even farther -- I don't particularly like efnet, but I do imagine there are still legitimate chat and discussions going on between real human beings. So resolving it to localhost means legitimate connections that have nothing to do with the botnet are dropped in order to stop the botnet.

      The only correct response to this is to sniff the legit connections for what looks like botnet activity (and even that's "a little sketchy", as you put it), and then notify those people that they seem to have a botnet installed. If it was SpamBotFoo, your next step is to watch that user's outbound SMTP, and if they are sending spam, tell them to stop. Third step, you block their account until they remove the bot.

      This is better because it's a long process, and there's always the option for the user to opt out -- to say something like "Ok, I'll just disconnect that computer" or "Actually, that was a sample spam, and no one should be reporting it."

      --
      Don't thank God, thank a doctor!
  30. Transcript of IRC by simpleguy · · Score: 3, Informative

    [ simple1 @ saturn ] ~ $ dig @ns1.dc.cox.net irc.mzima.net
    irc.mzima.net. 300 IN A 70.168.70.4

    Connecting to 70.168.70.4 (70.168.70.4) port 6667.

    [JOIN] You are now talking on #martian_
    [MODE] localhost.localdomain sets mode +n #martian_
    [MODE] localhost.localdomain sets mode +t #martian_
    [TOPIC] Topic for #martian_ is .bot.remove
    [TOPIC] Topic for #martian_ set by Marvin_ at Tue Jul 24 09:48:56 2007
    [TOPIC] Topic for #martian_ is .remove
    [TOPIC] Topic for #martian_ set by Marvin_ at Tue Jul 24 09:48:56 2007
    [TOPIC] Topic for #martian_ is .uninstall
    [TOPIC] Topic for #martian_ set by Marvin_ at Tue Jul 24 09:48:56 2007
    [TOPIC] Topic for #martian_ is !bot.remove
    [TOPIC] Topic for #martian_ set by Marvin_ at Tue Jul 24 09:48:56 2007
    [TOPIC] Topic for #martian_ is !remove
    [TOPIC] Topic for #martian_ set by Marvin_ at Tue Jul 24 09:48:56 2007
    [TOPIC] Topic for #martian_ is !uninstall
    [TOPIC] Topic for #martian_ set by Marvin_ at Tue Jul 24 09:48:56 2007 .bot.remove .remove .uninstall
      !bot.remove
      !remove
      !uninstall

    Thats it.

  31. This is bad....*how*? by IonOtter · · Score: 2, Funny

    TWC: "Sir, you have an IRC bot on your machine that's making DDoS attacks."

    Majority Computer User: "'IRC'? I'm seeing who??? Who am I seeing and when? Why am I seeing them? What're you talking about?!? Am I being charged for this?!? OMG, did Billy download music or movies or something?!? Oh Jesus Christ I'm going to kill that brat! Oh God, did you report me?!? I'm going to jail, aren't I?!?"

    TWC: (sweatdrop)

    So. Explain to me how castrating bots without disturbing or distressing the vast and overwhelming majority of computer users is a bad thing?

    --
    [End Of Line]
  32. The Golden Rule by BillGatesLoveChild · · Score: 2, Informative

    OP asks "Is this the right way to handle the botnet problem? Is hijacking DNS legal?""

    A good question. Let me check for you.... Hang on... looking up Time Warner's Bank Balance. Uh huh... HOLY COW!

    In answer to your question, yes, DNS hijacking is most definitely legal.

  33. Treacherous Computing by Dr_Barnowl · · Score: 3, Interesting

    Yes, the solution you propose is possible, and indeed, in progress.

    You've probably seen something similar when you have to install an ActiveX control in IE (for a bank, or Windows Update). It asks i) if you'd like to install it and ii) If you'd like to trust the publisher in the future.

    The binary is cryptographically signed which assures the computer that it is a product of the authorised holder of a particular crypto key. MS already uses this scheme for device drivers on 64-bit versions of Vista - at present, it can be disabled by a technically oriented user, but there's no guarantee that ability will persist.

    The downside is twofold - firstly, for this measure to have any teeth, you have to remove the ability of the user to ignore it. Secondly, it provokes ideas like Microsofts "Trusted Computing" initiative (aka "Palladium"), which hands over full control of your computer to a short list of people who know the secret keys embedded in your motherboard. The main motivator for requiring signed drivers in Vista is to prevent the loading of things like virtual devices which can be used to capture perfect digital copies of DRM protected media. A secondary consideration is quality assurance.

    http://www.gnu.org/philosophy/can-you-trust.html

    At some point it is inevitable that MS operating systems will produce an API that permits calling programs to determine the presence of unsigned drivers or software, and refuse to perform certain functions (like playback of DRMed media). Heck, this shouldn't be hard to implement right now with a little effort. With TP, because the only trusted root certificates will be stored in inaccessible firmware, there will be no way for the user to sign drivers himself and mark them as trusted. Therefore MS (and anyone they care about pleasing) will be in control of what your computer can or cannot do.

  34. Re:Since when is Cox = Time Warner? by makomk · · Score: 2, Informative

    The answer is, both are doing it. Apparently, there are different techniques - one lot is using forged DNS responses to redirect connections to their own server, and the other is intercepting packets to port 6667 on certain IP addresses and sending them to their own server.

  35. Re:Fair game by dougmc · · Score: 2, Interesting

    Anything goes on the Eris Free Network. OK, it's nice that you know what EF stands for in EFnet, but what you may have missed is that when the IRC network (it didn't have a name back then -- it was just `IRC') split, it split into AnarchyNet (or just Anet) and Efnet. There was no need for names before that, but after that, those are the names that were chosen.


    Anet was the one where `anything goes', and yes, it did have a server called eris. The big thing that went on Anet that didn't go on Efnet was that new servers didn't need a password to connect to the existing network (well, the server `eris' was like this anyways -- I don't know if others were too) -- anybody could bring up a server. Which sounds fine, this also means that these people can make themselves IRCops on their new server and can abuse that, and it's also simple to kill anybody off on the existing network just by pretending to be a server via some simple telnet commands. Anarchy. Anet died off pretty quickly.

    This page is pretty informative.

  36. This is the ISPs fault by humankind · · Score: 2, Informative

    I find it ironic that Time Warner is going at this from the wrong end of the problem. If they filtered port 25 traffic from broadband DUL space, the spammers wouldn't be interested in invading their customers' machines. It's almost always about spam. The fact that most of these ISPs do little to stop their customers' machines from being zombied, or anything to reduce the viability of them being exploited, shows how much they really care about the customers. All broadband ISPs should now be filtering SMTP traffic on their networks. Anyone that wants to run their own mail server can set up alternate ports and use special IP space designated for SMTP traffic. This would make the botnets obsolete.