Online Attack Hits US Government Web Sites
angry tapir writes "A botnet composed of about 50,000 infected computers has been waging a war against US government Web sites and causing headaches for businesses in the US and South Korea. The attack started Saturday, and security experts have credited it with knocking the Federal Trade Commission's (FTC's) web site offline for parts of Monday and Tuesday. Several other government Web sites have also been targeted, including the Department of Transportation."
ok let's blame China now for this.
The best defense is always a good offense. Why not launch an attack on North Korea? We have far more advanced technology and could probably cause more damage to them than they could cause to us. If we are crippling their systems, they won't be able to attack ours. I would love to see our government take off the gloves in the cyber world for a change rather than always invading everyone.
Just because you are wrong and I called you out on it doesn't mean I am a Troll.
4chan has been down also
Every reaction will result in a counterreaction. And with each itteration, things enhance. Now it is some group of assholes. When you take this cyber asshattery into the realm of militairy warfare, you can nolonger stick it undert the label of web-security, it becomes a... war activity. Who would you attack? The zombied systems? Or just govermental systems of a nation who you PRESUME to be responsible for the attack? And then the counter attack is made officially by the USA militairy, not an anonymous group. Nobody wins... except the asshats behind the original attack.
I'm just curious when or if rules are going to be put up about Internet sovereignty, so that an attack on a website is seen as an act of war.
I can totally see a situation where a US gov't website or economic hub (e.g. stock exchange servers) would get hit by a series of computers based out of N. Korea, the US declares war on N. Korea for violating US internet sovereignty, and the whole thing was a setup by a third party looking to create and exploit a power vacuum.
Maybe I've been reading too many NetForce novels, but the whole idea scares me, and I have the feeling that most people in America wouldn't understand why... particularly the people who make the laws about this kind of thing.
Whenever some whacko grabs a gun and kills a bunch of people, the hew and cry is for "gun control". When someone takes a computer and attacks government sites, and other important infrastructural servers, where is the cry for "Computer control?"
Why are people who harbor botnets not as guilty as those who harbor criminal and terrorists? If you let someone use your garage to store gasoline/petrol for Molotov Cocktails, you'd be arrested.
What was the OS and browser of the botnetted collaborators? Wouldn't it be fun if the FBI knocked on the doors of those whose machines were "hijacked*" and brought their computers in for questioning?
*I use the phrase 'hijacked' loosely. If a person leaves the car running, the keys in the ignition and the windows down (pun intended), can they say that their car was 'stolen'?
How much connectivity does NK have? How hard would it be to just cut them off for a day and see if all the attacks cease? It's not like NK wants anyone other than the military to have access to any information anyway. I don't think a severed backbone would inconvenience the general population in the slightest.
Niggerbuntu is a Linux-based operating system consisting of Free and Open Source software for laptops, desktops, and servers. Niggerbuntu has a clear focus on the user and usability - it should "Just Work", even if the user has only the thinking capacities of a sponge. The OS ships with the latest Gnomrilla release as well as a selection of server and desktop software that makes for a comfortable desktop experience off a single installation CD. It also features the packaging manager apeghetto, and the challenging Linux manual pages have been reformatted into the new 'monkey' format, so for example the manual for the shutdown command can be accessed just by typing: 'monkey shut-up -h now mothafukka' instead of 'man shutdown'.
Absolutely Free of Charge
Niggerbuntu is Free Software, and available to you free of charge, as in free beer or free stuffs you can get from looting. It's also Free in the sense of giving you rights of Software Freedom. The freedom to run, copy, steal, distribute, share, change the software for any purpose, without paying licensing fees.
Free software as in free beer!
Niggerbuntu is an ancient Nigger word, meaning "humanity to monkeys". Niggerbuntu also means "I am what I am because of how apes behave". The Niggerbuntu Linux distribution brings the spirit of Niggerbuntu to the software world. The dictator Bokassa described Niggerbuntu in the following way: "A subhuman with Niggerbuntu is open and available to others (like a white bitch you're ready to fsck), affirming of others, does not feel threatened by the fact that others species are more intelligent than we are, for it has a proper self-assurance that comes from knowing that it belongs to the great monkey specie." We chose the name Niggerbuntu for this distribution because we think it captures perfectly the spirit of sharing and looting that is at the heart of the open source movement.
US General: Bring me Bill Gates
(Bill Gates walks in)
US General: YOU TOLD US WINDOWS WOULD BE FASTER AND MORE SECURE WITH BETTER ACCESS TO THE INTERNET!!!
Bill Gates: It is more secure, over five million ti
(US General pulls out a gun and shoots him in the head. Gates falls to the floor, dead)
I'm sorry, but if this has nothing to do with Michael Jackson, apparently no one cares.
-- I really need to bleed off some of this
US Government websites attacked... but slashdot is OK so what the heck.
As suspicious as North Korea may be, with this incident, there is no proof that they are the culprits. Assuming that North Korea is behind it and acting accordingly could have disastrous results even if they are right. (Also see: Intensifying the conflict much)
These aren't the bots you are looking for. You can go about your business
I will not be pushed, filed, stamped, indexed, briefed, debriefed or numbered. My life is my own.
Seriously, if SC2 were out already those Asian tweens would have something else to keep them busy.
mmmm...forbidden donut
Honestly, when was the last time you went to ftc.gov? Nobody goes to those sites...
Now if google, wiki, or itunes goes down, then PANIC!
Its the July 4th weekend. They were probably down for maintenance and it took longer than expected.
What would you tell your PHB?
All that is required is to pull the damn plug on these bots. Each of these machines has and IP address which it advertises every time it makes an attack. That's right folks: The return IP address is part of the header. You can't route packets without this information.
These feral packets _ALSO_ come into the ISP's routers. It is easy to identify them. Uninfected machines don't normally sit there and hammer away at port Blah. Some of the worst ports are 80 (html), 25 (mail) and 22 (SSH).
One really needs to only look at the ports that the botnet tries to exploit.
A simple solution is to pull the plug. A solution which is slightly more difficult is to block the ports the botnet is trying to attack on and then redirect any web access to a banner page advising the owner their machine is cracked and what to do about it... or a tech could phone the client.
_any_ ISP can do this. If they don't do it then they don't want to. As for consumer rights - crap! Its the ISP's which write the Terms of Service. They can put pretty much any terms they want providing said terms are considered reasonable. The public will probably not object. Spammers might however but then who cares if they can't find an uplink.
So the first place to start is at the ISP level.
Next: I've blocked botnets of more than 50,000 machines. I use OpenBSD on the webservers and on the firewalls. Its not that hard to do. Pf can easily handle this. If the server admins over at the "US Government Web Sites" can't handle this then IMHO they are incompetent. If reference, here is an example of how to block these bots in PF:
pfctl -t spammers -T add 190.174.220.241
pfctl -t spammers -T add 67.10.200.220
pfctl -t spammers -T add 125.161.37.199
pfctl -t spammers -T add 71.218.209.198
pfctl -t spammers -T add 202.28.120.19
This is a shell script BTW. extracting the list of bots can be done by scanning the appropriate logs.
Government website?
"and nothing of any value was lost"
I am concerned that a sizable government department can't repel attacks from - allegedly - North Korea.
Sorry about the attack guys, tripped on a bag of dorrities and hit the wrong button. My bad.
They mentioned that there is a botnet of about 50000 computers that are infected which composed the attack.
It would be helpful if they provided a method for users to check to make sure that their systems are not part of this.
What on Earth gave you the idea that it was North Korea that did it?
As you have so insightfully put it "How much connectivity does NK have?".
Japan on the other hand has a lot more connectivity, and a huge bone to pick with both US and SC.
Or how about China? India? Germany? Vatican?
Even if the botnet CAME from a particular country, with each attack being accompanied by spamming of the mailboxes around the world with the .mp3s of the national anthem of the particular country - that is still NOT EVIDENCE that said country had anything to do with it.
It could all be work of a drunk Australian hacker for all we know.
Mit der Dummheit kämpfen Götter selbst vergebens
Skynet is online....
Japan.
Granted, Japan from 60-70 years ago but still...
How would USA feel about someone dropping not one, but two nukes on them AND robbing them of say... Texas (Korea)?
Mit der Dummheit kämpfen Götter selbst vergebens
I'm surprised no one has mentioned this yet, but to me it seems like a perfect solution. Warn a country with an official statement and 24hrs response required. Deploy autonomous cable cutting vehicles, then (if necessary) press the cut cable button at 24:00.01. If you want your computers to talk to our computers on the network we invented; you get to play by our rules or you don't get to play at all.
"Be prepared, son. That's my motto. Be prepared." --Joe Hallenbeck
...a WILD GUESS that Korea had anything to do with it.Possibility or even opportunity can not be considered proof.
Heck! It could have been Michael Jackson. In his sleep. Maybe he died from shock when he found out what he (his other self, that is) did?
It IS possible!
Mit der Dummheit kämpfen Götter selbst vergebens
Comment removed based on user account deletion
Comment removed based on user account deletion
The funny thing is, it's now somewhat difficult to see the troll posts, unless some idiot replies to them. Then you can show the parent from the reply.
Otherwise, add no_d2=1 to the params in the url.
Apparently cyber-warfare isn't an issue, at least according to Slashdot commenters a few weeks ago.
Any /. user could personally swamp North Korea's 56k leased line and their rack full of diesel-powered Pentium II boxes. For the US or China, it's not worth the trouble.
Give a man a fish and you have fed him for today. Teach a man to fish, and he'll say "WHERE'S MY FISH, YOU IDIOT?"
The problem in Iraq was that the US came in to stomp a religious body. Even after having lost the religious organization that had been in power is not willing to give up.
If the US went in and stomped NKorea, they'd be assaulting a political ideology. Something that traditionally people are a little less attached to than religion.
(not that idealogues are unwilling to die for their politics, but there generally seem to be fewer than in religion).
We need to establish a day to have all of the non-computer geeks (geek squad included) bring their computers and have them cleaned out.
Essentially, take the hard drive out, make a copy, wipe the sucker, reinstall an OS, copy any precious files and nuke the copy.
I saw... its thoughts. I saw what they're planning to do. They're like locusts. They're moving from planet to planet... their whole civilization. After they've consumed every natural resource they move on... and we're next. Nuke 'em. Let's nuke the bastards.
4chan is also down right now. Coincidence? Or is it part of the same attack? Take out the government websites, and the only website full of enough script kiddies to fight back.
Or someone is having some good lulz about now.
You hate China
Any news on which webservers are affected (apache or IIS), and which vulnerability was used in this attack?