Ask Security Guru Dave Dittrich About DDoS Attacks 274
Yes, this is the University of Washington Dave Dittrich behind the software the FBI is trying to get you to use to help find the people doing the massive DoS attacks that have made headlines all over the place. Learn more about Dave and check out the info about the current brou-hah-hah on his home page, then ask away. We'll send the 10 - 15 highest-moderated questions to Dave Friday evening, and post his answers as soon as he can get them to us in between answering questions from mainstream media types who, as you can imagine, are all over him right now.
why is it such a memory hog? (Score:1)
Re:Why exactly should the average citizen care? (Score:1)
Re:Why exactly should the average citizen care? (Score:1)
Re:Why exactly should the average citizen care? (Score:1)
Send down four skin divers!
Various questions (Score:2)
THIS IS FAKE (Score:2)
I was hit with this - what's wrong with Yahoo!? (Score:2)
A week or two before Yahoo!, CNN, and other big name companies were hit with this denial of service attack, some people (the same ones??) decided to try and take over one of the channels one of my machine's eggdrop bots runs. The attack lasted approximately 6 hours from beginning until end. When all was said and done, the network usage at Carnegie Mellon was 100% saturated and I received an e-mail in the morning that I had tried to crack a computer in the department of energy services (wherever that is).
Now, the box is usually not under too much of a load, but does have several purposes - it is an FTP server, and a file server (I play my MP3s from it).
All throughout the attack, my box actually held up against the attack! I was able to keep playing my MP3s, I was also able to continue (at a very slow pace however) my FTP transfers.
What I want to know is if MY box (and Carnegie Mellon in general) could stand up to the DDoS attack, why shouldn't Yahoo! and CNN and other huge companies have enough network infrastructure to waylay such an attack? Was it just that my box was hit on a very low scale? Or are corporate networks just not up to snuff?
"Zombie" client profile -- Windows or Linux? (Score:2)
Dave, we've seen several reports implicating Solaris and Linux specifically in the DoS attacks, and the tools provided by you and the FBI are aimed at Linux and Linux-like operating systems. Are these OSs representative of the actual clients which are being co-opted as zombies to launch the DoS attacks, or are they merely typical upstream or intermediate systems with sufficiently rich toolsets to allow monitoring and filtering of traffic.
Information I'd heard from someone who'd experienced an attack was that clients were in fact most typically Windows machines -- which makes sense as they are very common and very easily compromised. The compromising code was described as a windows or Java virus time bomb, pre-set to launch against a specified site at a specified time -- somewhat different from the "master" and "slave" scenario described in the trinoo papers. Several copies of the virus have been retained. How does this fit with your experience?
What part of "Gestalt" don't you understand?
Is a network proof against DDoS possible? (Score:4)
--
Who can fix this, hardware people or software? (Score:2)
Re:Why exactly should the average citizen care? (Score:1)
Well that's just spanky. At what point do we point to a rich private citizen and say "Okay chum, you're on your own!". Just because they're big and nasty doesn't mean they're not entitled to the protection of the law. What if they started enforcing their own laws? I mean, you're saying the burden of responsibilty is on them, wouldn't they be entitled to do so? I for one shudder at the thought of Microsoft coming up with and enforcing their own laws! :)
Corporations because like so many of the people here have said are EEEEEEEEEEEEVVVVVVVVVVVIIIIIIILLLLLLLL and are akin to the Third Reich in their effect
Hmm, does this count as a Hitler reference?
Re:Why exactly should the average citizen care? (Score:1)
<sarcasm>Well, I for one will sleep well at night knowing you're the one making these decisions for us.</sarcasm>. What is this, some kind of Slashdot Inquisition?
I was forced to use the internet to get what I wanted ...
In the early years of the third millennium, to combat the rising tide of corporate unorthodoxy, the Pope gave Cardinal slashdot-terminal leave to move without let or hindrance throughout the internet, in a reign of violence, terror and torture that makes a smashing post. This was the Slashdot Inquisition...
I'm no fan of evil corporations either, which is why I support the justice department when it goes after them. I also support privacy groups that look out for our rights. However, I recognize that without corporations we wouldn't have all that we have today... like the Internet! Tell you what, as soon as you figure out a way to send IP over smoke signals you let me know and I'll join your inquisition. ;)
Re:illegal? (Score:1)
I find it very difficult to belive you can't go work at Burger King for a week to earn enough money to buy a new modem.
And if some punk kids slash my tires on the way to work, yes I do feel cheated.
basic internet infrastructure (Score:1)
I just checked, noone's asked this one yet. Which of the proposed improvements in the internet's infrastructure (IPv6 et alia) do you think will actually do something about distributed DOS attacks of this nature?
Re:illegal? (Score:2)
First of all simply taking down a web site costs a company a huge amount, These web sites are the places where these companies conduct commerce. If they are not online they are loosing money.
Second, I can see this as being a form of Rackateering. I'm not sure how the law is written, but I can see them being hit under the RECO laws that were ment to hit the mob, They are using an interstate attack to stop a legit biz.
Third, Stock Fraud, Imagine that the people who did this took a short position on stock in Yahoo, then slamed the server, the stock goes down and they make a fortune. It does not take a big movement of the market to make (or lose) a lot of money for a lot of people. And this is definitly insider trading.
I'm sure the FBI and the DOJ will find a few others too. I hope they nail whomever did this one to the wall.
Re:Automated hacking? (Score:1)
I don't believe all the conspiracy theories for a second. It was a single guy, or a very small group, and they were just trying to show off who's got the longest. It's been going on on IRC for ages.
The Constant Fingerprint? (Score:3)
contains a covertly channeled service denial command.
What's more insidious is that I don't think we're going to even be able to determine the nature of an attack in progress. Given enough compromised clients, it's more than conceivable that enough pseudo-browsers surfing at a humanistic rate could take down at highly database-driven sites, not to even mention overload the maximum number
of streams a multimedia site can supply. Such an attack would only reflect itself as the attack of the <a href="http://slashdot.org/comments.pl?sid=00/02/0
If we won't always be able to detect the initiation of these attacks, and we won't always be able to detect the commencement of these attacks, would it be fair to say that the only moderately reliable fingerprint of an looming attack is the single packet or set of packets that compromised the OS into loading the attack daemon in the first place?
If so, how can we use such fingerprints to our advantage? Should arbitrary core routers initiate tracer logs and NOC notification when large scale OS compromise fingerprints are detected?
Yours Truly,
Dan Kaminsky
DoxPara Research
http://www.doxpara.com
Re:Answer: not viable (Score:3)
Nope, Sig. You need stateful analysis when you cross the single packet barrier--for example, when the presence of an outgoing SYN creates a temporary tunnel through the firewall for an incoming ACK of a given Port/ISN+1.
It's just a comparison of the 32 bit Source Address with the 32 bit Network Address of the physical interface. That kinda thing doesn't even require Store And Forward...it's one or two AND ops. Where you start getting problems is when you have a layer or two of peered networks...but how many universities route packets for eachother?
Yours Truly,
Dan Kaminsky
DoxPara Research
http://www.doxpara.com
Stop Spoofing At The Backbone? (Score:4)
Yes, you obviously get problems as peering scenarios get traveling-salesman levels of complexity, but most sites (to my knowledge) don't exceed more than a few levels of peering--we should take advantage of this fact to enforce a top down elimination of infinite source spoofability? And, if so, would the precedent that this creates help or hinder the growth and freedom of the Internet?
Yours Truly,
Dan Kaminsky
DoxPara Research
http://www.doxpara.com
Re:Answer: not viable (Score:4)
Not necessarily, anymore. L3 Switching and even L4 Switching is quite hot nowadays. Matching bits and ANDing them--that's what switches do, and that's what IP Interface checking does. L3 and L4 switches essentially match more bits in their quest to do better and more accurate QoS. I'm not absolutely sure if Cisco's switches will do the IP range checking, but I wouldn't be surprised if they did it in hardware. Sig, it's a cheap operation.
> A router works at a higher level, and CAN do
> stateful analysis... but for speed you really
> shouldn't - that's what the firewall is for.
> Firewalling the backbones would be... umm..
> very bad.
For cryin' out loud, this has NOTHING to do with State. Either I'm sending out a packet on a bogus source, or I'm not. This contrasts *heavily* against "Firewall receives an ACK packet--is it spoofed, or is it a response to a pre-existing SYN? Better check the state..."
I'm not talking about firewalling the backbones, only the entry points. And what the hell do you think Yahoo screamed at their ISPs to do when lots of traffic was coming down the pipe that had nothing to do with the Web? "KILL EVERYTHING BUT PORT 80!"
That's not firewalling the backbones. That's managing the access points.
Yours Truly,
Dan Kaminsky
DoxPara Research
http://www.doxpara.com
Just so there aren't only questions on DoS attacks (Score:2)
I'm currently looking for a job and I am very interested in the security side of System Administration. My question: Could you give a SysAdmin wanna-be some helpful advice, ideas, suggestions, etc. concerning career path? In my particular case, I don't have a CS or MIS degree (Liberal Arts actually) and about a year and a half of experience as an operator. I'm a Linux user and read O'Reilly books aplenty. Any advice would be greatly appreciated.
----------------
"Great spirits have always encountered violent opposition from mediocre minds." - Albert Einstein
Re: Please provide find_ddos source code (Score:2)
Not only that, but some of us can't run it even if we wanted to (and without source, I wouldn't want to anyway). Where's my Linux/Sparc executable? What about one for my DGUX/m88k machine? The internet is not just Linux/x86 and Solaris.
Re:Other methods? (Score:3)
I'm no IPv6 expert, but as I understand it, space is reserved for this information in an IPv6 packet, but it's not mandatory to fill it, it's only recommended. Maybe someone who knows more about IPv6 can confirm this?
there is - sm611551511357 (Score:2)
Did the Government Know of this in Advance? (Score:1)
What I am curios to know is, say that you have this foresight, that these attacks are likely to come. What could large sites, such as Yahoo!, do to help prepare for the coming onslaught?
Re:illegal? (Score:1)
Re:illegal? (Score:1)
Of course. The people were purposely trying to bring a large web site to its knees - malicious intent.
Furthermore, they illegally employed the use of other people's computers to purpotrate their crime.
Imagine you did some action to congest the highways of a large city with road blocking thingies. Imagine you got caught. Would you be arrested? I'd bet so... and you'd probably be fined or put in jail for a short while.
Motive for DDos attacks? (Score:1)
Okay, we have heard a few.. Geeks trying to "have fun", electronic protest, NSA/Government conspiricy.
Question: Are all the targets NASDAQ companies?
Remember when eBay crashed a while back and it's stock took a huge bite over the deal? Imagine if you had a very large investment on a "Sell Short" bet.
Say I "Sell Short" a million dollars worth of Yahoo! stock, then pound on Yahoo! to cause the stock to drop. However we noticed it did not drop the first day so we have to do it again the next day etc...
What do you think? Instead of making a DDos sniffer, I would look for a Yahoo! competitor to be purchasing "shorts" of Yahoo stock.
Re:Why exactly should the average citizen care? (Score:1)
Taking down a dot.com company is like grounding an airlines fleet.
hahaha (Score:1)
( just a little demotion, eh? )
Re:Steve Jackson Games?? (Score:1)
Ask Dave: Why you want to help the FBI? (Score:2)
This question might be seen as a troll, but it is not.
Why do you want to help the FBI, Dave?
The FBI is an apparatus for the Big Brother, the same Big Brother which has taken away so many of our basic rights, and the same Big Brothers which has done a lot to limit our rights online !
Why are you helping the FBI, Dave?
Distributed scanning? (Score:2)
I would like your opinion both on whether this is doable and whether it would likely prove useful.
Thanks,
Ben
Answer: not viable (Score:1)
It's just not practical right now at the backbone level - not without a major, major overhaul of the existing system. Besides.. how do you define a DoS attack in the first place? It's easy to spot one now.. but what about 80k queries/sec that all look like legitimate traffic? How do you filter THAT ?
Re:Answer: not viable (Score:1)
A router works at a higher level, and CAN do stateful analysis... but for speed you really shouldn't - that's what the firewall is for. Firewalling the backbones would be... umm.. very bad.
Re:Answer: not viable (Score:1)
trust (Score:2)
Why should businesses and individuals trust the government?
As a business, why should it try to help the FBI? I've seen and heard about "busts" which leave a company high and dry. As a business, I wouldn't want something like what happened to Steve Jackson Games happen to me. If you want the support of both businesses and individuals.. what are you doing to assure them that you won't use heavy-handed tactics like stealing their computers or data? More institutions would come forward with their logfiles and information if they knew the FBI could be a) trusted with that information (there has been rumor that agencies like the NSA give out trade-secrets to shut down competing industry) and b) would not conduct an investigation of a scale or type which would interfere with normal business operations. I don't want to hear about how "illegal" such operations are.. I want to know who's accountable when such abuses are made, what procedures are in place to deal with such a contingency, and how effective these measures are.
If you want to help national security - drop the pretenses and be honest with us.
Re:Motive for DDos attacks? (Score:2)
Doesn't have be a "Yahoo! competitor" -- it can be some lamer day trader with a short position on his ETrade account.
Re:Long term solutions? (Score:3)
You write:
But is that really true? If every router refused to pass packets that clearly lie about their origin, IP spoofing would be a lot harder to do.
Re:illegal? (Score:1)
Re:Questions of Jurisdiction, and coordination. (Score:2)
Of course, I have a very hard time imagining the Clinton Administration taking any kind of for-real action against terrorists. Remember his Great Crusade Against Terrorism in 1998? The one that coincided with impeachment, and dropped off radar in February 1999?
Collateral Damage (Score:2)
Is collateral damage a concern? I mean, if a site like Yahoo! is hit with a gigabit of data per second, won't that take up a lot of the bandwidth between the DoS clients and the target?
Or are these sites so close to the Internet backbone that the additional traffic is localized?
--
Seriousness of these attacks? (Score:2)
I know you're not a shrink or a sociologist, but I'm still very interested in your opinion: What is it about these smurf attacks that the people find so facinating, or horrible? Do they really pose that serious a threat to network security? Why do the media find it fascinating?
BTW, the DDoS scanner is a nice hack. Thanks for releasing the source!
Re:Recognizing DoS (Score:2)
In Quake, bots can be used to aim and fire weapons, and they're dealy efficient. How do you tell the difference from an exceptional human and a standard aiming bot?
With the schemes that pay you to surf, they try to make sure that someone is actually at the computer being exposed to the ads. They do this by monitoring mouse and keyboard activity. They claim to be able to detect bots, but I recall a quote from one CompSci professor who said that he'd fail any of his students that couldn't produce an undetectable bot.
In the real world, you can tell that a traffic jam is artificial when you see the truck parked across the road, but how do you detect a DDoS attack with a low probability of false positives (or false negatives)?
Re:Other methods? (Score:1)
The Silver Bullet against future DoS Attacks (Score:2)
Internet Worm -- Episode 2 (Score:3)
Re:Antionline: True help? (Score:1)
Ut-oh. Maybe ole JV will try to sue me now.
Antionline: True help? (Score:3)
Re: Please provide find_ddos source code (Score:1)
You need to ask whoever it is that is administrating the web site at the FBI why there isn't source code available.
Re:Stop Spoofing At The Backbone? (Score:1)
Thanks.
Way to go! (Score:1)
Way to go Dave!
Re:Why exactly should the average citizen care? (Score:1)
You can't use math like that. Sure - they expected that revenue during the 2 hours. What happened to those who couldn't buy? They didn't <I>all</I> run to a competitor. Some did what you always do with net trouble: waited, and tried again. Amazon probably had a period with slightly more sales than normal right after the attack, due to people catching up. Sure they lost some, but not all!
Re:Why exactly should the average citizen care? (Score:1)
You might as well ask "why should the average citizen care about shoplifters hitting large supermarket chains, large banks robbed, and so on?"
The same answers applies.
Re:Is a network proof against DDoS possible? (Score:1)
This has nothing to do with IP, or even computers. Parts of the phone system get blocked from time to time in the same way - for example when a popular TV show advertises a phone number. "Call inn first to get a prize..."
So there is no solution as long as thousands of machines are available for breaking in. Fixing that still leaves stuff like "Tomorrow is the day when <I>everybody</I> looks at the MS website" or
"Lets <I>all</I> call their shitty ordering number simultaneously" The only difference is that the latter two cases require cooperation by an interest group, while the DDOS attack simply require the "cooperation" of crackable machinery.
Re:Other methods? (Score:1)
Nope. First, IPV6 don't need to contain any MAC addresses. Second, you would merely track down the compromised systems. You can do that already using IPV4. It doesn't help, unless having a crackable machine becomes illegal. Third, these people are breaking rules already and wouldn't worry a bit about putting fake info in their IPV6 packets. Possibly causing trouble for some third party as well when angry but clueless sysadmins are misled onto them.
Re:A solution (Score:1)
where are the logs?? (Score:2)
Should security research be done in obscurity? (Score:4)
Recognizing DoS (Score:4)
The analogy to the "real" world is roads and bridges. During normal hours, they run well. During rush hour, they clog up and perform poorly. And during a demonstration (like recent examples in Seattle and Miami), they clog up and perform poorly. You can consider the recent anti-WTO situation up in Seattle to have been a DoS attack on downtown. But you wouldn't consider gridlock at 5:30PM in Los Angeles to be a DoS attack.
To solve these problems, you have to know what's causing it. If it's just normal traffic and the infrastructure is insufficient, it gets ignored until people get fed up enough to vote more tax money into building wider roads or better public transportation (again, analogous to buying more servers or a fatter pipe). If it's demonstrators, you either address their concerns or you send in the National Guard to beat the crap out of them (depending on the political climate).
In this world, it's easier to differentiate the two situations. If a bunch of cars are jammed together at rush hour, you know it's a traffic problem. If it's crowds of people singing songs and holding signs, you know it's a demonstration. And if it's a possible sick-out at Northwest Airlines, you're not sure if it's a DoS or not, so you get a warrant to read their home email and find out.
With computer protocols, though, usage and abuse can look identical. Even wild surges in activity can be from legitimate usage. How do you forsee systems being put in place that can differentiate between actual usage and DoS? Doesn't this almost inevitably lead to some non-forge-able, traceable, unique identifier? And doesn't this translate to the demise of privacy on the web?
Questions of Jurisdiction, and coordination. (Score:2)
Hey Rob, Thanks for that tarball!
Re:Firewalls for Dummies? (Score:2)
The Internet is being marketed like eye candy and everyone I repeat EVERYONE wants everyone to get on the "NET". These newbies and MSCE dime a dozen sys admins are setting up the whole net for a big crash. There is NOT WAY to protect the stuipd and lazy from crackers. Everyday there is more fresh meat for the crackers to exploit. Secure 3 systems and 20 more hit the net for the first time. I have scanned my subnet on RR and I have found people with their systems wide OPEN, I could have printed on their printers for christs sake.
This issue is about locking down systems connected to the net. That is where the whole problem started. The best admin can't be expected to keep up with all exploits on all of his systems all the time, but he should have this Internet pointed systems LOCK DOWN and a good firewalling/auditing plan in place to help him out.
If we can't get admins with big pipes and big iron to keep the lid on their systems how in the world do you think Joe PIII 750 with a DSL is going to fare ?
A persistant Internet connection is not a toy. People should have to take a class before they
are giving such a powerfull weapon. People have had to take driving tests for years and everyone is better off for it. I wager that I could cause more damage with my computer then with any type of moter vehical any day, of course nobody would get killed, but we seem to have even put a price tag on that as well.
Re:A solution (?) (Score:2)
#include "disclaim.h"
"All the best people in life seem to like LINUX." - Steve Wozniak
IPv6 and the Press (Score:2)
For the Slashdot community: Is now the time to start pushing IPv6 to the World At Large, since IPv4 now has two large weaknesses (spoofing and small address space)? And what would you say to convince them or unconvice Slashdot readers?
As you respond to this question, could you please reply in a fashion such that on-looking journalists can quote you to the general public?
Re:The question that we all REALLY want answered (Score:2)
at least, that's more or less how Linus pronounces it... which is the only thing that really counts...
Re:Antionline: True help? (Score:2)
Estimated "damage" (Score:2)
(I know sites like eBay and Amazon, for example, do a lot of business, but really, millions of dollers lost? If I really wanted to buy the book, I could wait three hours till the site was back up, and they wouldn't lose any money. Where do these numbers come from?)
Jazilla.org - the Java Mozilla [sourceforge.net]
Re:illegal? (Score:2)
Government (Score:3)
DDoS attacks ARE a problem. I could imagine that they could serve as terrorist/psychological attacks in time of war. Because the computers that are doing the actual DoS attacks could be within the country being attacked, the attacks would be nearly impossible to stop at the borders.
Traffic Analysis (Score:2)
correctly rather than flooding the network, at the pain of being
blacklisted. Could similar traffic analysis tools stop DDoS? How
might this work, or if not, why not?
It co$t$ you lot$ of buck$. But silver lining. (Score:2)
Because it cost the targets a lot of money. And they'll have to make that up. So their prices will go up to make it back. Which means their competitors don't have to cut prices as hard. And Joe Random Consumer ends up footing the bill.
And that's YOU, friend.
And meanwhile, the law enforcement people will spend a lot more money hunting down and prosecuting the perpetrators. Paid for by YOUR tax money. And so your taxes go up, or your other services go down. Bucks out of your pocket again, or inconvenience because your road wasn't fixed or whatever.
And sysadmins at ISPs and thousands of sites all over then internet will spend a bunch of time thrashing around over the issue. They don't work for free. Cost of internet service goes up - or doesn't go down as fast. That gets folded into the price of everything the ISP's customers sell, and into your internet bill. Meanwhile you don't get other fixes as fast.
I could go on.
But there's a silver lining:
The digital anarchy will start patching this set of holes. This kind of DoS attack will get harder, and an unmodified version may become impossible. The net will be more robust.
Script Kiddies or Cyber Terrorists? (Score:2)
Further, _if_ it is a protest, does it make it any less wrong? Let us assume for a second that a group calling themselves the "Anti-Open Source Brigade" starting shutting down Slashdot regularly, out of the sincere political conviction that Open Source was really a terrible evil? Forget that their logic may be flawed; these are a group of committed, idealistic young men who knock Slashdot off-line quite successfully for hundreds of hours during a two month period. And not just Slashdot: Freshmeat goes down, and all of the Anodover sites, and Redhat, and every important Open Source proponent site on the 'net? Is it okay because their motives were pure?
Lastly: if this were MS going down, how many cries of jubilation would we be hearing on Slashdot? And would it makes us hypocrites?
Long term solutions? (Score:2)
Short-term, your tools help act as "virus-checker" type solutions. In terms of long-term solutions for DoS+spoofing attacks, the main one I've seen proposed is to convince all ISPs to filter their outbound traffic to prevent outbound spoofing of packets claiming to come from other networks.
Given that IP spoofing is a fundamental flaw in IPv4, does this rise of spoofing-abetted DoS attacks increase the potential value of moving networks to IPv6 (with its per-packet authentication headers)? What solution would be best from your point of view?
--LP
Re:Long term solutions? (Score:2)
One would never do this with "every router"; at most, one would do this with routers on the "edge" of your network.
Even then, you're imposing a burden on routers and more importantly router administrators to configure each router appropriately. And (somewhat like IPv6 adoption), you are requiring everyone on the Internet to adopt a proceedure and process to make up for flawed technology. I'd call that a fundamental flaw.
--LP
Re:Other methods? (Score:2)
And back to point two, tracking compromised systems is a huge benefit since it A) speeds up the time to shut down/notify offending sites *much* more rapidly, even if they were hacked, and B) makes things much riskier for the hackers attempting to carry out such attacks.
--LinuxParanoid
Re:Stop Spoofing At The Backbone? (Score:2)
I'm all for such an initiative, but it would be tons of work and cost a lot of money.
A bit offtopic, but YAY /. (Score:2)
Re:A bit offtopic, but YAY /. (Score:2)
Re:Why exactly should the average citizen care? (Score:2)
As part of the wild life and as a lover of the wilderness, I'm so glad to see a post here without the anarchist-paranoid party line. Without the general public's support, both direct and indirect (through firms they patronize as well as through policies adopted by the government), there would probably have been no Internet and certainly there would have been no world wide web.
If people with good to excellent understanding ignore these net reliability issues, then people of little to no understanding will deal with them. Perhaps ending privacy and annonymity as we know it.
Personally I suspect that securing 10,000 networks belonging to corporations, universities, and others with big fat pipes would go a LONG ways to denying the average script kiddie any base for these DDoS attacks.
Re: Please provide find_ddos source code (Score:2)
What we're concerned with is the fact that you want us to run precompiled code. We don't know what this code does, because you won't release the source to it. We don't trust your assurances that it does what you advertise, and we're not about to potentially compromise our machines by installing government software on them.
What are you hiding? Surely you know that if someone really wants to get around your scanner, they'll take the time to disassemble it and figure out how they're being scanned. The average person responsible for doing actual work, however, doesnt have that type of time at his disposal; Joe Sysadmin is going to laugh at your attempts to get him to run untrusted software.
Why exactly should the average citizen care? (Score:2)
Why should I as the average net citizen and as a citizen of the United States care that sites are being taken down. And since the FBI is involved does this mean this is a serious matter?
Re:illegal? (Score:2)
For how much? A couple of bucks? I am sorry if you can afford DSL I don't think your hurting and if you can access E-trade I would especially say your not hurting at all.
I have access to only at 2400bps modem at home does that mean that it is a crime if I don't have a local number for a BBS to E-trade? When you get some technology you become dependent on it. When you chose to live 50 miles from work and relied on your can and it dies do you feel cheated?
I say you made the choice now live with it.
Re:Why exactly should the average citizen care? (Score:2)
Could someone give me a good example where a couple of hours of time really matters in a situation where I could just get off my lazy ass and just get the same item from a "real" store?
I really wouldn't mind getting some fresh air and still getting what I wanted from the store while not depriving people of freedom because some lazy cracker wants to bomb a site with IP packets.
Re:Why exactly should the average citizen care? (Score:2)
So you think that this is a form of sophisticated industrial terrorism? That seems highly unlikely.
Taking down a dot.com company is like grounding an airlines fleet.
I surely hope that the internet concept of business is not the dominate form of doing business and that no other could be done to the level that an actual place of business becomes secondary.
Re:Why exactly should the average citizen care? (Score:2)
Pardon my counter flame but I really was wanting to ask the individual who came up with this information exactly what *HIS* opinion on such things. However I will continue to remain civil throughout this discussion and not get overly excited.
First of all, corporations are owned and run by citizens. And what exactly does "average" mean? Anyone not like you is automatically a non-citizen and not deserving of protection under the law?
Gnerally there are groups that I would think have a better chance to "fend for themselves" so to speak. I think we all could agree that Microsoft is not entitled to such protection because they most likely could easily hire their own private army of assassins to do so form of quasi-legal garbage and just might get away with it.
Corporations because like so many of the people here have said are EEEEEEEEEEEEVVVVVVVVVVVIIIIIIILLLLLLLL and are akin to the Third Reich in their effect. Well I guess those widdle ol' corporations can just fend for themselves now that the heat is on or will you just moderate this down and just continue to think that the world is comprised of people who like money and moeny makers.
I mean average man is not a person who could easily buy a large mansion in southern France and who has real worries and real concerns that do not seem like he belongs to the court of Louis XVI.
Second, even if the attacks are against corporations not affiliated with you personally, others just might want to use the services they offer. Some of us even like the services they offer. Not to mention that attacks against them cause
problems for sites in the general subnet vicinity (which might be some non-profit socialist site that you like).
Nope can't say that I use the internet on a daily basis to satisify my hunger for stuff. I have only bought on the internet 2 times for a total of 3 items and that was only because I couldn't very easily get what I wanted at a store (debian CDs)
Lastly, the FBI is involved because this is a very serious matter. It was an attack on the economic infrastructure. Maybe it's not a huge deal right now, but the net is becoming more and more important to the economy (particularly
business-to-business services), and it's time to nip these idiots in the bud, and throw them in jail for twenty years to send a very strong message.
What that "The Business of America is Business" --Calvin Cooledge 1924. I really hate business and it's related power. That's why I got involved in CS because I didn't want to spend the rest of my life counting someone else's money for the rest of my professional career.
I can't even now see that a large portion of money is actually being transfered online versus traditional methods I would love some hard data to back up your claims.
Re:Why exactly should the average citizen care? (Score:2)
have stolen it by exploiting "average" citizens.
I could say that if one were to get at least $1,000,000,000 that said person has most likely defrauded some person or done something dishonest in their lives. That is a fact that I am at least 99.9% sure of.
Largely to get more money than anyone else infers that you have some very large advantage over others with similar levels of work. I think that parly is bad. One could say that perhaps because I don't cheat people I am making less money than you if you do. That is what is bad.
In fact, you've convinced me. By your standards, I think you're too rich to deserve protection under the law. I mean, it's pretty darn easy for you with your expensive computer, etc, when people are starving around the world.
Wish I could show you my computer some time. Incidentally the computer I am writing these posts dosn't even belong to me. I have a piece of shit for a machine. Sure if you want to to condemn me for at least getting something that would work half way decently then perhaps I am guilty of that.
I would almost bey $1,000,000 dollars that you in fact have bested me in the PC hardware arena any day of the week. However the people who are in other countries are in fact largely there because of policies that their government's took in the past which essentially made their countries less avaible for advancement. I really can't change history and neither can you.
So all that matters is what's important to you, I see. Yeah, that's a rational outlook.
It's called desperation I sure you have never heard of it either. Essentially when you have called every retailer or wholesaler in a 200 mile radius for a product you are forced to look to your only other option avaible to you. I was forced to use the internet to get what I wanted it was not a choice that would have resulted in getting the product to work properly without the choice so therefore I made the choice.
I already stated that it's "not a huge deal right now", but the time to nip it in the bud is when it's not a huge deal.
I really don't think that using the internet will ever supplant the traditional means of shopping at all. You may think so and others may think so but that would mean that business will crawl to a slow pace and that half of everyone will be going broke if they actually try to run their own business. Eventually this will gain even more power for corporations and take away your power.
I think I've been probably been taken by a troll.
Well haven't been moderated to that yet but I think with the sentiment that big business should be helped when things go wrong I guess I will be soon.
Incidently it is real hipocracy to think that corporations are evil and must be destroyed one minute and the next are the perfect angels of the universe the next. Which one is it? Make up your mind right here and now before you people do even more contradiction and say the Windows is the best and that the moon is composed of cheddar cheese.
Re:Why exactly should the average citizen care? (Score:2)
Pardon my flame, but what an idiotic question.
First of all, corporations are owned and run by citizens. And what exactly does "average" mean? Anyone not like you is automatically a non-citizen and not deserving of protection under the law?
Second, even if the attacks are against corporations not affiliated with you personally, others just might want to use the services they offer. Some of us even like the services they offer. Not to mention that attacks against them cause problems for sites in the general subnet vicinity (which might be some non-profit socialist site that you like).
Lastly, the FBI is involved because this is a very serious matter. It was an attack on the economic infrastructure. Maybe it's not a huge deal right now, but the net is becoming more and more important to the economy (particularly business-to-business services), and it's time to nip these idiots in the bud, and throw them in jail for twenty years to send a very strong message.
--
Re:Why exactly should the average citizen care? (Score:2)
Uh, and exactly who is supposed to decide who gets protection under the law? Perhaps everyone who has over a certain amount of money should be just thrown in jail, since we know they couldn't have actually earned it. They must have stolen it by exploiting "average" citizens.
In fact, you've convinced me. By your standards, I think you're too rich to deserve protection under the law. I mean, it's pretty darn easy for you with your expensive computer, etc, when people are starving around the world.
So all that matters is what's important to you, I see. Yeah, that's a rational outlook.
I already stated that it's "not a huge deal right now", but the time to nip it in the bud is when it's not a huge deal.
I think I've been probably been taken by a troll.
--
Re:Why exactly should the average citizen care? (Score:2)
In my experience, that is simply not true -- on balance. Does it happen? Of course; there will always be bad people in the world. But yes, on balance, those that work the hardest get the biggest rewards. I think where you get off track is in the definition of "hardest". Ditch diggers work very hard, but that doesn't mean they deserve to be millionaires. On the other hand, the president of a large multi-national corporation probably looks to a lot of people like he has a cushy job. However, what he has is the ability to manage a monster organization like that, and not many people can do it. That's an incredibly difficult job.
A surprisingly rational statement. However, it's the unequal distribution of capitalism that keeps their economies down. In other words, the lack of the corporations that you loath.
Why does it have to be all-or-nothing with you? Even Jeff Bezos says that he doesn't think e-commerce will supplant bricks-and-mortor. But that doesn't mean it won't be huge, particularly for business-to-business. B2B will probably be larger than the consumer space, because that's where linking supply-chains really makes sense.
Again, why does everything have to be all-or-nothing with you? Corporations are not living entities; they are owned by real people with real lives and real families. Are there evil people in the world that have abused workers or consumers? Of course. But so what? That's why we have laws. What does that have to do with the legal construction known as a corporation?
And by the way, Windows is the best. Of course, the rub is in the definition of "best". Most consumers define "best" as the platform that supports the most applications, which is where work gets done. And the client end-user applications under Windows are far superior to anything else, particularly Linux. Not one client application under Linux is superior to the ones in Windows. Not one.
--
A solution (Score:2)
illegal? (Score:2)
A fruitless exercise? (Score:3)
Isn't the intersection of the sets:
Questions. (Score:3)
It strikes me as insanely easy to propogate this type of flood attack using a virus with this little dealie as part of the payload. If the virus kept track of the IP addresses of the machines it tried to infect it could be quite deadly. (send command to ping target IP to all possibly infected IP addresses using forged information then Ping target IP) The worst part is that the system could get recursive. (Machine X knows that it tried to infect machine Y. Machine Y knows that it tried to infect machine X. Commands bounce back and forth between them. Ouch. And tracing that one back would be close to impossible...
-----
Other methods? (Score:4)
There seems to be several solutions floating around, mostly smart routers that track valid traffic and MAC addresses.
Would changing to IPv6 help eliminate these type of attacks? From what I read of the specs on IPv6, all the data needed to track a packet from destination right down to the MAC address is included in the packet.
Thanks.
Re:Why exactly should the average citizen care? (Score:2)
Re:Way to go! (Score:2)
Mr. Harper, the old fairgrounds caretaker
Re:Why exactly should the average citizen care? (Score:3)
I run revenue streams for companies like this and I can tell you the numbers that they attribute to loss are greatly exaggerated. They do it because it is more ecenomical to write it off as bad debt(LIN also includes general corp losses) and take the tax break. The more they report as bad debt, the bigger the tax break. Makes quarterly reports look very good at the top and then they bury it deep inside the report. DoS, Hacking, Fraud, Employee theft etc. all this goed into that line item.
security dialectic (Score:2)
-Colbey (Josh Rosenberg)
Firewalls for Dummies? (Score:3)
Re:Government (Score:2)
SANS and CERT have been on this in a low-key sort of way for a month and a half, and system administrators have been scanning, reading logs, and taking extra steps to secure their systems.
This has raised awareness, and while I sympathize with the victims of the past few days, it certainly vindicates the amount of time I have spent reading syslogs, installing patches, running scans for illicit activity, and so forth. And I am under no illusions that my systems are immune.
-----------------------------------------