ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Experts: Web attacks not over yet

Robert Lemos, ZDNet News ZDNet.co.uk

Published: 10 Feb 2000 09:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Even as two more major Web sites suffered outages, security experts issued a chilling warning: The attacks could continue into Thursday.

E*Trade and ZDNet joined Yahoo!, eBay.com, Buy.com, The Microsoft Network, CNN and Amazon.com in the dubious ranks of victims of what is known as a "distributed Denial of Service" attack.

The techniques used against those eight major Internet sites use a large number of compromised servers to flood a target with data. It takes only limited technical expertise, has software tools to help attackers and can be very hard to stop.

Worse -- experts foresee little relief in sight. Steve Bellovin, network security research fellow for AT&T Labs, expects more attacks to hit other sites Wednesday night and throughout Thursday. "I think it is going to continue for at least a few more days until they can track down who is doing it," he said.

That, despite a well-publicised pledge by the FBI to hunt down those responsible for the attacks.

"We are committed in every way possible to tracking those who are responsible," said Attorney General Janet Reno at a news conference late Wednesday morning.

"The longer the attacks continue, the easier it will be to track the person or people down," said Bellovin.

As the incidents mounted, security experts declared that the outages were almost certainly the result of a coordinated effort.

"I don't see how they couldn't be," said Stuart McClure, the president and chief technology officer at Ramparts Security Group LLC in Irvine, California. "The symptoms are all the same, the effects are all the same -- every time I talk to people [at the afflicted sites] they all say the same things."

Not everyone agreed, however. One security specialist argued that a single teenager could have pulled off the attacks because tools to find and exploit security holes in the Internet infrastructure are readily available online.

Tools, such as the Tribe Flood Network and a variant known as Stacheldraht, allow an attacker to set up remote "agents" on cracked computer systems that can conduct the same sort of attack as those that hit Yahoo!, eBay and others.

"Basically you are giving a kid an electronic AK-47," said James Atkinson, president and chief engineer for counter-surveillance firm Granite Island Group, based in Gloucester, Massachusetts, who added that Internet service providers need to start protecting themselves better.

"ISPs are going to go out of business if they do not (put in better defences)," he said. "A lot of Web firms have been big, fat targets for quite a while. This is a wake up call." Atkinson has being consulting with several victims of the denial of service attacks.

However, even the most responsible ISPs cannot fully protect themselves from flooding attacks and remain connected the Internet.

In fact, security experts are concerned that Denial of Service techniques are evolving to the point where the attacks will be impossible to prevent.

"Denial of service is becoming more sophisticated," said Weld Pond, a hacker working for security firm @Stake. "The problem is not going away."

What do you think? Tell the Mailroom. And read what others have said.

Take me to the Denial of Service round-up

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
16 out of 74 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:















Related Jobs

Account Director

Experience with leading management or IT consultancies latterly in a client relationship role Banking or life and pensions sector focus Excellent ...

Technical Team leader ITIL Prince II - Oxfordshire

We are currently seeking an established people manager preferably from a technical background to lead and develop the team of senior ...

Internet Operations Analysts

By 2012, we predict the main medium carrying intelligence on our targets will be via the internet. Our targets use of computers has become smarter, ...

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains