ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Distributed attack threat looms on the horizon

Will Knight ZDNet.co.uk

Published: 18 Sep 2000 09:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Malevolent computer crackers may be preparing the ground for distributed denial of service (DDoS) attacks that would pose a serious threat to major Web sites and to the infrastructure of the Internet.

Evidence gathered by the US government-funded Computer Emergency Response Team (CERT) suggests that many hundreds of computers have been contaminated with programs that form part of a distributed attack network.

CERT says that reports of computers being compromised in the same two ways and fitted with the same DDoS tools has increased dramatically in recent weeks.

The organisation warned Friday that this represents a major threat. "The combination of widespread, automated exploitation of two common vulnerabilities and an associated increase in distributed denial of service tool installation poses a significant threat to Internet sites and the Internet infrastructure," reads the alert from CERT's Coordination Centre.

This dramatic assessment of the situation reflects the fact that in February a distributed attack technique was used to bring down some of the Internet's largest web sites including eBay, Amazon and Yahoo! in probably the most high-profile Internet attack ever seen. The assault even caused the White House to hold an Internet security summit.

The targeted hosts are predominantly Red Hat Linux machines -- although other flavours of Linux may also be vulnerable -- that have not been made safe from two common vulnerabilities, with rpc.statd and FTPD. Hundreds of these machines have since then been fitted with one of three DDoS applications: Tribe Flood Network, Tribe Flood Network 2000 and Stacheldraht, according to CERT.

CERT advises network administrators to review the two Linux vulnerabilities and to install the appropriate software patches. A DDoS attack method gives a single user control of a whole legion of compromised "zombie" machines. The combined bandwidth of these computers can be used to target a single host with a flood of fake traffic rendering the host inoperable. It is far from a sophisticated technique, but can have a dramatic impact on a target system.

Take me to Hackers

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
48 out of 88 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

JavaScript / AJAX / Web 2.0 development role

I have a brand new, exciting opening in Edinburgh for a rapidly expanding software house poised to further attack the market on the back of recent ...

VB.Net developer. Move into C#. South Manchester Mid/Junior level

Microsoft Gold Partner working with a whole host of Blue Chip clients are currently on the lookout for a junior AND Mid-Level .Net developer. The ...

C++ Specialist - Financial Software Development - Equity Derivatives

The development team is responsible for highly distributed systems. The team works in close collaboration at all levels with business users in ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment