Advertisement
Promo

Security threats Toolkit

Distributed attack threat looms on the horizon

Will Knight ZDNet.co.uk

Published: 18 Sep 2000 09:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Malevolent computer crackers may be preparing the ground for distributed denial of service (DDoS) attacks that would pose a serious threat to major Web sites and to the infrastructure of the Internet.

Evidence gathered by the US government-funded Computer Emergency Response Team (CERT) suggests that many hundreds of computers have been contaminated with programs that form part of a distributed attack network.

CERT says that reports of computers being compromised in the same two ways and fitted with the same DDoS tools has increased dramatically in recent weeks.

The organisation warned Friday that this represents a major threat. "The combination of widespread, automated exploitation of two common vulnerabilities and an associated increase in distributed denial of service tool installation poses a significant threat to Internet sites and the Internet infrastructure," reads the alert from CERT's Coordination Centre.

This dramatic assessment of the situation reflects the fact that in February a distributed attack technique was used to bring down some of the Internet's largest web sites including eBay, Amazon and Yahoo! in probably the most high-profile Internet attack ever seen. The assault even caused the White House to hold an Internet security summit.

The targeted hosts are predominantly Red Hat Linux machines -- although other flavours of Linux may also be vulnerable -- that have not been made safe from two common vulnerabilities, with rpc.statd and FTPD. Hundreds of these machines have since then been fitted with one of three DDoS applications: Tribe Flood Network, Tribe Flood Network 2000 and Stacheldraht, according to CERT.

CERT advises network administrators to review the two Linux vulnerabilities and to install the appropriate software patches. A DDoS attack method gives a single user control of a whole legion of compromised "zombie" machines. The combined bandwidth of these computers can be used to target a single host with a flood of fake traffic rendering the host inoperable. It is far from a sophisticated technique, but can have a dramatic impact on a target system.

Take me to Hackers

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
48 out of 88 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters