ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

Web attackers knock out Microsoft sites

Published: 26 Jan 2001 09:18 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Network attackers overwhelmed Microsoft's connection to the Internet on Thursday, causing traffic to the company's major Web sites to slow to a crawl.

"During the morning of 25 January, Microsoft was the target of a denial-of-service attack against the routers that direct traffic to the company's Web sites," Microsoft said in a statement late Thursday afternoon. "As a result, access to some of the Microsoft Internet properties, including Microsoft.com and MSN.com, was intermittent for many customers throughout this morning."

The company emphasised that Thursday's attack, which began in the morning and extended into the afternoon, was not related to the technical glitch that crippled its sites late Tuesday and most of Wednesday.

Microsoft said it has asked the FBI to investigate and that the company's Web sites were fully functioning late Thursday. The timing and duration of the embarrassing outage came as Microsoft -- which operates the third most-visited sites on the Web -- is trying to bolster its reputation among corporate customers.

The company launched a $200m (£121m) advertising campaign Monday touting its business software in competition with Oracle, IBM and Sun Microsystems. The theme for the ads is "software for the agile business".

A denial-of-service attack overloads a site's servers with a flood of data, effectively blocking surfers from accessing the site. In this case, the attack was aimed not at the servers, but at the hardware switches that route data to the Web sites, Microsoft said. After hackers flooded these so-called routers, legitimate requests for Web pages could not be processed by Microsoft's servers.

According to networking consultancy Keynote Systems, at the height of the attack, as little as two percent of the requests for Microsoft Web pages were being completed Thursday. Normally, sites are able to fulfill 97 percent of all page requests, said Keynote representatives. "For about two hours, the attack was a hundred percent successful," said Eric Siegel, senior Internet consultant for Keynote.

Siegel noted that a flaw in Microsoft's network design -- which was highlighted by Tuesday's and Wednesday's outages -- may have given the attackers the idea to flood Microsoft's key routers. The flaw: The Redmond, Washington company connected its key DNS (domain name service) servers to a single switch that acted as the spigot for data going to the Internet.

DNS servers act as phone books for the Internet, linking Web sites names, such as Microsoft.com and Yahoo.com, to the numerical computer addresses that locate the proper server on the network. "If Microsoft is using a single router as the entrance to a series of DNS servers and you take down that router, then the attack would be very successful," Siegel said. Essentially, Microsoft's Web sites would virtually disappear from the Internet.

Which is precisely what happened, according to the software giant. Thursday's attack comes almost exactly one year after massive distributed denial-of-service (DDoS) attacks slowed, and in some cases halted, access to eight major Web sites, including Yahoo, eBay and CNN.com. DDoS attacks are denial-of-service attacks that use hundreds of servers to attack a single target, which makes finding the source of the attack much more difficult.

Canadian and United States law-enforcement officials are prosecuting a Canadian teenager -- who allegedly used the handle "Mafiaboy" -- as the culprit in the attacks last Feburary. Such attacks are fairly common but rarely so damaging, said Elias Levy, chief technology officer for security Web site SecurityFocus.com. "They tend to occur nowhere near the magnitude of taking down Microsoft," he said. "But they do happen quite often to individual Web sites -- more often than most people know."

Microsoft's network of Web properties ranks as the third most-visited destination on the Internet. According to Net research company Jupiter Media Metrix, Microsoft Web sites drew 54 million unique visitors in December, trailing only America Online's 61 million and Yahoo's 55 million.

No suspects have been named in the current investigation. FBI officials in Washington DC, and San Francisco could not be reached for comment late Thursday.

The Sun vs. Microsoft Java suit brought out the worst among the software-wars rhetoric slingers. Mary Jo Foley advises that you prepare yourselves for more wars of words between the two archrivals during the next few weeks, as Sun rolls out its Web services strategy. Go to AnchorDesk UK for the news comment.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
18 out of 43 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Customer Advisor

Verifying accounts posted in to the Court Teams Routers are suitable to sue. Providing timely responses to all Court requests to ensure successful ...

Applications Management Analyst

To perform operational tasks, such as morning checks, batches and monitoring. To follow incident management processes in order to respond to support ...

Technician Network Operations - London, South East

Nortel/Cisco and Juniper Router Support. Vendors: Alcatel : ATM and Frame Relay Platforms Nortel : Switches and CPE Routers Juniper : Core and Edge ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

1 comment