Author Topic: DOS Attack ! Who? Why?  (Read 206 times)

kneelsit

  • Newbie
  • *
  • Posts: 0
    • View Profile
DOS Attack ! Who? Why?
« on: January 01, 1970, 12:00:00 am »
From my host this a.m.[/b}

Quote
<<


What is a Ddos attack :
http://www.webopedia.com/TERM/D/DoS_attack.html


News article from CNN : http://www.cnn.com/2003/TECH/intern...k.ap/index.html


Micosoft\'s spin to why they broke the internet:


This is a post that was on MS Sql Server Security NG,


At approximately 2130hrs (PST) or 0530hrs (GMT) an
apparent worm (still being analyzed for payload content)
began distributing itself across the Internet via port
1434/UDP (Microsoft-SQL-Monitor). It apparently is
making effective use of the buffer overrun security issue
as outlined in http://www.intelenet.net/news/mssql-
udp.txt


So far several of the major backbone providers have gone
down due to the nature of how this system propigates.
Since it is using UDP across a blanket of IPs (no
specific target), routers, switches, and other network
devices are being flooded with the UDP port openings.
Most router CPUs were maxing at 100% and began dropping
ASN advertisements causing huge segments of the Internet
to \\\"flap\\\" in place.


All major backbone providers are rapidly installing port
1434/UDP filters at all borders and within colocation
spaces to attempt to isolate this as fast as possible.


Current speculation is that stopping and restarting the
SQL process will clear the worm until another hit is
made. Suggest not only patching your SQL server
(assuming that there is a patch for this) as well as
installing any firewall rules that you can to filter out
BOTH inbound and outbound port 1434/UDP>>>
Is it just paranoia on my part -  - or does this attack on the whole operation of the internet seem suspiciously close to January 27th reporting date for U.N. inspectors in Iraq??

ihelpyou

  • Newbie
  • *
  • Posts: 0
    • View Profile
DOS Attack ! Who? Why?
« Reply #1 on: January 01, 1970, 12:00:00 am »
Who knows but it was not that bad. Most routers, etc had it blocked after a few hours. I did notice some sites that were not accessible today. The forums seemed fine all day long though.

robertclough

  • Newbie
  • *
  • Posts: 0
    • View Profile
DOS Attack ! Who? Why?
« Reply #2 on: January 01, 1970, 12:00:00 am »
A couple more interesting bits:

Bank of America ATMs Disrupted by Virus
http://www.washingtonpost.com/wp-dy...-2003Jan25.html


The Internet Traffic Report
http://www.internettrafficreport.com/main.htm

kneelsit

  • Newbie
  • *
  • Posts: 0
    • View Profile
DOS Attack ! Who? Why?
« Reply #3 on: January 01, 1970, 12:00:00 am »
Thank you Robert for those links.

Sorry Doug, but I do not believe we can be too complacent in this regard.  What more effective way to mount a counterattack than to work at disrupting the internet itself, the underpinning to our whole commercial system.

  I do sincerely hope our Internet Security experts are \"on their toes\" and maintaining constant vigilance.