At this point I think it's just FBI/CIA trying to troll us and get more cyber-laws passed.
'Anonymous' hackers plan to shut down the Internet this Saturday
51–59 of 59 posts
Re: 'Anonymous' hackers plan to shut down the Internet this Saturday
#52I really hate the fact that this nonsense keeps getting reported. Even the article itself, while it has the headline "'Anonymous' hackers plan to shut down the Internet this Saturday", states that "there is really no need to fear". Better title: 'A few individuals make crazy claims of doing something impossible.'. Not only would it be basically impossible to take down the DNS servers even if they had large participat…
While it is unlikely that this will actually happen you are still far from correct saying that this is virtually impossible, for certain this is possible.
If anyone here recalls the blackhat heydays pre-2003 you may have/have not recalled a group known as "Fluffy Bunny" that broke into (at the time) what were thought to be the some of the most secure box's on the net, a few to name were VA software, UU.net(efnet), (cross site scripting) securityfocus.com, sans.org, (even a site dedicated to making fun of and host mirrors of defaced websites) attrition.org.
Getting back to the original point I was trying to make, one of their most notable hacks was breaking into multiple Akamai servers. No remote exploits were used against Akamai servers, every computer they had access to at Akamai was gained through a patch version of ssh which recorded all users password before encryption and placed it in a log file within a hidden directory on the system, this patch was installed on every box they exploited, they got lucky when a user from the uu.net box logged into an Akamai box using the compromised ssh client.
So they have Akamai, now what? The group further infiltrated their way into Akamai's intranet and gained access to other computers on their network through social engineering. Finally they located the development server that stored the source code that Akamai used to update some 12,000+ high bandwidth servers they used. The plan was to patch the update software they used to automate the patching process to also include a rootkit&DDoS client. With this they would be able to control a ridiculously large botnet, joined with their already amassed 4000+ DDoS net from other compromised computers this would have effectively timed out all 13 top level root name servers. More then likely you can tell what happens after that.
If you were interested to know, these guys were caught out out of the stupidity of this guy. http://articles.latimes.com/2000/sep/22/local/me-24959 Whom was drunk and instead of hanging up decided to curse out a field technician that came onto the centrex line(thanks AT&T) they used to communicate through. This resulted in the tech recording the line 24/7 and eventually handing the information over to the authorities.
Re: 'Anonymous' hackers plan to shut down the Internet this Saturday
#53At this point I think it's just FBI/CIA trying to troll us and get more cyber-laws passed.
The fundamental problem is that we're trusting vigilantes when we should be trusting courts to bring justice.
Re: 'Anonymous' hackers plan to shut down the Internet this Saturday
#54At this point I think it's just FBI/CIA trying to troll us and get more cyber-laws passed.
Arg! I hate to say this but "I came here to post this." This is not the sort of thing Anonymous does, they've been careful not to aggravate the public and make clear it is the elite and not the common man that is their nemesis. We also know for a fact that US intelligence agencies have infiltrated and have been in control of many Anonymous operations. Not too hard to see that this will be a test run of whether intell…
Re: 'Anonymous' hackers plan to shut down the Internet this Saturday
#55Earlier quoted context omitted.
Arg! I hate to say this but "I came here to post this." This is not the sort of thing Anonymous does, they've been careful not to aggravate the public and make clear it is the elite and not the common man that is their nemesis. We also know for a fact that US intelligence agencies have infiltrated and have been in control of many Anonymous operations. Not too hard to see that this will be a test run of whether intell…
If you hated to say it, couldn't you have left it out or just said "I agree" instead? The rest of your post doesn't depend on us knowing what you came here to say.
I sometimes maintain a conversational tone here, so expressing personal surprise at seeing what I was going to type as the top comment just sort of came out. I "hated to say it" because it's such an overused trite idiom. But yeah, it added little and "I agree" would have been a smoother intro.
Re: 'Anonymous' hackers plan to shut down the Internet this Saturday
#56Unless they keep their attack up / the DNS root down long enough to make cache timeout, this should not be noticed by any "normal" people.
With google.com and many other big players having a TTL of 300s, that's not a long time.
The .com delegation is set to cache for 48 hours, for example. This simply will not work at all.
Re: 'Anonymous' hackers plan to shut down the Internet this Saturday
#57How much redundancy is built into the GMail nameservers? That worries me more than http requests. Also, should I host my own nameservers and assume I'll fly under the radar of attacks?
This is allegedly targeted at the root servers. It doesn't matter what DNS provider you use if your TLD is offline.
Re: 'Anonymous' hackers plan to shut down the Internet this Saturday
#58Has anyone besides RTM ever successfully dropped the majority of the network?
The name escapes me for the moment, but there was a famous computer virus which I believe did almost to do that. They key wasn't that it was particularly clever and the attack vector it used had been patched by MS months before. The key was that the attack happened over UDP which meant that there was no handshake, no congestion control, no need to worry about dropped packets, etc. The only limitation was the bandwidt…
Re: 'Anonymous' hackers plan to shut down the Internet this Saturday
#59Earlier quoted context omitted.
This is allegedly targeted at the root servers. It doesn't matter what DNS provider you use if your TLD is offline.
Delegations from the root to the TLDs and from the TLDs to second-level domains generally have TTLs of over 24 hours. This attack will have zero effect.
Is it likely that the big email providers keep the caching longer and could maintain some functionality in the event the TLD nameservers are down for more than 24 hours?