Live data from Hacker News

'Anonymous' hackers plan to shut down the Internet this Saturday

bgr.com

51–59 of 59 posts

Re: 'Anonymous' hackers plan to shut down the Internet this Saturday

#52

I really hate the fact that this nonsense keeps getting reported. Even the article itself, while it has the headline "'Anonymous' hackers plan to shut down the Internet this Saturday", states that "there is really no need to fear". Better title: 'A few individuals make crazy claims of doing something impossible.'. Not only would it be basically impossible to take down the DNS servers even if they had large participat…

You can read http://www.wired.com/science/discoveries/news/2002/07/54040?...

While it is unlikely that this will actually happen you are still far from correct saying that this is virtually impossible, for certain this is possible.

If anyone here recalls the blackhat heydays pre-2003 you may have/have not recalled a group known as "Fluffy Bunny" that broke into (at the time) what were thought to be the some of the most secure box's on the net, a few to name were VA software, UU.net(efnet), (cross site scripting) securityfocus.com, sans.org, (even a site dedicated to making fun of and host mirrors of defaced websites) attrition.org.

Getting back to the original point I was trying to make, one of their most notable hacks was breaking into multiple Akamai servers. No remote exploits were used against Akamai servers, every computer they had access to at Akamai was gained through a patch version of ssh which recorded all users password before encryption and placed it in a log file within a hidden directory on the system, this patch was installed on every box they exploited, they got lucky when a user from the uu.net box logged into an Akamai box using the compromised ssh client.

So they have Akamai, now what? The group further infiltrated their way into Akamai's intranet and gained access to other computers on their network through social engineering. Finally they located the development server that stored the source code that Akamai used to update some 12,000+ high bandwidth servers they used. The plan was to patch the update software they used to automate the patching process to also include a rootkit&DDoS client. With this they would be able to control a ridiculously large botnet, joined with their already amassed 4000+ DDoS net from other compromised computers this would have effectively timed out all 13 top level root name servers. More then likely you can tell what happens after that.

If you were interested to know, these guys were caught out out of the stupidity of this guy. http://articles.latimes.com/2000/sep/22/local/me-24959 Whom was drunk and instead of hanging up decided to curse out a field technician that came onto the centrex line(thanks AT&T) they used to communicate through. This resulted in the tech recording the line 24/7 and eventually handing the information over to the authorities.

Re: 'Anonymous' hackers plan to shut down the Internet this Saturday

#53

At this point I think it's just FBI/CIA trying to troll us and get more cyber-laws passed.

The bigger problem is that Anonymous is a lynch mob. Maybe in it for good, maybe in it for lulz, but it's still a digital lynch mob.

The fundamental problem is that we're trusting vigilantes when we should be trusting courts to bring justice.

Re: 'Anonymous' hackers plan to shut down the Internet this Saturday

#54

At this point I think it's just FBI/CIA trying to troll us and get more cyber-laws passed.

Arg! I hate to say this but "I came here to post this." This is not the sort of thing Anonymous does, they've been careful not to aggravate the public and make clear it is the elite and not the common man that is their nemesis. We also know for a fact that US intelligence agencies have infiltrated and have been in control of many Anonymous operations. Not too hard to see that this will be a test run of whether intell…

If you hated to say it, couldn't you have left it out or just said "I agree" instead? The rest of your post doesn't depend on us knowing what you came here to say.

Re: 'Anonymous' hackers plan to shut down the Internet this Saturday

#55

Earlier quoted context omitted.

Arg! I hate to say this but "I came here to post this." This is not the sort of thing Anonymous does, they've been careful not to aggravate the public and make clear it is the elite and not the common man that is their nemesis. We also know for a fact that US intelligence agencies have infiltrated and have been in control of many Anonymous operations. Not too hard to see that this will be a test run of whether intell…

If you hated to say it, couldn't you have left it out or just said "I agree" instead? The rest of your post doesn't depend on us knowing what you came here to say.

Sure I think you are right.

I sometimes maintain a conversational tone here, so expressing personal surprise at seeing what I was going to type as the top comment just sort of came out. I "hated to say it" because it's such an overused trite idiom. But yeah, it added little and "I agree" would have been a smoother intro.

Re: 'Anonymous' hackers plan to shut down the Internet this Saturday

#56
post #30

Unless they keep their attack up / the DNS root down long enough to make cache timeout, this should not be noticed by any "normal" people.

With google.com and many other big players having a TTL of 300s, that's not a long time.

They are not planning to attack Google's name servers, just the root servers that hold the delegations for the TLDs.

The .com delegation is set to cache for 48 hours, for example. This simply will not work at all.

Re: 'Anonymous' hackers plan to shut down the Internet this Saturday

#57

How much redundancy is built into the GMail nameservers? That worries me more than http requests. Also, should I host my own nameservers and assume I'll fly under the radar of attacks?

This is allegedly targeted at the root servers. It doesn't matter what DNS provider you use if your TLD is offline.

Delegations from the root to the TLDs and from the TLDs to second-level domains generally have TTLs of over 24 hours. This attack will have zero effect.

Re: 'Anonymous' hackers plan to shut down the Internet this Saturday

#58
post #21

Has anyone besides RTM ever successfully dropped the majority of the network?

The name escapes me for the moment, but there was a famous computer virus which I believe did almost to do that. They key wasn't that it was particularly clever and the attack vector it used had been patched by MS months before. The key was that the attack happened over UDP which meant that there was no handshake, no congestion control, no need to worry about dropped packets, etc. The only limitation was the bandwidt…

Relevant: http://en.wikipedia.org/wiki/Robert_Tappan_Morris Also: http://en.wikipedia.org/wiki/Morris_worm

Re: 'Anonymous' hackers plan to shut down the Internet this Saturday

#59
post #57

Earlier quoted context omitted.

This is allegedly targeted at the root servers. It doesn't matter what DNS provider you use if your TLD is offline.

Delegations from the root to the TLDs and from the TLDs to second-level domains generally have TTLs of over 24 hours. This attack will have zero effect.

Good point. They'll bring it down for a day and nothing will happen.

Is it likely that the big email providers keep the caching longer and could maintain some functionality in the event the TLD nameservers are down for more than 24 hours?

Post reply on HN