EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

01.24.09

DNS Suspended by Microsoft Windows Botnets

Posted in Microsoft, Security, Servers, Windows at 12:37 pm by Dr. Roy Schestowitz

Warpath of Web destruction

TWO DAYS ago I was unable to use the Internet properly. This network’s DNS servers came under massive attack at a time when hundreds of millions of Windows zombies ran rampant. It’s neither a new problem [1, 2] nor does affect just the network that I’m on. There are similar complaints and status reports out there on the Web right now.

Potential Latency on Network Solutions DNS

There is a spike in DNS query volumes that is causing latency for the delay in web sites resolving. This is a result of a DDOS attack. We are taking measures to mitigate the attack and speed up queries

—————-

There may be some latency on Network Solutions DNS Severs and some queries may be timing out. This may include instances when someone types a domain name into a browser and the website will temporarily not resolve. Network Solutions Operations is working on optimizing the DNS queries and investigating the issue.

There is nothing that prevents a determined cracker (or a gang of them) from taking down DNS globally [18, 19], especially given Windows botnets of biblical proportions . This almost happened 2 years ago and there are still no effective defenses in place. The same goes for the scale of botnets — a solution to which Microsoft cannot deliver.

“Microsoft slammed over security advice

US COMPUTER Emergency Readiness Team (US-CERT) has warned that Microsoft’s advice about how to beat the Downadup worm is flawed.

And things are getting worse before they get better.

A security expert has managed to transfer the digital signature of one Windows program to another, without invalidating the signature. Didier Stevens, who presented the attack in his blog, exploited the fact that Microsoft’s Authenticode code signing standard accepts the vulnerable MD5 hash algorithm. Stevens used this to generate two programs which have identical code signatures, but behave differently.

How long can this chaos [1, 2, 3] go on for? Many related news (2006-2008, re: DNS) are added as references below.

Airplane crash
What if aircrafts accepted Microsoft quality control?

_____
[1] Open source DNS server takes on BIND

Four companies led by Dutch non-profit NLnet Labs have launched an open source, Linux-compatible DNS (Domain Name System) server. “Unbound,” which is also sponsored by VeriSign, Nominet, and Kirei, claims to offer a validating, recursive, and caching DNS server that is faster than the open source DNS mainstay BIND.

[2] VeriSign Takes Aim at Open Source DNS

Now VeriSign, the company that runs that .com and .net domains, is aiming to provide an open source alternative to BIND, called Unbound.

[3] SocialDNS: Free Domains for a Free Internet

John Sullivan (FSF) invited me to present in this mailing list the SocialDNS project (http://www.socialdns.net).
I am very interested in obtaining feedback from the GNU community because we want to submit our project to the Free Software Directory soon.

[4] DNS Patches Slow Servers, but Fast Action Is Advised

Microsoft issued a mea culpa about its DNS update on July 17, saying that the patch was crippling some machines running its Windows Small Business Server suite. Then, on July 25, it said the patch could also affect some network services on systems running Windows Server 2008, Windows Server 2003 and Windows 2000. In both instances, Microsoft detailed work-arounds.

[5] DNS poisoners hijack typo domains

People arrive at these pages when the domain name they request is unavailable, because, for example, they mistyped the URL. ISPs use this redirection method, known as Typosquatting, to advertise free domains or competing products. In the present case, however, clients don’t arrive on the Typosquatter pages, but on pages with a crafted trojan.

[6] Microsoft DNS fix causes trouble for some

The Microsoft Corp. released a DNS fix in its patch slate for July, but the company seems to have problems just getting it to end users. Moreover, some users of the DNS fix have experienced additional difficulties.

So far, since Microsoft’s DNS fix was issued on July 10, there have been two separate problems associated with its installation.

[7] H D Moore has NOT been owned

From the “half truths that journo’s tell” file:

I’ve been following the Kaminsky DNS cache exploit issue closely since it was first announced – and no doubt so has everyone else in the security business. As such I was surprised to read a headline this morning that said that Metasploit founder H D Moore (and yes Virginia, there is a Santa Claus and I run Metasploit on a test machine too – who doesn’t?) had been ‘owned’ (should’ve been p’wned I think) by the DNS flaw.

The story is not true – at least according to H D Moore who claims he was misquoted by the journalist in question.

“In a recent conversation with Robert McMillan (IDG), I described a in-the-wild attack against one of AT&T’s DNS cache servers, specifically one that was configured as an upstream forwarder for an internal DNS machine at BreakingPoint Systems,” H D Moore wrote in a blog post. “Shortly after our conversation, Mr. McMillan published an article with a sensationalist title, that while containing most of the facts, attributed a quote to me that I simply did not say. Specifically, `”It’s funny,” he said. “I got owned.”

[8] SUBJECT: Microsoft SWI blog inaccuracies

As you know, 3 weeks ago I published my paper, “Microsoft Windows DNS Stub Resolver Cache Poisoning” (http://www.trusteer.com/docs/Microsoft_Windows_resolver_DNS_cache_poisoning.pdf),

simultaneously with Microsoft’s release of MS08-020 (http://www.microsoft.com/technet/security/Bulletin/MS08-020.mspx). A day later, Microsoft’s Secure Windows Initiative (SWI) team published their blog entry for MS08- 020 (http://blogs.technet.com/swi/archive/2008/04/09/ms08-020-how-predictable-is-the-dns-transaction-id.aspx).

Unfortunately, the SWI blog entry contains two serious mistakes. The first mistake is an inaccurate description of the PRNG used for the Microsoft Windows DNS client transaction ID. The second mistake is SWI’s claim that “attackers cannot predict a guaranteed, known-next TXID exactly even with this weakness”.

I contacted Microsoft about those mistakes, and while Microsoft did not refute my statements, they also refused to revise the blog entry. On one hand, I am inclined to tag this as a simple unwillingness on the side of the vendor to revise its materials and admit its mistakes. On the other hand, I cannot ignore the fact that the two mistakes, when combined, result in misleading the blog reader about the nature and the severity of the problem.

[...]

This is in stark contrast to SWI’s claims. Furthermore, Microsoft did have the full paper (actually, a draft of it which contains all the relevant technical information) well before the SWI blog was published. So the problem here is not an issue of SWI not having access to the paper when they wrote their blog entry.

[9] Microsoft preps 133 patches for Windows DNS hole

Microsoft is working on 133 separate updates for the problem, Budd wrote.

[10] Microsoft DNS Server Attacks Continue

The concept enables malicious users to run code remotely under the system privileges generally granted to the DNS service itself.

[11] Microsoft: Patch for critical DNS flaw may be ready by 8 May

The cmopany has been under pressure to address the flaw, reported last week, since software that exploits it has now been widely disseminated, and criminals are beginning to use it in attacks.

[12] Attack code raises Windows DNS zero-day risk

At least four exploits for the vulnerability in the Windows domain name system, or DNS, service were published on the Internet over the weekend, Symantec said in an alert Monday.

[13] Cybercrooks exploiting new Windows DNS flaw

Cybercrooks are using a yet-to-be-patched security flaw in certain Windows versions to attack computers running the operating systems, Microsoft warned late Thursday.

[14] Microsoft’s advisories giving clues to hackers

How’s this for a new twist on the old responsible disclosure debate: Hackers are taking advantage of information released in Microsoft’s pre-patch security advisories to create exploits for zero-day vulnerabilities.

[15] DNS security improves as firms tool up to tackle spam

Infoblox’s survey found that the number of internet-facing DNS servers increased from 9m in 2006 to 11.5m in 2007, indicative of the overall growth of the internet. Percentage usage of the most recent and secure version of open-source domain name server software – BIND 9 – increased from 61 per cent to 65 per cent over the last year. Use of BIND 8, by contrast, dropped from 14 per cent in 2006 to 5.6 per cent this year. Usage of the Microsoft DNS Server on web-facing systems also fell, decreasing to to 2.7 per cent in 2007 from five per cent last year.

[16] Use of rogue DNS servers on rise

The paper estimates roughly 68,000 servers on the Internet are returning malicious Domain Name System results, which means people with compromised computers are sometimes being directed to the wrong Web sites — and often have no idea.

[17] New shield foiled Internet backbone attack

ICANN has yet to determine the exact techniques used in the February attack. The incident will be discussed at a meeting of DNS root server operators later this month, the organization said.

[18] Zombie botnets attack global DNS servers

Hackers launched a sustained attack last night against key root servers which form the backbone of the internet.

Security firm Sophos said that botnets of zombie PCs bombarded the internet’s domain name system (DNS) servers with traffic.

“These zombie computers could have brought the web to its knees,” said Graham Cluley, senior technology consultant at Sophos.

[19] EveryDNS, OpenDNS Under Botnet DDoS Attack

The last time the Web mob (spammers and phishers using botnets) decided to go after a security service, Blue Security was forced to fold and collateral damage extended to several businesses, including Six Apart.

[20] Homeland Security sees cyberthreats on the rise

To test the nation’s response to a cyberattack, the Department of Homeland Security plans to hold another major exercise, called Cyberstorm II, in March 2008, Garcia said. A first such exercise happened early last year.

[21] Perspective: Microsoft security–no more second chances?

As if Homeland Security Secretary Michael Chertoff didn’t have enough on his plate.

Not only has he had to deal with Katrina and Osama. Now he’s also got to whip Steve Ballmer and the crew at Microsoft into shape. If past is prologue, that last task may be the most daunting of all.

[22] U.S. cyber counterattack: Bomb ‘em one way or the other

If the United States found itself under a major cyberattack aimed at undermining the natio’s critical information infrastructure, the Department of Defense is prepared, based on the authority of the president, to launch a cyber counterattack or an actual bombing of an attack source.

[23] US plans for cyber attack revealed

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

2 Comments

  1. Needs Sunlight said,

    January 24, 2009 at 12:50 pm

    Gravatar

    Dumping laws apply on the land. Why not also on the net?

    Want to run Windows? Ok, that’s your right. Want to plug your Windows box to the next? Bzzzt. First time, misdemeanor + fee. Second time, misdemeanor + community service + bigger fee. Third and subsequent times, misdemeanor + hefty fine + confiscation of all electronic equipment (TV, phone, vcr, camera, computer, etc.)

  2. DOUGman said,

    January 24, 2009 at 4:21 pm

    Gravatar

    Your laws seem extreme, but lets face facts. People must realize that they are responsible for their actions. When you learn to drive a car, you get educated for its use. Rough analogy, I know but you get the point.

    Education for computer use is KEY.

    D.

What Else is New


  1. Links 19/1/2018: Linux Journalism Fund, Grsecurity is SLAPPing Again

    Links for the day



  2. The EPO Ignores This Week's Decision Which Demonstrates Patent Scope Gone Awry; Software Patents Brought Up Again

    The worrisome growth of European Patents (EPs) — a 40% jump in one year in spite of decline in the number of patent applications — is a symptom of the poor judgment, induced largely by bad policies that impede examiners’ activities for the sake of so-called ‘production’; this week's decision regarding CRISPR is another wake-up call and software patents too need to be abolished (as a whole), in lieu with the European Patent Convention (EPC)



  3. WesternGeco v ION Geophysical (at the US Supreme Court) Won't Affect Patent Scope

    As WesternGeco v ION Geophysical is the main if not sole ‘major’ patent case that the US Supreme Court will deal with, it seems safe to say that nothing substantial will change for patent scope in the United States this year



  4. Links 18/1/2018: MenuLibre 2.1.4, Git 2.16 Released

    Links for the day



  5. Microsoft, Masking/Hiding Itself Behind Patent Trolls, is Still Engaging in Patent Extortion

    A review of Microsoft's ugly tactics, which involve coercion and extortion (for businesses to move to Azure and/or for OEMs to preload Microsoft software) while Microsoft-connected patent trolls help hide the "enforcement" element in this whole racket



  6. Patent Prosecution Highway: Low-Quality Patents for High-Frequency Patent Aggressors

    The EPO's race to the bottom of patent quality, combined with a "need for speed", is a recipe for disaster (except for litigation firms, patent bullies, and patent trolls)



  7. Press Coverage About the EPO Board Revoking Broad's CRISPR Patent

    Even though there's some decent coverage about yesterday's decision (e.g. from The Scientist), the patent microcosm googlebombs the news with stuff that serves to distract from or distort the outcome



  8. Links 17/1/2018: HHVM 3.24, WordPress 4.9.2

    Links for the day



  9. No Patents on Life (CRISPR), Said EPO Boards of Appeal Just a Few Hours Ago

    Broad spectacularly loses its key case, which may soon mean that any other patents on CRISPR too will be considered invalid



  10. Only Two Weeks on the Job, Judge Patrick Corcoran is Already Being Threatened by EPO Management

    The attack on a technical judge who is accused of relaying information many people had already relayed anyway (it was gossip at the whole Organisation for years) carries on as he is again being pushed around, just as many people predicted



  11. EPO Board of Appeal Has an Opportunity to Stop Controversial Patents on Life

    Patent maximalism at the EPO can be pushed aback slightly if the European appeal board decides to curtail CRISPR patents in a matter of days



  12. Links 16/1/2018: More on Barcelona, OSI at 20

    Links for the day



  13. 2018 Will be an Even Worse Year for Software Patents Because the US Supreme Court Shields Alice

    The latest picks (reviewed cases) of the Supreme Court of the United States signal another year with little or no hope for the software patents lobby; PTAB too is expected to endure after a record-breaking year, in which it invalidated a lot of software patents that had been erroneously granted



  14. Patent Trolls (Euphemised as “Public IP Companies”) Are Dying in the United States, But the Trouble Isn't Over

    The demise of various types of patent trolls, including publicly-traded trolls, is good news; but we take stock of the latest developments in order to better assess the remaining threat



  15. EPO Management and Team UPC Carry on Lying About Unified Patent Court, Sinking to New Lows in the Process

    At a loss for words over the loss of the Unitary Patent, Team UPC and Team Battistelli now blatantly lie and even get together with professional liars such as Watchtroll



  16. China Tightens Its Knot of Restrictive Rules and Patents

    Overzealous patent aggressors and patent trolls in China, in addition to an explosion in low-quality patents, may simply discourage companies from doing production/manufacturing there



  17. Microsoft's Patent Racket Has Just Been Broadened to Threaten GNU/Linux Users Who Don't Pay Microsoft 'Rents'

    Microsoft revisits its aggressive patent strategy which it failed to properly implement 12 years ago with Novell; it wants to 'collect' a patent tax on GNU/Linux and it uses patent trolls to make that easier



  18. EPO Scandals Played a Considerable Role in Sinking the Unified Patent Court (UPC)

    Today's press coverage about the UPC reinforces the idea that the EPO saga, culminating in despicable attacks on Patrick Corcoran (a judge), may doom the UPC once and for all (unless one believes Team UPC)



  19. J Nicholas Gross Thinks Professors Stop Being Professors If They're Not Patent Extremists Like Him

    The below-the-belt tactics of patent trolls and their allies show no signs of abatement and their tone reveals growing irritation and frustration (inability to sue and extort companies as easily as they used to)



  20. The US Supreme Court Has Just Denied Another Chance to Deal With a Case Similar to Alice (Potentially Impacting § 101)

    There is no sign that software patents will be rendered worthwhile any time in the near future, but proponents of software patents don't give up



  21. Litigation Roundup: Nintendo, TiVo, Apple, Samsung, Huawei, Philips, UMC

    The latest high-profile legal battles, spanning a growing number of nations and increasingly representing a political shift as well



  22. Roundup of Patent News From Canada, South America and Australia

    A few bits and pieces of news from around the world, serving to highlight patent trends in parts of the world where the patent offices haven't much international clout/impact



  23. Links 15/1/2018: Linux 4.15 RC8, Wine 3.0 RC6

    Links for the day



  24. PTAB is Being Demeaned, But Only by the Very Entities One Ought to Expect (Because They Hate Patent Justice/Quality)

    The latest rants/scorn against PTAB -- leaning on cases such as Wi-Fi One v Broadcom or entities like Saint Regis Mohawk Tribe, Apple etc. -- are all coming from firms and people who profit from low-quality patents



  25. If Ericsson and Its Patent Trolls (Like Avanci and Unwired Planet) Cannot Make It, the Patent Microcosm Will Perish

    The demise of patent-asserting/patent assertion business models (trolling or enforcement by proxy) may see front groups/media supportive of it diminishing as well; this appears to be happening already



  26. European Patent Office Causes Physical Harm to Employees, Then Fires Them

    Another one (among many) EPO documents about the alarming physical wellbeing of EPO employees and the management’s attitude towards the issue



  27. Battistelli Was Always (Right From the Start and Since Candidacy) All About Money

    “I have always admired creative people, inventors, those who, through their passion and their work, bring about scientific progress or artistic evolution. I was not blessed with such talent myself,” explained the EPO‘s President when pursuing his current job (for which he was barely qualified and probably not eligible because of his political work)



  28. “Under the Intergovernmental EPC System It is Difficult to Speak of a Functional Separation of Powers”

    An illustration of the glaring deficiency that now prevails and cannot be tolerated as long as the goal is to ensure democratic functionality; absence of the role of Separation of Powers (or Rule of Law) at the EPO is evident now that Battistelli not only controls the Council (using EPO budget) but also blatantly attacks the independence of the Boards of Appeal



  29. The Patent Microcosm Thinks It's Wonderful That IP3 is Selling Stupid Patents, Ignores Far More Important News

    IP3, which we've always considered to be nothing but a parasite, does what it does best and those who love stupid patents consider it to be some sort of victory



  30. Automotives, Artificial Intelligence, Internet of Things and Industry 4.0 Among the Buzz Terms Used to Bypass Alice and the EPC Nowadays

    In order to make prior art search a lot harder and in order to make software patents look legitimate (even in various courtrooms) the patent microcosm and greedy patent offices embrace buzzwords


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts