Bonum Certa Men Certa

DNS Suspended by Microsoft Windows Botnets

Warpath of Web destruction

TWO DAYS ago I was unable to use the Internet properly. This network's DNS servers came under massive attack at a time when hundreds of millions of Windows zombies ran rampant. It's neither a new problem [1, 2] nor does affect just the network that I'm on. There are similar complaints and status reports out there on the Web right now.

Potential Latency on Network Solutions DNS



There is a spike in DNS query volumes that is causing latency for the delay in web sites resolving. This is a result of a DDOS attack. We are taking measures to mitigate the attack and speed up queries

—————-

There may be some latency on Network Solutions DNS Severs and some queries may be timing out. This may include instances when someone types a domain name into a browser and the website will temporarily not resolve. Network Solutions Operations is working on optimizing the DNS queries and investigating the issue.


There is nothing that prevents a determined cracker (or a gang of them) from taking down DNS globally [18, 19], especially given Windows botnets of biblical proportions . This almost happened 2 years ago and there are still no effective defenses in place. The same goes for the scale of botnets -- a solution to which Microsoft cannot deliver.

"Microsoft slammed over security advice



US COMPUTER Emergency Readiness Team (US-CERT) has warned that Microsoft's advice about how to beat the Downadup worm is flawed.


And things are getting worse before they get better.

A security expert has managed to transfer the digital signature of one Windows program to another, without invalidating the signature. Didier Stevens, who presented the attack in his blog, exploited the fact that Microsoft's Authenticode code signing standard accepts the vulnerable MD5 hash algorithm. Stevens used this to generate two programs which have identical code signatures, but behave differently.


How long can this chaos [1, 2, 3] go on for? Many related news (2006-2008, re: DNS) are added as references below.

Airplane crash
What if aircrafts accepted Microsoft quality control?



_____ [1] Open source DNS server takes on BIND

Four companies led by Dutch non-profit NLnet Labs have launched an open source, Linux-compatible DNS (Domain Name System) server. "Unbound," which is also sponsored by VeriSign, Nominet, and Kirei, claims to offer a validating, recursive, and caching DNS server that is faster than the open source DNS mainstay BIND.


[2] VeriSign Takes Aim at Open Source DNS

Now VeriSign, the company that runs that .com and .net domains, is aiming to provide an open source alternative to BIND, called Unbound.


[3] SocialDNS: Free Domains for a Free Internet

John Sullivan (FSF) invited me to present in this mailing list the SocialDNS project (http://www.socialdns.net). I am very interested in obtaining feedback from the GNU community because we want to submit our project to the Free Software Directory soon.


[4] DNS Patches Slow Servers, but Fast Action Is Advised

Microsoft issued a mea culpa about its DNS update on July 17, saying that the patch was crippling some machines running its Windows Small Business Server suite. Then, on July 25, it said the patch could also affect some network services on systems running Windows Server 2008, Windows Server 2003 and Windows 2000. In both instances, Microsoft detailed work-arounds.


[5] DNS poisoners hijack typo domains

People arrive at these pages when the domain name they request is unavailable, because, for example, they mistyped the URL. ISPs use this redirection method, known as Typosquatting, to advertise free domains or competing products. In the present case, however, clients don't arrive on the Typosquatter pages, but on pages with a crafted trojan.


[6] Microsoft DNS fix causes trouble for some

The Microsoft Corp. released a DNS fix in its patch slate for July, but the company seems to have problems just getting it to end users. Moreover, some users of the DNS fix have experienced additional difficulties.

So far, since Microsoft's DNS fix was issued on July 10, there have been two separate problems associated with its installation.


[7] H D Moore has NOT been owned

From the "half truths that journo's tell" file:

I've been following the Kaminsky DNS cache exploit issue closely since it was first announced - and no doubt so has everyone else in the security business. As such I was surprised to read a headline this morning that said that Metasploit founder H D Moore (and yes Virginia, there is a Santa Claus and I run Metasploit on a test machine too - who doesn't?) had been 'owned' (should've been p'wned I think) by the DNS flaw.

The story is not true - at least according to H D Moore who claims he was misquoted by the journalist in question.

"In a recent conversation with Robert McMillan (IDG), I described a in-the-wild attack against one of AT&T's DNS cache servers, specifically one that was configured as an upstream forwarder for an internal DNS machine at BreakingPoint Systems," H D Moore wrote in a blog post. "Shortly after our conversation, Mr. McMillan published an article with a sensationalist title, that while containing most of the facts, attributed a quote to me that I simply did not say. Specifically, `"It's funny," he said. "I got owned."


[8] SUBJECT: Microsoft SWI blog inaccuracies

As you know, 3 weeks ago I published my paper, "Microsoft Windows DNS Stub Resolver Cache Poisoning" (http://www.trusteer.com/docs/Microsoft_Windows_resolver_DNS_cache_poisoning.pdf),

simultaneously with Microsoft's release of MS08-020 (http://www.microsoft.com/technet/security/Bulletin/MS08-020.mspx). A day later, Microsoft's Secure Windows Initiative (SWI) team published their blog entry for MS08- 020 (http://blogs.technet.com/swi/archive/2008/04/09/ms08-020-how-predictable-is-the-dns-transaction-id.aspx).

Unfortunately, the SWI blog entry contains two serious mistakes. The first mistake is an inaccurate description of the PRNG used for the Microsoft Windows DNS client transaction ID. The second mistake is SWI's claim that "attackers cannot predict a guaranteed, known-next TXID exactly even with this weakness".

I contacted Microsoft about those mistakes, and while Microsoft did not refute my statements, they also refused to revise the blog entry. On one hand, I am inclined to tag this as a simple unwillingness on the side of the vendor to revise its materials and admit its mistakes. On the other hand, I cannot ignore the fact that the two mistakes, when combined, result in misleading the blog reader about the nature and the severity of the problem.

[...]

This is in stark contrast to SWI's claims. Furthermore, Microsoft did have the full paper (actually, a draft of it which contains all the relevant technical information) well before the SWI blog was published. So the problem here is not an issue of SWI not having access to the paper when they wrote their blog entry.


[9] Microsoft preps 133 patches for Windows DNS hole

Microsoft is working on 133 separate updates for the problem, Budd wrote.


[10] Microsoft DNS Server Attacks Continue

The concept enables malicious users to run code remotely under the system privileges generally granted to the DNS service itself.


[11] Microsoft: Patch for critical DNS flaw may be ready by 8 May

The cmopany has been under pressure to address the flaw, reported last week, since software that exploits it has now been widely disseminated, and criminals are beginning to use it in attacks.


[12] Attack code raises Windows DNS zero-day risk

At least four exploits for the vulnerability in the Windows domain name system, or DNS, service were published on the Internet over the weekend, Symantec said in an alert Monday.


[13] Cybercrooks exploiting new Windows DNS flaw

Cybercrooks are using a yet-to-be-patched security flaw in certain Windows versions to attack computers running the operating systems, Microsoft warned late Thursday.


[14] Microsoft's advisories giving clues to hackers

How's this for a new twist on the old responsible disclosure debate: Hackers are taking advantage of information released in Microsoft's pre-patch security advisories to create exploits for zero-day vulnerabilities.


[15] DNS security improves as firms tool up to tackle spam

Infoblox's survey found that the number of internet-facing DNS servers increased from 9m in 2006 to 11.5m in 2007, indicative of the overall growth of the internet. Percentage usage of the most recent and secure version of open-source domain name server software - BIND 9 - increased from 61 per cent to 65 per cent over the last year. Use of BIND 8, by contrast, dropped from 14 per cent in 2006 to 5.6 per cent this year. Usage of the Microsoft DNS Server on web-facing systems also fell, decreasing to to 2.7 per cent in 2007 from five per cent last year.


[16] Use of rogue DNS servers on rise

The paper estimates roughly 68,000 servers on the Internet are returning malicious Domain Name System results, which means people with compromised computers are sometimes being directed to the wrong Web sites — and often have no idea.


[17] New shield foiled Internet backbone attack

ICANN has yet to determine the exact techniques used in the February attack. The incident will be discussed at a meeting of DNS root server operators later this month, the organization said.


[18] Zombie botnets attack global DNS servers

Hackers launched a sustained attack last night against key root servers which form the backbone of the internet.

Security firm Sophos said that botnets of zombie PCs bombarded the internet's domain name system (DNS) servers with traffic.

"These zombie computers could have brought the web to its knees," said Graham Cluley, senior technology consultant at Sophos.


[19] EveryDNS, OpenDNS Under Botnet DDoS Attack

The last time the Web mob (spammers and phishers using botnets) decided to go after a security service, Blue Security was forced to fold and collateral damage extended to several businesses, including Six Apart.


[20] Homeland Security sees cyberthreats on the rise

To test the nation's response to a cyberattack, the Department of Homeland Security plans to hold another major exercise, called Cyberstorm II, in March 2008, Garcia said. A first such exercise happened early last year.


[21] Perspective: Microsoft security--no more second chances?

As if Homeland Security Secretary Michael Chertoff didn't have enough on his plate.

Not only has he had to deal with Katrina and Osama. Now he's also got to whip Steve Ballmer and the crew at Microsoft into shape. If past is prologue, that last task may be the most daunting of all.


[22] U.S. cyber counterattack: Bomb 'em one way or the other

If the United States found itself under a major cyberattack aimed at undermining the natio's critical information infrastructure, the Department of Defense is prepared, based on the authority of the president, to launch a cyber counterattack or an actual bombing of an attack source.


[23] US plans for cyber attack revealed

Comments

Recent Techrights' Posts

In Techrights, Gemini and HTTP/HTML Are Very Different
Those were never equivalents or mirrors, those are two things that are inherently different and are maintained by different teams
"The War on Children" Explained by The Cyber Show
Consumer protection and the war on children
 
Hate Consumes the Haters
If you hate someone (or something) and you're willing to do anything for "hate rituals", then at the end the emotion will outweigh reason and it'll backfire, surely
GNU/Linux Rises Some More Internationally, statCounter Now Estimates Its Usage on Desktops/Laptops at 7.7%
significant growth for GNU/Linux in Japan, China, Thailand, Vietnam, Indonesia and Cambodia
IBMers on PIPs and the Age (or Cost) Factor
People in their 50s seem to be targeted as they are considered "expensive"
Sad State of Troll-Feeding British Media (Establishment Channels Promoting Total Idiots)
Breeding ignorance means people will assume they have a choice between two pieces of trash: "Nige" or a literal trash can
Links 27/07/2026: Sleepless Japan PM Takaichi Becomes Unpopular and Data Centre Magnate Confiscate Land Without Consent
Links for the day
A Few Hours Ago The Register MS Published an 'Article' With "AI" 32 Times in It, Including First Word in Headline and Summary. It Was Paid SPAM "Sponsored by Hammerspace".
The lost media is engaging in self-harm
Microsoft is Down
This relates in a timely fashion to what we published yesterday
Gemini Links 27/07/2026: Gemified Internet RFCs, “Junk DNA” Is Commented-Out Code, and More
Links for the day
The Techrights Gemini Capsule Was Never a Mirror
Techrights has long taken accessibility quite seriously
Americans Are Not Our Masters
If you are subjected to online abuse, don't give up
Daniel Pocock Campaigns Around "Safety of Children Online" and "Cybersecurity"
There seems to be a growing 'coalition' in the UK based around important issues which impact the entire planet
XBox the Console is Practically Finished (Unofficially), Even the Streaming ("Live") or DRM Service is Dead
XBox has never been closer to profitability
Many CEOs Are Just Glorified Scammers With Suits and Ties
Economies cannot function when few people abuse them for self-enrichment
After statCounter Figures Out Many "Unknowns" Were in Fact GNU/Linux the "Market Share" Estimate in China More Than Doubles
Japan is the same for similar reasons
peppe8o - a Site About Raspberry Pi, Arduino and Electronics - Has Turned Into a Slopfarm
We won't be linking to it anymore
Feeding 'the Children'
Maybe some time soon we'll do a fund-raiser to help feed the birds
Japan: GNU/Linux Crosses the 5% Threshold, Two Years Ago It Was Only 1%
Now it's at over 5%
We Need More Transparency
Our heads of state are very much aware of and concerned about SLAPPs and censorship
EPO Cocainegate and Current EPO/EU Series to Carry on for Months to Come
Another week has begun
When IBM "Managers Have to Mark 15% of Their Teams as Low Performers" a PIP Means Likely Layoffs (Disguised as a Performance Issue)
"IBM is a Law firm with an I/T department."
Links 27/07/2026: Chatbots Lead to Suicides, Social Control Media Intentionally Designed for Addiction
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, July 26, 2026
IRC logs for Sunday, July 26, 2026
Daniel Pocock in Mainstream Media Again
AFR wrote an article today. It is about Pocock and another contender.
Millions of Daily Requests
4.5+ million requests in 4 days
In statCounter, a Lot of "Unknown" Turns Out to be GNU/Linux
GNU/Linux has more than doubled
3,500 Active Gemini Capsules Soon
How much longer before 3,500+ active? A month?
Gemini Links 26/07/2026: European Eclipse, Writing About Writing, and Comments on Formatting Gopher Posts
Links for the day
Stigma of Being Laid Off by Microsoft
One might call this the "curse" of having worked for Microsoft
Silent Layoffs (PIPs) Have Allegedly Accelerated Since IBM's Stock Cratered
"IBM is Managing Decline, Not Building Growth"
Non-Techs Using Slop Run Fedora and It's Turning Out to be a Total Disaster
RIP, Fedora?
Gemini Links 26/07/2026: Beach Day, CAs, and Plaintext
Links for the day
Sweden Needs GNU/Linux and Free Software, Not GAFAM
home of IKEA and ABBA
Being Pro-Slop is Death Knell to One's Credibility
It's not hard to see Ubuntu users resisting and antagonising this
Maintenance Today
Preparing for more mass-publication activities
Links 26/07/2026: "Zelenskyy Says Russia Wants To Bring North Korean Troops Into Ukraine", Muslim Van Ramming Attack on Berlin Pride
Links for the day
Centrica fraud exposed: worse than Palestine Action 'terrorists' with cardboard placards
Reprinted with permission from Daniel Pocock
Links 26/07/2026: "Nate Silver Discovers the Educated Poor" and "India’s “Cockroach” Protest Movement Faces State Repression"
Links for the day
The Slop Bubble is Killing the Planet, Not Just the Economy
The chatbot/LLM speculation bubble not only causes a health crisis, a mental health epidemic, and climate change; it's also crashing the economy on several levels
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, July 25, 2026
IRC logs for Saturday, July 25, 2026
IBM Hammers a CoI Into a CoCed Fedora, RIP Fedora?
Also in the "Fedora is dead" dept. today
Gemini Links 25/07/2026: Zoo, MUD, Literature, EMF Camp, and e-ID
Links for the day
European Patent Office (EPO) Series: The Solution of No Choice: A Shortlist of One
deployment of the "shortlist of one" by Campinos
Wife of Dan Williams Has Explained Mental Factors Leading to His Death
"We need to be open and honest about mental health," his wife pleads
Several New Series Coming Soon
we'll publish 8 series in tandem, in parallel
Insolvency as the New Norm in the United States' Economy
this is vastly worse than then 2008 subprime mortgage crisis
IBM's CEO Might 'Retire' or 'Step Down' by Christmas
PIP the CEO
Misleading Articles About YouTube and Google Financial Performance
The future of Google is self-serving monopolisation and destruction of the Web
Microsoft Cannot Survive the Fall of Windows
It has amassed way too much debt
Links 25/07/2026: Hong Kong Squashing Criticism/Dissent, Mirror Caught Breaking Into Voicemail
Links for the day
PIPs Are Shrinking IBM and "IBM is Managing Decline, Not Building Growth"
IBM is going down the drain
IBM is Killing the Fedora Community, Replacing It With LLM Slop From IBM Staff
Krishna buys companies only to gut them. They've all learned this from experience.
Give Me Your "Dumbest" (Devices)
Why can't people accept that a "modern "smart" "phone" isn't necessary to check the time (overkill) and playing social control media "on the go" is far from necessary?
Earlier This Year Dan Williams Prepared for Scenario Where Linus Torvalds Dies
He had only just started a job at NVIDIA
Links 25/07/2026: Data Breaches Abundant and Attribution Imperiled in the Age of Slop Hype
Links for the day
Gemini Links 25/07/2026: Poetry and Plaintext Pages
Links for the day
What is Doctor of Philosophy (Ph.D.)
In many cases, the acronym became a misnomer
IBM PIPs Continue Until Morale Improves, Silent or Quiet Firings at IBM Explained
IBM is a dying company
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 24, 2026
IRC logs for Friday, July 24, 2026