DC++ Used for Denial of Service (DoS) AttacksBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard - New Version 9 Out Now - Dld 30-day trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/7 19:22:16
2009/11/7 19:22:16
2009/11/7 19:22:16
2009/11/7 15:40:03
Our Partners
Downloads
P2P Security News : DC++ Used for Denial of Service (DoS) Attacks
Posted by Max on 2007/6/1 7:00:00 (2421 reads)
P2P Security News

A fault in the design of the popular peer-to-peer network software DC++  has given attackers the capability to create massive denial-of-service (DoS) attacks that can easily overwhelm corporate Web sites, a security firm warned last week.

Over the past three months, more than 40 companies have endured attacks emanating from hundreds of thousands of Internet protocol addresses (IPs), with many of the attacks producing more than a gigabit of junk data every second, according to security solutions provider Prolexic Technologies. The sheer number of Internet addresses has caused problems for routers and firewalls, burying solutions that rely on some form of blacklisting, said Paul Sop, chief technology officer for the firm.


"It's like asking how fast can you bail your boat?" Sop said. "If you stop for a minute you get overwhelmed."

Unlike past attacks, which use tens of thousands of compromised computers to deluge a Web server or network with data, the latest attacks came from a collection of computers running peer-to-peer software known as DC++. The software is based on Direct Connect, a protocol which allows the exchange of files between instant messaging clients.

While the file-sharing network is distributed, the directories of where to find certain files resides in a few servers, known as hubs. Older versions of the hub server software have a flaw that allows an attacker to direct clients to get information from another server, said Fredrik Ullner, a developer for the DC++ project and an computer-science undergraduate at Sweden's Lund Institute of Technology. Maliciously redirecting those client results in a large number of computers continuously demanding data from the victim's Web server, overwhelming it with requests.

The attacks were used against DC++ own developers and hub directories as early as 2005. The first attacks targeted the project's directory of hubs, known as Hublist.org. Rogue DC++ users had created tools to flood a hub, and when Hublist.org removed the rogue users' servers, the group responded by attacking Hublist.org, Ullner said. The site is no longer accessible. The rogue group also hit DCPP.net, the project's main site, forcing the developers to move to SourceForge.

"These attacks are, unfortunately, getting more common," Ullner stated in an e-mail interview with SecurityFocus.

The technique proved so effective that attackers have turned it on other companies.

In March, companies started seeking out Prolexic to help them stave off some devastating denial-of-service attacks. In many of the attacks, more than 150,000 computers would open a handful of connections each, burying the Web server in a avalanche of network data. The largest attacks seen by the company involved more than 300,000 computers, said Prolexic's Sop.

"We had millions and millions of connections in," Sop said. "We could identify the attacks with zero difficulty but new IPs were hitting us faster than we could block them."

While many of the attacks were part of an extortion attempt -- a common way in the past to turn denial-of-service capabilities into cash -- about three quarters of the attacks were motivated by industrial espionage, Sop said.

"The amount of money involved is pretty large," Sop said. "If you have a good Internet business in Europe, and you can knock out your competitor, why spend money on marketing?"

The firm announced on Wednesday that it had developed a way to defend against the attacks.

A general solution is unlikely to appear from the DC++ project. While the problem has already been fixed in the DC++ hub software, it's hard to force everyone to adopt the fix, said developer Ullner.

"The attackers take advantage of people's reluctance to upgrade," he said.

Moreover, even if all the hub administrators upgraded their systems, the attackers could run their own hubs until they commanded enough DC++ clients to attack a target.

"It's difficult to impossible to restrict this," said Ullner.
Source: SecurityFocus




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.

Poster Thread
sarai166
Posted: 2009/2/2 16:07  Updated: 2009/2/2 16:07
Just popping in
Joined: 2009/2/2
From:
Posts: 3
 Re: DC++ Used for Denial of Service (DoS) Attacks
Greetings. Check my site with quality info: craigs list, face book