[98733] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: ONS - The few the proud ... the sleeping

daemon@ATHENA.MIT.EDU (J. Oquendo)
Thu Aug 16 13:00:55 2007

Date: Thu, 16 Aug 2007 11:22:06 -0400
From: "J. Oquendo" <sil@infiltrated.net>
To: nanog@nanog.org
In-Reply-To: <20070816144839.GF29648@MrServer.telecomplete.net>
Errors-To: owner-nanog@merit.edu


This is a cryptographically signed message in MIME format.

--------------ms000407090603070102040701
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Stephen Wilcox wrote:

>=20
> Given that the fastest edge connections (outside of Peter Lothbergs bat=
hroom) are 10Gb this traffic can easily be directed to take out multiple =
parts of a networks critical connectivity.

(removed annoying cc's)

Well I was actually hoping Mrs. Lothberg would be the next
MAE-Scandanavia backbone provider. Do the math (anyone):

// SNIP

=E2=80=9CThe number of unique, infected hosts (bots), from which the atta=
ck is
being launched by email, has also increased dramatically,=E2=80=9D said S=
tewart.
=E2=80=9CThey went from 2,815 in the beginning of 2007 through the end of=
 May to
a total of 1.7 million for the months of June and July.=E2=80=9D

http://www.darkreading.com/document.asp?doc_id=3D130745

// END SNIP

Let's say its exaggerated and say this botnet is 1/4 of this size:
425,000 hosts waiting for a C&C dumbarse to launch a command. Something
simple ping... 64bytes * 425,000 hosts =3D 25MB ... ping -s 128 or higher=
?
A GET|HEAD|POST|etc would kill my server before the majority of traffic
even eeked its way through. Bad scenario ... Cause a flap between two
heavy peers (see Randy Bush's take on dampening/flapping). I could see
this become a problem no matter what you think you can throw at it.

Somewhere, someone down the line, will have something a bit
misconfigured/*oops I forgot to place tcp intercept here*/etc and will
cause some "could have been avoided if one woke up and smelled the
coffee" scenario which will cause a major outage. Poop happens when you
let it, why not open ones eyes now and be alert/aware of what's out
there and make sure solutions are in place before its too late.

Then again, I wonder what outside of massive filtering on fwsm's can one
do in a situation like this. Its not like these are spoofed connections
which something like tcp intercept would be able to mitigate against.
RFC1918 filtering... Useless. Different story if there was filtering on
provider side that says "Hey gee... This botnet that's 1.7 million
strong is connecting on port xxxxx, let me take a pre-emptive strike and
monitor this"

http://atlas.arbor.net/

+207.0 % Slammer variant as of yesterday... School is what one two weeks
away. Synonymous with all sorts of new improved crap... I can't for the
life of me figure out why some of the best engineers in the world who
are on this and other networking lists shrug these things off. Makes me
wonder who profits via bandwidth sales from this. Someone obviously will
irrespective of how rude, condescending it sounds.



--=20
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D
J. Oquendo
"Excusatio non petita, accusatio manifesta"

http://pgp.mit.edu:11371/pks/lookup?op=3Dget&search=3D0xF684C42E
sil . infiltrated @ net http://www.infiltrated.net



--------------ms000407090603070102040701
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIQGDCC
BIowggNyoAMCAQICECf06hH0eobEbp27bqkXBwcwDQYJKoZIhvcNAQEFBQAwbzELMAkGA1UE
BhMCU0UxFDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYDVQQLEx1BZGRUcnVzdCBFeHRlcm5h
bCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0ZXJuYWwgQ0EgUm9vdDAeFw0w
NTA2MDcwODA5MTBaFw0yMDA1MzAxMDQ4MzhaMIGuMQswCQYDVQQGEwJVUzELMAkGA1UECBMC
VVQxFzAVBgNVBAcTDlNhbHQgTGFrZSBDaXR5MR4wHAYDVQQKExVUaGUgVVNFUlRSVVNUIE5l
dHdvcmsxITAfBgNVBAsTGGh0dHA6Ly93d3cudXNlcnRydXN0LmNvbTE2MDQGA1UEAxMtVVRO
LVVTRVJGaXJzdC1DbGllbnQgQXV0aGVudGljYXRpb24gYW5kIEVtYWlsMIIBIjANBgkqhkiG
9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsjmFpPJ9q0E7YkY3rs3BYHW8OWX5ShpHornMSMxqmNVN
NRm5pELlzkniii8efNIxB8dOtINknS4p1aJkxIW9hVE1eaROaJB7HHqkkqgX8pgV8pPMyaQy
lbsMTzC9mKALi+VuG6JG+ni8om+rWV6lL8/K2m2qL+usobNqqrcuZzWLeeEeaYji5kbNoKXq
vgvOdjp6Dpvq/NonWz1zHyLmSGHGTPNpsaguG7bUMSAsvIKKjqQOpdeJQ/wWWq8dcdcRWdq6
hw2v+vPhwvCkxWeM1tZUOt4KpLoDd7NlyP0e03RiqhjKaJMeoYV+9Udly/hNVyh00jT/MLbu
9mIwFIws6wIDAQABo4HhMIHeMB8GA1UdIwQYMBaAFK29mHo0tCb3+sQmVO8DveAky1QaMB0G
A1UdDgQWBBSJgmd9xJ0mcABLtFBIfN49rgRufTAOBgNVHQ8BAf8EBAMCAQYwDwYDVR0TAQH/
BAUwAwEB/zB7BgNVHR8EdDByMDigNqA0hjJodHRwOi8vY3JsLmNvbW9kb2NhLmNvbS9BZGRU
cnVzdEV4dGVybmFsQ0FSb290LmNybDA2oDSgMoYwaHR0cDovL2NybC5jb21vZG8ubmV0L0Fk
ZFRydXN0RXh0ZXJuYWxDQVJvb3QuY3JsMA0GCSqGSIb3DQEBBQUAA4IBAQAZ2IkRbyispgCi
54fBm5AD236hEv0e8+LwAamUVEJrmgnEoG3XkJIEA2Z5Q3H8+G+v23ZF4jcaPd3kWQR4rBz0
g0bzes9bhHIt5UbBuhgRKfPLSXmHPLptBZ2kbWhPrXIUNqi5sf2/z3/wpGqUNVCPz4FtVbHd
WTBK322gnGQfSXzvNrv042n0+DmPWq1LhTq3Du3Tzw1EovsEv+QvcI4l+1pUBrPQxLxtjftz
Mizpm4QkLdZ/kXpoAlAfDj9N6cz1u2fo3BwuO/xOzf4CjuOoEwqlJkRl6RDyTVKnrtw+ymsy
XEFs/vVdoOr/0fqbhlhtPZZH5f4ulQTCAMyOofK7MIIFwTCCBKmgAwIBAgIQCtGhjfhz35st
CJNIS5OrJzANBgkqhkiG9w0BAQUFADCBrjELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcw
FQYDVQQHEw5TYWx0IExha2UgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3Jr
MSEwHwYDVQQLExhodHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xNjA0BgNVBAMTLVVUTi1VU0VS
Rmlyc3QtQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBFbWFpbDAeFw0wNjEwMDUwMDAwMDBa
Fw0wNzEwMDUyMzU5NTlaMIHZMTUwMwYDVQQLEyxDb21vZG8gVHJ1c3QgTmV0d29yayAtIFBF
UlNPTkEgTk9UIFZBTElEQVRFRDFGMEQGA1UECxM9VGVybXMgYW5kIENvbmRpdGlvbnMgb2Yg
dXNlOiBodHRwOi8vd3d3LmNvbW9kby5uZXQvcmVwb3NpdG9yeTEfMB0GA1UECxMWKGMpMjAw
MyBDb21vZG8gTGltaXRlZDETMBEGA1UEAxMKSi4gT3F1ZW5kbzEiMCAGCSqGSIb3DQEJARYT
c2lsQGluZmlsdHJhdGVkLm5ldDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAvcecKOQO
JDqytURULI+i0ju6GBa7bHBqxalyuhBT6jrSIwQmx+J5KpjuRaXQgSm73AJNSPx+qGGl1X65
w1gMZ8jHZ0nnVranOic31Um089ulE6pBY1V8MsVeiue+77xi6O/mEn8Jnea+ysIlTu+GZeQf
+W2RBTHXM6ErPKBES3UCAwEAAaOCAjAwggIsMB8GA1UdIwQYMBaAFImCZ33EnSZwAEu0UEh8
3j2uBG59MB0GA1UdDgQWBBRuQC562baQcF8itYR4eJVy0awkFzAOBgNVHQ8BAf8EBAMCBaAw
DAYDVR0TAQH/BAIwADAgBgNVHSUEGTAXBggrBgEFBQcDBAYLKwYBBAGyMQEDBQIwEQYJYIZI
AYb4QgEBBAQDAgUgMEYGA1UdIAQ/MD0wOwYMKwYBBAGyMQECAQEBMCswKQYIKwYBBQUHAgEW
HWh0dHBzOi8vc2VjdXJlLmNvbW9kby5uZXQvQ1BTMIGlBgNVHR8EgZ0wgZowTKBKoEiGRmh0
dHA6Ly9jcmwuY29tb2RvY2EuY29tL1VUTi1VU0VSRmlyc3QtQ2xpZW50QXV0aGVudGljYXRp
b25hbmRFbWFpbC5jcmwwSqBIoEaGRGh0dHA6Ly9jcmwuY29tb2RvLm5ldC9VVE4tVVNFUkZp
cnN0LUNsaWVudEF1dGhlbnRpY2F0aW9uYW5kRW1haWwuY3JsMIGGBggrBgEFBQcBAQR6MHgw
OwYIKwYBBQUHMAKGL2h0dHA6Ly9jcnQuY29tb2RvY2EuY29tL1VUTkFkZFRydXN0Q2xpZW50
Q0EuY3J0MDkGCCsGAQUFBzAChi1odHRwOi8vY3J0LmNvbW9kby5uZXQvVVROQWRkVHJ1c3RD
bGllbnRDQS5jcnQwHgYDVR0RBBcwFYETc2lsQGluZmlsdHJhdGVkLm5ldDANBgkqhkiG9w0B
AQUFAAOCAQEABj58KGEDtRZdukfsQ6F5wvMo4/yXdO/rpEYaPKEmBFOOu+o27qJ3pet9+ubi
cL5s6iPoq/pdonReD6bQKGyOmnUZdoznN7/S/sTJ65gjBogLk1BHc2JUiYsH79PuXT6kLqRJ
G3ufchBFNUuz4wSUs/j4hXRXz8vbWBncykNvtPmy1vIK4LSyccP1RIeU/uMMcneoZ5Urayso
YDlx8pAh3dL/12cTBpof3Iusl7e+TR5Vf/W3HmjzQrHyuMTueiB7lbwDhXyohjaB4FMHlhgm
lOf8SveLjvVKFZPJ5oJb/fVUKoDS6dInb0Vq09YMI0Jcwzj0CvajjtmUja/xpjcftjCCBcEw
ggSpoAMCAQICEArRoY34c9+bLQiTSEuTqycwDQYJKoZIhvcNAQEFBQAwga4xCzAJBgNVBAYT
AlVTMQswCQYDVQQIEwJVVDEXMBUGA1UEBxMOU2FsdCBMYWtlIENpdHkxHjAcBgNVBAoTFVRo
ZSBVU0VSVFJVU1QgTmV0d29yazEhMB8GA1UECxMYaHR0cDovL3d3dy51c2VydHJ1c3QuY29t
MTYwNAYDVQQDEy1VVE4tVVNFUkZpcnN0LUNsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQgRW1h
aWwwHhcNMDYxMDA1MDAwMDAwWhcNMDcxMDA1MjM1OTU5WjCB2TE1MDMGA1UECxMsQ29tb2Rv
IFRydXN0IE5ldHdvcmsgLSBQRVJTT05BIE5PVCBWQUxJREFURUQxRjBEBgNVBAsTPVRlcm1z
IGFuZCBDb25kaXRpb25zIG9mIHVzZTogaHR0cDovL3d3dy5jb21vZG8ubmV0L3JlcG9zaXRv
cnkxHzAdBgNVBAsTFihjKTIwMDMgQ29tb2RvIExpbWl0ZWQxEzARBgNVBAMTCkouIE9xdWVu
ZG8xIjAgBgkqhkiG9w0BCQEWE3NpbEBpbmZpbHRyYXRlZC5uZXQwgZ8wDQYJKoZIhvcNAQEB
BQADgY0AMIGJAoGBAL3HnCjkDiQ6srVEVCyPotI7uhgWu2xwasWpcroQU+o60iMEJsfieSqY
7kWl0IEpu9wCTUj8fqhhpdV+ucNYDGfIx2dJ51a2pzonN9VJtPPbpROqQWNVfDLFXornvu+8
Yujv5hJ/CZ3mvsrCJU7vhmXkH/ltkQUx1zOhKzygREt1AgMBAAGjggIwMIICLDAfBgNVHSME
GDAWgBSJgmd9xJ0mcABLtFBIfN49rgRufTAdBgNVHQ4EFgQUbkAuetm2kHBfIrWEeHiVctGs
JBcwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwIAYDVR0lBBkwFwYIKwYBBQUHAwQG
CysGAQQBsjEBAwUCMBEGCWCGSAGG+EIBAQQEAwIFIDBGBgNVHSAEPzA9MDsGDCsGAQQBsjEB
AgEBATArMCkGCCsGAQUFBwIBFh1odHRwczovL3NlY3VyZS5jb21vZG8ubmV0L0NQUzCBpQYD
VR0fBIGdMIGaMEygSqBIhkZodHRwOi8vY3JsLmNvbW9kb2NhLmNvbS9VVE4tVVNFUkZpcnN0
LUNsaWVudEF1dGhlbnRpY2F0aW9uYW5kRW1haWwuY3JsMEqgSKBGhkRodHRwOi8vY3JsLmNv
bW9kby5uZXQvVVROLVVTRVJGaXJzdC1DbGllbnRBdXRoZW50aWNhdGlvbmFuZEVtYWlsLmNy
bDCBhgYIKwYBBQUHAQEEejB4MDsGCCsGAQUFBzAChi9odHRwOi8vY3J0LmNvbW9kb2NhLmNv
bS9VVE5BZGRUcnVzdENsaWVudENBLmNydDA5BggrBgEFBQcwAoYtaHR0cDovL2NydC5jb21v
ZG8ubmV0L1VUTkFkZFRydXN0Q2xpZW50Q0EuY3J0MB4GA1UdEQQXMBWBE3NpbEBpbmZpbHRy
YXRlZC5uZXQwDQYJKoZIhvcNAQEFBQADggEBAAY+fChhA7UWXbpH7EOhecLzKOP8l3Tv66RG
GjyhJgRTjrvqNu6id6Xrffrm4nC+bOoj6Kv6XaJ0Xg+m0Chsjpp1GXaM5ze/0v7EyeuYIwaI
C5NQR3NiVImLB+/T7l0+pC6kSRt7n3IQRTVLs+MElLP4+IV0V8/L21gZ3MpDb7T5stbyCuC0
snHD9USHlP7jDHJ3qGeVK2srKGA5cfKQId3S/9dnEwaaH9yLrJe3vk0eVX/1tx5o80Kx8rjE
7noge5W8A4V8qIY2geBTB5YYJpTn/Er3i471ShWTyeaCW/31VCqA0unSJ29FatPWDCNCXMM4
9Ar2o47ZlI2v8aY3H7YxggPPMIIDywIBATCBwzCBrjELMAkGA1UEBhMCVVMxCzAJBgNVBAgT
AlVUMRcwFQYDVQQHEw5TYWx0IExha2UgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBO
ZXR3b3JrMSEwHwYDVQQLExhodHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xNjA0BgNVBAMTLVVU
Ti1VU0VSRmlyc3QtQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBFbWFpbAIQCtGhjfhz35st
CJNIS5OrJzAJBgUrDgMCGgUAoIICYTAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqG
SIb3DQEJBTEPFw0wNzA4MTYxNTIyMDZaMCMGCSqGSIb3DQEJBDEWBBT5hMHVLIqc5Ti5JnOq
cS+VUDROADBSBgkqhkiG9w0BCQ8xRTBDMAoGCCqGSIb3DQMHMA4GCCqGSIb3DQMCAgIAgDAN
BggqhkiG9w0DAgIBQDAHBgUrDgMCBzANBggqhkiG9w0DAgIBKDCB1AYJKwYBBAGCNxAEMYHG
MIHDMIGuMQswCQYDVQQGEwJVUzELMAkGA1UECBMCVVQxFzAVBgNVBAcTDlNhbHQgTGFrZSBD
aXR5MR4wHAYDVQQKExVUaGUgVVNFUlRSVVNUIE5ldHdvcmsxITAfBgNVBAsTGGh0dHA6Ly93
d3cudXNlcnRydXN0LmNvbTE2MDQGA1UEAxMtVVROLVVTRVJGaXJzdC1DbGllbnQgQXV0aGVu
dGljYXRpb24gYW5kIEVtYWlsAhAK0aGN+HPfmy0Ik0hLk6snMIHWBgsqhkiG9w0BCRACCzGB
xqCBwzCBrjELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExha2Ug
Q2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMSEwHwYDVQQLExhodHRwOi8v
d3d3LnVzZXJ0cnVzdC5jb20xNjA0BgNVBAMTLVVUTi1VU0VSRmlyc3QtQ2xpZW50IEF1dGhl
bnRpY2F0aW9uIGFuZCBFbWFpbAIQCtGhjfhz35stCJNIS5OrJzANBgkqhkiG9w0BAQEFAASB
gBg5b9Ug8Xy6lb7K/GXOwvd472Kut6wor6IXxBQ5tDT2lY6OajvpbTgjI4AcT+pAzos63+7x
yqnk5qNqwTACF71JIKVg6AE7zz2jKse4Ru2w4X+ZH3zDttQ3JNbaZjE56Yain7ZEfq8lmXyQ
e9lQHLRK4ducKK6yAh+U5CVdS6mXAAAAAAAA
--------------ms000407090603070102040701--


home help back first fref pref prev next nref lref last post