Denial of Service Attacks

I presume many of you have heard on TV or Radio about the Denial of Service Attacks by Hackers that took Yahoo down for three hours, and which have been made against other sites like eBay, Amazon, etc

I recently installed a ZoneAlarm FireWall (http://www.zonelabs.com/) on my system because my cable modem is connected all the time, and began seeing a lot of attempts to probe my system. Interestingly the first I caught was someone else on the @home cable modem system, and the most recent one (last night) was also on that system, but I have had many from non @home IPs as well.

I was in the process of writing an email to ZoneLabs about wanting to be able to log these attacks when one began, and they probed me 8 times while I was writing the email, giving me enough time to switch to another window and do a tracert to them, which I included in the email to ZoneLabs and to a couple of people with @home, and which I have forwarded to the FBI:

Subject:logs
Date:Wed, 09 Feb 2000 23:22:41 -0600
From: Don Singleton <djs@ionet.net>
Organization:Tulsa Computer Society
To: feedback@zonelabs.com, support@zonelabs.com
CC: Mark Fancher <fancherboy@home.com>, customer.care@tci.com
I understand that Zone Alarm does not currently log attempts to get past the firewall but are considering adding it. I don't know how much trouble that would be, but I have had a LOT of attempts to probe me, from a number of IPs, in the last day or two, and I am suspicious that the people killing Yahoo, etc may be looking for other machines to hijack, and if you were able to add something, even if crude, that allowed them to be caught, it would be one heck of a feather in your cap. While writing this message 24.10.237.210 attempted to access my Port 12345 from their port 1699 AND they also tried to access my port 12346 from their port 1953 AND tried to access my port 31337 from their port 2207 AND my port 1243 from their port 2461 AND my port 6670 from their port 2715 AND someone tried to access my NetBIOS Name (10.76.118.1) AND (10.0.192.5) and (10.0.236.38)

In fact I got so many that I did not think I could type fast enough to copy them (since I can't seem to mark the text in your pop up windows).

FYI here is a tracert to 24.10.237.210

Since this site is apparently an @home customer as I am, I am also forwarding it to the man who installed my cable modem and a tech number with TCI. Mark, you may want to forward this to the abuse number you gave me as well.

C:\WINDOWS>tracert 24.10.237.210
Tracing route to cc298468-a.hwrd1.md.home.com [24.10.237.210] over a maximum of 30 hops:
1 13 ms 13 ms 13 ms 10.76.118.1
2 13 ms 14 ms 15 ms r1-fe1-0-100bt.tulsa1.ok.home.net [24.10.24.1]
3 34 ms 32 ms 27 ms 10.0.192.5
4 28 ms 25 ms 27 ms bb1-fe0-0-100bt.rdc1.tx.home.net [24.4.0.1]
5 65 ms 37 ms 54 ms c1-se6-0.ftwotx1.home.net [24.7.72.225]
6 29 ms 30 ms 41 ms c1-pos5-0.dllstx1.home.net [24.7.64.134]
7 38 ms 46 ms 54 ms c1-pos5-0.tulsok1.home.net [24.7.64.161]
8 55 ms 40 ms 52 ms c1-pos3-0.omahne1.home.net [24.7.64.149]
9 57 ms 49 ms 51 ms c1-pos1-0.chcgil1.home.net [24.7.64.142]
10 60 ms 57 ms 73 ms c1-pos3-0.clevoh1.home.net [24.7.64.174]
11 77 ms 66 ms 68 ms c1-pos5-1.cmdnnj1.home.net [24.7.67.150]
12 75 ms 71 ms 73 ms c1-pos2-0.bltmmd1.home.net [24.7.68.129]
13 69 ms 79 ms 79 ms bb1-pos1-0-0.rdc1.md.home.net [24.7.72.94]
14 88 ms 70 ms 71 ms 10.0.236.38
15 80 ms 92 ms 74 ms cr1.hwrd1.md.home.net [24.3.0.59]
16 106 ms 80 ms 86 ms cc298468-a.hwrd1.md.home.com [24.10.237.210]

Trace complete.

The FBI web site has information about these attacks (http://www.fbi.gov/nipc/trinoo.htm) and they even have sofware which can be installed on Unix systems to help identify the culprits. As far as I can tell, they don't have Windows software, so I guess the ZoneAlarm is the best that can be used there.

I wanted to let you know about ZoneAlarm, in case you wanted to install it on your systems. Just go to http://www.zonelabs.com/ Its use is not limited to DSL and Cable Modem connections. It was installed on my system yesterday during a dial up connection for a Sig Meeting, and we were interrupted with at least 10 different probes during the meeting.

See also:
http://www.zdnet.com/zdnn/special/doswebattack.html
http://cnn.com/2000/TECH/computing/02/08/yahoo.assault.idg/index.html
http://cnn.com/2000/TECH/computing/02/09/cyber.attacks.01/index.html
http://www.forbes.com/forbes/00/0221/6504068a.htm
http://www.forbes.com/forbes/00/0221/6504068s1.htm

Previous TCS Virus Alerts:



This page has been accessed times.
Tulsa Computer Society
Don Singleton, President
djs@ionet.net