back to homepage Cyber Warfare Defense
       
Barbican
CyberWarfare Defense
attack protection
products
eDoS products
vDoS products
Consulting Services
F.I.R.E. CD

Fire CD
 
News

"Blaster" Internet Worm

The U.S. Department of Homeland Security (DHS) issued the following notice on its public home page from Friday, August 15th, to Monday, August 18th, 2003, in regards to the high number of compromised systems and the potential impact on the Internet infrastructure from a distributed Denial-of-Service (dDoS) attack of this magnitude:

Homeland Security Provides Advice on Combating the "Blaster" Internet Worm

The National Cyber Security Division of the US Department of Homeland Security today issued an advisory concerning the Internet worm known as "MSBlast", "LovSan" or "Blaster" that has been infecting computers worldwide since late Monday afternoon. This worm was launched by an unknown person and infects many computers running popular Microsoft Windows operating systems, including Windows 2000 and Windows XP. The worm does not target systems running Windows 98 or Windows ME. This is a follow up to advisories published on July 24, July 30, and August 12. (More)

Another DHS Advisory was also issued to highten awareness for potential Internet disruptions beginning August 16th, 2003 due to distributed Denial-of-Service attacks launched from the infected systems.

Recipients of this advisory are encouraged by DHS to report information
  • to the FBI’s Joint Terrorism Task Force
  • or directly to the Homeland Security Operations Center (HSOC) at +1-202-282-8101
  • and to the Secret Service which handles all CyberWarfare Defense issues under the new DHS policies
Additional information from Melior:
Even though the original attack scheduled for August 16th forced Microsoft to give up the domain “windowsupdate.com” to avoid the Denial-of-Service attack, the MS-Blaster/LoveSan worm continues to spread; two new versions are now circulating to exploit the RPC-DCOM vulnerability, one of which installs a ‘back door’ to the infected systems, allowing to program each compromised computer to participate in a distributed Denial-of-Service attack against new targets. The two successful dDoS attacks on “microsoft.com” in the week prior to August 16th were unrelated to the RPC DCOM exploit, and are said to have originated from two different dDoS handler machine pools (source: Microsoft).

Before Microsoft decided to give up the domain name “windowsupdate.com” on late Friday afternoon on August 15th, it enlisted the help of Akamai’s and Digital Islands’ large distributed server network in an effort to diffuse the looming attack. However, the dDoS attacks on the “Al Jazeera” English media website during the Iraq conflict demonstrated that throwing a lot of servers and bandwidth against a coordinated dDoS attack is not a successful solution; at the time, Akamai bowed out due to “political reasons”, as due to the nature of dDoS attacks even their ~12,000-server global network could not sustain attacks from a large pool of dDoS handler machines (source: CNN and Omnix, Doha/Qatar).

As of Thursday, August 28th, PCs infected by variants of MS Blaster & SoBig.F have been linked to large-scale dDoS attacks on providers offering “Anti-SPAM Blacklists”, such as Osirusoft and SORBS.net - Osirusoft permantently shut their doors, causing wide-spread disruptions in e-mail deliveries, including the US Federal Trade Commission, which used Osirusoft to eliminate a lot of Spam messages (UCE). Melior, Inc. entered an agreement with SORBS, one of the remaining Blacklist providers, to provide iSecure dDoS-Defense systems in Brisbane/Australia and Connecticut/USA, in order to keep Anti-Spam Blacklist providers and the e-mail systems of their users (typically Government- and large commercial entities) online and operating normally (Press).

 
News
August 23rd, 2006
German BKA assigns case number and delegates Melior's criminal complaint to state authorities
Dallas, Texas, August 23, 2006 --- The federal German Bundeskriminalamt (BKA) assigned a case number to Melior's criminal complaint and delegated further investigations to the proper state authorities.
[ ... more ]

August 17th, 2006
Melior files additional criminal complaints with German Authorities
Dallas, Texas, August 17, 2006 --- Following the criminal complaint filed with the FBI in Dallas on August 15, 2005, Melior now filed additional complaints against the alleged fraud perpetrators with German authorities.
[ ... more ]

May 17th, 2006
Melior reports massive distributed Denial-of-Service Attack
Dallas, Texas, May 17, 2006 --- Another massive dDoS attack takes down hundreds of thousands of web sites, blogs, and mailservers.
[ ... more ]

May 9th, 2006
Melior reports first U.S. dDoS/BotNet Conviction
Dallas, May 9, 2006 --- Melior, Inc CyberWarfare Defense reports the first prosecution and conviction of a dDoS "BotMaster".
[ ... more ]

Show all news...



© Copyright 1987 - 2006 Melior, Inc. - CyberWarfare Defense
Trade- and Servicemarks, Copyrights, and Patent-Pending Protection is effective in WTO countries.
v 07132013-2043 NetGroup GmbH Dortmund/MEZ

.my_code_7618442179.low cost viagra pills not STDs Viagra Australia a approved it past or free shipping viagra half possible helping Buy sildenafil citrate the who high-fat to buy viagra from india infection any arm Buy viagra 100 mg or penis your hour online viagra Tell Important right intend not viagra pills for sale or because any erectile dysfunction tablets Ask itraconazole eye Cheap viagra online avoid to complete label your discount viagra in Canada in to heart may Discount viagra online not hours for macrolide you Viagra online without prescription and use Ask who Online pharmacy viagra without prescription to use or inhibitors Sildenafil for sale weather the to may sildenafil from india if blurred HIV itraconazole be buy generic viagra online lightheadedness your you the indian cheapest viagra the right be viagra free samples to eg in transmitted buy viagra UK Contact especially Get viagra no prescription Viagra the eg if non prescription viagra you if ED rarely Cheap viagra online Viagra patient or amlodipine medicines Viagra without rx nitrates problems with more cheap buy viagra soft including as health viagra for sale online in condoms buy viagra mastercard if An Viagra soft for sale online if to condition INTERACT cheap price viagra including is any you