Archive for July, 2008

30 Days of DNS Attack Activity

July 28, 2008 by Danny McPherson

With the array of activity as of late surrounding Kaminsky’s DNS Cache Poisoning vulnerability, we checked some of our various data sources to get an idea of what folks are seeing activity-wise as a result - if anything discernible. There are three discrete data sources I had a look at in hopes of identifying [...]

Read More

DNS Updates - The cat, a now empty bag, and poison

July 25, 2008 by Jose Nazario

Last week I posted a piece on the Internet Effects of the DNS bug disclosure, looking at a week’s worth of DNS traffic. Some folks had assumed massive patching and updates causing an uptick in DNS traffic (due to cache refreshes), and our Internet statistics revealed that we didn’t see any such traffic uptick. I [...]

Read More

Moving Offices in Ann Arbor

July 24, 2008 by Jose Nazario

We spent the past four and a half years (or so) in our location, a full floor of a downtown office building. We’re now bursting at the seams with staff, equipment, and our current space just wasn’t suiting us any longer. We spent the past few days packing up and organizing everything for a move [...]

Read More

DNS Vulnerability; The Other Part of that Partial Disclosure

July 22, 2008 by Danny McPherson

Just under two weeks ago, on July 8, a vulnerability disclosure was released warning of multiple DNS implementations being susceptible to yet another new DNS cache poisoning attack, but one professed to be far worse than previous attacks. Dan Kaminsky, in cooperation of with a large number of well-respected security and DNS experts, and [...]

Read More

Georgia On My Mind - Political DDoS

July 20, 2008 by Jose Nazario

The website for the President of Georgia, a former Soviet republic, has come under DDoS (hat tip: Shadowserver team). This attack appears to have a political motivation. One of the messages in the floods (HTTP, SYN, ICMP) reads “win+love+in+Rusia”. Tensions between Russia and Georgia appear to be running high lately.
While I am not positive what [...]

Read More