CNN site hit by China attack

April 23, 2008, 08:17 AM —  IDG News Service — 

After being called
off Friday
, the on-again, off-again cyber attack against CNN's Web site
again picked up steam early this week, according to network security analysts.

At its peak, the attack has sucked up 100MB/S in bandwidth, enough to slow
the news Web site for some visitors. "That's a decent-sized attack,"
said Jose Nazario, a senior security engineer with Arbor
Networks
. "Globally speaking, it's probably garden-variety."

Organizers had originally called for the attack to be launched on April 19.
But they soon called off their efforts with one organizer, CN-Magistrate, saying
that "too many people are aware of it, and the situation is chaotic."

CN-Magistrate soon disbanded his Web site devoted to these attacks and dropped
out of public view.

Hackers had launched some low-intensity attacks against CNN ahead of the April
19 deadline, but on Sunday, another group calling itself HackCNN picked up the
attack. CNN visitors experienced a noticeable slowdown during the early hours
of Sunday and Monday, researchers said.

This group also managed to deface
a Sports Network Web site (sports.si.cnn.com),
replacing sports scores with slogans such as "Tibet was, is, and always
will be a part of China!"

Although a CNN spokeswoman said that the Web site was not taken down by the
attacks, Web monitoring company Netcraft
said
that some of its sensors were unable to get a response from CNN servers
in Phoenix, San Jose, California, London and Pennsylvania for about three hours
on Sunday. On Monday, response times to CNN were as slow as two-tenths of a
second, Netcraft said.

CNN did slow down the rate at which network traffic from the Asia-Pacific region
was able to reach its Web site, the spokeswoman said.

Nazario said that a botnet network of hacked computers has now been involved
in the attacks, but the hackers have mostly relied on voluntary downloads to
spur their efforts.

Angered by Western coverage of unrest in Tibet by CNN, organizers had hoped
to knock the Web site offline using tactics similar to those seen in recent
attacks on Internet servers run by the Church of Scientology and the Baltic
nation of Estonia. Hackers made easy-to-use Web attacking tools available for
download on hackcnn.com and then encouraged as many computers as possible to
join in on the attack.

"People would purposely infect themselves with malware released on behalf
of Chinese hacktivists to automatically utilize their Internet bandwidth for
the purpose of a coordinated attack against a particular site," said Dancho
Danchev, a Bulgarian security researcher, via instant message.

"These guys are young. they're usually 20-25 years old, college students,
they spend their life online," said Scott Henderson, a retired U.S. intelligence
analyst who has been following the CNN attacks on
his blog
. "It is really a way of expressing themselves."

Security experts said that the Estonian and CNN attacks more closely resembled
a cyber riot than anything else, with no central figure in command and many
different groups, loosely coordinating their activities and attacking computers
in many ways.

The attacks can be hard to stop at first, and they tend to garner attention
to the attacker's political cause, Nazario said. "We're going to see this
again because it's effective to some degree."

IDG News Service

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff

VMware ESX Server in the Enterprise
By Edward L. Haletky
Published Dec 29, 2007 by Prentice Hall.
Enter now! | Official rules | Sample chapter

Green IT
By Toby Velte, Anthony Velte, Robert C. Elsenpeter
To be published Oct. 10, 2008 by McGraw Hill Professional
Enter now! | Official rules | About the book

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

More Resources