A “bazooka” cyberattack described as the most powerful ever seen has slowed traffic on the Internet, security experts said on Wednesday, raising fresh concerns over online security.
The attacks targeted Spamhaus, a Geneva-based volunteer group that publishes spam blacklists used by networks to filter out unwanted e-mail, and led to cyberspace congestion that may have affected the Internet overall, according to Matthew Prince of the US security firm CloudFlare.
The attacks began last week, according to Spamhaus, after it placed on its blacklist the Dutch-based Web hosting site Cyberbunker, which claimed it was unfairly labeled as a haven for cybercrime and spam.
Photo: Reuters
The origin of the attacks has not yet been identified, but a BBC report said Spamhaus alleged that Cyberbunker, in cooperation with “criminal gangs” from Eastern Europe and Russia, was behind the attack.
The New York Times quoted Sven Olaf Kamphuis, who claimed to be a spokesman for the attackers, as saying that Cyberbunker was retaliating against Spamhaus for “abusing their influence.”
However, Kamphuis told the Russian news site RT that Cyberbunker was just one of several Web firms involved, protesting what he called Spamhaus’ bullying tactics.
“Spamhaus have pissed off a whole lot of people over the past few years by blackmailing ISPs [Internet service providers] and carriers into disconnecting clients without court orders or legal process whatsoever,” he said.
“At this moment, we are not even conducting any attacks... it’s now other people attacking them,” he said.
CloudFlare, which was called for assistance by Spamhaus, said the attackers changed tactics after the first layer of protection was implemented last week.
“Rather than attacking our customers directly, they started going after the network providers CloudFlare uses for bandwidth,” Prince said.
“Once the attackers realized they couldn’t knock CloudFlare itself offline ... they went after our direct peers,” he said.
Prince said the so-called distributed denial of service attack (DDoS), which essentially bombards sites with traffic in an effort to disrupt, was “one of the largest ever reported.”
Over the last few days, he added: “We’ve seen congestion across several major Tier 1 [networks], primarily in Europe, where most of the attacks were concentrated, that would have affected hundreds of millions of people even as they surfed sites unrelated to Spamhaus or CloudFlare.”
“If the Internet felt a bit more sluggish for you over the last few days in Europe, this may be part of the reason why,” Prince said in a blog post called “The DDoS That Almost Broke the Internet.”
Prince said these attacks used tactics different than the “botnets” — these came from so-called “open resolvers” that “are typically running on big servers with fat pipes.”
“They are like bazookas and the events of the last week have shown the damage they can cause,” he said. “What’s troubling is that, compared with what is possible, this attack may prove to be relatively modest.”
A spokesman for the network security firm Akamai said that based on the published data, “the attack was likely the largest publicly acknowledged attack on record.”
“The cyberattack is certainly very large,” added Johannes Ullrich of the US-based SANS Technology Institute, saying it was “a factor of 10 larger than similar attacks in the recent past.”
“But so far, I can’t verify that this affects Internet performance overall,” he said.
Spamhaus, which also has offices in London, essentially patrols the Internet to root out spammers and provides updated lists of likely perpetrators to network operators around the world.
CloudFlare estimates that Spamhaus “is directly or indirectly responsible for filtering as much as 80 percent of daily spam messages.”
The attacks began after Spamhaus blacklisted Cyberbunker, a Web hosting firm that “offers anonymous hosting of anything except child porn and anything related to terrorism.”
Cyberbunker denounced the move on its blog.
“According to Spamhaus, CyberBunker is designated as a ‘rogue’ host and has long been a haven for cybercrime and spam,” the Cyberbunker statement said.
“Of course, Spamhaus has not been able to prove any of these allegations.”
Prince said of the latest incident: “While we don’t know who was behind this attack, Spamhaus has made plenty of enemies over the years.
“We’re proud of how our network held up under such a massive attack and are working with our peers and partners to ensure that the Internet overall can stand up to the threats it faces,” Prince said.
Experts said the attacks flooded Spamhaus servers with 300 billion bits (35 gigabytes) per second of data. Prior DDoS attacks have been measured at 50 gigabytes per second.
Because of the way Internet traffic flows, these DDoS attacks created congestion and ripple effects around the Web.
REBUILDING: A researcher said that it might seem counterintuitive to start talking about reconstruction amid the war with Russia, but it is ‘actually an urgent priority’ Italy is hosting the fourth annual conference on rebuilding Ukraine even as Russia escalates its war, inviting political and business leaders to Rome to promote public-private partnerships on defense, mining, energy and other projects as uncertainty grows about the US’ commitment to Kyiv’s defense. Italian Prime Minister Giorgia Meloni and Ukrainian President Volodymyr Zelenskiy were opening the meeting yesterday, which gets under way as Russia accelerated its aerial and ground attacks against Ukraine with another night of pounding missile and drone attacks on Kyiv. Italian organizers said that 100 official delegations were attending, as were 40 international organizations and development banks. There are
TARIFF ACTION: The US embassy said that the ‘political persecution’ against former Brazilian president Jair Bolsonaro disrespects the democratic traditions of the nation The US and Brazil on Wednesday escalated their row over US President Donald Trump’s support for former Brazilian president Jair Bolsonaro, with Washington slapping a 50 percent tariff on one of its main steel suppliers. Brazilian President Luiz Inacio Lula da Silva threatened to reciprocate. Trump has criticized the prosecution of Bolsonaro, who is on trial for allegedly plotting to cling on to power after losing 2022 elections to Lula. Brasilia on Wednesday summoned Washington’s top envoy to the country to explain an embassy statement describing Bolsonaro as a victim of “political persecution” — echoing Trump’s description of the treatment of Bolsonaro as
The tale of a middle-aged Chinese man, or “uncle,” who disguised himself as a woman to secretly film and share videos of his hookups with more than 1,000 men shook China’s social media, spurring fears for public health, privacy and marital fidelity. The hashtag “red uncle” was the top trending item on China’s popular microblog Sina Weibo yesterday, drawing at least 200 million views as users expressed incredulity and shock. The online posts told of how the man in the eastern city of Nanjing had lured 1,691 heterosexual men into sexual encounters at his home that he then recorded and distributed online. The
Hundreds of protesters marched through the Mexican capital on Friday denouncing gentrification caused by foreigners, with some vandalizing businesses and shouting “gringos out!” The demonstration in the capital’s central area turned violent when hooded individuals smashed windows, damaged restaurant furniture and looted a clothing store. Mexico City Government Secretary Cesar Cravioto said 15 businesses and public facilities were damaged in what he called “xenophobic expressions” similar to what Mexican migrants have suffered in other countries. “We are a city of open arms... there are always ways to negotiate, to sit at the table,” Cravioto told Milenio television. Neighborhoods like Roma-Condesa