Download the
Tom's Guide App from the AppsStore
News and trends on internet
/ mobile / "sound & picture" / IT
Yes No

Want To Nuke A Website? A Botnet For Hire

- By - Source : Tom's Guide US

Apparently there's a botnet for hire.

Recently we reported that Hollywood and other international film studios are hiring "cyber hitmen" to take down websites playing host to illegal movies and music. These agencies use denial-of-service attacks to flood the offending servers until they're knocked offline. Sometimes said firms even swoop in an destroy the actual data, preventing further circulation.

Security firm Damballa is now reporting of another form of "cyber hitmen," however in this case the contract isn't based on taking down pirates. Rather, a commercial botnet has been established by a China-based managed services provider (MSP) for anyone wishing to take down a website using Distributed Denial of Service attacks.

"While DDoS-oriented botnets aren’t particularly new, our investigation and subsequent exposure of an MSP that specializes in offering a fee-based service sheds new light in to the growing commercialization of this criminal space," the security firm reports.

Dubbed as IMDDOS, this particular botnet was found to be growing at rates in excess of 10,000 additional victims each day. Initially the MSP registered the necessary domains back in March, and then began testing the botnet in April. The actual fee-based "service" went live shortly thereafter.

"This publicly available service, hosted in China, is available for lease to anyone willing to establish an on-line account, input the domain(s) they wish to attack, and pay for the service," Damballa reports.

Currently the firm is working with various authorities to shut down the components of the botnet that are accessible from the USA. Unwitting hosts of the botnet domains have also been notified and all appropriate information has been shared to contain--and ultimately dismantle--the botnet.

Damballa's full report can be downloaded here in PDF format.

Share:
23
Comments
X

Comments

sabot00 09/15/2010 2:19 AM
Hide
-7+

I think Tom's is getting nuked now.

Gin Fushicho 09/15/2010 2:24 AM
Hide
--2+

I just grinned. How do I get there and how much do I have to pay?

joz 09/15/2010 2:27 AM
Hide
-3+

I think I want to pay to have it nuked...quality level is horrible. News is old and frankly, this is the most intresting thing posted in MONTHS.
DDOS TIME!

Seriously, joking here. But only about the DDOS.

azconnie 09/15/2010 3:29 AM
Hide
-2+

Alms for the irritated? How about you? Care to help the collection to kill Myspace, Facebook, and Photobucket?

spectrewind 09/15/2010 3:55 AM
Hide
-0+

Thwarted by round-robin DNS?

Demonslay335 09/15/2010 4:23 AM
Hide
-20+

What if you hire it to nuke its own domain? Does a black hole emerge?

cpburns 09/15/2010 5:27 AM
Hide
-5+

Demonslay335 :
What if you hire it to nuke its own domain? Does a black hole emerge?



Did you just divide by zero?

Anonymous 09/15/2010 5:30 AM
Hide
-7+

From China??!! Didn't see that coming...

RicardoK 09/15/2010 5:34 AM
Hide
-3+

Than china says: "It isn't us! It's the Taiwaneese guys." so now they can start a war. [jk]

Anyway, where else could you create such a huge botnet? 99% of the PCs there have some kind of gov. rootkit installed, so why not use that power to DDoS US websites?

stingstang 09/15/2010 5:39 AM
Hide
-1+

Ermm.. Could someone hire them to take down the website hosted by that church group who's mantra is "Thank God for IEDs"?
ty

Zingam 09/15/2010 6:01 AM
Hide
-1+

Now that's a great service!

jsc 09/15/2010 10:44 AM
Hide
-1+

It was only a matter of time.

whysobluepandabear 09/15/2010 12:06 PM
Hide
--1+

They need to consider this vandalism and charge them accordingly with the crime(s).

dextermat 09/15/2010 5:17 PM
Hide
-1+

hire itself to nuke itself and other malware website: that what we should do

Anomalyx 09/15/2010 6:15 PM
Hide
-1+

Aren't DDOS attacks illegal in the US? Hiring someone to do something illegal, regardless of whether or not it's illegal where they live, is also illegal!

idoln95 09/15/2010 7:59 PM
Hide
-1+

Anomalyx :
Aren't DDOS attacks illegal in the US? Hiring someone to do something illegal, regardless of whether or not it's illegal where they live, is also illegal!


But the crime is committed in china...

it's like an Iranian will hire some girl to walk around the US without an hair cover, its legal here and not there, yet the action of hiring is legal.

Razor512 09/15/2010 8:16 PM
Hide
-0+

if this is known then it is illegal, a bot network is illegal to have and hiring them is considered paying for illegal services.

Think of it like buying illegal drugs, if the supplier gets caught then you may also get caught and arrested.

Hiring illegal services to attack other illegal services is also illegal.
think of it as if you owned an illegal drug company and another company was moving in on your turf and you hired a gang to kill the competition. you will still be arrested, not just for the illegal company that yo are running but for also hiring illegal services.

idoln95 09/15/2010 8:22 PM
Hide
-1+

Well, but DDOS attacking is legal in china...

eddieroolz 09/15/2010 8:25 PM
Hide
-1+

We're screwed.

But in all honesty, China is the land of immorals.

eyemaster 09/15/2010 8:55 PM
Hide
-4+

Let's pool our money, buy their services and kill the RIAA and such?

cyb34 09/15/2010 9:27 PM
Hide
-1+

That's not the solution, you simpletons.

TheWhiteRose000 09/18/2010 7:19 AM
Hide
-0+

You wonder if you can hire them to nuke there own site.