MASSIVE DDOS ATTACKS ALL OVER U.S.

Page 4 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

mcveigh

Diamond Member
Dec 20, 2000
6,457
6
81
anyone know how to figure out who is the major carrier in your area?, who is the biggest backbone provider? I live in the tampa bay area.
 

MrBond

Diamond Member
Feb 5, 2000
9,911
0
76
Originally posted by: mcveigh
anyone know how to figure out who is the major carrier in your area?, who is the biggest backbone provider? I live in the tampa bay area.
It all depends on who the ISP uses. There could be one ISP using UUNet and another using Sprint.

My Wifi router had crashed this morning. As of 12:30 EST last night it was working fine. I'm sure it has nothing to do with the DDOS attacks (it's actually behind another router and just functionng as a WAP), but it's a strange concidence.
 

Gaard

Diamond Member
Feb 17, 2002
8,911
1
0

Skyclad1uhm1

Lifer
Aug 10, 2001
11,383
87
91
Actually, according to a Dutch Tech site, it is a massive scan for a vulnerability in Microsoft SQL server.

My ISP already is blocking all MS SQL packets (UDP port 1434), but there are several larger sites which have already received more than 12GB of data purely from these scans.

Edit: There has been a patch for the vulnerability for quite a while now, but a lot of servers haven't been patched yet.
The attacks in the USA are lessening, the ones in Europe are still at full strength.
 

Bullhonkie

Golden Member
Sep 28, 2001
1,899
0
76
Originally posted by: snooker
I was just now able to reconnect to the net.

My ISP has been down since like 2am EST this morning. It was affecting their login servers (At least it was giving me an invalid UN and PW). It is still running pretty slow..... especially UUNet from what I can tell.

UUNet looks to have gotten slammed especially hard by this worm (I heard that the UUNet Dallas backbone was completely gone at one point). Around 2am EST is when it kicked into full gear. If your ISP is using UUNet that's probably why you weren't able to connect for so long.

www.internetpulse.net still shows UUNet having terrible response times.

Some of the latest bulletins I've been able to find about it:
Internet Security Systems Alerts
Symantec Security Response - W32.SQLExp.Worm

Some other fun stuff to look at:
Internet Status to Root Name Servers
Internet Average Statistics
 

Priit

Golden Member
Nov 2, 2000
1,337
1
0
Don't you just love Microsoft and careless (or just stupid) admins of it's software :) I bet attacs like that will get rather daily in the future unless something changes dramatically...
 

IGBT

Lifer
Jul 16, 2001
17,974
140
106
Noticed anandtech home page not loading completly..haven't noticed any other probs...
 

Desslok

Diamond Member
Jun 14, 2001
3,780
11
81
Originally posted by: VBboy
Originally posted by: Insane3D
Originally posted by: VBboy I turned off my DDOS appliance in the kitchen. Service should be restoring as we speak :)
Hey...it took you almost 3 hours to get to your kitchen and turn that thing off??? Damn...you must have a big house! :p ;) :D
Nah, man, I had to please my girlfriend on my way to the kitchen :)

Just because you call your palms Rosie doesn't mean you have a GF VB.:)
 

element

Diamond Member
Oct 9, 1999
4,635
0
0
Originally posted by: CorporateRecreation
Don't blame microsoft too hard, almost every platform has programs with buffer overflow errors. You only see the Microsoft servers get hit because they are the most popular platform, and they are easy to target. Buffer overflow is a VERY common thing, and it just so happens that MS's SQL is the target this time. If you run a MS Server, look out. Personally I am glad both my servers run unix.

No I don't blame Microshaft for this. I blame them for making it difficult for me to uninstall Windows Messupinger on my WinXP box. EAT IT MS!

Btw I uninstalled it eventually but what a pain.
 

SnapIT

Banned
Jul 8, 2002
4,355
1
0
Originally posted by: element®
Originally posted by: CorporateRecreation
Don't blame microsoft too hard, almost every platform has programs with buffer overflow errors. You only see the Microsoft servers get hit because they are the most popular platform, and they are easy to target. Buffer overflow is a VERY common thing, and it just so happens that MS's SQL is the target this time. If you run a MS Server, look out. Personally I am glad both my servers run unix.

No I don't blame Microshaft for this. I blame them for making it difficult for me to uninstall Windows Messupinger on my WinXP box. EAT IT MS!

Btw I uninstalled it eventually but what a pain.

Yes, you download the script, doublecklick it... that is so damn hard to do... :|
 

KK

Lifer
Jan 2, 2001
15,903
4
81
Theres a script to do that? Can you provide a linky? Thanks

KK
 

her209

No Lifer
Oct 11, 2000
56,336
11
0
Originally posted by: KK
Theres a script to do that? Can you provide a linky? Thanks

KK
Start > Run

Cut and paste: RunDll32 advpack.dll,LaunchINFSection %windir%\INF\msmsgs.inf,BLC.Remove

Press Enter.
 

Nemesis77

Diamond Member
Jun 21, 2001
7,329
0
0
Maybe MS should be banned from the Internet :p? I mean, look at the harm their software brings: IIS-servers are routinely hacked and defaced, thanks to MS SQL-server, Internet has slowed to a crawl and several root-servers are offline, Outlook spreads viruses faster than the eye can see, Hotmail is a spam-magnet, Code Red, Nimda etc. etc...
 

Evadman

Administrator Emeritus<br>Elite Member
Feb 18, 2001
30,990
5
81
I was wondering why everything ws slower than sh!t last night. I just assumed it was my connection and went to bed :)

UUNet and Quest got Owned!
 

pulse8

Lifer
May 3, 2000
20,860
1
81
Originally posted by: Nemesis77
Maybe MS should be banned from the Internet :p? I mean, look at the harm their software brings: IIS-servers are routinely hacked and defaced, thanks to MS SQL-server, Internet has slowed to a crawl and several root-servers are offline, Outlook spreads viruses faster than the eye can see, Hotmail is a spam-magnet, Code Red, Nimda etc. etc...

If it wasn't Microsoft, it'd only be someone else's software.
 

Nemesis77

Diamond Member
Jun 21, 2001
7,329
0
0
Originally posted by: pulse8
Originally posted by: Nemesis77
Maybe MS should be banned from the Internet :p? I mean, look at the harm their software brings: IIS-servers are routinely hacked and defaced, thanks to MS SQL-server, Internet has slowed to a crawl and several root-servers are offline, Outlook spreads viruses faster than the eye can see, Hotmail is a spam-magnet, Code Red, Nimda etc. etc...

If it wasn't Microsoft, it'd only be someone else's software.

Propably. But at least the overall level of security would improve when the weakest link gets removed. I mean, MS-servers are hacked even though they are not the most widely used ones.
 

CraigRT

Lifer
Jun 16, 2000
31,440
5
0
it was brutal last night... too bad i didn't feel any of it.. but everyone else apparently did :p
 

SnapIT

Banned
Jul 8, 2002
4,355
1
0
Originally posted by: pulse8
Originally posted by: Nemesis77
Maybe MS should be banned from the Internet :p? I mean, look at the harm their software brings: IIS-servers are routinely hacked and defaced, thanks to MS SQL-server, Internet has slowed to a crawl and several root-servers are offline, Outlook spreads viruses faster than the eye can see, Hotmail is a spam-magnet, Code Red, Nimda etc. etc...

If it wasn't Microsoft, it'd only be someone else's software.

You mean like the systems that are used twice as often as MS systems today? (only counting servers)

Obviously MS servers are are more vunerable to attacks... (or it's the people who uses the other systems that are more alert)
 

charrison

Lifer
Oct 13, 1999
17,033
1
81
Originally posted by: SnapIT
Originally posted by: pulse8
Originally posted by: Nemesis77
Maybe MS should be banned from the Internet :p? I mean, look at the harm their software brings: IIS-servers are routinely hacked and defaced, thanks to MS SQL-server, Internet has slowed to a crawl and several root-servers are offline, Outlook spreads viruses faster than the eye can see, Hotmail is a spam-magnet, Code Red, Nimda etc. etc...

If it wasn't Microsoft, it'd only be someone else's software.

You mean like the systems that are used twice as often as MS systems today? (only counting servers)

Obviously MS servers are are more vunerable to attacks... (or it's the people who uses the other systems that are more alert)


Name me 1 product that has never had an exploitable bug? I will give you all the time you need.

SQL has a very good track for being quality software. A patch for this exploit has existed for more than 6 months. This is about clueless admins, not bad software.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Did anyone notice that this attack coincided very closely with the addition of the Clown avatar? :Q
 

Spac3d

Banned
Jul 3, 2001
6,651
1
0
I still can only get to half of the websites I have wanted to get too :(

I was just able to get to get Anandtech a few minutes ago.

Spac3d
 

Aves

Lifer
Feb 7, 2001
12,232
30
101
Originally posted by: mechBgon
Did anyone notice that this attack coincided very closely with the addition of the Clown avatar? :Q
I thought I was the only one who noticed!!! :Q

 

rgwalt

Diamond Member
Apr 22, 2000
7,393
0
0
So this is what happened to the internet... My router has been getting HAMMERED with access requests on port 1434.

Ryan