Showing posts with label EN. Show all posts
Showing posts with label EN. Show all posts

Tuesday, 2 February 2016

Cyber attack on Israel Electricity Authority

According to SANS Industrial Control Systems Security Blog, Dr. Yuval Steinitz (Minister of National Infrastructure, Energy, and Water Resources) confirmed at the CyberTech Conference that massive cyberattack taken place on January 25th, 2016 and was aimed on Israeli Electricity Authority.

According to Eyal Sela cited by Robert M. Lee, cyber attack was simply ransomware delivered via phishing emails to the regulatory body's office network and it appears in no way endangered any infrastructure [1].

The Israeli Electric Authority is a regulatory body of ca. 30 individuals and this "cyber attack" is only referencing their networks, not the electric grid or electric companies.
 
Steinitz told Cybertech Conference attendees in Tel Aviv, Israel, that his agency has already identified the virus and is now prepared to deploy the software that will work to neutralize the bug on computer networks [2] [3] [4].

The attack on Israel comes one month after hackers caused the power blackout in Ukraine in December 2015, when the SCADA systems were hit with a trojan named BlackEnergy that resulted in the power cuts across the Ukraine's Ivano-Frankivsk Oblast.

Israel had suffered from cyber attacks previously including coordinated attack by anti-Israeli groups which was first conducted on 7th April 2013 and repeated every year, codenamed #OpIsrael. #OpIsrael targets web sites with DDoS. A denial-of-service attack (DdoS) is characterized by an explicit attempt by attackers to prevent legitimate users of a service from using that service. #OpIsrael attempt in 2015 failed to bring down government websites, however numerous web sites of organizations and individuals were taken down. According to Michal Margalit and Ran Boker, major government websites were targeted but were not brought down, including the sites for the Knesset, Education Ministry and the government portal [5].

About Israeli Electricity Market Regulatory Authority

In 1996, the Israeli Electricity Market Regulatory Authority was was established. Its purpose is, among others, to balance between maintenance of a fair rate framework to be imposed upon electricity consumers, and support of private entrepreneurs in the field and the promotion of electricity production in a competitive and equitable manner.

About Dr. Yuval Steinitz

Dr. Yuval Steinitz was appointed Minister of National Infrastructure, Energy and Water Resources (May 2015). Minister Steinitz kept his leading role on behalf of the Israeli government in the international campaign against the Iranian nuclear program and is overseeing the Israeli Atomic Energy Committee from the previous government. Prior to his current position, Minister Steinitz was the Minister of Intelligence 2013 - 2015. In that capacity, Dr. Steinitz was responsible for overseeing the intelligence community, including the Mossad (Israeli CIA), Shin-Bet (Israeli FBI) and Israeli Atomic Energy Committee. Minister Steinitz was also in charge of economic aspects in the Israeli-Palestinians peace talks.

Sources

  1. Context for the Claim of a Cyber Attack on the Israeli Electric Grid https://ics.sans.org/blog/2016/01/27/context-for-the-claim-of-a-cyber-attack-on-the-israeli-electric-grid?reply-to-comment=312
  2. Israel’s Yuval Steinitz: ‘Severe Cyber Attack’ Shuts Down Electricity Authority’s Computer Systems http://www.executivegov.com/2016/01/israels-yuval-steinitz-severe-cyber-attack-shuts-down-electricity-authoritys-computer-systems/
  3. No, Israel's power grid wasn't hacked, but ransomware hit Israel's Electric Authority http://www.computerworld.com/article/3026609/security/no-israels-power-grid-wasnt-hacked-but-ransomware-hit-israels-electric-authority.html
  4. Israeli Power Grid Authority Suffers Massive Cyber Attack http://thehackernews.com/2016/01/power-grid-cyberattack.html
  5. Israeli sites targeted by annual Anonymous 'OpIsrael' cyber attacks http://www.ynetnews.com/articles/0,7340,L-4644894,00.html
 

Wednesday, 21 December 2011

CEO of Yonita thanked by the Director of Auschwitz-Birkenau State Museum


CEO and President of Yonita Inc., Dr. Andrzej Bartosiewicz has been thanked by the Director of the Auschwitz-Birkenau State Museum, Dr. Piotr Cywinski, for the commitment and successful actions that brought about the handing over of the domain "auschwitz.org" to the Museum. Letter can be found here (in English) and here (in Polish).

In his letter to A.Bartosiewicz, Dr. Cywinski writes:
Dear Andrzej Bartosiewicz,

I wish to thank you personally for your great commitment and successful actions that brought about the handling over of the internet domain auschwitz.org to the Museum. It will allow us the transfer of the current website of the Auschwitz Museum and memorial to the new address.

These actions are done in accordance with the policy of the Polish Ministry of Culture and National Heritage. Its aim is to support the efforts of the Polish Government
directed against the erroneous associating of the concentration and extermination camps with Polish post-war locations of those places.

Your negotiation skills were a decisive element which got the desired result, even in a situation when the chances for success were to be estimated with great reserve. That is why I would like to express my seep gratitude and once again thank you for your commitment to this case, which lead to this highly satisfactory result.

Dr. Piotr M.A.Cywinski
Director

Monday, 26 September 2011

EU position on ICANN, IGF Nairobi

EU Presidency Paper on Internet Governance Forum taking place in Nairobi, Kenya, to be presented on September 27, 2011 says that "the Internet Governance Forum (IGF) created an open space for discussion and information sharing. Its uniqueness in having a non-decision making format and an open and inclusive participatory structure has allowed the Forum to grow in momentum in the course of recent years. Increasing attendances at the IGF meetings demonstrate that this forum continues to be perceived useful. The General Assembly renewed the mandate of the IGF for further 5 years in December 2010 recognizing its uniqueness, openness and flexibility"

EU Presidency refering to the Internet Corporation for Assigned Names and Numbers (ICANN) says, that European Union:

  • continue to uphold the importance of a secure; stable and inclusive domain name system which has global interconnectivity;
  • recognize the role of ICANN in this respect, and also welcome the recent adoption by it of the ATRT Recommendations which we consider an important development in the overall context of the internet governance;
  • will continue to work with international partners in identifying (and thus implementing) further improvements in the modus operandi of ICANN and how it serves the needs of the global Internet community.
The full text of "an informal Presidency paper, with informal initial positions" can be obtained @ Yonita Inc.

Tuesday, 6 September 2011

Unicart Ltd. and Yonita Inc. join forces to address cyber security threts in Bulgaria.

MOUNTAIN VIEW, Calif. & SOFIA (September 6, 2011): Yonita Inc. and Unicart Ltd. today announced that the two companies have signed an agreement to provide Web Scanner solution to domain name holders on Bulgarian market. 

Yonita Web Scanner provides unique capabilities for automatic detection of vulnerabilities that can affect online application owners. A successful attack against a company’s site or an online application can result in a wide spectrum of negative consequences including expenses of restoration of an IT infrastructure to its original “pre-attack” state, the cost of stolen, compromised, or otherwise degraded data, as well as loss of reputation and damage to the brand.

The President and CEO of Yonita Inc., Dr. Andrzej Bartosiewicz said: “We are happy to start cooperation with leading Bulgarian domain Registrar. Our companies focus now on providing the most advanced on-line security scanning tool for the Bulgarian community”

Yonita Web Scanner performs dynamic verification of web applications based on automated tests generated by the Smart Test Generator and Randomized Data Generator. The main threats detected by the Smart Web Scanner are:
  • Defects in authentication, authorization, and session management
  • Injections, such as script injection, OS command injection, SQL injection, CRLF injection, and others
  • Cross-site Scripting (XSS)
  • Cross-site Request Forgery
  • Defects in forward and redirect mechanisms
  • Content spoofing
  • Buffer overflow
  • Direct object references
Service provided by REGIA.BG to their customers will include premium customer’s service and full spectrum of configuration capabilities. Technical Support will be provided by Yonita Inc. from its center located in Warsaw, Poland, serving Europe, Middle East and Africa Region.

About Unicart Ltd.

REGIA.BG is the domain registrar and web hosting branch of Unicart Ltd., a top Bulgarian company working in the field of publishing, printing and IT services. REGIA.BG started in 2008  with the goal to provide domain registration in all existing TLDs and quickly became one of the top 10 domain registrars in the country and the top place for domain registration in all TLDs. Apart from domains, REGIA.BG provides web and VPS hosting, SSL certificates and useful software.

About Yonita Inc.

California-based Yonita, Inc., offers a family of products dedicated to the detection of security vulnerabilities and the identification of other quality defects in software early in a development lifecycle. Yonita Inc., founded in 2010 and headquartered in Silicon Valley, Mountain View with R&D center in Warsaw, Poland, is one of the leading companies offering solutions for automated software engineering.

Contact

Andrzej Bartosiewicz, CEO and President
800 West El Camino Real
Suite 180
Mountain View, CA 94040
+1 650 249 3707

Thursday, 7 July 2011

USA accounts for almost half of .CO registrations

CO internet S.A.S (.CO Interent), an organization responsible for .CO (Colombia) domains has published some interesting statistics: top-10 countries - origins of registrations.

Top-five countries are not surprising...

#1 USA - 48.94% registrations of .CO domains
#2 UK - 13.05%
#3 Colombia - 7.95%
#4 Canada - 4.05%
#5 Australia - 3.68%

The following five are more surprising...
#6 Germany - (only) 2.06%
#7 India -1.75%
#8 China -1.44%
#9 Poland - 1.35%
#10  France -1.17%

Germany... with only 2.06% of .CO domains (Germany is biggest ccTLD, #1 in .EU registrations and #2 in .COM registrations). Only 2.06% of .COs. Surprising?

Poland... 1.35% of .CO? Surprising, very surprising... Poland is not in the top-10 of .COM registrations, so why the hell, Poles started using .COs? Trademarks protection - definitely not due to the fact that there is not much well known trademarks owned by Polish businesses. Business expansion - rather not - Polish companies expand generally into European Union, not outside EU.

And France... yep, past restrictions in .FR registrations were driving factor for French businesses to register .COMs in the past 10 years. But now? Probably because of trademarks protection.




Saturday, 2 July 2011

.TEL plunges since March 2011

HosterStats.com published domain statistics as of July 2011. We can see the steady growth of almost all gTLDs and ccTLDs. There are two exemptions: .US and .TEL. 

In the past months I had already reported symptoms of quite unusual behavior of US and TEL. In December 2010 in the article entitled "November closed down for .US domain count" I have reported decrease of US, MOBI and TEL total number of domains.

Since 2010 situation has changed for .MOBI - now it faces fast and steady growth. Problems remained with .US (decline in June for the first time in 2011) and .TEL (decline since March 2011).

Recent stats, presented by HosterStars.com shows steady decline for .TEL (total domain count):
For .TEL, situation is actually worse than in 2010, when domain count declined for 4 months. Now we face decline for 5 consecutive months and no signs of recovery (summer months are not the best timing for aggressive marketing of services like hosting or domain names)


.TEL domains are based on ENUM technology (E.164 NUmber Mapping "ENUM" is a technology for telephone number mapping on special DNS record types to translate a telephone number into a Uniform Resource Identifier or IP address). As one of early adopters of ENUM technology, I have been always an advocate of .TEL.

After so many years of ENUM presence without any spectacular success, I'm afraid, public ENUM is not going to become popular anymore and the fact that TEL is based on ENUM is not going to bring .TEL popularity. Since deployment, TELNIC has introduced several tools (website integration, telfriends, telpages, advertisement support, support for iPhone and Android), making .TEL domains more useful for average users. Regardless of investments in R&D as well as advertising and PR, TELNIC is loosing customers. It's question to TELNIC management, what's next? gTLD with 300,000 names will not be able to play important role when new TLDs arrive in mid-2013. There is no much time left for adjusting strategy and gaining new registrations.

Good luck to TELNIC. I will stay with my .TEL domains including bartosiewicz.tel ubt TELNIC marketing strategy definitely needs adjustments to play any role in the market of 1000+ top level domains.

Monday, 20 June 2011

ICANN Board finally approves new gTLD program.

On June 20, 2011, at around 12:00PM local time, during its meeting in Singapore, ICANN's Board adopted resolution on new Top Level Domains program. The adopted resolution gives the opportunity for applicants to submit their proposals for new gTLD starting January 12, 2012. The application period would end April 12, 2012 and the initial evaluations will be published by November 2012.

Overwhelmingly approved resolution by the Board (13 approving, 1 opposed, and 2 abstaining) has been greeted with cheering and applause from the attendees of the ICANN conference in Singapore. I didn't know that just by raising hands, ICANN Board members can trigger orgasm among new gTLD applicants. ;)

Anyway, I can imagine how much alcohol will be consumed tonight… ;)

Congratulations to ICANN Board and good luck to all applicants! I personally expect around 300-500 applications to be submitted by April 2012. Assuming that 90% will be accepted by ICANN, it will dramatically increase number of gTLDs in 2013 from today's 22 gTLDs.

The real game and the real hard work just start. Back-end registry providers, consultants and applicants – this year there will be no Christmas for you. If you work hard enough, Santa Claus will come to you in November 2012 with the letter from ICANN stating “your application(s) has been accepted”.
source: http://www.icann.org/images/singapore-new-gtlds-vote-721-245.jpg

Monday, 13 June 2011

CEO of Yonita, Inc. invited by ICANN to join the team of experts.

CEO and President of Yonita Inc., Dr. Andrzej Bartosiewicz has been invited by ICANN to join the IDN Variant Issues Project as an expert.

The IDN Variant Issues Project undertakes work to identify issues associated with the beneficial and safe delegation of IDN (Internationalized Domain Names) variants of the Top Level Domains. Managing IDN variants is a complex and important subject and the success of the project is dependent on significant community expertise input and cooperation in doing the work.

On June 9th, ICANN announced the formation of six case study teams, comprising a total of 66 top experts from 29 countries and territories. Case Study members provide expertise in the following areas: DNS, IDNA, linguistics, security & scalability, policy, registry/registrar operations, and community relations.

ICANN is responsible for the global coordination of the Internet's system of unique identifiers like domain names (like .org, .museum and country codes like .uk) and the addresses used in a variety of Internet protocols that help computers reach each other over the Internet. Careful management of these resources is vital to the Internet's operation, so ICANN's global stakeholders meet regularly to develop policies that ensure the Internet's ongoing security and stability. ICANN is an internationally organized, public benefit non-profit company.

For more about IDN Variant TLD Case Study visit ICANN:
http://www.icann.org/en/announcements/announcement-3-09jun11-en.htm

Tuesday, 24 May 2011

Net Neutrality finally in Europe

Net Neutrality in Europe

May 25, 2011 is a deadline for all 27 Member States of the European Union for provisions - of revised EU regulatory framework - to be transposed into national regulations.

Why the new EU Regulatory Framework is so important? The amended telecoms framework adopted in 2009 favours the preservation of the open and neutral character of the Internet, which safeguard users' rights to access and distribute information online and ensure transparency about traffic management.

Under the revised rules, national telecoms regulatory authorities are required to promote the ability of end users to access and distribute information or run applications and services of their choice (Article 8 of the Framework Directive). This is supported by new transparency requirements (Article 21 of the Universal Service Directive).

When subscribing to a service and in case of any changes thereafter, consumers will be informed about:
  • conditions limiting access to and/or use of services and applications, in conformity with Union law,
  • procedures put in place by the provider in order to measure and shape traffic so as to avoid filling or overfilling a network link, and how these may impact on service quality,
  • minimum service quality levels offered, namely the time for the initial connection and, where appropriate, other quality of service parameters, as defined by the national regulatory authorities, 
Thanks to the new Universal Service Directive, safeguards for preserving the open and neutral character of the internet are provided for in the regulatory framework and NRAs should avail themselves of the provisions under Article 22 and set appropriate minimum quality of service requirements, where they are made aware of degradation of service, hindering or slowing down of traffic over networks.


The following regulations are to be transposed into national regulation no later than May 25, 2011:
  • Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009 amending Directive 2002/22/EC on universal service and users’ rights relating to electronic communications networks and services, Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector and Regulation (EC) No 2006/2004 on cooperation between national authorities responsible for the enforcement of consumer protection laws;
  • Directive 2009/140/EC of the European Parliament and of the Council of 25 November 2009 amending Directives 2002/21/EC on a common regulatory framework for electronic communications networks and services, 2002/19/EC on access to, and interconnection of, electronic communications networks and associated facilities, and 2002/20/EC on the authorisation of electronic communications networks and services

Are those regulations already transposed…? The answer is… NO. It’s European Union and national administrations are not - let’s say - “effective”. European Commission will review the results of the new regulations by November 2011, so we may expect that majority (?) of Member States will implement majority (?) of the new regulations by November

Saturday, 14 May 2011

Disney steals Seals?

Source: link to disney.com
Just recently Disney Enterprises Inc. claimed right on the "SEAL TEAM 6". Information about Team 6 of Navy Seals raid on Osama bin Laden's compound in Pakistan has been released on May 1, 2011. Disney filled applications on... May 3rd.

Disney’s trademark applications for Clothing, footwear and headwear, toys, games and playthings; gymnastic and sporting articles (except clothing); hand-held units for playing electronic games other than those adapted for use with an external display screen or monitor; Christmas stockings; Christmas tree ornaments and decorations; snow globes. Wow, sounds strange...

Source: USPTO
Disney's action is the perfect example of unjustified desire to profit from the other people achievements.  I'm curious if the TM will pass the United States Patent and Trademark Office, but at least in most European countries it would be declined... 

Huffington Post commented on this saying: It remains to be seen what products will come of these trademarks, but the bin Laden raid video game and pajama set has to be just around the corner.





Wednesday, 11 May 2011

Obama could send text-message warnings directly to your mobile

FEMA announced that the US Government is introducing a new emergency alert system, which is an expansion of the Federal Communications Commission's existing emergency alert system, which is designed to broadcast warnings over radio and television.The new system called PLAN (Personal Localized Alerting Network), instead of broadcasting alerts via radio and TV, will send text messages directly to mobile phones.

Nokia Siemens BTS
PLAN enables government officials to target alerts to specific geographic areas. Messages will be sent to mobile devices based on their geographic location determined by BTS (base transceiver station). No need for GPS support will be required - all cell phones in the range of base stations located in the area will receive SMS with warning message (actually SMS-CB).

This solution (SMS to be sent to all phones in targeted area) is actually the simplest and the most effective in emergency communications. Existing means of alerting people of immediate danger like warning horns, sirens, public address system with loudspeakers, TV or radio broadcast are not always efficient. Horns or announcements may be mistaken with non-crucial "background" voice or some people may just not hear the alert sound. The best example is Japan's tsunami where many people were not alerted on time, despite the fact that alert about tsunami has reached emergency centers 30 (!) minutes before tsunami reached the shoreline.

PLAN allows national, state or local government officials in the US send alerts regarding public safety emergencies, such as a tornado, tsunami or a terrorist threat without delay. Thanks to the possibility to alert mobile phones in the affected areas only, we make sure, that alerts will not create unnecessary panic and people will not start ignoring alerts as irrelevant.

What is also very important, GSM or CDMA based emergency alert systems are relatively cheap if compared to traditional warning systems based on the several layers of bureaucracy and 20th century traditional technologies. Alerting systems based on short-messages are also easy to deploy in a very short time. 

I must say, that I'm very happy that such system will be finally implemented at least in the United States. Few years ago I tried to convince authorities from European Commission as well as representatives of at least three European governments to build similar system.  Unfortunately, instead of focusing on the project similar to "PLAN", European Commission decided to start implementation of the eCall system (automatic notification of motor crashes). The main reason behind implementation of eCall was to... follow the US deployment of ACN. As the result, European Union countries neither have working eCall/ACN nor the Short Message Service-Cell Broadcast-based public alerting system like PLAN.


More info:

Thursday, 5 May 2011

Department of Commerce on .XXX domain for porn sites

Courtesy: ISOC
Here is the letter from Lawrence E. Strickling, Assistant Secretary of Commerce, Department of Commerce, US Government to Commissioner Neelie Kroes, Vice President of the European Commission on the .XXX and further Internet Governance issues.

The key points:
  • Obama Administration does not support decision of ICANN to approve Registry contact with ICM Registry on .XXX domain delegation
  • ICANN ignored the "clear advice" from governments including the US Gov
  • USG respects the multi-stakeholder process
  • ICANN Board took its action without the full support of the community
  • DoC is dedicated to improve the responsiveness of ICANN to all stakeholders


Monday, 10 January 2011

Yon Consulting web page facelifting...

After 9 months we launched our company's web page, it's time for some face-lifting. Patrycja Wegrzynowicz, Founder of Yon Consulting is the sole author of the new logo and the new design of YonConsulting.com.

First of all we've changed our logo. The first one (March 2010) can be found below:

The old one has been replaced by the following logo (January 2011):


The front page has been replaced too. The previous one can bee seen here:

The new one is already on-line:

The main aim of the redesign is to make it easy to navigate and to provide all key "entry points" already on the front page.

The main question is always, how do react end-users to the new design :) Do you like new logo and design? Feedback welcomed!

Tuesday, 4 January 2011

With 1,353,039 2nd level domains, Poland is on 8th position in Europe

On January 4th, 2011, Polish ccTLD Registry which I managed for 9 years and left last year, has registered its 2,000,000th domain name (including both 2nd and 3rd level domains under .COM.PL, .NET.PL etc).

Polish ccTLD Registry is registering not only 2nd level .PL domain names (registrations directly under .PL) but also 3rd level names under .COM.PL, .NET.PL, .BIZ.PL, .WAW.PL and many more extensions. Diversity of domain extensions is a very good business strategy, providing additional sources of revenue to the Registry and Registrars.

Let's look at the example: There is only one "google.pl" domain, but if you sell also 3rd level names, Registry and Registrars can also make money on "google.com.pl", "google.net.pl", "google.biz.pl", "google.waw.pl" and... 154 such extensions.

Let's do the math. Renewal for .PL is 40 PLN (Polish zloty), renewal for "regional" PL domains is 10 PLN (25% of .PL) and for "generic" (like .COM.PL) is 30 PLN (75% of .PL). Bearing in mind that Polish Registry is holding 33 generic 2nd level names and 119 "regional" 2nd level names, "google" can generate not 40 PLN but up-to 2220 PLN revenue for the Registry annually.


Isn't it much better financial strategy than only 2nd level domains registrations like in (almost) all other country code TLDs???

As of January 3rd, NASK has registered:
  • 1,353,039 .PL domains (2nd level names)
  • 330,347 .COM.PL domains (3rd level names)
  • 47,606 .WAW.PL domains 
  • 34,077 .NET.PL 
  • 23,594 .ORG.pl 
  • 20,852 .INFO.PL 
  • 11,791 .BIZ.pl domains and so on...
Of course the most valuable for end-users are 2nd level domains (directly under .PL), but 3rd level names especially under .COM.PL are still very popular among Polish companies and domainers and are important part of Registry's and Registrars' revenue. Among those 152 extensions, only 26 extensions have lost 3rd level names in 2010. All the rest gained, showing still existing demand for not only 2nd level names but 3rd level too.

With 1,353,039 domains Poland is on the 8th position among European ccTLDs. The top European's TLDs are as follows (as of November 30, 2010):
1. .de 14,007,185
2. .uk 8,966,685
3. .nl 4,168,836
4. .eu 3,312,453
5. .ru 3,096,193
6. .it 2,048,160
7. .fr 1,857,310 

If we just take the total number of domain names run by the Registry (both 2nd and 3rd level), it's actually 7th position in Europe with impressive 2,000,000 names.

Congratulations to my colleagues running the registry and all Registrars doing the hardest job!

Thursday, 9 December 2010

Operation Payback

updated on UltraDNS Anycast solution on Dec 9, 0815 EST 
updated on Visa, MC on Dec 10, 0600 EST 
Here is the follow up of the story of Amazon, VISA, MasterCard, PayPal, SwissPost and many more companies involved in "cablegate". More than week ago those companies took WikiLeaks.org web page and WikiLeaks donations off-line (more: [1] [2] [3]).Today WikiLeaks' supporters are taking them down.

Due to the DDoS (Distributed Denial of Service) attack called "Operation Payback" both VISA and MasterCard's web pages were off-line on Thursday. People behind so called Operation Payback campaign are targeting all corporations that have withdrawn services from Wikileaks.

What is DDoS?
DoS (Denial of Service) attack is an attempt (successful in case of VISA and MasterCard) to make a computer resources unavailable to its users. In case of a DDoS (Distributed Denial of Service) attack, large numbers of computers distributed across the networks attack a single target. Computers used for the attack are either compromised systems (botnets) or legitimate hosts managed by people who decide to use their machines to flood the victim. In the Operation Payback most of the "attackers" were legitimate hosts deliberately used by their owners to send large number of queries to the Visa and MC servers.  (D)DoS attack can force different services of the victim including Web site (WWW), e-mail or transaction systems to cease operation. In some cases denial of service attack can also destroy files in the affected computer systems.

DDoS attacks are tools used by "hacktivists" as form of protest or revenge (WikiLeaks case). Today DDoS are generally used for cyber criminals to profit from:
  • ransom payed by victim to stop the attack and avoid further financial losses,
  • companies who want to knock out competitors from the market (sabotage, brand damage)
Current situation
As of December 9th, 2010, 0740 EST, VISA.com has not been reachable, but at least their Name Servers were reachable. In the contrary neither MASTERCARD.COM's web page nor their Name Servers have been reachable. Due to the fact that Name Servers of MasterCard haven't been reachable, it's likely that not only web page but also e-mail service were disrupted.

UPDATE: After 8+ hours of inaccessibility, web pages of VISA and MasterCard were back on-line.


And the winner is...
Attack on VISA and MasterCard shows, that "Operation Payback has actually one big winner - NeuStar's UltraDNS service. VISA made a good decision choosing UltraDNS as DNS provider. UltraDNS is using so called "UltraDNS Managed DNS Service" with the ability to advertise the same public IP addresses out of multiple machines and networks. By using IP Anycast, UltraDNS is bringing the answers for a DNS query closer to the end user, and it becomes far more likely that the query will reach its destination and be responded to quickly. IP Anycast makes DDoS attacks much more difficult, requiring more botnets or attacking computers to be involved in the attack. As UltraDNS says IP Anycast and BGP protect our network from security threats and Distributed Denial of Service attacks. Because queries are routed based upon where they enter the UltraDNS network, DDoS attacks will be "distributed" amongst our servers, thus "diluting" the strength of any DDoS attack.


VISA.COM - ping on Dec 9, 0815 EST
Ping 72.52.5.101
[visa.com]
Timed out
Destination network unreachable
Timed out
Timed out
Destination network unreachable
Destination network unreachable
Timed out
Timed out
Destination network unreachable
Timed out

Average time over 10 pings: 0 ms



VISA.COM - Name Servers query on Dec 9, 0815 EST
Retrieving DNS records for visa.com...
DNS servers
pdns3.ultradns.org
pdns2.ultradns.net
pdns1.ultradns.net
pdns6.ultradns.co.uk
pdns5.ultradns.info
pdns4.ultradns.org


Answer records
visa.com
TXT
3600s
visa.com
TXTv=spf1 ip4:198.80.42.3 ip4:198.241.159.4 ip4:69.20.125.232 ip4:198.241.175.106 ip4:216.251.253.98 ip4:67.208.216.61 ~all3600s
visa.com
SOA
server:pdns1.ultradns.net
email:hostmaster@visa.com
serial:2010120909
refresh:10800
retry:3600
expire:604800
minimum ttl:300
300s
visa.com
A72.52.5.101300s
visa.com
MX
preference:10
exchange:portal5.visa.com
3600s
visa.com
MX
preference:10
exchange:portal2.visa.com
3600s
visa.com
MX
preference:10
exchange:portal1.visa.com
3600s
visa.com
NSpdns6.ultradns.co.uk86400s
visa.com
NSpdns5.ultradns.info86400s
visa.com
NSpdns4.ultradns.org86400s
visa.com
NSpdns3.ultradns.org86400s
visa.com
NSpdns2.ultradns.net86400s
visa.com
NSpdns1.ultradns.net86400s

Authority records

Additional records
portal5.visa.com
A198.241.174.1383600s
portal2.visa.com
A198.241.159.33600s



MASTERCARD.COM ping on Dec 9, 0815 EST
IP address:
Error: Try again

Host name: mastercard.com
Alias:
mastercard.com
is from () in region



TraceRoute to [mastercard.com]
Hop(ms)(ms)(ms)
IP AddressHost name
Trace complete

Retrieving DNS records for mastercard.com...
DNS servers
dns2.mastercard.com [209.64.210.34]
dns1.mastercard.com [216.119.210.196]

DNS server returned an error: Name server failed

Monday, 6 December 2010

Swiss bank closes Assagne account

PostFinance Logo (link)
Few days ago in my BLOG I said "The last but not least is the choice of a bank. For such organization as WikiLeaks banks registered in US or with US investors are not an option... WikiLeaks decided to use Commerzbank and Swiss Post (PostFinance), especially the last one to guarantee rather uninterrupted service."

I was definitely wrong.  Today PostFinance said in statement "PostFinance has ended its business relationship with Julian Paul Assange". In the explanation, PostFinance says that Assagne "provided false information regarding his place of residence during the account opening process".

PostFinance is another financial institution after PayPal getting rid of WikiLeaks and WikiLeaks founder... Interesting story but no more blogs about WikiLeaks problems. It becomes boring...

WikiLekas upgrades its DNS

After long struggle with DNS providers and hosters (read HERE and HERE), WikiLeaks finally upgraded their DNS by using several Name Servers provided by different companies and distributed along many networks. Good news for WikiLeaks and its supporters and bad news for USG and the secret diplomatic files.

Here you can see dig query on "wikileaks.ch".
  
; <<>> DiG 9.2.3 <<>> @dns1.menandmice.com wikileaks.ch ANY
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1455
;; flags: qr rd ra; QUERY: 1, ANSWER: 17, AUTHORITY: 15, ADDITIONAL: 19

;; QUESTION SECTION:
;wikileaks.ch. IN ANY

;; ANSWER SECTION:
wikileaks.ch. 1777 IN A 46.59.1.2
wikileaks.ch. 1777 IN A 213.251.145.96
wikileaks.ch. 1212 IN NS ns3.pcdog.ch.
wikileaks.ch. 1212 IN NS ns4.pcdog.ch.
wikileaks.ch. 1212 IN NS dns1.syshack.org.
wikileaks.ch. 1212 IN NS dns2.easydns.net.
wikileaks.ch. 1212 IN NS dns2.syshack.org.
wikileaks.ch. 1212 IN NS arjeplog.scnr.ch.
wikileaks.ch. 1212 IN NS marmotta.brabbel.ch.
wikileaks.ch. 1212 IN NS v217241437.yourvserver.net.
wikileaks.ch. 1212 IN NS s2.s3cr3t.de.
wikileaks.ch. 1212 IN NS dns.wikileaks.ch.
wikileaks.ch. 1212 IN NS lou.porcus.ch.
wikileaks.ch. 1212 IN NS ns1.pcdog.ch.
wikileaks.ch. 1212 IN NS ns1.buzzernet.net.
wikileaks.ch. 1212 IN NS ns2.pcdog.ch.
wikileaks.ch. 1212 IN NS ns2.easydns.com.

;; AUTHORITY SECTION:
wikileaks.ch. 1212 IN NS ns2.easydns.com.
wikileaks.ch. 1212 IN NS ns3.pcdog.ch.
wikileaks.ch. 1212 IN NS ns4.pcdog.ch.
wikileaks.ch. 1212 IN NS dns1.syshack.org.
wikileaks.ch. 1212 IN NS dns2.easydns.net.
wikileaks.ch. 1212 IN NS dns2.syshack.org.
wikileaks.ch. 1212 IN NS arjeplog.scnr.ch.
wikileaks.ch. 1212 IN NS marmotta.brabbel.ch.
wikileaks.ch. 1212 IN NS v217241437.yourvserver.net.
wikileaks.ch. 1212 IN NS s2.s3cr3t.de.
wikileaks.ch. 1212 IN NS dns.wikileaks.ch.
wikileaks.ch. 1212 IN NS lou.porcus.ch.
wikileaks.ch. 1212 IN NS ns1.pcdog.ch.
wikileaks.ch. 1212 IN NS ns1.buzzernet.net.
wikileaks.ch. 1212 IN NS ns2.pcdog.ch.

;; ADDITIONAL SECTION:
s2.s3cr3t.de. 77276 IN A 216.245.206.111
dns.wikileaks.ch. 1212 IN A 178.63.167.108
dns.wikileaks.ch. 1212 IN A 188.40.194.13
dns.wikileaks.ch. 1212 IN A 193.28.181.57
dns.wikileaks.ch. 1212 IN A 193.138.215.125
dns.wikileaks.ch. 1212 IN A 216.18.205.196
dns.wikileaks.ch. 1212 IN A 216.245.206.111
dns.wikileaks.ch. 1212 IN A 217.147.219.146
dns.wikileaks.ch. 1212 IN A 46.4.160.2
dns.wikileaks.ch. 1212 IN A 72.52.2.1
dns.wikileaks.ch. 1212 IN A 80.246.50.106
dns.wikileaks.ch. 1212 IN A 85.124.44.140
dns.wikileaks.ch. 1212 IN A 85.124.251.171
dns.wikileaks.ch. 1212 IN A 91.121.168.144
ns1.buzzernet.net. 1668 IN A 193.138.215.125
dns1.syshack.org. 34076 IN A 46.4.160.2
dns2.easydns.net. 37 IN A 72.52.2.1
dns2.syshack.org. 412 IN A 91.121.168.144
v217241437.yourvserver.net. 9012 IN A 188.40.194.13

;; Query time: 192 msec
;; SERVER: 217.151.171.7#53(dns1.menandmice.com)
;; WHEN: Mon Dec 6 08:29:22 2010
;; MSG SIZE rcvd: 955


To the contrary to .CH domain, wikileaks.org is not responding.