'Anonymous' hackers plan to shut down the Internet this Saturday
bgr.com
bgr.com
This is not the sort of thing Anonymous does, they've been careful not to aggravate the public and make clear it is the elite and not the common man that is their nemesis.
We also know for a fact that US intelligence agencies have infiltrated and have been in control of many Anonymous operations.
Not too hard to see that this will be a test run of whether intelligence agencies can shut down the internet.
I sometimes maintain a conversational tone here, so expressing personal surprise at seeing what I was going to type as the top comment just sort of came out. I "hated to say it" because it's such an overused trite idiom. But yeah, it added little and "I agree" would have been a smoother intro.
The fundamental problem is that we're trusting vigilantes when we should be trusting courts to bring justice.
"I can't get online!"
"Yeah anonymous took down the internet"
Not only would it be basically impossible to take down the DNS servers even if they had large participation, but there will be essentially no participation since most main 'anonymous' sites/leaders are telling people to have nothing to do with it.
This is just nonsense intended to drive up hit counts. I really don't think a person needs to be very technical to realize this is nonsense. Most people aren't rocket scientists, but would have the sense to call bullshit pretty quickly if I claimed I was going to test a working warp drive on Friday. I've never understand why computers seem so complicated and strange to people that the same common sense and critical thinking that makes it obvious I don't really have a warp drive don't seem to apply.
While it is unlikely that this will actually happen you are still far from correct saying that this is virtually impossible, for certain this is possible.
If anyone here recalls the blackhat heydays pre-2003 you may have/have not recalled a group known as "Fluffy Bunny" that broke into (at the time) what were thought to be the some of the most secure box's on the net, a few to name were VA software, UU.net(efnet), (cross site scripting) securityfocus.com, sans.org, (even a site dedicated to making fun of and host mirrors of defaced websites) attrition.org.
Getting back to the original point I was trying to make, one of their most notable hacks was breaking into multiple Akamai servers. No remote exploits were used against Akamai servers, every computer they had access to at Akamai was gained through a patch version of ssh which recorded all users password before encryption and placed it in a log file within a hidden directory on the system, this patch was installed on every box they exploited, they got lucky when a user from the uu.net box logged into an Akamai box using the compromised ssh client.
So they have Akamai, now what? The group further infiltrated their way into Akamai's intranet and gained access to other computers on their network through social engineering. Finally they located the development server that stored the source code that Akamai used to update some 12,000+ high bandwidth servers they used. The plan was to patch the update software they used to automate the patching process to also include a rootkit&DDoS client. With this they would be able to control a ridiculously large botnet, joined with their already amassed 4000+ DDoS net from other compromised computers this would have effectively timed out all 13 top level root name servers. More then likely you can tell what happens after that.
If you were interested to know, these guys were caught out out of the stupidity of this guy. http://articles.latimes.com/2000/sep/22/local/me-24959 Whom was drunk and instead of hanging up decided to curse out a field technician that came onto the centrex line(thanks AT&T) they used to communicate through. This resulted in the tech recording the line 24/7 and eventually handing the information over to the authorities.
http://www.grc.com/sn/sn-341.pdf Transcript and links to audio.
If my memory serves, he also noted that there also some uncertainty if this was even an "official" anonymous action...whatever that might mean.
It's easier to benefit from a false-flag attack by just doing it- denials don't carry as much weight in an emotional, post-attack context. When forewarning is given for a false-flag, you give the accused a chance to back away and say "it's not us" before an event, lodging enough doubt that the size of the crowd with torches and pitchforks isn't as big afterwards... I think this would be counter-productive for the guys staging the false-flag attack.
Who knows... -We- surely don't. I feel like I'm outlining a plot for a Tom Clancy novel.
IIRC, the "operation" was disavowed by all of the twitter accounts associated with the more 'mainstream' anons.
The key was that the attack happened over UDP which meant that there was no handshake, no congestion control, no need to worry about dropped packets, etc. The only limitation was the bandwidth of the infected host -- the virus itself was less than 500 bytes (not kilo, just straight bytes) so a single host could infect tens of millions of computers.
It was a pretty fascination piece of malware.
Also, should I host my own nameservers and assume I'll fly under the radar of attacks?
Is it likely that the big email providers keep the caching longer and could maintain some functionality in the event the TLD nameservers are down for more than 24 hours?
The .com delegation is set to cache for 48 hours, for example. This simply will not work at all.
If anything, this will just damage them by exposing assets used in the attempt.