Home / Blogs

End of the World/Internet on 31-March-2012?

Well… Maybe not the world, but the Internet it seems.

According to a Pastebin letter, Anonymous announced they will black-out Internet on 31st of March.

See the announcement here: Announcement

They even explained how to do it by attacking the DNS Root Servers on Internet using a reflected amplification attack.

If this is successful, the root DNS servers will become unresponsive and cannot handle any other requests, making DNS resolution as we know it break and render many internet-applications like browsers, mail, VoIP and instant-messaging useless or unavailable.

I am bit 50/50 on this. First of all, would Anonymous be capable? Probably they are if we look at their track-record in the last months/years (with a bit of a difference that the magnitude of the attack is much bigger than before). Previous targets where mostly companies/governments that where directly attacked, this is a world-network and will affect most of us as well.

What if this is just fake? Still it scares me somehow. I have wondered about the root DNS servers for some time now and in the past there were some semi-successful attacks already utilising vulnerabilities in DNS software or by just overload/DDOS.

I guess it’s possible but I can not compute what is needed to do so. Lots and lots of DNS servers I’m guesstimating.

It may be a domino effect when they start and probably the attacking DNS servers used will be locked out of the Internet. But if these are legitimate DNS servers that are mis-used, it shuts out users of the DNS server as well and so the problem becomes larger.

Then there is caching, the announcement states that many providers use low TTL’s anyway, making their attack more successful. This implies that they “override” the TTL ignoring the TTL’s that are accompanied with the root DNS server records. Which is plausible, but still it takes time to bleed dry. And of course this is against the DNS “law” :-).

So DNS admins, please don’t override the TTL’s, and change them now to honour them as intended, you still have 6 weeks to go! :-).

Even then… There is some consensus that it will take roughly 5 to 7 days of continuos attack before “Internet” will be unusable. It will break bit by bit during that time of course.

Then the attack itself is described as a reflective amplification attack. Reflective because the “attacker” is not attacking the root DNS servers directly, but uses other DNS servers, spoofing itself as the root DNS server. And amplification, as the response/answer to the (attack) query is larger than the query itself.

Makes sense, but relies on vulnerabilities of the DNS software, and DNS servers free to use without any security measures… And that scares me because there are many DNS servers out there, and many of them are vulnerable. Studies last year even tells us that the number of these (vulnerable) servers increase, not decrease.

How about the public DNS services like Google Public DNS and OpenDNS? Well, they probably will not be “used” in the attack, but they use the DNS root servers as well for DNS resolution. So they will be affected. I guess they counter-measure things by easing the pain—like statically cache all the TLDs.

Still trying to figure out the impact of this, depending how hard the root DNS servers will be hit. If hit at all of course, the effect could be noticeable to complete unavailability of the prime services and applications we use daily/hourly.

I think we should worry and rethink this whole root DNS server thing anyway, as besides the Anonymous announcement, they are becoming increasingly attractive to attack.

It’s all an “if” story but we will be on our toes…

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By Chris Buijs, Cultivator of Organizations, Products and Services

Filed Under

Comments

Timing? Garth Bruen  –  Feb 17, 2012 2:29 PM

Why March 31st? May 1st would be more symbolic, or Guy Fawkes Day - November 5th. Is there a significance behind the date?

Not sure why 31st of March has Chris Buijs  –  Feb 17, 2012 4:41 PM

Not sure why 31st of March has been chosen... The 1st of April would be much more appropriate I guess :-). I guess other groups will give it a try before now and claim victory (or not)... Or maybe it's just a fake date and the attack will or will not happen at an off-guard moment... Well... We are talking about it, so maybe that's the only reason, fear, uncertainty and doubt... :-) Why announce it anyway?

Duh... Garth Bruen  –  Feb 17, 2012 5:01 PM

Right, the night before April Fools Day

Google DNS and OpenDNS do not use the root name servers in real time Paul Vixie  –  Feb 21, 2012 6:31 PM

I asked. They said they use the root zone in “transfer mode”. So the two largest public recursive DNS services, Google and OpenDNS, never send any queries to the name servers that the threat signed by Anonymous claims to plan to target.

“Transfer mode” access is a mixed blessing and it’s not for everybody. But it’s free and it’s available and I encourage expert DNS operators to consider using this the same way that Google and OpenDNS do.

The Internet has the response JFC Morfin  –  Feb 29, 2012 1:10 AM

The internet has the response:

1. it may use 65.635 different root files.
2. it does not need real time root servers.

However, this is true: the ICANN/NTIA class “IN” is vulnerable to this kind of DoS attack the way it is being used. This is why we need to get rid of the ICANN maintained single point of failure and contention in the whole digital ecosystem (WDE) and keep the Internet fool/merchant proof, the way it is designed.

For those interested in exploring, documenting and deploying a more robust and smarter Internet: http://www.ietf.org/internet-drafts/draft-iucg-iutf-tasks-00.txt and http://www.ietf.org/internet-drafts/draft-iucg-internet-plus-08.txt. There are opportunities and work ahead.

We really need to be protected from the Icannonymous!

jfc

We are still here... Chris Buijs  –  Mar 31, 2012 8:55 PM

Seems it was a fake as expected! Glad to see Internet is still here ;-).

The stophaus reflective attack ... Chris Buijs  –  Mar 29, 2013 8:00 AM

So, with the stophaus attack going on last week, it seems that this now is feasible material and potential real threat I would say.

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

Threat Intelligence

Sponsored byWhoisXML API

Cybersecurity

Sponsored byVerisign

IPv4 Markets

Sponsored byIPv4.Global

Domain Names

Sponsored byVerisign

DNS

Sponsored byDNIB.com

Brand Protection

Sponsored byCSC

New TLDs

Sponsored byRadix