• On The Insider: James Van Der Beek Files for Divorce
July 14, 2009 8:22 AM PDT

Researchers: Attacks on U.S., Korea sites came from U.K.

by Elinor Mills
  • Font size
  • Print
  • 5 comments

The denial-of-service attacks launched on Web sites in South Korea and the United States earlier this month appear to have come from a master server in the United Kingdom, according to security researchers in Vietnam.

The master server controls all of the eight command and control servers involved in the series of distributed denial-of-service attacks that started on the July 4 weekend, security firm Bkis said in a blog posting on its Web site on Monday. Bkis said it gained control of two of the servers.

The Vietnamese firm estimated the number of compromised PCs involved in the attacks to be around 167,000 in 74 countries.

Botnet expert Joe Stewart of SecureWorks told CNET News that that number sounded high. Security experts had been estimating that there were 50,000 infected PCs in the botnet.

The attacks targeted dozens of government and commercial sites in the U.S. and South Korea, causing temporary outages at many of them.

Code on the compromised PCs was set to erase or overwrite data late last week but researchers in the U.S. were not aware of any reports of that happening.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click Here
Recent posts from Security
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
E-tailers snagged in marketing 'scam' blame customers
McAfee warns about '12 Scams of Christmas'
Cisco launches iPhone security app
Town to photograph every car that enters and leaves
New Firefox 3.6 beta aims to cut crashes
Facebook adopts new privacy policy
Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
by ThreeMilesNorth July 14, 2009 9:08 AM PDT
Politics, isn't it? The US and S. Korea knew the source of the attack from day one...
Reply to this comment
by cnation July 14, 2009 9:20 AM PDT
You right about it nothings new about it
Reply to this comment
by inachu1 July 14, 2009 9:34 AM PDT
It's easy to block by ip address.
they just refuse to take the issue at hand and stop it within 8 hours.
It is not hard to do.
Reply to this comment
by alegr July 14, 2009 9:58 AM PDT
The solution is to make sure the ISP's routers validate the "source IP" field in the outgoing packets, and drop those that are issued with bogus IP. Solves the problem of backtracing at once.
Reply to this comment
by testdirectly September 2, 2009 3:55 AM PDT
But it's really good, for all of us, I quite think thats.
Finding out main the servers, it's the most important ...
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

E-tailers linked to 'scam' blame customers

Priceline, Classmates.com, and Orbitz say customers should read the fine print before complaining about being charged to join loyalty programs they didn't want.

The 411 on early-termination fees

Verizon Wireless has doubled its early-termination fees for smartphones, but what does it mean for the rest of the industry?

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right