North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: How should ISPs notify customers about Bots (Was Re: DNS Hijacking

  • From: Suresh Ramasubramanian
  • Date: Tue Jul 24 13:33:40 2007
  • Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=KDAVJoghO8/1woKkfgI7Mfro2dOwd8ikMm7AVnF4B0BHgSMqa8xrlfnAwvMV0xLUxyjZgq0N0Zq2Rn/vyCANinkxMuT2iHufPJ4cbl9Br9DzW+2BSDSsBS35Tq8MiYVzegnFp0BICHY3JESZ2WaUhv031e7f2J8rOnJj/pHPW/4=
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=l1KwEVlaxT1FAjUknGr+CF4CYKgpU5jvzPgodPCti2aFySk72zL+l0Q7j2atiSDQxliBfsDFw0ki1pRPK1PpQhTnl6JjzNWCs0329R9QNpnDFSPNLKDA0IZ6bbyA5cWd7YTaPlgrV8GjibwUvlieBcEWhPhwdAiO2paH3Ra1ciE=


On 7/24/07, Joe Greco <[email protected]> wrote:


The problem is isolating the traffic in question.  Since you DO NOT HAVE
GIGABITS OF TRAFFIC destined for IRC servers, this becomes a Networking
101-style question.  A /32 host route is going to be effective.
Manipulating DNS is definitely the less desirable method, because it has
the potential for breaking more things.  But, hey, it can be done, and
with an amount of effort that isn't substantially different from the
amount of work Cox would have had to do to accomplish what they did.

Yup - though I still dont see much point in specialcasing IRC. It would probably be much more cost effective in the long run to have something rather more comprehensive.

Yes there are a few bots around still using IRC but a lot of them have
moved to other, better things (and there's fun "headless" bots too,
hardcoded with instructions and let loose so there's no C&C, no
centralized domain or dynamic dns for takedown.. you want to make a
change? just release another bot into the wild).