
On Friday, a powerful hacker attack blocked users from the USA access to a number of popular Internet sites. Twitter, CNN, The New York Times, Reddit, Wall Street Journal, Spotify PayPal payment system turned out to be inaccessible. All of them were attached to Dyn - one of the largest holders of domain names (DNS) servers. The company's infrastructure is located in New Hampshire in the United States. For Internet traffic, it is a kind of address book.
The disconnects were intermittent, geographically they were not consistent, but, as it was possible to find out, began in the east of the United States before spreading through the rest of the country and Europe. DDOS-Atak on DYN began at about 7:00 local time (14:00 in Moscow) and stopped after two and a half hours, but at noon resumed again. According to The New York Times, it was possible to cope with the attack only at 21:00 Moscow time.
Large Internet sites regularly encounter DDOS attacks, and often the technical support service of the editorial office can beat these attacks, but this time we are talking about an unusual attack. Hackers used thousands of “smart” devices connected to the Internet, previously infected with harmful code and united in the so -called “botnet” or “zombie army”. With the help of the Betnets network, DDOS-Atak was carried out, the essence of which is to direct the artificially created traffic to the server, blocking access to the site for ordinary users. Imagine an open door, which thousands of people are trying to go to simultaneously.
Dyn says that this was one of the largest DDOS attacks in history, requests came from millions of online addresses. Part of the harmful traffic proceeded from the connected devices-webcams, digital recording devices, routers, etc. According to Dyn representatives, the attack was well planned and took place in three waves. The first wave began after the speech of the director of the Internet analysis company Daga Madori at the profile conference. He spoke precisely about the ways to combat DDOS-grinders used by BackConnect.
None of the cyber groups has yet taken responsibility for the attack on DYN. Experts say that the authorities of any state are unlikely to be involved in it. Computer security researchers working with DYN found out that some of the false queries came from video surveillance cameras with Internet access made by the Chinese Corporation Xiong MAI. The representative of the Flashpoint security company Elison Nixon claims that their webcams and DVRs were forcibly combined into the network and infected with Trojan Mirai, who directed the attack on DYN. This Trojan was already used in September to attack on the investigating cybercrimination of journalist Brayn Krebs and the OVH hosting provider.