------------------------------------------------------------------------
Shabang!com is the place to get your FREE eStore, Absolutely FREE
Forever. If you have any desires to sell your products or services
online, or you want to expand your customer base for FREE, Come check
out Shabang!com FREE eStores!
http://click.egroups.com/1/1299/5/_/480272/_/951727088/
------------------------------------------------------------------------
There is 1 message in this issue.

 Topics in today's digest:

      1. Net-Alert Volume 3, Issue 1
           From: Mark Neely <[EMAIL PROTECTED]>


_______________________________________________________________________________
_______________________________________________________________________________

Message: 1
   Date: Sun, 27 Feb 2000 22:16:46 +0930
   From: Mark Neely <[EMAIL PROTECTED]>
Subject: Net-Alert Volume 3, Issue 1


- - - - - - - - - - - - - - - - - - - -

Net-Alert
27 February 2000

If you have any questions, comments or other feedback concerning
Net-Alert articles, contact the Editor at <mailto:[EMAIL PROTECTED]>

Previous editions of Net-Alert are available at
http://www.onelist.com/archive/net-alert

Subscription and unsubscription details are available at the end of this
newsletter.
____________________

Contents:

##     Welcome back
##     Distributed Denial of Service Attacks
##     DDoS Attacks - My Take
##     Recording electronic conversations OK
##     Double Click Privacy Warning
##     Online auction warnings

____________________
Welcome back

Welcome to the first issue of Net-Alert for 2000. A combination
of client projects and a nasty bout of the "Sydney flu" has put
me out of action until recently.

Somewhat ironically, my preparation for this issue was put
on hold temporarily as a result of a recent "spam fest" directed
at the Net-Alert mailing list, and a number of other mailing
lists hosted by OneList.

As I promised in my email message last week, I have investigated
the cause of the problem, which appears to be two-fold:

When I created Net-Alert, it was configured as a "moderator
announcement only" list, which means that only I, as moderator,
am authorised to send messages to subscribers. Messages sent by
anyone else are automatically discarded by the OneList software.

Mailing lists hosted by companies such as OneList are a prime
target for spammers and other email "marketing" companies. They
subscribe to thousands of mailing lists at a time. They don't
actually read messages sent to the lists - they're not
interested.

Rather, they join because - as a general rule - joining a
mailing list gives the subscriber the right to post messages to
it. These spammers have signed onto hundreds of OneList mailing
lists for the sole purpose of posting their spam messages.

Normally, OneList's mailing list administration software prevents
such would-be spammers from reaching my subscribers.

Unfortunately, during an upgrade of OneList's software on
Saturday 19 February, Net-Alert's status was temporarily changed
to that of a discussion list, which gave all subscribers the
right to post to the list. While the list was only left exposed
for a mere 2 hours, this was more than enough time for several
spammers to spam the list with dozens of messages.

This was very quickly remedied, and OneList's Director of
Customer Support, Kate Shambarger, was profuse in expressing her
apologies, to both myself and Net-Alert members.

I would like to express a hearty "Thank you" to all those members
who emailed me directly advising of the spam attack, and for the
words of support that I received after making my announcement
that the spam was not authorised.

With a bit of luck, we shall never encounter such a glitch again!

____________________
Distributed Denial of Service Attacks

Few readers would have missed the news in the fortnight
concerning attacks on the Web sites of several high-profile
companies, including Yahoo! and eBay, which brought their Web
sites to a grinding halt for a few hours.

These attacks were what is known as Distributed Denial of Service
(DDoS) attacks, which involve several computers located in
geographically diverse locations sending a large volume of data
(i.e. packets) to nominated Internet hosts, with the express
purpose of crashing them by tying up their system resources until
they can no longer process incoming packets.

Such attacks rely on special software to co-ordinate the efforts
of the attacking computers, which can range from a handful of PCs
to dozens or even hundreds of PCs acting in unison.

Few computer vandals would be foolish enough to use their own PCs
for such an attack. Instead, they break into exposed Internet
hosts, install the necessary software and trigger it remotely,
then disappear while the dirty work is done.

The ability of such attacks to be triggered remotely on
compromised systems contributes to the difficulties the various
authorities have in locating the culprits.

For a comprehensive discussion of the nature of these attacks and
how they work, see:

Have Script, Will Destroy (Lessons in DoS)
   http://www.hackernews.com/bufferoverflow/00/dosattack/dosattack
   .html

____________________
DDoS Attacks - My Take

In the days following the attacks, I was quite alarmed by two
issues raised in the press.

The first was the quantum of damages alleged to have been caused
by the attacks which, according to some articles, was assessed in
the billions!

How can crashing a few computers possibly generate losses of this
magnitude? Granted, some companies affected by the attacks were
prevented from accepting orders while their systems were down,
but equating this to direct losses is somewhat questionable.

The second was how quickly various groups and organisations -
invariably from a law enforcement background - pointed to the
attacks as justification for increasing law enforcement budgets
and broadening powers of investigation for dealing with computer
crime.

A few reality checks are required here:

Denial of Service attacks are not new. Nor are Distributed Denial
of Service attacks. You don't even need to be particularly adept
at computers to initiate them (thanks to the point-n-click
software now available to satisfy the "script kiddies").

Anyone who had their Web site shut down as a result of the DDoS
attacks needs to seriously question the way in which they run
their Web site.

The fact that companies with billion dollar capitalisations didn't
pay sufficient attention to well-known and well-publicised
security threats is a serious concern.

There is no excuse for failing to develop plans and strategies
for minimising the risk of such attacks and for counteracting
them. Frankly, I'll bet the companies concerned spend more on
print advertising in a single month than they spend on security
for an entire year.

If you peer through the media hype, what you see is several
(presumably very embarrassed) chief technical officers caught
with their pants down, who are jumping on the "cyber terrorist"
bandwagon purely to deflect attention away from their own
inadequacies.

Within days, US President Clinton had called together a summit to
deal with the "rising threat of cyber terrorists".

This does not bode well for online privacy and civil liberties!

One point that was lost in the media ruckus is that the DDoS
attacks did NOT result in credit card details or other financial
information being obtained by those behind the attacks. No
consumer information was compromised.

____________________
Recording electronic conversations OK

In a worryingly under-reported judgement, a US judge has ruled
that it is ok to secretly record conversations that take place on
online chats, instant messaging services (e.g. ICQ) as well as
email communications.

The New York Times article reports:

     In 12 states, it is illegal to record your own telephone
     conversations without the consent of the person at the other
     end of the line. Now a judge in Washington, one of those
     privacy-conscious states, has ruled that the state's law does
     not apply to the new world of e-mail and online chats.


Interesting reading.

URL:

Article: Judge Says Recording of Electronic Chats Is Legal
   http://www.nytimes.com/library/tech/00/01/cyber/cyberlaw/14law.
   html

____________________
Double Click Privacy Warning

Double Click, one of the world's largest online advertising
firms, has recently attracted considerable negative press as a
result of deploying new "profiling" technology, which allows it
to track individual users as they move from Web site to Web site
(not just within a single Web site).

It does this by cross-referencing both the information it
receives from Web sites carrying its advertisements and details
recorded within cookies that it sets whenever its banner ads are
displayed on client Web sites, with an extensive database of
personal consumer profiles.

To date, this database primarily contains information about US
consumers, but that is likely to change in the near future.

Double Click is allowing individuals to "opt out" of its
monitoring process. Users can do this by visiting the URL shown
below, scrolling to the bottom of the page and clicking on the
"please click here" link.

URLs

USA Today article
   http://www.usatoday.com/life/cyber/tech/cth211.htm
Opt Out Web page
   http://www.doubleclick.net/optout/

____________________
Online auction warnings

I'd like to sound a timely warning to users considering
participating in online auctions for the first time. Unlike
traditional auctions, the company running the auction Web site
generally has no relationship with either the buyer or seller,
who are left to finalise the deal between themselves, generally
by email.

There have been several high-profile criminal prosecutions
recently of individuals who fraudulently offered non-existent
goods for sale via online auctions. There is also a growing
number of Web auction scams that users need to keep an eye out
for.

One of the more common scams concerns those interested in selling
goods via a Web auction site. The scam involves "bid shielding",
which typically works like this: when a desirable item is listed,
a user immediately jumps in and makes an unrealistically high
bid. This deters anyone else from bidding. Just prior to the
close of the auction bidding process, a collaborator enters a
very low bid. Once it is made, the first bidder retracts the high
bid, leaving the vendor with only a very low bid and no other
bidders, with the result that the low bid wins.

There have also been reports of "bid poaching", where individuals
approach bidders via email with offers to sell them the same
product that they are bidding for. Often, however, the offers
come from scam artists looking to make a quick dollar.

Here are a few tips for playing it safe with online auctions:

-   Pay by credit card. Be wary of users who want you to send
    cash or money orders. If you pay by credit card, you have the
    option of cancelling the payment in the event of
    non-delivery. If the vendor cannot accept credit card
    payments, consider using an escrow service (see below).

-   Prefer online auction sites that automatically cover their
    users with insurance protection against fraudulent
    transactions. Check the fine print of their insurance
    coverage, however, as some sites place a fairly low cap on
    the maximum amount that they will pay in the event of a
    fraudulent transaction.

-   If you are making a major purchase, seek confirmation of the
    vendor's reliability. Ask the vendor for the contact details
    of other users who have bought from him/her in the past, and
    follow these up. A number of online auctions now allow their
    members to "rate" vendors according to how promptly they
    delivered purchased items etc. Check the vendor's profile if
    such a rating system is available.

-   Steer clear of potentially illegal items offered for sale.
    Vendors of such items realise that bidders are less likely to
    complain about being ripped off, for fear of getting
    themselves into trouble.

-   Double-check your bid to make sure that you haven't mistyped
    the figure, otherwise you may find yourself liable for more
    than you wanted to pay.

-   Avoid spur-of-the-moment bids and don't let the hype and
    excitement of a live auction dupe you into buying something
    you don't really need or want.

-   Be wary of artificial bid boosting, where the vendor enlists
    a group of friends to submit dummy bids in an effort to
    artificially inflate the final bid price.

Some online auction sites offer their patrons an "escrow"
service. If you are making large purchases, you should consider
making use of such services.

Escrow services are pretty straightforward. In essence, they
buyer pays the full purchase price to an independent "escrow
agent", who holds onto the payment until the goods have been
delivered to the buyer. Once delivered, the agent pays the
vendor.
____________________

Send a copy of Net-Alert to a friend.

Forwarding this newsletter to friends and colleagues is encouraged,
providing the message is forwarded in its entirety, including the copyright
notice.

____________________

If you received this copy of Net-Alert from a friend, you can subscribe
by visiting the following URL:

    http://www.onelist.com/subscribe/net-alert

or by sending a blank email to

    [EMAIL PROTECTED]

To UNSUBSCRIBE, send a blank email to

    [EMAIL PROTECTED]

____________________

Net-Alert is copyright (c) Mark Neely 2000.

Forwarding this message to friends and colleagues is encouraged,
providing the message is forwarded in its entirety, including this copyright
notice.

- - - - - - - - - - - - - - - - - - - -



_______________________________________________________________________________
_______________________________________________________________________________





Reply via email to