------------------------------------------------------------------------ Shabang!com is the place to get your FREE eStore, Absolutely FREE Forever. If you have any desires to sell your products or services online, or you want to expand your customer base for FREE, Come check out Shabang!com FREE eStores! http://click.egroups.com/1/1299/5/_/480272/_/951727088/ ------------------------------------------------------------------------ There is 1 message in this issue. Topics in today's digest: 1. Net-Alert Volume 3, Issue 1 From: Mark Neely <[EMAIL PROTECTED]> _______________________________________________________________________________ _______________________________________________________________________________ Message: 1 Date: Sun, 27 Feb 2000 22:16:46 +0930 From: Mark Neely <[EMAIL PROTECTED]> Subject: Net-Alert Volume 3, Issue 1 - - - - - - - - - - - - - - - - - - - - Net-Alert 27 February 2000 If you have any questions, comments or other feedback concerning Net-Alert articles, contact the Editor at <mailto:[EMAIL PROTECTED]> Previous editions of Net-Alert are available at http://www.onelist.com/archive/net-alert Subscription and unsubscription details are available at the end of this newsletter. ____________________ Contents: ## Welcome back ## Distributed Denial of Service Attacks ## DDoS Attacks - My Take ## Recording electronic conversations OK ## Double Click Privacy Warning ## Online auction warnings ____________________ Welcome back Welcome to the first issue of Net-Alert for 2000. A combination of client projects and a nasty bout of the "Sydney flu" has put me out of action until recently. Somewhat ironically, my preparation for this issue was put on hold temporarily as a result of a recent "spam fest" directed at the Net-Alert mailing list, and a number of other mailing lists hosted by OneList. As I promised in my email message last week, I have investigated the cause of the problem, which appears to be two-fold: When I created Net-Alert, it was configured as a "moderator announcement only" list, which means that only I, as moderator, am authorised to send messages to subscribers. Messages sent by anyone else are automatically discarded by the OneList software. Mailing lists hosted by companies such as OneList are a prime target for spammers and other email "marketing" companies. They subscribe to thousands of mailing lists at a time. They don't actually read messages sent to the lists - they're not interested. Rather, they join because - as a general rule - joining a mailing list gives the subscriber the right to post messages to it. These spammers have signed onto hundreds of OneList mailing lists for the sole purpose of posting their spam messages. Normally, OneList's mailing list administration software prevents such would-be spammers from reaching my subscribers. Unfortunately, during an upgrade of OneList's software on Saturday 19 February, Net-Alert's status was temporarily changed to that of a discussion list, which gave all subscribers the right to post to the list. While the list was only left exposed for a mere 2 hours, this was more than enough time for several spammers to spam the list with dozens of messages. This was very quickly remedied, and OneList's Director of Customer Support, Kate Shambarger, was profuse in expressing her apologies, to both myself and Net-Alert members. I would like to express a hearty "Thank you" to all those members who emailed me directly advising of the spam attack, and for the words of support that I received after making my announcement that the spam was not authorised. With a bit of luck, we shall never encounter such a glitch again! ____________________ Distributed Denial of Service Attacks Few readers would have missed the news in the fortnight concerning attacks on the Web sites of several high-profile companies, including Yahoo! and eBay, which brought their Web sites to a grinding halt for a few hours. These attacks were what is known as Distributed Denial of Service (DDoS) attacks, which involve several computers located in geographically diverse locations sending a large volume of data (i.e. packets) to nominated Internet hosts, with the express purpose of crashing them by tying up their system resources until they can no longer process incoming packets. Such attacks rely on special software to co-ordinate the efforts of the attacking computers, which can range from a handful of PCs to dozens or even hundreds of PCs acting in unison. Few computer vandals would be foolish enough to use their own PCs for such an attack. Instead, they break into exposed Internet hosts, install the necessary software and trigger it remotely, then disappear while the dirty work is done. The ability of such attacks to be triggered remotely on compromised systems contributes to the difficulties the various authorities have in locating the culprits. For a comprehensive discussion of the nature of these attacks and how they work, see: Have Script, Will Destroy (Lessons in DoS) http://www.hackernews.com/bufferoverflow/00/dosattack/dosattack .html ____________________ DDoS Attacks - My Take In the days following the attacks, I was quite alarmed by two issues raised in the press. The first was the quantum of damages alleged to have been caused by the attacks which, according to some articles, was assessed in the billions! How can crashing a few computers possibly generate losses of this magnitude? Granted, some companies affected by the attacks were prevented from accepting orders while their systems were down, but equating this to direct losses is somewhat questionable. The second was how quickly various groups and organisations - invariably from a law enforcement background - pointed to the attacks as justification for increasing law enforcement budgets and broadening powers of investigation for dealing with computer crime. A few reality checks are required here: Denial of Service attacks are not new. Nor are Distributed Denial of Service attacks. You don't even need to be particularly adept at computers to initiate them (thanks to the point-n-click software now available to satisfy the "script kiddies"). Anyone who had their Web site shut down as a result of the DDoS attacks needs to seriously question the way in which they run their Web site. The fact that companies with billion dollar capitalisations didn't pay sufficient attention to well-known and well-publicised security threats is a serious concern. There is no excuse for failing to develop plans and strategies for minimising the risk of such attacks and for counteracting them. Frankly, I'll bet the companies concerned spend more on print advertising in a single month than they spend on security for an entire year. If you peer through the media hype, what you see is several (presumably very embarrassed) chief technical officers caught with their pants down, who are jumping on the "cyber terrorist" bandwagon purely to deflect attention away from their own inadequacies. Within days, US President Clinton had called together a summit to deal with the "rising threat of cyber terrorists". This does not bode well for online privacy and civil liberties! One point that was lost in the media ruckus is that the DDoS attacks did NOT result in credit card details or other financial information being obtained by those behind the attacks. No consumer information was compromised. ____________________ Recording electronic conversations OK In a worryingly under-reported judgement, a US judge has ruled that it is ok to secretly record conversations that take place on online chats, instant messaging services (e.g. ICQ) as well as email communications. The New York Times article reports: In 12 states, it is illegal to record your own telephone conversations without the consent of the person at the other end of the line. Now a judge in Washington, one of those privacy-conscious states, has ruled that the state's law does not apply to the new world of e-mail and online chats. Interesting reading. URL: Article: Judge Says Recording of Electronic Chats Is Legal http://www.nytimes.com/library/tech/00/01/cyber/cyberlaw/14law. html ____________________ Double Click Privacy Warning Double Click, one of the world's largest online advertising firms, has recently attracted considerable negative press as a result of deploying new "profiling" technology, which allows it to track individual users as they move from Web site to Web site (not just within a single Web site). It does this by cross-referencing both the information it receives from Web sites carrying its advertisements and details recorded within cookies that it sets whenever its banner ads are displayed on client Web sites, with an extensive database of personal consumer profiles. To date, this database primarily contains information about US consumers, but that is likely to change in the near future. Double Click is allowing individuals to "opt out" of its monitoring process. Users can do this by visiting the URL shown below, scrolling to the bottom of the page and clicking on the "please click here" link. URLs USA Today article http://www.usatoday.com/life/cyber/tech/cth211.htm Opt Out Web page http://www.doubleclick.net/optout/ ____________________ Online auction warnings I'd like to sound a timely warning to users considering participating in online auctions for the first time. Unlike traditional auctions, the company running the auction Web site generally has no relationship with either the buyer or seller, who are left to finalise the deal between themselves, generally by email. There have been several high-profile criminal prosecutions recently of individuals who fraudulently offered non-existent goods for sale via online auctions. There is also a growing number of Web auction scams that users need to keep an eye out for. One of the more common scams concerns those interested in selling goods via a Web auction site. The scam involves "bid shielding", which typically works like this: when a desirable item is listed, a user immediately jumps in and makes an unrealistically high bid. This deters anyone else from bidding. Just prior to the close of the auction bidding process, a collaborator enters a very low bid. Once it is made, the first bidder retracts the high bid, leaving the vendor with only a very low bid and no other bidders, with the result that the low bid wins. There have also been reports of "bid poaching", where individuals approach bidders via email with offers to sell them the same product that they are bidding for. Often, however, the offers come from scam artists looking to make a quick dollar. Here are a few tips for playing it safe with online auctions: - Pay by credit card. Be wary of users who want you to send cash or money orders. If you pay by credit card, you have the option of cancelling the payment in the event of non-delivery. If the vendor cannot accept credit card payments, consider using an escrow service (see below). - Prefer online auction sites that automatically cover their users with insurance protection against fraudulent transactions. Check the fine print of their insurance coverage, however, as some sites place a fairly low cap on the maximum amount that they will pay in the event of a fraudulent transaction. - If you are making a major purchase, seek confirmation of the vendor's reliability. Ask the vendor for the contact details of other users who have bought from him/her in the past, and follow these up. A number of online auctions now allow their members to "rate" vendors according to how promptly they delivered purchased items etc. Check the vendor's profile if such a rating system is available. - Steer clear of potentially illegal items offered for sale. Vendors of such items realise that bidders are less likely to complain about being ripped off, for fear of getting themselves into trouble. - Double-check your bid to make sure that you haven't mistyped the figure, otherwise you may find yourself liable for more than you wanted to pay. - Avoid spur-of-the-moment bids and don't let the hype and excitement of a live auction dupe you into buying something you don't really need or want. - Be wary of artificial bid boosting, where the vendor enlists a group of friends to submit dummy bids in an effort to artificially inflate the final bid price. Some online auction sites offer their patrons an "escrow" service. If you are making large purchases, you should consider making use of such services. Escrow services are pretty straightforward. In essence, they buyer pays the full purchase price to an independent "escrow agent", who holds onto the payment until the goods have been delivered to the buyer. Once delivered, the agent pays the vendor. ____________________ Send a copy of Net-Alert to a friend. Forwarding this newsletter to friends and colleagues is encouraged, providing the message is forwarded in its entirety, including the copyright notice. ____________________ If you received this copy of Net-Alert from a friend, you can subscribe by visiting the following URL: http://www.onelist.com/subscribe/net-alert or by sending a blank email to [EMAIL PROTECTED] To UNSUBSCRIBE, send a blank email to [EMAIL PROTECTED] ____________________ Net-Alert is copyright (c) Mark Neely 2000. Forwarding this message to friends and colleagues is encouraged, providing the message is forwarded in its entirety, including this copyright notice. - - - - - - - - - - - - - - - - - - - - _______________________________________________________________________________ _______________________________________________________________________________
