<?xml version="1.0" encoding="utf-8"?>
<feed
    xmlns="http://www.w3.org/2005/Atom"
    xmlns:at="http://www.sixapart.com/ns/at"
    xmlns:icbm="http://postneo.com/icbm"
    xmlns:rvw="http://purl.org/NET/RVW/0.2/"
    xml:lang="en">
    <title>Somnus Vox</title>
    <link rel="self" type="application/atom+xml" title="Somnus Vox (Atom)" href="http://somnus.vox.com/library/posts/tags/ddos/page/1/atom.xml" />
    <link rel="alternate" type="text/html" title="Somnus Vox" href="http://somnus.vox.com/library/posts/tags/ddos/page/1/"/>

    <link rel="service.post" type="application/atom+xml" title="Somnus Vox" href="http://www.vox.com/services/atom/svc=post/collection_id=6a00d4142a48563c7f00d09e5e19d7be2b" />

    <link rel="service.subscribe" type="application/atom+xml" title="Somnus Vox" href="http://somnus.vox.com/library/posts/tags/ddos/atom.xml" />

    
    
    <link rel="last" type="application/atom+xml" title="Somnus Vox" href="http://somnus.vox.com/library/posts/tags/ddos/page/1/atom.xml" />


    <category term="ddos" scheme="http://somnus.vox.com/tags/ddos/?_c=feed-atom-full" label="ddos" />

    <generator uri="http://www.vox.com/">Vox</generator>
    <updated>2008-04-30T05:54:47Z</updated>

    <author>
        <name>somnus</name>
        <uri>http://somnus.vox.com/?_c=feed-atom-full</uri>
    </author>

    <id>tag:vox.com,2006:6p00d4142a48563c7f/tags/ddos/</id>

    <subtitle>&quot;It&#39;s like all day long he&#39;s just talking in his sleep...&quot;</subtitle>


    
    <entry>
        <title>Fake Whois used in DDoS</title>
    
    
    
        <link rel="alternate" type="text/html" title="Fake Whois used in DDoS" href="http://somnus.vox.com/library/post/fake-whois-used-in-ddos.html?_c=feed-atom-full" />
    
        
        <link rel="service.post" type="application/atom+xml" title="Fake Whois used in DDoS" href="http://somnus.vox.com/library/post/fake-whois-used-in-ddos.html?_c=feed-atom-full#comments" />
    
        <link rel="service.edit" type="application/atom+xml" title="Fake Whois used in DDoS" href="http://www.vox.com/atom/svc=post/asset_id=6a00d4142a48563c7f00f48cf3669d0003" /> 
                <id>tag:vox.com,2008-04-30:asset-6a00d4142a48563c7f00f48cf3669d0003</id>
        <published>2008-04-30T05:54:47Z</published>
        <updated>2008-04-30T05:54:47Z</updated>
    
        <author>
            <name>somnus</name>
            <uri>http://somnus.vox.com/?_c=feed-atom-full</uri>
        </author>
    
        
        <content type="html" xml:base="http://somnus.vox.com/?_c=feed-atom-full">
            <![CDATA[
                <div xmlns="http://www.w3.org/1999/xhtml" xmlns:at="http://www.sixapart.com/ns/at">
    
    
        
            
            <p>I ran into an interesting, and troubling, situation today where some folks I know received an email informing them that their domain was being used in a <a href="http://en.wikipedia.org/wiki/Distributed_denial_of_service#Distributed_attack">DDoS</a> attack on a website in Australia.</p><p>The really weird things was that the website listed in the complaint email was one they had never heard of.</p><p>At first glance, it appeared to be some kind of fishing email.&#160; But, upon digging further it turned out that the domain the complaint named was indeed listed under the address and phone number of my associates for technical, organization, and billing contacts.&#160; Only the email address was different (clearly a one-off yahoo mail address).</p><p>Someone had lifted the contact information of my associates from, either one of their legitimate domain registrations, or from their corporate site and used it to register a domain at <a href="http://smallbusiness.yahoo.com/domains/">Yahoo! Domains</a>. The domain was then used in a DDoS attack and the blame (at least initially) fell on my associates.</p><p>There is no reason that whoever was behind this could not have inserted my associates corporate email too, leaving no trail at all (especially if they uses a stolen credit card number for the transaction, as I suspect they did).</p><p>With enough domains falsely registered under a single company&#39;s contact info, not only could a DDoS service be launched, but the spoofed company could end up spending a tremendous amount of time clearing their name and getting rid of the spoofed domain registrations. A double DDoS. One virtual. One real.</p><p>I have to admit, I&#39;m actually surprised I haven&#39;t heard about this being a widespread problem...it certainly seems like it could easily and quickly become one.</p><p>I must give a plug for Yahoo here ...once contacted they quickly shut down and canceled the domain and promised to investigate further.</p><p><br /> </p>
        
    
                <p style="clear:both;"> 
    <a href="http://somnus.vox.com/library/post/fake-whois-used-in-ddos.html?_c=feed-atom-full#comments">Read and post comments</a>   |   
    <a href="http://www.vox.com/share/6a00d4142a48563c7f00f48cf3669d0003?_c=feed-atom-full">Send to a friend</a> 
</p>

                </div>
            ]]>
        </content>
    
    <category term="web" scheme="http://somnus.vox.com/tags/web/" label="web" />
    
    <category term="fake" scheme="http://somnus.vox.com/tags/fake/" label="fake" />
    
    <category term="attacks" scheme="http://somnus.vox.com/tags/attacks/" label="attacks" />
    
    <category term="whois" scheme="http://somnus.vox.com/tags/whois/" label="whois" />
    
    <category term="domain registration" scheme="http://somnus.vox.com/tags/domain+registration/" label="domain registration" />
    
    <category term="spoofing" scheme="http://somnus.vox.com/tags/spoofing/" label="spoofing" />
    
    <category term="ddos" scheme="http://somnus.vox.com/tags/ddos/" label="ddos" />
    
    </entry>

</feed>


