Register    Login    Forum    Search    FAQ

Board index » Site info » Site Info




 Page 1 of 1 [ 5 posts ] 



Author Message
 Post subject: Will Your Internet Connection Disappear in July, 2012?
 Post Posted: Fri Apr 20, 2012 2:52 pm 
Offline
User avatar

Joined: Sun Aug 01, 2010 7:48 am
Posts: 5360
Location: The carpark outside Milliways
WASHINGTON (AP)-- For computer users, a few mouse clicks could mean the difference between staying online and losing Internet connections this summer.

Unknown to most of them, their problem began when international hackers ran an online advertising scam to take control of infected computers around the world. In a highly unusual response, the FBI set up a safety net months ago using government computers to prevent Internet disruptions for those infected users. But that system is to be shut down.

The FBI is encouraging users to visit a website run by its security partner, www.dcwg.org , that will inform them whether they're infected and explain how to fix the problem. After July 9, infected users won't be able to connect to the Internet.

Most victims don't even know their computers have been infected, although the malicious software probably has slowed their web surfing and disabled their antivirus software, making their machines more vulnerable to other problems.

Last November, the FBI and other authorities were preparing to take down a hacker ring that had been running an Internet ad scam on a massive network of infected computers.

"We started to realize that we might have a little bit of a problem on our hands because ... if we just pulled the plug on their criminal infrastructure and threw everybody in jail, the victims of this were going to be without Internet service," said Tom Grasso, an FBI supervisory special agent. "The average user would open up Internet Explorer and get 'page not found' and think the Internet is broken."

On the night of the arrests, the agency brought in Paul Vixie, chairman and founder of Internet Systems Consortium, to install two Internet servers to take the place of the truckload of impounded rogue servers that infected computers were using. Federal officials planned to keep their servers online until March, giving everyone opportunity to clean their computers. But it wasn't enough time. A federal judge in New York extended the deadline until July.

Now, said Grasso, "the full court press is on to get people to address this problem." And it's up to computer users to check their PCs.

This is what happened:

Hackers infected a network of probably more than 570,000 computers worldwide. They took advantage of vulnerabilities in the Microsoft Windows operating system to install malicious software on the victim computers. This turned off antivirus updates and changed the way the computers reconcile website addresses behind the scenes on the Internet's domain name system.

The DNS system is a network of servers that translates a web address -- such as www.ap.org -- into the numerical addresses that computers use. Victim computers were reprogrammed to use rogue DNS servers owned by the attackers. This allowed the attackers to redirect computers to fraudulent versions of any website.

The hackers earned profits from advertisements that appeared on websites that victims were tricked into visiting. The scam netted the hackers at least $14 million, according to the FBI. It also made thousands of computers reliant on the rogue servers for their Internet browsing.

When the FBI and others arrested six Estonians last November, the agency replaced the rogue servers with Vixie's clean ones. Installing and running the two substitute servers for eight months is costing the federal government about $87,000.

The number of victims is hard to pinpoint, but the FBI believes that on the day of the arrests, at least 568,000 unique Internet addresses were using the rogue servers. Five months later, FBI estimates that the number is down to at least 360,000. The U.S. has the most, about 85,000, federal authorities said. Other countries with more than 20,000 each include Italy, India, England and Germany. Smaller numbers are online in Spain, France, Canada, China and Mexico.

Vixie said most of the victims are probably individual home users, rather than corporations that have technology staffs who routinely check the computers.

FBI officials said they organized an unusual system to avoid any appearance of government intrusion into the Internet or private computers. And while this is the first time the FBI used it, it won't be the last.

"This is the future of what we will be doing," said Eric Strom, a unit chief in the FBI's Cyber Division. "Until there is a change in legal system, both inside and outside the United States, to get up to speed with the cyber problem, we will have to go down these paths, trail-blazing if you will, on these types of investigations."

Now, he said, every time the agency gets near the end of a cyber case, "we get to the point where we say, how are we going to do this, how are we going to clean the system" without creating a bigger mess than before.

===============================================================

COMPUTER CHECK

Here's how the FBI says you can check your computer:

Go to www.dcwg.org

Click on "Detect" in the upper left corner, or on the Green Button next to it.

You will be directed to a new page. Pick your language from the list and click on the link next to it.

If your computer is not infected, you will see a green logo with the message: "DNS Resolution=Green. Your computer appears to be looking up IP addresses correctly!"

If you see that message, you don't need to do anything more.

If you see a message with a red logo saying your computer appears to be infected, you will be directed to a new page. You will be directed to websites that will provide antivirus tools that cybersecurity experts have identified as being effective in removing the malware.

The website also provides information on the case and the malware.

===============================================================

Here is more information to check your Windows or Mac OS:

Have you been infected? How can you detect if your computer has been violated and infected with DNS Changer?

If you are running Windows 7: http://www.dcwg.org/detect/checking-windows-7-for-infections/

If you are running Windows XP: http://www.dcwg.org/detect/checking-windows-XP-for-infections/

If you are running OSX: http://www.dcwg.org/detect/checking-OSX-for-infections/

_________________
Meet the new new FO... Same as the old new FO. The bag may be permanent.


Top 
 Post subject: Re: Will Your Internet Connection Disappear in July, 2012?
 Post Posted: Fri Apr 20, 2012 4:03 pm 
Offline
User avatar

Joined: Sat Jul 31, 2010 5:33 pm
Posts: 1915
Location: Chandler
Many thanks for spreading the word, EJ.


Top 
 Post subject: Re: Will Your Internet Connection Disappear in July, 2012?
 Post Posted: Sat Apr 21, 2012 9:34 am 
Offline
User avatar

Joined: Mon Aug 02, 2010 2:20 pm
Posts: 1363
Location: San Francisco
Luckily Comcast got rid of their "Domain Helper"-- which automatically redirected DNS traffic by default-- in January. They now use DNSSEC servers, meaning that if you do the computer check above, you can trust the results if you're a Comcast subscriber. Whew.

_________________
Bad Ortiz, No Donut!


Top 
 Post subject: Re: Will Your Internet Connection Disappear in July, 2012?
 Post Posted: Sat Jul 07, 2012 10:59 pm 
Offline
User avatar

Joined: Mon Aug 02, 2010 6:17 pm
Posts: 2261
Location: Oakland, CA
Comcast sucks. I hate their cable box so much. The channel guide is even worse. They have the whole screen available but you only see 4 channels per page.


Top 
 Post subject: Re: Will Your Internet Connection Disappear in July, 2012?
 Post Posted: Sun Jul 08, 2012 8:58 am 
Offline
User avatar

Joined: Sun Aug 01, 2010 7:37 am
Posts: 5048
Thanks again for posting this! We are good!


Top 
Display posts from previous:  Sort by  
 
 Page 1 of 1 [ 5 posts ] 




Board index » Site info » Site Info


Who is online

Users browsing this forum: No registered users and 1 guest

 
 

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron