logo

Select Sidearea

Populate the sidearea with useful widgets. It’s simple to add images, categories, latest post, social media icon links, tag clouds, and more.
hello@youremail.com
+1234567890

Spamhaus Cyber Attack Slows Computers Across Europe

Apr 2, 2013

Last week, an epic cyber attack on a spam-blocking company slowed global internet services and the effects could be ongoing, according to experts.

Spamhaus, a London and Geneva-based non-profit gro

up which publishes blacklists to help its customers identify known spammers, announced that it had been hit by “distributed denial of service” (DDoS) attacks for more than a week. Until recently, this company was successfully blocking as much as 80% of spam messages for its clientele.

 

A DDoS attack is launched by attackers taking control of several (in this case, about 1000) computers and harnessing the power of those machines to generate as much as 300 gigabits/second of traffic to the targeted site to flood that site’s servers. The attackers sent commands to the computers under their control to request information as Spamhaus from open resolver internet servers. The resolvers responded with much bigger messages (100 times larger) than the initial request. Spamhaus, overwhelmed by the amount of traffic, was unable to respond to legitimate requests.

 

To defend against the attack, Spamhaus hired CloudFlare, who provided servers to filter out attack messages and allow legitimate requests to access Spamhaus. When the hackers failed to shut down their original target, they escalated to an attack on CloudFlare, then went after CloudFlare’s bandwidth providers. Internet service throughout Europe was slowed according to users.

 

It is suspected that Sven Olaf Kamphuis could be the mastermind behind the attack. Mr. Kamphuis, a self proclaimed Internet freedom fighter, considers Spamhaus to be a nemesis of his since the company has a few of his businesses on their spam offenders blacklist. He has publically accused Spamhaus of censorship.

 

Spamhaus has responded to the incident by publishing FAQ on their site about their experience and they even go as far as to recommend how to prevent something like this from happening to your company. According to their site, it is possible to avoid these types of attacks by ensuring that you do not allow traffic to leave your network if it has forged sending addresses and by verifying that DNS resolvers are secure.

 

If you feel your network may be susceptible to an attack or would like an evaluation of your system, call Teltek IT today!

 

Teltek is proud to offer IT services as the fourth component to our multi-systems approach as your single source technology services company. This Managed Service Provider (MSP) offering completes our longstanding goal to provide our clients with a one-call resource for all of their business technology needs. IT outsourcing, remote back up and disaster recovery, helpdesk support, computer network relocations, security products and server/desktop virtualization are just a few of the services available.