DDoS attack, Internet knocked out by security cameras

The hackers hit DynDNS, one of the most widely used web service providers in the world. The connection problems went on for hours

Twitter, Spotify, SoundCloud, Github, Airbnb, Reddit, Heroku and Shopify. These are some of the portals that, in the morning of October 21 (11 am UTC, about 1 pm in Italy), have recorded serious disruptions, so as not to be reachable by users.

At the base of everything, according to the first information that have begun to circulate on the network in recent minutes, there would be a massive DDoS attack, capable of knocking out the servers of the provider Dyn DNS, web and Internet service provider for the companies mentioned above. According to the rumors, the problems would have affected mainly the US citizens of the East Coast, but it is not to be excluded that the effects of the attack could have caused some slowdown in the rest of the world.

La componente IoT

In the meantime, the first details regarding the two DDoS attacks against Dyn DNS are beginning to emerge. According to a spokesman for the U.S. company, the servers would have been reached simultaneously by millions of requests generated by millions of different IP addresses. The hypothesis is therefore gaining ground that the botnet (the network composed of zombie computers or bots) is largely composed of smart and IoT devices. Reinforcing this scenario is Brian Krebs, one of the world's leading experts on computer security. In his blog (Krebsonsecurity.com), the U.S. analyst points out how an attack of such a large scale can be set up only thanks to the devices that populate the Internet of Things and also identifies a possible culprit: IP security cameras made with components of Chinese XiongMai Technologies.

According to Krebs, the hackers used the Mirai botnet, scanning the Net for poorly protected devices (at most by a simple access passowrd and not shielded by firewalls and other security components), infecting them and thus adding them to their botnet. In a second moment all these devices - millions of devices - have sent access requests to DynDNS network, knocking it out and making unreachable all those web services that exploit its functionalities.

What are DNS

The Domain Name System (whose acronym is, precisely, DNS) is one of the fundamental infrastructures of Internet. The addresses of the various resources present in the Net (from servers to images, from web portals to videos, passing through texts and audio tracks) are formed by four triplets of numbers, each of which ranges from 000 to 255: this is the so-called IP address, usually written in the form "xxx.xxx.xxx.xxx". A code that can hardly be remembered by heart and, for this reason, it was preferred to replace it with URLs (acronym for Uniform Resource Locator), the alphanumeric addresses that we usually use to connect to any site (for example, www.libero.it). The task of DNS providers is to translate IP addresses (numeric) into URLs (alphanumeric) and vice versa: when you type the URL of a site in the browser's address bar, the DNS "flips through" a sort of web directory looking for the exact match and ensures that the user displays the correct content in his browser.

Cosa sono gli attacchi DDoS

DDoS attacks are the most dangerous type of cyber attack in circulation today. An acronym for Distributed Denial-of-Service, it employs thousands and thousands of computing devices (in the past only computers, today also connected devices such as IP cameras and smart appliances) to make a portal, a web server, a distribution network or, as in this case, a DNS provider unreachable. The tactic employed is extremely simple: all computing devices, infected with malware that turns them into "zombies" and allows hackers to control them remotely, connect simultaneously to the IP address of the server or portal. In this way the incoming traffic is so high that the network is unable to manage it and, in fact, a digital traffic jam is created. Obviously, the greater the attack scope, the greater the incoming traffic and the more difficult it will be to reach the attacked site or web resource.