<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; timewarner</title>
	<atom:link href="http://www.darknet.org.uk/tag/timewarner/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>TimeWarner DNS Hijacking IRC Servers to Stop DDoS Attacks</title>
		<link>http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/</link>
		<comments>http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/#comments</comments>
		<pubDate>Thu, 26 Jul 2007 08:33:52 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[denial-of-service]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[dns-hijacking]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[irc-servers]]></category>
		<category><![CDATA[time-warner]]></category>
		<category><![CDATA[timewarner]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/</guid>
		<description><![CDATA[An interesting happening this week, some ISP&#8217;s have been jacking the DNS entries for certain IRC networks to crack down on zombie/bot infections. Is it ethical? Should they be doing this to their users? I first got wind of this from a post on Full Disclosure mailing list from an IRC network administrator. You can [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>An interesting happening this week, some ISP&#8217;s have been jacking the DNS entries for certain IRC networks to crack down on zombie/bot infections.</p>
<p>Is it ethical? Should they be doing this to their users?</p>
<p>I first got wind of this from a post on Full Disclosure mailing list from an IRC network administrator.</p>
<p>You can read that e-mail here:</p>
<p><a href="http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/55016">Major ISPs arbitrarily blocking IRC and hijacking DNS entries</a></p>
<blockquote><p>Internet service provider Cox Communications is reportedly diverting attempts to reach certain online chat channels and redirecting them to a server that attempts to remove spyware from the computer.  By doing so the company seems to be attempting to cleanse computers of malware that hijacks the computers resources to send spam and participate in online service attacks as part of a large network of compromised computers known as a botnet. </p>
<p>Specifically, Cox&#8217;s DNS server is responding to a domain name request for an Internet Relay Chat server. Instead of responding with the correct IP address for the server, Cox sends the IP address of its own IRC server (70.168.70.4).  That server then sends commands to the computer that attempt to remove malware. </p></blockquote>
<p>They seem to run some kind of script when the user connects to try and &#8216;clean&#8217; the machine from infection&#8230;.even if it&#8217;s not infected.</p>
<p>IRC is still used heavily, I don&#8217;t really use it much anymore apart from Freenode. The Darknet channel used to be on DALnet back in the day.</p>
<p>Freenode is pretty happening for open source projects though.</p>
<blockquote><p>Though clever, the tactic is being heavily debated by networking experts on the NANOG mailing list, some of whom question the effectiveness of the technique and who question whether blocking access to the channels for all users (by breaking the DNS protocol) in order to stop some malware is the appropriate solution. Cox does not seem to be blocking all IRC channels, but anyone trying to reach those channels using Cox&#8217;s DNS servers will be unable to reach them.</p>
<p>IRC channels are heavily used by programmers, non-traditional communities and black-hat hackers, among others.  The malware-infected zombie computers Cox is attempting to clean can also be controlled remotely by having them connect to an IRC channel where they get instructions from their controller.</p></blockquote>
<p>Interesting stuff eh?</p>
<p>I&#8217;m not really sure where I stand ethically on this&#8230;what about you?</p>
<p></p>
<p>Source: <a href="http://blog.wired.com/27bstroke6/2007/07/isp-seen-breaki.html">Wired Blog</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D644+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;t=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;title=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;title=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;title=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;title=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F07%2Ftimewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
	</channel>
</rss>

