Attack on SCO's servers intensifies

Robert Lemos, Special to ZDNet

12 December 2003 11:30 AM

Tags: linux, server, unix, sco, attack, robert, lemos, source

A day-old denial-of-service attack on the Web server of the controversial SCO Group has been expanded to assault the company's mail and file servers, SCO's top network administrator said.

The attack, which first hit the company's Web and file servers on Wednesday around 3:20 a.m. PST, paused briefly last night in the U.S. before resuming against more SCO servers, said Jeff Carlon, director of worldwide information technology infrastructure for the Lindon, Utah, company.

"There is no way to fully prevent the attack; we are somewhat at the mercy of the guy that is doing the attack," he said.

The deluge of data that has swamped the company's network has also swept up its critics in a new wave of theories as to why the company cannot, or will not, stop the third such attack on its network in six months. Such attacks can usually be largely mitigated by buying up more bandwidth and connecting through Internet service providers that have special technology aimed to defeat the assaults.

Security experts said that previous attacks in May and August should have been adequate warning for the company to have taken steps to protect its connection to the Internet.

"There are definitely things out there that they can buy, or services that solve this problem," said David Moore, assistant director and researcher at the Cooperative Association for Internet Data Analysis (CAIDA) and an expert on denial-of-service attacks. "It is just a question of how important your Web site is to you and how much you are willing to spend."

The attacks have been the third blow to SCO in the past three weeks: News of the attack appears as SCO has lost a key tactical battle in its court case against IBM and as the company delayed its earnings announcement.

SCO has gained the ire of the open-source community for its pursuit of a legal case that, if successful, would essentially give the company rights to important parts of the Linux source code. Most Linux users don't take the claims seriously, however, and the case hasn't slowed the growth of Linux. A recent report published by market researcher IDC found that sales of Linux servers grew almost 50 percent in the third quarter of 2003, compared with the same period a year earlier.

"The thing we have to keep in mind is that this is not something that we are doing," said SCO's Carlon, referring to the attack. "This is not something that we have made up. It is an illegal activity that is having a sizeable impact on our company." SCO, in a rare move, is publicising the attack.

The attack, which SCO identified as a SYN flood, tries to open a connection with a server across the Internet by sending a SYN packet to the computer. That data is a part of the normal communications process between computers and indicates that a computer on the Internet wants to start communicating with the server. The server would normally respond to the packet and await a connection, allocating memory for the process. An attacker, by sending a relatively small number of requests to a server, can essentially use up the target computer's resources.

The SCO Web site outage was confirmed by Internet performance company NetCraft. CAIDA's Moore also confirmed the attack by analysing backscatter data showing that both SCO's Web server and FTP server had been inundated by network traffic. As many as 50,000 packets per second hit the company's servers on Wednesday night in the U.S. By Thursday morning, the attack had been reduced to some 3,000 packets per second and the company's servers were responding to one in every three requests.

The statistics suggest, however, that the attack is more a brute-force tactic of inundating a network with data than a simple SYN flood.

"A SYN flood would have been trivially preventable," said David Conrad, chief technology officer for Nominum, an Internet infrastructure technology company. "Every major operating system vendor in the world could have defeated it."

A SYN flood can be prevented by using a Linux feature known as SYN cookies. The technique uses basic encryption to prevent memory from being used up by fake connection requests. However, it also constitutes a tradeoff: lower memory usage for higher processor usage.

Moreover, while the technique does protect the target computer, it doesn't prevent the network from succumbing to the onslaught of data. A SYN flood that fails to use up the target server's memory could still overwhelm its connection to the network, CAIDA's Moore said.

A flood of data can't easily be dodged, but by buying more bandwidth or by using an Internet service provider that has technology to shunt such an attack, it can be mitigated, Moore said.

"There is always kind of an arms race between how much money you are willing to spend and how much the attacker wants to bring down your network," said Moore.

SCO said that it is spending enough, if not too much, on defence.

"I can assure you that we are expending significant amounts of resource and money to combat this activity," Carlon said. "In doing so, as a result of these attacks, we have to spend money that we might not be able to spend elsewhere."

Like this article? Click below to send it to your mobile for free!

Talkback 5 comments

  1. http://www.groklaw.net/article.php?story=20031210163721614 Anonymous -- 12/12/03

    http://www.groklaw.net/article.php?story=20031210163721614

  2. Carlon says "we have to spend money that we might not be able to spend elsewhere." I assume the "elsewhere" Carlon's referring to is on defense lawyers for McBride and co when they have to face the various criminal charges t Anonymous -- 12/12/03

    Carlon says "we have to spend money that we might not be able to spend elsewhere."

    I assume the "elsewhere" Carlon's referring to is on defense lawyers for McBride and co when they have to face the various criminal charges that they deserve after the whole farce is over? I personally dislike Linux but I find it hard to cry for a company like SCO. Almost as hard as sympathising with the RIAA....

  3. Just more lies and FUD to try and paint the Open Source Linux crowd as a bunch of ne'er-do-wells. Once again, SCO is going for the court of public opinion, rather than court of law. Maybe, just maybe, if they could teach their lawyers MrDamage -- 12/12/03

    Just more lies and FUD to try and paint the Open Source Linux crowd as a bunch of ne'er-do-wells.

    Once again, SCO is going for the court of public opinion, rather than court of law.

    Maybe, just maybe, if they could teach their lawyers to code, and put all of that imagination of theirs into some software, they might have a product worth purchasing.

  4. Who else could it be, but a Linux fanatic who has decided to take matters into their own hands? MrDamage, do you honestly believe that all Linux users have such high moral values that they couldn't perpetrate this act? I think you're living in a fantasy Anonymous -- 15/12/03

    Who else could it be, but a Linux fanatic who has decided to take matters into their own hands? MrDamage, do you honestly believe that all Linux users have such high moral values that they couldn't perpetrate this act? I think you're living in a fantasy world...

  5. lol @ mrDamage maybe ... you know what most companys would try and keep this sort of thing under radar.... if they cant secure their own site how are they going to help you??????? Anonymous -- 27/12/03

    lol @ mrDamage maybe ... you know what most companys would try and keep this sort of thing under radar.... if they cant secure their own site how are they going to help you???????

Add your opinion


Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay Australian Govt funds IT start-ups
    This week Australia's Federal Government announced it had allocated $3.6 million in funding to 57 local research projects so that they could be commercialised, with many of them being web or IT-related start-ups.
  • Array Google should come clean on datacentres
    It's nice that Google says it has put an effort into making its datacentres more energy efficient, but the search giant's pledges won't mean much until it discloses just how many of the beasties it's actually running.
  • Array US shows what OPEL could have been
    Sprint's WiMAX roll-out in Baltimore will prove the Australian government's decision to worm its way out of the Opel WiMAX contract was a short-sighted, and ultimately damaging, political stunt that has benefited nobody.
  • More blogs »

Tags

Back to top

Featured