NODE 2245fca1The penet compromise
roy@sendai.cybrspc.mn.org (Roy M. Silvernail)Thu, 28 Jul 94 22:05:21 PDT
-----BEGIN PGP SIGNED MESSAGE-----
I wrote earlier that I thought the penet attack was a forked strategy
intended to out anon users and flood anon.penet.fi. Now I'm not so sure
it was forked.
I remember trying an experiment a while back, where I posted a message
to alt.test and saved all the replies. There were less than a dozen.
misc.test provides much better response.
That lessens the probable impact of the return traffic to a rough
multiplier of 10. And given the time spread (my experiment yielded
replies over 4 days), I don't know if this can be counted on to yield a
denial-of-service attack. (I suppose it's possible the perp might be
trying to spam penet in the original sense, by trying to overrun
arbitrary limits in the server)
That leaves outing as the motive. Now I'm wondering if the idea is to
out as many people as possible, or if the perp is searching for
a particular party or parties. The formation of the messages (from
reports... I don't get alt.test locally) appears tailored for some kind
of automated data collection.
- --
Roy M. Silvernail [ ] roy@sendai.cybrspc.mn.org
PGP public key available by mail
echo /get /pub/pubkey.asc | mail file-request@cybrspc.mn.org
These are, of course, my opinions (and my machines)
-----BEGIN PGP SIGNATURE-----
Version: 2.6
iQCVAwUBLjh9+hvikii9febJAQFMqwP7B1fmRFT2BHSh1N4PseiexsxZOcQ4xxJz
HzddvlkcditxGjdOUMD3HAzosIKr1IBj0mk1N9bnE2L6nBR4L6583wF551CTOEVD
h9SvPp10N+FDT34DmYsb9yGoL7OXMK5Bov76++liE16NEaIdI5YvspCZ1hdcjzH0
Zhq2tV+Vhhw=
=Frx+
-----END PGP SIGNATURE-----
NODE 66231939The penet compromise
pstemari@bismark.cbis.com (Paul J. Ste. Marie)Fri, 29 Jul 94 07:29:23 PDT
> That lessens the probable impact of the return traffic to a rough
> multiplier of 10. And given the time spread (my experiment yielded
> replies over 4 days), I don't know if this can be counted on to yield a
> denial-of-service attack. (I suppose it's possible the perp might be
> trying to spam penet in the original sense, by trying to overrun
> arbitrary limits in the server)
I was thinking about this as I thought about the combination of
mail->news gateways such as anon.penet.fi and news autoresponders, and
it stuck me that a denial of service attack could be based on
including a *.test newsgroup in a Reply-To: header, causing the
autoreplies to get posted back into the *.test groups.
Some of the autoresponders seem to be set up to prevent this, others
not. I don't know if anon.penet.fi is set up to prevent this sort of
regurgitation.
--Paul