Whirlpool DDoS investigation dropped

 

Is Bulletproof letting the script kiddies win?

Hosting company Bulletproof Networks and Whirlpool have decided to pull the plug on an official investigation into those responsible for distributed denial of service attacks levelled against the broadband forum this week.

The attacks, which took Whirlpool offline for two days this week, were set to be escalated to the Australian Federal Police after Bulletproof informed NSW Police.

But after evading further attacks using a reverse proxy hosted at Amazon.com, Whirlpool and Bulletproof have decided not to proceed with the investigation.

In a prepared statement, Bulletproof chief operating officer Lorenzo Modesto told iTnews it had decided to "suspend investigations for the moment as a sign of goodwill."

Whirlpool founder Simon Wright later told iTnews in an interview that the "effort involved to follow through the investigation would mean a large amount of work.

"All that work would probably be to find a schoolkid at the other end who is upset he got banned from forums for using bad language," Wright said. "All that effort over a kid. At the end of the day, the benefit wouldn't scale to the effort."

Security analyst James Turner commented that it was a "classic" dilemma for the IT industry. Attributing the work of security commentator Bruce Schneier, Turner said there is a "cost asymmetry" involved in protecting any network.

"It costs very little to direct a very concerted attack, but it is quite expensive for a target to defend themselves," he said. "The economics are badly in favour of the attacker."

Wright agreed wholeheartedly.

"You can boil it down further," he said. "It is easier to destroy than to create. Causing chaos in any sphere is easy to do, creating a web site or community, hosting it, that takes a hell of a lot more effort."

The volume of HTTP packets used in the attack was "absolutely outrageous", Wright noted.

"It was the kind of volume that could take down banks - very few companies could be prepared for this," he said. "You would need so much excess infrastructure to cope."

Should the police be involved?

While he feels that "reporting criminal activity to the relevant authorities is the right thing to do", Turner said he understood the difficulty any not-for-profit would have in justifying the resources required to assist in a lengthy investigation.

Wright told iTnews it would be unfair to say that Whirlpool or Bulletproof has capitulated to the attacker(s). The investigation would "still be happening" if the DDoS attacks continued, he said.

"If [the attacker] was willing to pursue it, they would leave us no choice," he said. "We can't accept the situation of the site being down. We would have been pushing ahead with an investigation, with every avenue we could think of."

Turner said DDoS attacks are becoming increasingly common, and more Australian organisations need to be frank with their peers and go public after an attack.

"I firmly believe that Australian organisations do need to declare when they have been attacked," he said. "It is really important.

"Security professionals only have access to attack information from vendor reports, which are inherently self-serving. There is very little information to go on in the wider industry.

"If organisations are reasonably confident as to how an attack was orchestrated or who was responsible, they should go to the media," he said.

"They might think that they should keep quiet because they are alone - but that is probably not the case."

For now, the Whirlpool problem is resolved. Wright described Bulletproof's solution as "inspired".

"They did exactly what they should have done," he said. "Bulletproof's first step was and should be to ensure the integrity of their network.

"Whirlpool was the target, we didn't get to go back online straight away, but that's understandable. We had to cop it. I'd still recommend Bulletproof."


Whirlpool DDoS investigation dropped
"Yes, Mordd, sad but true."
By anonymous
 
 
 
Comments: 14
Rossyduck
Jul 2, 2010 8:34 AM
Maybe ITNews could conduct a bit of old fashioned investigative journalism instead of just republishing press releases and try and get to the bottom of this story ? The whole thing stinks, and now the back down makes me even more curious.
DanielBrown
Jul 2, 2010 9:55 AM
Agrred... There is more to this story here...
HubertCumberdale
Jul 2, 2010 9:59 AM
Investigation dropped? well this is the most laughable thing I've heard in the history of wp, you'd think a site with some of the best control freaks on the planet would want to follow something like this through... meh well I guess the kiddys can go back to bitching about telstra and masterchef contestants now.
BrettWinterford
Jul 2, 2010 11:42 AM
@Rossy, @DanielBrown, this is an update in an evolving story.
I'll just get my crack team of forensic computing investigators to trace the source of attack for you....
:)
btone
Jul 2, 2010 2:26 PM
HumbertCumbersome or whatever his latest trolleration is alludes to control freaks. I wonder how many times he/she/it has been sin binned there to ellicit such irrational, illogical and irresponsible claptrap.

Well thats my troll feeding for the day, time to go back to addressing the real control freaks, and we all know who they are eh Mr ACME?
DJ
Jul 2, 2010 3:46 PM
Whingepool / Bulletproof this is rubbish.

The service provided was impacted, you raced off to the Federal Police to launch a "serious investigation" then all of a sudden after setting up a $15 per month virtual server in the US everything is OK again.

Why the hell would you not investigate the source(s) of DDoS attack traffic ?

With all the geeks and tools potentially at your disposal, you could be giving back to the industry and helping find the culprits, instead of whinging about ISPs and how users can't download pr0n or play their online games fast enough.

Please. What a rort. We are obviously not hearing the full story here.

It smells.
HubertCumberdale
Jul 2, 2010 4:19 PM
Awww, looks like I hurt someones feelings again, you seem to think wp is some kind of magical place that everyone should aspire to be part of, you know even if wp wasn't the cesspool it is you have to wonder about some of the people that defend it so much. Quite disturbing really, just a message board dudes.
anonymous
Jul 2, 2010 6:00 PM

Yes, Hubert, it's called free speech, and that can include any things which you don't agree with. But other people still have the right to say those things without being flamed by some insecure trollbot.
HubertCumberdale
Jul 2, 2010 10:46 PM
"it's called free speech"

I assume I am allowed this free speech you talk about too? I thought I was doing it right at "Jul 2, 2010 9:59 AM" & at "Jul 2, 2010 4:19 PM" tell me if I didn't do the free speech the right way, I'd really like to improve my free speech skills.
anonymous
Jul 3, 2010 11:20 AM

Hubert, your free speech input skills are fine, if somewhat obnoxious in presentation.

The more important point about free speech is the respect you have, or haven't, for the rights of everyone else. Schoolyard abuse of people whose views you don't share, in an attempt to silence them, is not good participation in free speech.
Flaschengeist
Jul 3, 2010 1:59 PM
"Quite disturbing really" "it's called free speech"
Congratulations Hubert, well spotted "you do need to improve your free speech skills"
That wasn't too hard, was it?
HubertCumberdale
Jul 3, 2010 4:45 PM
"Schoolyard abuse"

yeah talk about being melodramatic again, you know I could use the same sort of rhetoric on you lot but I wouldn't because I'm not one that expects everyone to wrap me in cotton wool like they do at wp.

Do you seriously think I'm trying to silence people? I totally welcome EVERYONE'S input here, unlike wp I want to know everyone's genuine opinions these topics not to be shielded behind some wall of false/forced politeness.

You know the real problem is here is if you lot weren't so emotionally tied to a place like wp which is really nothing more than an internet forum my comments wouldn't mean much and you could just disregard them. I mean you'd rather be commenting on my comments rather than the actual story here? says alot about the types that frequent wp really. oh but that's something you cant even do over there is it? if this thread was wp every post mine and yours included would be deleted for being "off topic" totally disrupting real conversation flows. nice.
Mordd
Jul 3, 2010 5:34 PM
I stoppped paying attention to Huberts rants about 48 hours ago, much easier to just ignore him than feed the troll.
anonymous
Jul 5, 2010 11:32 AM

Yes, Mordd, sad but true.
Comments have been disabled for this article.
 
 
 
Top Stories
The New Zealand telco problem
Opinion: Could Telstra save Kiwi telcos?
 
IT price probe to 'name and shame' gougers
Industry ducking the issue, committee claims.
 
Revealed: 2012 e-government award winners
Government highlights projects, professionals of the year.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Should the Government enact new legislation to protect copyright holders in the digital age?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 480

Vote