8 ms·
US airport websites under DoS attack
- TecoAndJix 4y ago@dang I feel like this qualifies for the "Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize" rule. The airports themselves are not under attack.
- dang 4y agoYes. The original title is both misleading and linkbait, so there are two reasons to change it.
- auslegung 4y ago> Importantly, the systems targeted do not handle air traffic control, internal airline communications and coordination, or transportation security. > "It's an inconvenience," the source said. > The attacks have resulted in targeted "denial of public access" to public-facing web domains that report airport wait times and congestion.
- bvogelzang 4y agohttps://www.flychicago.com https://www.flychicago.com still appears to be down
- citilife 4y ago> (NEW YORK) -- Some of the nation's largest airports have been targeted for cyberattacks Monday by an attacker within the Russian Federation, a senior official briefed confirmed to ABC News. Senior official from what agency / organization are making those claims? > The attacks have resulted in targeted "denial of public access" to public-facing web domains that report airport wait times and congestion Why would they be doing DDoS on this service? > Hartsfield-Jackson Atlanta International Airport reported around 10:30 a.m. ET that its site is back up and running and that "at no time were operations at the airport impacted." And operations are not being impacted... I hear "Russia" is doing X and at this point I don't believe it without evidence being presented. Anonymous sources are equivalent to saying "some random person says X". Also why would they do anything with not negative impacts. This isn't much of a story IMO
- snake_doc 4y agoDo you want more than a name and a organization? Would you like John’s home address? > Over a dozen airport websites were impacted by the "denial of service" attack, John Hultquist, head of intelligence analysis at cybersecurity firm Mandian[t], told ABC News. That type of attack essentially overloads sites by jamming them with artificial users. >” Killnet," a pro-Russian hacker group, is believed to be behind the attack, according to Hultquist. While similar groups have been found to be fronts for state-backed actors, Hultquist said there is no evidence the Russian government was involved in directing this attack.
- mkoryak 4y agoSerious question: How do they know that? I assume killnet does not have a static IP address and doesn't leave it's return address
- woodruffw 4y agoI don’t know about the details in this case, but hacking (particularly DDoS) groups can be remarkably childish: they sometimes intentionally leave their name in requests, knowing that it’ll show up in logs. The other identifying technique is correlation: if they’re using a network of hacked devices to create a flood of traffic, any previous attacks that saw traffic from those same devices are possibly from the same group. So it’s possible killnet has a public chronology here.
- Minor49er 4y agoThe former of these would easily open the possibility of a false flag. Same with the latter, though it would be harder to pull off
- woodruffw 4y agoThis would be a pretty strange false flag: why bother blaming some random group that hasn’t been linked to the Russian government? To my mind, the most likely explanation here is the simplest one: airport websites make good testing targets, and Russia doesn’t punish hackers who target non-military resources in the West.
- ramesh31 4y agoIt seems like the big bad boogeyman of Russian cyberwarfare has also turned out to be a paper tiger. They are grasping at straws.
- radicaldreamer 4y agoThis is likely just a warning or nuisance (but intentionally not destructive). An actual cyberattack which disrupts air traffic will likely be considered an act of war.
- ramesh31 4y ago> This is likely just a warning or nuisance (but intentionally not destructive). An actual cyberattack which disrupts air traffic will likely be considered an act of war. That theory sounds a lot like the argument of “why not just shoot their legs” applied to escalation of force. That’s not how it works. When you make the decision to shoot, you shoot to kill. And similarly, revealing your cyberattack capabilities through a “warning” attack is highly unlikely from a state based actor.
- woodruffw 4y agoTaking down an airport’s website does not meaningfully reveal a nation’s “cyberattack” capabilities. It’s the same thing as a shot across the bow, and nobody doubts that the other guy’s boat has a gun.
- A4ET8a8uTh0 4y agoI would have agreed with you assessment in pre-MAD world, but in MAD world, "shoot to kill" means we all, likely, die. Those that don't initially perish, do so shortly thereafter. In other words, there are good and valid arguments to ( using your words ) shoot in the legs first.
- matai_kolila 4y agoROE for cyber are fundamentally different. You deliberately do not "shoot to kill" in cyber, for tons of reasons, at least one being it's a much more opportunistic environment; hacking isn't magic, and many systems aren't penetrable at will. You often don't get to choose exactly what you target, you just hit what's vulnerable and see how you can pivot. Flip the incentives for a sec; the group that executed this hack can present it as an "attack on American infrastructure" to their superiors, even though we here in the US know it was 100% ineffective.
- bush-bby 4y agoSo basically we can assume that a lot of airports use the same service for hosting?
- woodruffw 4y agoProbably not, unless that service is AWS or GCP. It’s more likely that none of them have meaningful DDoS protection, since it isn’t really worth it.
- OJFord 4y agoI don't think free Cloudflare has a usage cap does it? (My point being it's so easy it probably is 'worth it'? .. Especially after the first time this happens, even if only so you can tell media/bosses/whatever that mitigations have been put in place.)
- jgrahamc 4y agoCorrect. We do not: https://blog.cloudflare.com/unmetered-mitigation/ https://blog.cloudflare.com/unmetered-mitigation/
- woodruffw 4y agoIs Cloudflare’s free tier available to businesses? My understanding was that it’s for personal and hobby use only. Airports probably fall under Cloudflare’s “enterprise” tier, which has no billing ceiling (as far as I can tell), even if the bandwidth might be free. Put another way: I would not want to be the underpaid airport IT guy who has to justify tripling my operational budget because of a DDoS attack that (1) almost never happens, and (2) doesn’t actually affect critical systems.
- yamtaddle 4y agoLast I checked there's no SLA whatsoever until the top-tier "self-serve" plan, and that SLA's not an impressive one. I've also heard (admittedly, from their competitors, but they turned out to be right about other things) that if your usage gets too crazy they'll encourage you to start paying. And nb. that 100% of the "self-serve" plans (not the "call us" pricing) specify web traffic, like from a browser. If you're using it for e.g. delivering data to apps you might get away with it, but it's not technically permitted. Again, last I checked.
- VoidWhisperer 4y agoGiven what the article says, this seems like a bit of fearmongering on ABC's part.
- deleted 4y ago[deleted]
- matai_kolila 4y agoAgreed, this is a terrible headline designed exclusively for clicks. > "It's an inconvenience," the source said. How wildly irresponsible of the editor who came up with this headline. > Jamming attacks like the one seen Monday morning are highly visible but largely superficial and often temporary Gee, I wonder why these superficial attacks are so visible, ABC...
- atourgates 4y agoAs far as "airport-travel related systems that could be affected without seriously impacting anyone's travel", "airport websites" are the top of the list. I think the last time I used one, it was to find out if there was an airport lounge in a specific terminal. "Airport Websites Briefly Unavailable" is a much less exciting, but much more accurate headline.
- mindslight 4y agoEvery article about "cyber" is fundamentally fearmongering, because they incorrectly analogize to the physical world where security is outsourced to an ambient third party (post facto law enforcement), implying an attacker is the purely responsible party. In digital reality, this headline would be more appropriate as "Airline website insecurities taken advantage of by Russia to disrupt business". The focus should be on the irresponsible duct-tape-and-string operations these businesses are running, rather than the people half a world a way sweet talking the computers into misbehaving.
- CompuHacker 4y ago"... taken advantage of by an entity capable of causing Russian computers to convince U.S. computers to misbehave, or to convincingly mis-attribute that activity in at least the preliminary stages of an investigation."
- dangerface 4y agoinb4 it was the Russians as retaliation for nord stream. As a brit im still glad the US blew it up. edit: Should have read the article before shit posting.
- NovemberWhiskey 4y agoObligatory xkcd reference: https://xkcd.com/932/ https://xkcd.com/932/
- rdxm 4y ago
- wil421 4y agoHere’s a much better article from CNN. [1] [1] https://www.cnn.com/2022/10/10/us/airport-websites-russia-hackers/index.html https://www.cnn.com/2022/10/10/us/airport-websites-russia-ha...
- benatkin 4y agoAnother article about it: https://www.nbcnews.com/tech/security/us-travel-websites-knocked-offline-russian-hacker-group-calls-attack-rcna51482 https://www.nbcnews.com/tech/security/us-travel-websites-kno... > there is no indication that any airport operations were affected
- lima 4y agoObligatory XKCD: https://xkcd.com/932 https://xkcd.com/932