You are here: silicon.com > Software > Security Strategy

Security Strategy

Security giant hit by hacker attack

Security vendor Network Associates (NAI) came under attack from hackers last night just days after it issued an advisory on security flaws in DNS software BIND. Although the network struggled, it managed to weather the storm.

By Sally Watson

Published: 1 February 2001 18:00 GMT

NAI's US servers were bombarded in a Denial of Service (DoS) attack after malicious software was posted anonymously on a security mailing list with 85,000 members, called BugTraq.

Chris McNab, network security analyst at MIS Corporate Defense Solutions, said the BugTraq monitor would have been hard pushed to spot the exploit. "The hacker had spent a lot of time, effort and resources on this," he said.

McNab claimed NAI's network was up and down intermittently overnight.

However, Douglas Hurd, business development manager for Northern Europe at NAI, said the company's servers stood up well to the attack. "NAI were aware as soon as it happened. Within 90 minutes we were able to do something to mitigate the attack," he said.

The BugTraq list is used by security professionals to share information, publish exploits and post fixes. Postings are monitored for malicious content, but the DoS software passed through unnoticed, hidden in the shellcode.

The hacker software was hidden in a posting that claimed to be the first exploit of the BIND vulnerabilities in the wild. Security experts have been waiting for the code to be published since last Friday when NAI announced it had a copy in its US labs.

"This was probably a revenge attack for telling the world about the vulnerability," said McNab.

NAI's Hurd said the company will not take action against BugTraq. "We're obviously very disappointed. But we can't fault them for being imperfect," he said, "BugTraq plays a valuable role."

He added that the damage caused to NAI was minimal. "It's never good news to be attacked, but its proof that NAI's defences worked this time."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Vulnerability / Penetration tester (CEH) -

An immediate opening has arisen for a penetration / Vulnerability tester who also has a broad general Info sec background. The primary focus of the ...

Security Operations Centre Manager (SOC Manager), SC Security Cleared

Basic awareness of computer based vulnerability analysis testing. Moderate awareness of computer based vulnerability analysis testing. You will be ...

Penetration Testing Consultant - UK Wide

ll need to clearly explain the technical issues and risks identified from testing and create strategies and processes to resolve and mitigate these. ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: