Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Submission + - 4,300 Publicly Reachable Servers Are Posing a New DDoS Hazard To the Internet (arstechnica.com)

An anonymous reader writes: DDoS mitigation provider Netscout said on Wednesday that it has observed DDoS-for-hire services adopting a new amplification vector. The vector is the Datagram Transport Layer Security, or D/TLS, which (as its name suggests) is essentially the Transport Layer Security for UDP data packets. Just as TLS prevents eavesdropping, tampering, or forgery of TLS packets, D/TLS does the same for UDP data. DDoSes that abuse D/TLS allow attackers to amplify their attacks by a factor of 37. Previously, Netscout saw only advanced attackers using dedicated DDoS infrastructure abusing the vector. Now, so-called booter and stressor services—which use commodity equipment to provide for-hire attacks—have adopted the technique. The company has identified almost 4,300 publicly reachable D/LTS servers that are susceptible to the abuse.

The biggest D/TLS-based attacks Netscout has observed delivered about 45Gbps of traffic. The people responsible for the attack combined it with other amplification vectors to achieve a combined size of about 207Gbps. [...] The 4,300 abusable D/TLS servers are the result of misconfigurations or outdated software that causes an anti-spoofing mechanism to be disabled. While the mechanism is built in to the D/TLS specification, hardware including the Citrix Netscaller Application Delivery Controller didn’t always turn it on by default. Citrix has more recently encouraged customers to upgrade to a software version that uses anti-spoofing by default.

Besides posing a threat to devices on the Internet at large, abusable D/TLS servers also put organizations using them at risk. Attacks that bounce traffic off one of these machines can create full or partial interruption of mission-critical remote-access services inside the organization’s network. Attacks can also cause other service disruptions. Netscout’s Hummel and Dobbins said that the attacks can be challenging to mitigate because the size of the payload in a D/TLS request is too big to fit in a single UDP packet and is, therefore, split into an initial and non-initial packet stream.

Earth

Plan to Slow Global Warming By Dumping Iron Sulphate into Oceans 407

ananyo writes "In the search for methods of geoengineering to limit global warming, it seems that stimulating the growth of algae in the oceans might be an efficient way of removing excess carbon dioxide from the atmosphere after all. Despite attracting controversy and a UN moratorium, as well as previous studies suggesting that this approach was ineffective, a recent analysis of an ocean-fertilization experiment eight years ago in the Southern Ocean indicates that encouraging algal blooms to grow can soak up carbon that is then deposited in the deep ocean as the algae die. Each atom of added iron pulled at least 13,000 atoms of carbon out of the atmosphere by encouraging algal growth which, through photosynthesis, captures carbon. The team reports that much of the captured carbon was transported to the deep ocean, where it will remain sequestered for centuries — a 'carbon sink' (abstract)."

Comment Regarding Flash (Score 2, Insightful) 1348

"the fragmentation of the Linux platform and the hurdles presented by..."alpha-quality" drivers for audio and video hardware made success elusive for the [Linux] Flash development team."

Okay, fair enough. But how does Adobe/Macromedia then explain the failure to deliver a decent plug-in on the two other major platforms, Mac OS X and Windows?

Comment Re:Maybe she can answer in hindsight (Score 5, Insightful) 651

In fairness, the fact that someone can crack a "your mum" joke in this discussion scares me a lot less than some of the other posts here that suggest "your life = your salary."

The truth is your life is worth more than your salary. For starters, even if you only wanted to focus on money, it's not just your salary that matters but your potential future salary. However this thinking is still severely flawed, humans do a lot of activities that aren't costed. They care for people, fall in love, contribute to the cultural and political life of society, write open source software, complete volunteer work and provide social engagement for others.

We should never underestimate the value of surviving, surviving is what humans do, everything else (including sex) is just a footnote.

Sci-Fi

Real-World Synthehol In Development 273

Ada_Rules writes "Researchers at the Imperial College London have announced development of an alcohol substitute that has many of the same properties as the Synthehol from the series Star Trek, in that one will get a buzz from it but will not end up with a hangover. In addition you will have the option of getting immediately sober if you so desire it. Let's hope this is not the typical vaporware. It is not that I really want a drink of Synthehol, but with its release I assume Romulan Ale won't be far behind."
Medicine

Drug Vending Machines 97

An anonymous reader writes "If you guessed San Bernardino County prisons as the ideal place to put drug vending machines, come claim your prize. From the article, 'Corrections departments are responsible for so many burdensome tasks that many of their everyday functions, like administering prescription drugs to inmates, are afterthoughts for the public. However, dispensing medication was so laborious and wasteful for the San Bernardino County (Calif.) Sheriff-Coroner Department that officials sought a way to streamline the process. The end product was essentially a vending machine that links to correctional facility databases and dispenses prescription medications.'"
Spam

Yahoo Revives Pay-Per-Email, With Charitable Twist 287

holy_calamity writes "Yahoo research have started a private beta of a scheme that resurrects the idea of charging people to send email to cut spam. Centmail users pay $0.01 for each message they send, with the money going to a charity of their choice. The hope is that the feel good effect of donating to charity will reduce the perceived cost of paying for mail and encourage mass adoption, making it possible for mail filters to build in recognition of Centmail stamps."
Networking

Intel Boosts Optical Communication Speeds 32

An anonymous reader writes "Intel has developed a device, the Avalanche Photodetector, that senses light pulses and amplifies output signals for faster data transfer over long distances. Researchers claim this is a big advancement in the field of silicon photonics, in which silicon is used to transfer light pulses for data exchange between chips and devices. APD can detect light at higher frequencies and moves data at rates of 40Gbps, making it more sensitive and quicker than earlier photodetectors, at a tenth the cost."
The Media

Reuters Pulls Out of Second Life, Army Heads In 77

A little over two years ago, Reuters made headlines by setting up a reporter as a go-between for Second Life and the real world. Now, they've evidently decided that the buzz is no longer there, so they've ended the virtual-reporting experiment. The reporter, Eric Krangel, offered his own take on the situation, and what he thinks Linden Labs could do to make Second Life a better place. Whether or not the advice is taken, the US Army has decided to carve out its own presence in the virtual world by setting up a pair of islands that will function as recruiting tools. An article at Massively suggests that interest in Second Life is still high among a variety of organizations, saying, "at present it appears that more businesses are coming in than going out."
The Courts

Hacker Admits To Scientology DDoS Attack 275

lbwbl writes with news that a New Jersey man will plead guilty to one felony count of 'unauthorized impairment of a protected computer' for his distributed denial of service attacks on Scientology websites as part of 'Anonymous' earlier this year. From Wired: "He faces a likely sentence of 12 to 18 months in prison based on stipulations in his plea agreement, which also obliges him to pay $37,500 in restitution. ... Friday's case, in US District Court in Los Angeles, marks the first prosecution of an Anonymous member for a series of attacks against the Church of Scientology that began in mid-January. The secretive religious group strayed into Anonymous' sights after trying to suppress the publication of a creepy Tom Cruise video produced for Scientology members."
Networking

Why Do We Have To Restart Routers? 936

jaypaulw writes "I've owned a WRT54G, some cheap D-Link home Wi-Fi/firewall/routers, and now an Apple Airport Extreme (100/10 ethernet ports). In the context of the discussion about the worst uses of Windows — installation in places where an embedded device is superior — I've gotten to wondering why it's necessary to reboot these devices so frequently, like every few days. It seems like routers, purpose-built with an embedded OS, should be the most stable devices on my network."
It's funny.  Laugh.

Study Shows Males Commonly Mistake Sexual Intent 825

seattle-pk writes "Males are apparently clueless when it comes to interpreting sexual intent from females, according to a recent study (PDF) from Indiana University's Department of Psychological and Brain Sciences. Men were found commonly to perceive more sexual intent in women's behavior than women were intending to convey. (A campus survey showed that 68% of college females had an experience where a male mistook signs of friendliness for affection.) However, the study also shows that men were quite likely to misperceive sexual interest as friendliness. 'Rather than seeing the world through sex-colored glasses, men seemed just to have blurry vision of sorts, overall,' according to the article. If you're a male who ever mistook the meaning of a barista's smile, looks like you're not alone."
PC Games (Games)

NVIDIA Quad SLI Disappoints 427

Vigile writes "While the death of PC gaming might be exaggerated, it's hard not to see the issues gamers have with the platform. A genre that used to dominate innovation in the field now requires a $1200 piece of graphics technology just to participate, and that's just plain bad for the consumer. NVIDIA's SLI technology was supposed to get a boost today by going from two GPUs to four GPUs with the introduction of Quad SLI but both PC Perspective and HardOCP seem to think that NVIDIA drastically missed the mark by pushing an incredibly expensive upgrade that really does nothing for real-world game play and performance. If PC gamers are left with these options to save them from consoles, do they even have a chance?"

Slashdot Top Deals

And it should be the law: If you use the word `paradigm' without knowing what the dictionary says it means, you go to jail. No exceptions. -- David Jones

Working...