134
Hal Roberts, Ethan Zuckerman, and John Palfrey
free e-mail addresses and send spam. In this case, the zombie computers sent an extraordinary number of requests to http://bauxitevietnam.info , crashing the site.
Shortly after the DDoS attacks on the site began, Google announced that it would
no longer censor its search results in China
4 because of attacks on its Gmail service,
which it found had originated from within China. While investigating the source of
those Gmail attacks, Google found evidence that the botnet attacking bauxitevietnam
.info — though not involved in the Gmail attacks — consisted largely of computers that
had been infected by a malicious program hidden by an attacker within a program
called VPSKeys.
5
Technicians at Google and at the antivirus fi rm McAfee then unraveled the story
of the bauxitevietnam.info DDoS attacks. VPSKeys is the most popular Vietnamese
keyboard input program. Distributed by the Vietnamese Professionals Society (VPS),
it allows Vietnamese users to enter Vietnamese characters easily using Western keyboards. Some months before the attacks on bauxitevietnam.info, likely in late 2009,
the Web site hosting the VPSKeys software had been compromised. The attacker
replaced the VPSKeys program with a Trojan version designed to infect the host computer with botnet software. The attackers also alerted thousands of VPSKeys users by
e-mail that a new (secretly infected) version of the software was available. Many Vietnamese users updated their software in response. It is likely that the attackers were
able to obtain the mailing list used to send this e-mail through a separate attack —
possibly intrusions that seized membership databases of popular Vietnamese discussion forum sites in 2009.
Tens of thousands of users downloaded the Trojan software, which infected the
host computers and added them to a botnet before the Trojan software was discovered.
The makers of VPSKeys replaced the infected software with a clean version, but not
before the Trojan software had created the network of compromised computers. This
botnet was used to mount the DDoS attack on bauxitevietnam.info and may have
been used against additional targets.
Why did the attackers go through the effort of compromising computers and creating their own botnet? There is a thriving underworld business devoted to the sale of
lists of infected computers, which in essence allows attackers to rent these computers
for the purpose of a one-time attack like the one on bauxitevietnam.info.
6 A plausible
explanation is that a botnet of computers based in Vietnam would be diffi cult for a
site administrator to defeat through geographic fi ltering. If bauxitevietnam.info were
attacked by thousands of computers located in South Korea, an administrator might
respond by blocking all requests to the Web site from that country. But blocking
requests from Vietnam would defeat the purpose of raising awareness within Vietnam
itself. It is also possible that the botnet was an added benefi t in a scheme that primarily sought to monitor the activity of Vietnamese-speaking users around the world. The
botnet was certainly capable of spying on the owners of the infected computers,
Hal Roberts, Ethan Zuckerman, and John Palfrey
free e-mail addresses and send spam. In this case, the zombie computers sent an extraordinary number of requests to http://bauxitevietnam.info , crashing the site.
Shortly after the DDoS attacks on the site began, Google announced that it would
no longer censor its search results in China
4 because of attacks on its Gmail service,
which it found had originated from within China. While investigating the source of
those Gmail attacks, Google found evidence that the botnet attacking bauxitevietnam
.info — though not involved in the Gmail attacks — consisted largely of computers that
had been infected by a malicious program hidden by an attacker within a program
called VPSKeys.
5
Technicians at Google and at the antivirus fi rm McAfee then unraveled the story
of the bauxitevietnam.info DDoS attacks. VPSKeys is the most popular Vietnamese
keyboard input program. Distributed by the Vietnamese Professionals Society (VPS),
it allows Vietnamese users to enter Vietnamese characters easily using Western keyboards. Some months before the attacks on bauxitevietnam.info, likely in late 2009,
the Web site hosting the VPSKeys software had been compromised. The attacker
replaced the VPSKeys program with a Trojan version designed to infect the host computer with botnet software. The attackers also alerted thousands of VPSKeys users by
e-mail that a new (secretly infected) version of the software was available. Many Vietnamese users updated their software in response. It is likely that the attackers were
able to obtain the mailing list used to send this e-mail through a separate attack —
possibly intrusions that seized membership databases of popular Vietnamese discussion forum sites in 2009.
Tens of thousands of users downloaded the Trojan software, which infected the
host computers and added them to a botnet before the Trojan software was discovered.
The makers of VPSKeys replaced the infected software with a clean version, but not
before the Trojan software had created the network of compromised computers. This
botnet was used to mount the DDoS attack on bauxitevietnam.info and may have
been used against additional targets.
Why did the attackers go through the effort of compromising computers and creating their own botnet? There is a thriving underworld business devoted to the sale of
lists of infected computers, which in essence allows attackers to rent these computers
for the purpose of a one-time attack like the one on bauxitevietnam.info.
6 A plausible
explanation is that a botnet of computers based in Vietnam would be diffi cult for a
site administrator to defeat through geographic fi ltering. If bauxitevietnam.info were
attacked by thousands of computers located in South Korea, an administrator might
respond by blocking all requests to the Web site from that country. But blocking
requests from Vietnam would defeat the purpose of raising awareness within Vietnam
itself. It is also possible that the botnet was an added benefi t in a scheme that primarily sought to monitor the activity of Vietnamese-speaking users around the world. The
botnet was certainly capable of spying on the owners of the infected computers,
