Attacks/Breaches
7/22/2013
12:52 PM
50%
50%

Network Solutions Recovers After DDoS Attack

Customers still report ongoing outages in wake of last week's attacks.

9 Android Apps To Improve Security, Privacy
9 Android Apps To Improve Security, Privacy
(click image for larger view)
Network Solutions said it's fully mitigated a distributed denial of service (DDoS) attack that compromised some services last week, and that attack volumes against the company had returned to normal.

"We experience DDoS attacks almost daily, but our automatic mitigation protocols usually handle the attacks without any impact to our customers," said John Herbkersman, a spokesman for Network Solutions' parent company, Web.com, via email. Network Solutions manages more than more than 6.6 million domains, provides hosting services, registers domain names and also sells SSL certificates, among other services.

But Monday, some customers reported still experiencing domain name server (DNS) and website updating difficulties that dated to the start of the DDoS attacks. The company, however, disputed those claims. "Some customers may be experiencing issues, but they are not related to last week's DDoS attack," said Herbkersman.

[ Are distributed denial of service -- DDOS -- attacks increasing? Read DDoS Attack Bandwidth Jumps 718%. ]

The DDoS attacks began last week, with Network Solutions at first reporting that "some Network Solutions hosting customers are reporting latency issues," according to a "notice to customers who are experiencing hosting issues" posted to the company's website on Tuesday, July 16. "Our technology team is aware of the problem, and they're working to resolve it as quickly as possible. Thank you for your patience," it said.

As the week continued, the company posted updates via Twitter and to its Facebook page. By Wednesday, it said that the outages were due to a DDoS attack "that is impacting our customers as well as the Network Solutions site." It said that the company's technology staff were "working to mitigate the situation."

Later on Wednesday the company declared via Twitter: "The recent DDOS attack affecting customers has now been mitigated. Customer websites should be resolving normally. Thanks for your patience."

The Network Solutions website wasn't available or updateable for the duration of the attacks. But that wasn't apparent to all customers, who might not have turned to Facebook and Twitter seeking updates about the company's service availability. One InformationWeek reader, who emailed Friday, accused Network Solutions of being less than forthcoming about the fact that the outages were being caused by a DDoS attack, "which they acknowledged only when calling them," after he found only the "notice to customers who are experiencing hosting issues" post on the company's site. "They have been trying to bury it," he alleged. "Some sites were down for the entire day."

Herbkersman brushed off the criticism. "In addition to Facebook, we communicated via the Network Solutions' website and via Twitter," he said. "We also responded directly to customers who called our customer service team and those who contacted us via social media channels."

Friday, the company did publish a fuller accounting of the outage to its website. "Earlier this week, Network Solutions experienced a distributed denial of service (DDoS) attack on its servers that affected our customers. The Network Solutions technology team quickly identified the issue and implemented measures to mitigate the attack," read a statement posted to the company's site and cross-referenced on its Facebook page. "We apologize to our customers who were impacted."

"Are we getting refunded some money because of your 99.99% uptime guarantee?" responded one member via Facebook. "Feel free to call our support team and they will be happy to discuss," came a reply from Network Solutions.

Customers might have had to contend with more than just the DDoS attack. A Tuesday Facebook post -- since deleted, which the company said it made to help direct customers to more recent information about the DDoS-driven outages -- drew comments from customers reporting DNS issues. "There were multiple reports on the July 16, 2013 Facebook thread that appear to indicate customer DNS records were corrupted before the DDoS induced outage," Craig Williams, a technical leader in the Cisco Systems threat research group, said in a blog post.

The one-two punch of domain name resolution difficulties and a DDoS attack could have left numerous sites inaccessible not just during the attack, but in subsequent days, as the company attempted to identify the extent of the damage and make repairs in subsequent days.

Last week's DDoS attack was the second such attack for Network Solutions customers in less than a month. "In [the] previous outage, domain name servers were redirected away from their proper IP addresses," said Williams. In that case, however, at least some of the DNS issues appeared to be "a result of a server misconfiguration while Network Solutions was attempting to mitigate a DDoS attack." Herbkersman, the Web.com spokesman, said last week's outages were entirely driven by the DDoS attacks, rather than the company's response to those attacks.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
squingynaut
50%
50%
squingynaut,
User Rank: Apprentice
7/24/2013 | 8:02:34 PM
re: Network Solutions Recovers After DDoS Attack
As a customer of Network Solutions or another company, is there anything we can do to mitigate the effects of DDoS attacks like these? Or are we at the mercy of the systems put in place by our domain registrars?
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.