The Mexican Congress and founder of the Foundation for Peace and Democracy, Emelio Betances, director of the Latin American Studies Department of Gettysburg College, and many others. That's Our Americas, a special edition, Friday, September 27th, from 3 to 6 p.m., only on WBAI 99.5 FM. This is WBAI in New York. It's time for Off the Hook. ALARM BLARES BADLY BEAT THEME SONG The telephone keeps ringing So I ripped it off the wall I cut myself off shaving Now I can't make a call It couldn't get much worse But if they could, they would Bondedly bond for the best, expect the worst I hope that's understood Bondedly bond! And a very good evening to everybody. The program is off the hook. This is Emanuel Goldstein with you for the next hour talking about high technology and the world of hackers. FiberOptic is here this week. Yes, I am. How you doing? How are you? I'm pretty good, pretty good. I just checked out this article in this week's Newsweek. You see this one? How to thwart a national panics attack? Wow. Boy, I imagine some people have been hearing about this over the past couple of weeks. We've been too preoccupied with the Bernie S. case to devote the attention that we should devote to this. This week we will be doing that. We'll be speaking with someone from panics a little later on in the program. But you may have heard about this. The panics internet site, panics.com, was the, I guess, recipient of a massive attack known as a sin flood. Not S-I-N, you fundamentalists out there. S-Y-N. It's a whole different kind of sin. And it's probably worse than the kind that you're always preaching about. Because this, this kind of sin attack can render the internet completely and utterly useless. Helpless. You know, just completely broken. We broke the internet. Because I say we, because in 2600 we printed a story that had to do with a sin flood. But we weren't the only ones. We weren't the only ones. There were other magazines too. Let me read the article from Newsweek and then we'll explain just what exactly is going on and hopefully we'll be able to figure this out. It wasn't one of the much dreaded brownouts on the overloaded information highway. What are the much dreaded brownouts of the information highway? I would assume when a router's screwed up and you can't reach somewhere. Well, you know, it's funny. They call it the information highway now. It's not the super highway anymore. Well, they probably realize it's not such a big deal anymore. I guess so. Maybe it's a different highway. Anyway, nor was it the result of a software glitch or the horrible hair virus. Which you notice on TV they were saying again that you're going to be hit by this virus. It didn't get you last month. It'll get you this month. And it didn't get anybody this month either. If you thought Michelangelo was bad. Yeah. I mean, these viruses aren't really hitting as well as the media hopes they will. Maybe one day. Maybe we should just make a virus so that they'll be happy. Yeah, for sweeps week. That's right. A little present from the hackers. When Public Access Networks Corporation, which is what Panic's, not Stanton, Panic's stands for. Yeah. Panic's stands for. Okay, yeah. I thought I got it backwards. A small internet service provider in New York went down for nearly a week. It turned out to be the unwholesome handiwork of a saboteur. The unknown culprit or culprits jammed the system by sending 150 requests a second to the Panic's computers seeking to establish a connection. But each request contained a fake internet return address that threw the computers into catatonic chaos. Into catatonia. I understand that's outside of Atlanta. Anyway, thanks to FRAC and 2600, two publications catering to the computer underground that recently published recipes for this particular type of sabotage, dozens of other places on the net were hit. This was an attack on all of us says the CEO of one anonymous internet service provider on the West Coast. I don't know why you wouldn't want to be identified. Netcom? I don't know. Who could it be? Could be Netcom. These things always seem to get traced back to Netcom in the end anyway. He claims that almost all major ISPs have been affected. Those who claim otherwise, he adds, are lying or lucky. Launcher systems were only slowed down so they weren't forced to go public. What does that mean? Launcher systems were only slowed down so they weren't forced to go public. I know what he's trying to say. He's trying to say that they weren't forced to confess that they were attacked because they were only slowed down. It's kind of a weird way of saying it. There's no simple defense against the sabotage. The easiest solution would be for all internet access companies to filter their outgoing traffic to make sure the data have legitimate return addresses. Late last week, the Computer Emergency Response Team at Carnegie Mellon University's Software Engineering Institute issued just that recommendation, but it could take months for companies to take the necessary technical steps. No files have been destroyed, and the attacks so far have caused little more than inconvenience still. If companies are slow to respond, large pockets of the internet could be brought to a standstill. Well, Fiber, is this an exaggeration? Um, yes and no. The, uh, yes in the way that they make it sound like it's the end of the world, but, uh, no in the way that, um, people aren't completely defenseless against it. Although it is a major problem. What exactly is it that's going on? What is a SYN flood? Okay, basically a SYN flood, a SYN attack, a SYN storm, whatever you want to call it, is, um, essentially the way a, uh, TCP connection gets opened. That's, um, the, uh, transmission or transport control protocol that runs, um, on top of the internet protocol. The way that, um, a TCP connection is actually opened is, um, say, for example, you want to connect to me. I'm a host, and you're somebody out on the net. Okay. What you do is that you send me a SYN packet, and a SYN packet is basically a message saying, you know, hi, um, so-and-so, and I want to connect to you on such-and-such address on such-and-such a port. So you're synchronizing. Yeah, that's what SYN stands for, as a matter of fact. Ah, okay, fine. And now what I do normally is, um, I accept a connection in my queue, and I say, okay, I'm going to acknowledge the fact that I received your SYN, and I'm going to send you back what's known as a SYNACK. And, um... An acknowledgment. Right, a SYN acknowledgment. Got it. And now what you do after you receive the SYN acknowledgment is you simply send an ACK, and then we start talking. An ACK of your ACK? An ACK to my SYNACK. Okay. So it's like a three-way handshake. So I'm acknowledging that you acknowledged me. That I acknowledged, exactly. Okay, but you don't acknowledge the fact that I acknowledged that. It stops somewhere. No, that... No, actually, after that point, the connection is open. Okay. But then if either end sends a packet to the other, each one of those is ACKed. Okay, I understand. Okay. Because the way TCP works, it's meant for full-duplex connection, or it's called a connection-oriented connection. Mm-hmm. That is, both sides of the connection on the net, the person, the client, and the host, or the server, are sentient of each other while this is actually happening. Okay, so now, forgetting the weird return addresses that took place in this particular attack... Well, that's the key. That is the key, but I just want to... The SYN attack itself, let's just focus on how somebody would do a denial of service... Right. ...using this. It's got something to do with the number of requests in a certain amount of time? It's not so much the time as it is the number. Like, for example, even somebody with the slowest modem is gonna usually be able to do a successful SYN attack. And the way it works, and one of the ways that an administrator can defend against it, is the accept queue for a particular TCP service. Like, let's just say, for example, Telnet. Okay? The Telnet daemon, which runs as a service of the Internet daemon, which runs on, let's say, for example, a Unix machine. Okay? Going deeper, delving deeper than, like, the actual Telnet service. The Telnet service runs on port 23 on the host or the server. Okay? But as far as the actual operating system kernel is concerned, it can only accept eight simultaneous connections at once. By simultaneous, you don't mean eight Telnet sessions. You mean at that very second. At that very moment, it could accept eight levels deep, eight connections coming in. All right, what is that very moment defined as? That very moment is a millisecond? Is it one second? What is it? You could deal in terms of milliseconds, seconds, whatever you want to call it. You could call it jiffies if you want to. Right, but is it definable by the administrator or is it just something in the... No, the time isn't really the issue. The way that an administrator could get around it is simply by increasing the size of that queue. You could make it 100 if you wanted to and you can get around that problem because a lot of the programs floating around out there only send eight at a time because they know that the ninth one is going to flood the queue. Well, let's say you made it a million. What would happen? You'd slow down everything if somebody was sin flooding you? Well, you couldn't because there's no upper limit that you could set it to. Let's say you could, though. Okay, in theory, let's say you could set it to a really, really high number, the number of simultaneous connections you could receive. Well, number one, you probably wouldn't have enough memory to do something like that, but let's just say you could. Essentially, what would happen is the person would be sending eight at a time and you're hoping that there's going to be some break-even point between the number of connections you can accept and the number of connections you can reject, so that eventually, your side is going to time out a lot of those connections early on. So, it'll sort of have this cyclical effect, is that the connections that came in earliest on, your machine is going to time those out and those spaces in the queue will now be available again, while the most recent connection attempts will still be hung with your machine trying to acknowledge them. That's where your machine actually gets hung. It tries to acknowledge the packets that are in the SYN packets from an invalid source address. Okay. Now, one of the things that, well, a lot of the attacks in the past have been really simple. Somebody will write a program that it'll just pick an invalid address and it'll just use that one address and all somebody has to do if they notice this is happening is simply block that one address in their router and everything's fine, but in the case of Panix's attack, the problem was whatever program was being run randomized through a whole series of invalid source addresses, so it was extremely difficult to block. Now, the problem with the proposed solution in that article that you read is everybody's looking to the service providers to do something about it. That'll only be of limited success. The problem is going to be you can't always verify with 100% certainty that a particular source address is valid because it might be behind a firewall and so on and so forth, so I mean that's not 100% of a solution, although it would certainly help. Well, it sounds also like a way of... Passing the buck. And also kind of making illegal almost any sort of anonymity, you know, if you try to like fake your mail somehow all of a sudden that won't be allowed, you can't be anonymous, you have to be anonymous. I wouldn't go that far, I mean as it stands, even if they do take steps like that you'll still be able to forge packets, I mean you could forge a packet from a real address and a machine will simply acknowledge that it came from a real address but the packet is still forged. That's what happened last year with the Shimomori incident, correct? Yeah, a packet which was forged from a trusted host, it was a real host, and it was flooded. Right, that was a sin flood? It could have been a sin flood but more specifically it was probably just a flood in general that just slowed the machine down so it couldn't answer. All right, so basically what this means to people out there that aren't administrators is that when they try to reach a certain machine, in this case it was Panix, it won't be available, they won't be able to use mail, if mail is being attacked they won't be able to get to the machine. Right, but getting to that point, I mean lots of times you're going through a connection, like an R-login connection of some sort, when you call in, so if that particular port is being attacked, you won't get anywhere, you'll just call in and you'll be stranded. Usually what happens is a lot of the programs I've seen floating around, they target port 23 which is a Telnet daemon, port 25, send mail, and often times port 80 in case there's a web server, and those are the most common ones. Right, but they could target anything else. Yeah, they could pick any port they want to. Well now, I said, if you want to say move your Telnet daemon from port 23 to say port 800, would that somehow be effective in combating this? That would help you as the administrator, in fact, I'd say it would help you as the Telnet daemon. If they're an administrator of a system out there, you can modify your inetd.com file, and also your etsy services file, to simply start another Telnet daemon on a different port that you just made up out of your head that only you know, or obviously anybody who's on the machine might have read in the file. Do the remote you're a system administrator, and you're currently offsite, and you're trying to Telnet into your site remotely, you can't get in, it just hangs, you don't know what the problem is, or you get a connection refused. So what you want to do is you suspect foul play, so you want to try your backup Telnet port, so you Telnet to this port, say, 6789, that you know that you set up a Telnet daemon to run on, and only you know one of the people that have done a port scan might know about it. But, you know, you can take as many countermeasures as you want to, but you're going to hope that you're going to be able to get in somehow. What I'm wondering is, supposing you had some sort of randomization going on that changes your Telnet port every couple of seconds, would something like that conceivable? Because they wouldn't be able to sin flood the right one consistently. Maybe for a few seconds, and you'd If you have some program running on your end remotely that's in sync with the server, that's going to be changing it at whatever interval it is. But as far as, in a case like Panix with legitimate users that are expecting the Telnet into a well-known service, they're not going to be able to reach that well-known service, Telnet or RLogin. And they're not going to know that they can say Telnet with a different port number after the address. Right. So they would have to know that. They'd have to say the port number. Right. But again, like you say, I mean, if it's something where, if they're not changing it on a regular basis, it's a relatively trivial task to just do a port scan. I guess the other question is why? Why would somebody do something like this? Why pick Panix? I guess these are questions to ask when we have someone from Panix on the line. Yeah. But it seems kind of strange that somebody would just target one site. Well, it's not really strange. And you don't really know Panix was the only one targeted. All you know is that Panix was the most vocal about it. Only a few months ago, another internet service provider in Manhattan was also targeted. And fortunately, it was a relatively simple attack. And I was able to instruct them on how to block the actual SYN flooding in their router because it was coming from, it wasn't, they weren't randomizing source addresses, whoever was doing it. So it was relatively easy to stop. It was easy to find out where it was coming from. No, there's no way that you could find out where a SYN flood is coming from. You could tell relativistically how far away it is. But even then, you're guessing. By how far away, I mean how many hops away it is. Because that is preserved in the packet. But I mean, even if someone's, like for example, say I work at a particular company. And our internet service provider is UUNet. And yours is also UUNet. We might be only three hops away from each other. And normally, the hop count starts at 255 and counts backwards. So we would end up at, say, 255, 254, 253. Say if I saw the hop count was 252, I knew that there's a fairly good chance that we're on the same network and we're probably local. But it's still a shot in the dark. You might want to try calling your service provider and see if the people at the network operations center can find this flood of traffic coming from some source and pinpoint it. But if it's numerous hops away, it could be anywhere in the country or anywhere in the world. So when do you think this is going to end? It's really hard to say. I mean, there's no real mechanism right now that exists in routers that are commonplace and use on the internet that can detect or stop something like that. I mean, the detection part right now really has to be done by a human, an administrator. And stopping it can be relatively easy all the way up to difficult or nearly impossible. In the case of panics where the source address is being randomized, the only two things I could imagine you could really do is increase the size of the accept queue much higher than eight simultaneous incoming connections. And the other thing is if you can notice some kind of pattern, then you might block an entire class of addresses at least until the person gets bored and goes away. Like, for example, if you notice that the floods are always coming from fake addresses at universities or they always begin with 128, I mean, you can block all addresses from 128. But then again, you might block a legitimate customer. So it gets really difficult if you're running a public access site. Now, do you think it's something that we should keep quiet as far as being specific as to how it works? Like, should we have printed that article? Should Frack have printed that article? No, I don't think being quiet about it is going to contribute to it being fixed, certainly not. I think that as many people about it as possible should be informed. The only way you're really going to have a solution is if you put enough of a scare in the router manufacturers to come up with some kind of scheme or mechanism that could detect and control that kind of attack. It's always been possible. That kind of attack has been present in the internet protocol since it came about in the 70s. So the fact that it's only becoming commonplace now doesn't really surprise me. It's sort of like, eventually, the deep, dark secrets of the internet protocol trickle down to the masses or the miscreants that hang out on IRC. Yes, and we know what happens when they get a hold of it. Yep. All right, well, that's an interesting topic, something that I think we'll be seeing a lot more of in the future, hopefully some solutions. We're supposed to hear from Alexis over at Panix within the next 10 minutes or so, but I guess we can take phone calls in the interim. 212-279-3400 is our telephone number. Anything else interesting happen to you in the world of communications or computers this past week or couple of weeks? Well, one thing I could say without going into too many details is there is definitely a change in attitude that I'm seeing firsthand amongst various corporations in approaching hackers that have a good security background. In the last week? Well, it's sort of come to a, I don't know, it's. You've seen it firsthand. Yeah, it's a snowballing effect that I think is. So this changing attitude means what? That they're accepting us for what we are or more afraid of us than ever? What? No, I think, well, obviously, you're always going to have corporations that are afraid, but I think that more and more corporations are turning on to the fact that hackers can and are a valuable resource to improving computer security and that they can no longer rely upon all the computer security people running around, which I know we've pointed out lots of times in the past. A lot of them are just like the anti-virus software authors that are promising the world and aren't really dealing with the facts. Well, these computer security people must not be too happy about that change in attitude. No, unless these computer security people happen to be working with the hackers firsthand, which some are. That's good. Wow, I've noticed a couple of things phone-wise. I don't want to be too generous here, but I have to say 9x seems to be getting better, a little bit. Not a lot. All the phones are still broken. They don't work. But apart from that, they seem to be, I don't know, fixing things a little bit more. Really? For instance, our ISDN now works. It works perfectly on 56k, which it never did before. All of a sudden, it just works. It's like they listened. It took them a year to do something, but they listened. The payphone I wanted to fix, they fixed. It was only one payphone, but they fixed it. It took about 14 calls, but they listened. I think it's just a question of who is stronger, the consumer or the corporation. I think if the consumer is willing to really become a pain in the ass about it and make lots of phone calls, it'll eventually get done. I'm just starting to wonder if there is a cause and effect. I think there might be, but it's still very hard to get things done. I got this huge rebate. Actually, I got several huge rebates on my phone bills. Some sort of rebate over a year and a half for missed appointments. Now, they're always missing appointments. They're always saying they're gonna be there between the hours of nine and five, Monday through Friday, whatever. They try to narrow it down as much as possible. Then they don't show up, and you call and complain about that. Well, apparently something happened, and they had to refund all this money for a year and a half. I was getting rebates of $150. Wow. Yeah, that's a lot of missed appointments. Too bad it wasn't Domino's Pizza. No, actually, I wouldn't want a rebate from them. But I just think they're being held accountable, and I think that's a good thing when you hold someone accountable for their mistakes or inappropriate actions. Well, probably the FCC or the Public Service Commission that held them accountable. Yeah, and we hold them accountable. They won't do anything unless we're constantly pestering them. So I just think that we've seen over the last couple of weeks a lot of public pressure on various issues, and we've seen it work. So what I'm trying to say is that I think it does work. It doesn't feel like it works, but over time, I think it does. You know something I noticed yesterday? I was heading down to Philadelphia, and I had to make a phone call there, and all the 9-5-0s seem to be blocked now. That's a bad thing when 9X is done. For some reason, they're always pay phones uptown, all beginning with the 223 exchange, all right, somewhere in Midtown. You can't dial 9-5-0 from there. You get a recording saying your call can't be completed as dialed. I don't know if that's a new thing, but it was always like that. But I had to make a regular phone call. You know, I couldn't use a calling card because I didn't have one on me. You know, I didn't have a calling card. I hadn't mugged any old ladies lately. You know, I didn't have any means of making a phone call, and I left all my calling cards at home. So I had to actually dial 1-plus and see how much it costs, and I was in New Jersey, right? I was calling down to Philadelphia in New Jersey. It cost $2.95 just to connect, just to connect. Just to connect. Yeah. And then it's like, I know within the city, it's like $0.25 for two minutes now. Yeah, but that's $0.25. All right, that's bad, but you know, I can deal with that. But $2, how can a phone call? I mean, AT&T announces today that they're going to charge $0.15 a minute, 24 hours a day for residential customers, you know, to make their lives easier. You know, you don't have to worry about nighttime discounts and, you know, $0.10 a minute to God knows where, you know, and all that kind of thing. $0.15 a minute all the time. You know, nice and simple. How come a payphone costs $2.95 just to make the connection? I don't get it. You know, and no one can seem to explain that to me. No wonder people are using red boxes. It's the only way to make a phone call. No one in their right mind would put $3 worth of quarters into a payphone just to connect. And you know what else they do? When you connect and you talk to somebody for, I guess it's like three minutes. I think that's what you get, three minutes. You used to get, you know, all the money would go into the hopper. Right. And that would be your warning that, you know, you're now in overtime. You know, you're sudden death overtime. You're going to get some sort of a warning at some point and operators will be calling you and chasing you and things like that. Well, that doesn't happen anymore. Now you get a recording that all the money goes in and you instantly get a recording demanding money and you don't get reconnected to your party. You don't get the chance to say goodbye. You don't get any more. Even a cold card gives you more warning than that. It just, all the money goes down and it says, $0.50 please, you know, some arbitrary figure. For the next 10 seconds, $0.50, you know, whatever. And you have to come up with the money there or you don't talk to your friend anymore. What happened to me, this is kind of funny, the operator comes on after a while, the AT&T operator comes on and says, you know, where's the money? I was very upset at this point. I said, you cut me off with absolutely no warning. You know, I mean, that's not very nice. And she said, oh no, we didn't cut you off. Your party is still there. You just can't hear him. So I said, well, could you just reconnect me for a second so I could say goodbye? And she did, you know, I was able to say goodbye. But I mean, I don't know what he was hearing during that whole time. You know, if he was hearing me talking and cussing into the phone because I couldn't hear him, it's a bizarre way of doing business, you know, just sort of a ransom, you know, you have to pay right now or that's it. You're not gonna hear from your friend anymore. $2.95, I mean, where do they come up with figures like this? I don't know. So yeah, that's something I think we should hold long distance companies accountable for. You know, if you're local, yeah, it's a quarter. And if you're across the state line, it's $2.95. It doesn't make any sense. Well, soon, I figure it's probably gonna be a quarter for a minute or something. Used to be a quarter for five minutes. That's 10 cents up in Massachusetts, you know. Oh, really? 10 cents at a payphone still. Yeah. I don't understand. I mean, I know they have a lower quality of life up there, but it's not 150% lower. Yeah. You know, I don't understand why they get such a big discount. So I'll be pushing to get them increased. No, actually, I want them to account for their prices. Yeah. It's kind of insane. All right, 212-279-3400 is our telephone number. If you have anything to contribute as far as telephones or the internet or hacking or whatnot, give us a call. 212-279-3400. Good evening. You're on Off The Hook. Yes, Emanuel. Hi, I have something to contribute on telephones. Wait a minute, wait a minute, wait a minute. Wait, wait, wait, wait, wait. That is the voice, if I'm not mistaken, of Rebel. But I just saw Rebel in the studio. So how is it that you're on the phone too? It's my magical touch here. Anyway. I can't escape this guy. Okay, yeah, go ahead. Go ahead. Did you know that when you dial 10-69-8-0 from most areas in Queens and Manhattan, you get, not 9x operator, AT&T? You do. Okay, you get AT&T, let's hear this out. All right, let's hear this out. Okay, let's try this out. People putting guns to their heads. No, let's like, you know, let this play out for a second. Well, before you pull the trigger. Yeah, 10-69-8-0, you will get AT&T. That's right. Okay. Why would we care? I mean, explain. Why would we care? Because actually, it was happening in Queens and I thought that it was only happening in my exchange because it didn't happen in another part of Queens. So I told the phone company this and of course it never got fixed. And then I recently discovered that it's happening in Manhattan. You don't say. Yeah, try it. All right, but let's say it works. Is there any significance to this other than the fact that- Well, there is, because let's say that, well, first of all, 10-69-8-0, you're supposed to get 9X. That's the point of that. Well, 6-9-8 spells NYT, New York Telephone. That would be 9X. But second of all, the reason why I discovered it is because I was on a call card and I had to dial a 9X operator because when I dialed zero, it connected me with a strange long distance company. So I dialed 10-69-8-0 and I got AT&T. Okay. Is there any advantage to this or disadvantage to this? Not really, but the other thing is is that if you dial 10-216-0, the area code and number, which would be zero, a local area code and number from any pay phone, it'll put the call through for free, believe it or not. And this sometimes works, this sometimes doesn't. Then you try this from pay phones. Right. All right. Well, we're probably fairly certain that now it definitely doesn't work anymore because millions of people are trying it right now. Yeah, you're probably getting all circuits busy recording if you try now, but try later and it might just go through. Well, dial the 6-9-8-0 thing. No, I believe, I've heard you talking about this for a number of, well, it seems like forever actually, but it's been a while. And I remember you saying at one point that you were able to actually get the network to ask you for money from your house. Right, that's the other thing. How did you do that? Well, it wasn't from my house. What happened was is that as I told them, the person in the, what's known as the, I guess, MAC Center, which is the, I guess, Fiber, you can explain what a MAC Center is. MAC as in M-A-C? Right, I think it's a control center. It's a major account center. Okay, okay, I was referred there. Well, you are a major account. I seem to be. They told me, okay, we'll fix it. They fixed it for a while, but then it sort of malfunctioned and now, and when you dialed that way, it connected you with Coin Operator. And the other thing is is that if you dial from any, most of the pay phones uptown, actually, a lot of pay phones in Manhattan, 10, like 222 or 333, like 10, any other carrier access code but AT&T, plus I think it's either 1E, long-distance area code number, or 0, the long-distance area code number, you will get Coin Operator. Okay, and where is Coin Operator located? That's what I want to know. I said, what company is this? And they said, well, we represent a lot of companies. I want to see if they, I mean, I'm sure you could Redbox with this company. Interesting, now, you only get this from pay phones or can you get this from any phone? You can only get this from pay phones, unfortunately. And, believe it or not, it works on a co-cut. Well, okay, a co-cut that allows carrier access codes. Right. All right. Well, you know what? We're gonna try your 10698 for you. I'll be updating this on my webpage if anyone wants to see these updates, please. Do you have a webpage? What could that address be? It would be www.escape.com. That's E-S-C-A-P-E.com slash tilde rebel, R-E-B-E-L. And if anyone wants to send me email, they can email rebel at escape.com. Okay, all right, fine, great. Now, we're gonna check that out. Thanks very much for the input there. Fiverr, you have any comment on that? Just a little comment that if 106980 doesn't get you anywhere, you'd probably have better luck reaching 9X by calling their 800 number, that new 549X. 549X, whatever that's all about. Yeah. But let's see if we can actually get a dial tone. That would be nice. I guess we can't do that there. There's one, okay. Now, we're gonna dial 10698, and then zero. See what kind of operator we get, if we get any operator whatsoever. AT&T, to place a call, please dial the number that you are calling. Well, that sounds like AT&T to me. Yeah, it does. So, why is AT&T showing up on 10698? I don't know, but I'd be suspicious, because obviously you're supposed to be able to use 10698 to call 201, area code, northern Jersey. Well, do you think 9X has signed some sort of an agreement with AT&T to handle, 9X is gonna be going into the long distance market pretty soon. Right. So, I don't know why they would give away their carrier access code to AT&T. I don't know, but that would be weird, because that would kind of violate the ladder boundaries, and you don't wanna do that, because then there'll be chaos and mayhem with it. That's right. Well, I think there's only one thing we can do, and that is, confuse the operator. Yeah, we're gonna have to ask the operator what this means when we call, we're gonna have to ask the operator what this means when we call a carrier access code and get them. They're not supposed to be there. So, why are we getting them? Let us connect one more time to 106980, and we will ask just, what's going on? First, we have to get a dial tone, though. There we go. Okay, in a moment, we will, oh, that sounded weird. We will have AT&T on the line. AT&T, to place a call, please dial the number that you are calling. For other requests, please say information, credit, or operator. What if you don't say any of that? What if I say operator? Cool. Oh, okay. I don't know. AT&T. Whoa, that's loud. Por favor, marque el codigo de área y el numero al cual está llamando. This hurts. Para llamadas internacionales, marque 01. Spanish is double the volume of... Please, please help. Help. Well, we just need help, that's all. Okay, okay. I don't know what's going on at this point. Dial zero. Dial zero? Okay. Dialed zero. There is butthead in that language, is there in English? Uh-oh. Yes, do you speak English? Yes. Hi, I dialed 10698. Am I supposed to get AT&T when I dial that carrier access code? 10698? Yes. No. Did you say anything? Well, I might have said something, but I don't think I said anything. I just went into the Spanish part by accident. Okay, yeah, see the machine picked up on an accident or something and just transferred you over to Spanish. Wow, that doesn't sound like a Spanish accent you have. What part of the country am I in? Texas. Ah, Texas, okay. Well, I don't wanna run up the bill, but I'm just curious if Y10698, which used to get me 9X, now gets me AT&T, if there's some sort of a deal going on there. No. You wanna hang up and try again? Maybe I'll do that. Maybe it'll work different if I try that. Thank you very much. Uh-huh, bye. All right, that always seems to be the answer that they give, hang up and try again. All right, well, we confused them. I think we have Alexis from Panix on the line, do we? Yes, we do. I don't know how that happened, how we got you on the line just now, but we did it. And well, we were just talking about the whole Panix thing a little while ago. And can you hear me? Yes, I can. Can you hear me? Yes, we can hear you just fine. We got fiber optic here. Excellent. Hi, Mark. Hi, how are you? I guess basically right now, we'd like to find out what's going on with you guys. We talked about the attack, the theory behind the attack a little bit, but have you guys survived? Yeah, we have. Touch and go for the first couple of days. We sort of got lucky. There was a routing glitch inside of Sprint that we had nothing to do with at Sprint 6, but for its duration, which was about eight hours, we were immune to these hacks simply because packets are getting lost out in the ether. So that helped us out. And then on Sunday, I was able to do a little kernel hack to discard all of the attackers' packets because the attacker carelessly left the same TCP sequence number on every packet. So that was an easy hack I could do to get rid of them. There was another day, part of Monday, where we were attacked fairly badly and there was not much we could do about it at that point. But later, late that night, I did a more significant kernel hack that was able to protect us and has continued to protect us until now. But the bad thing is that this hack is not really a true solution. It's a combination of lack of clue on the part of the attacker and lack of bandwidth and a bunch of other things. Any determined and clever attacker could still take us down or take anybody else down in the entire net, for that matter. Well, what kind of response have you gotten since making this public? From who are you asking? From computer security people, from media? Well, let's see. I mean, just bit by bit, let's see. First of all, the customers, the ones who we've heard from have been extraordinarily supportive, which is really nice. But you have to assume that there's gonna be that silent group that just says, oh, the hell with this. We don't need this. We'll go somewhere else. Not really understanding that it could easily follow them no matter where they go. Then there is the computer security groups, the various people who are professionally interested in this. They've been very interested in it. We've had high-level conference calls with numerous people about this. Pretty much the entire industry where the industry is involved with this is now working on various solutions. We've got a couple of notions, one of which we think is gonna be a pretty good guard against this. The problem is that it's only gonna be useful on some machines, mostly the more heavily supported Unix systems, like Consons or HPs or IBM, that sort of thing, or digital, whatever. It's really not gonna help people with less popular boxes. It'll also take a long time, I think, for it to migrate down into the public domain systems like Linux and NetBSD, although, actually, my understanding is that it works underway on them, too. I think that in the next month, you'll see a lot of Unixes become immune or almost immune to this kind of attack, but you're gonna see all these special-purpose boxes that are very important to the functioning of the internet as a whole, the routers, the terminal servers, the special-purpose dial-up boxes. They'll all stay subject to this sort of attack, and there won't be any quick and ready fix for it, so that's a great concern. The only long-term solution to this problem, I think, is going to be to, sorry, is going to be to have all the service providers out there cooperate and prevent this attack at its source. It's kind of a funny situation where if I'm a service provider and my customer is attacking you, I can protect you, but you can't protect yourself, and if you have a customer who's attacking me, you can protect me, but I can't, so everybody has to cooperate, and if they do, they'll be able to protect each other very well, but if even only a few people don't cooperate, the entire NIST stays open to attack. And are you even able to tell what people are not cooperating, or you just know that somebody out there isn't cooperating? Well, at the point where we get people cooperating, it will be easier to trace the attacks back. I mean, we know how to trace the attack back. It's just a very difficult project because it involves a lot of work on the part of every organization through which an attacking package travels, and a package getting to me from the attacker could travel through six different organizations. It could go to Sprint and to ANS and to UUNet and to BBN before it gets to us, and doing so and doing it while the attack is still underway, that's difficult, especially if the attacks are short-lived. There are possibly one or two other techniques that we have thought of that might actually help us catch the attacker, which are a lot trickier and which I don't really want to go into on the air, but in general, yes, it will be possible to trace them, and the more that the providers take this seriously, which will be evident, it'll be evident that they do when they actually start cooperating in this way, then the easier it will be to trace the attacks back quickly and deal with them. I think that we've gotten a lot of attention in the last couple of weeks. I mean, certainly I haven't enjoyed plastering our names all over the national media in attachment with this incident, but if it accomplishes our goal of making all the providers really aware of this as a major problem, then it will have been worth it. Do you think there's other sites out there that are being attacked? I know for a fact that there are many other sites being attacked. It's amazing to me that, you know, when we first went public with this, nobody had really talked about it all out. When we talked to CERT, they said, oh, yeah, well, we've heard about maybe a couple dozen trickle attacks, but this is the first flood. But since we went public with this, I've gotten private calls and mail from people. Dozens of sites have been attacked before we were, who had not spoken to anybody at all, and since then, there have been even more. One of them called us and said, help, what do we do? And I said, well, look, here's what I know how to do so far. Here are the other things that you'll be able to do soon if, you know, when your UNIX vendor provides this support. And in the meantime, do the right thing and go public. And they did. And, you know, the more that that happens, the more people become aware. In that case, it was the Internet Chefs, or our folks, Dan Flaherty and his crowd. And I just wish that more people would admit it when they got hit, because it would provide everybody else with more awareness of the problem and, you know, perhaps a quicker response to it. Yeah, that's one thing I've always said about panics is that you're extremely accountable if you have a power flicker, there's a message of the day about it 10 minutes later. Yeah, we try. I mean, it really aggravates me that for the second time in three or four years, we're at the forefront of a major, major Internet attack. And we're there only by default because nobody else is willing to talk about it. But it's, you know, it's what we gotta do. We gotta talk about it. We can't just keep it quiet because, you know, we sort of conspiracy of silence by default. And if nobody spoke up, the Internet would have crumbled halfway, you know, to nothing before anybody even noticed that we were having such a major problem. What has the customer response been so far? Well, I mean, as I said, the customers who we've heard from have been really wonderfully supportive. I don't get very gushy as a rule, but I mean, it really made a difference. You know, spending, you know, a week straight getting almost no sleep working on this problem and trying to solve it and having such an incredibly difficult time. Having, you know, such really good support from our customers made a big difference. But, you know, also, as I said, for every one of those, there's gotta be a customer or two or five or 10 who just said, geez, the heck with this. You know, why do we need to stay with this site that's having problems? Many of them may not, you know, have paid attention or are not technically savvy enough to properly judge the accuracy of our words and just may think that, you know, we're just being incompetent. So, you know, who knows how much that's cost us? I mean, it can't be good. I know that three years from now, we're still gonna be hearing about this from people who don't really know the whole story and will just come, oh, yeah, isn't it panic? Aren't you those guys that had that big service problem three years ago and, you know, trying to explain to them what happened is gonna be a complete waste of time. Has the media, for the most part, gotten the story right? Compared to a lot of mangling of stories that I've seen in the past, I would say the media did very well on this. Of course, we tried very, very, very hard to get things right. I would say that mostly they did okay, especially considering that, you know, it's not, you know, the New York Times or Wall Street Journal writer's responsibility to write down all the technical details. You know, nobody wants to read that in the papers. The one thing that disturbed me was a lot of the reporters, especially the early ones, they all loved the same phrase, brought to its knees. And they all said we were brought to our knees for five days, which is completely bogus. I mean, we were, various different services, if you combine all their downtime together, we're down for about 36 hours over the space of five days. And we weren't almost put out of business. I think that phrase came from, you know, our original message of the day, which said that, you know, if an attack like this went on for a week, we could be out of business. It's not the way it happened. And we did figure out several defenses to it, one of which so far is holding two weeks later. And by the way, we are still getting attacked every day. What kind of person do you think is behind this? It's not really clear, although we have some substance. Oh, by the way, before I go on, I'd like to point out one writer who did, I thought, an especially extraordinarily good task. That was Elizabeth Corcoran of the Washington Post. She used to be a panelist before she moved. And we just thought that her story was so dead on, it was amazing. Which does not say that the other writers didn't do a good job, but that was one of the earlier articles and it really got everything just very well. In any event, to answer your question, while there's obviously no way for us to be sure, there is one good lead that we have, which is that in the first week of attacks, of all of the machines that we have at our site, we have a web machine which is for use for Panix itself and for Panix's individual customers who have homepages on it that they get there for free. And then we have close to a thousand corporate sites, customers that keep their entire site online on machines at our office. And of all of the customers who use that type of service, only one of them was attacked the same way that our own site was attacked. And that was a customer who gets all their service for free, the Voters' Telecom Watch. And my guess is that, first of all, for those who aren't aware, Voters' Telecom Watch is an organization which has been remarkably effective in focusing net support for the fight against the so-called Communications Decency Act, which is an outrageous and obviously unconstitutional piece of legislation, about which I think more has been said in the past and probably will be said in the future, so I won't go into that here. But they've been wonderful in fighting against that and also in fighting to eliminate the really unreasonable restrictions on export of cryptography, which, of course, already exists everywhere else in the world already. So they've done a lot of really good stuff, but they've made a lot of enemies on the right wing and in the irreligious right. Whether or not one of their enemies is behind the attack is only a matter of supposition, and whether or not that enemy is part of the religious right is also just a guess. It's not a guess I have a lot of confidence in, but it's the best theory I can come up with, because, as I said, of close to 1,000 corporate sites here, only VTWs was attacked. Were the packets similar in structure? The packets were guaranteed identical in structure to the ones that came from us because they were coming in at exactly the same time from the same forged address with the same forged sequence number. So it's very clear that the VTW attack and our attack were, in fact, not only from the same person, but were being generated by the same program at the same instant. Now, do you see just one attack happening a lot, or do you see different attacks? It's very clear that there are many different people running different types of code. For example, while this I am far from certain about, it seems likely, given the pattern of attack and the type and the contents of the packets involved, that the attacks we're facing now and which we've been undergoing for the last week are not, in fact, from the same person as originally attacked us. But again, that's not something I'm by any means confident about. It's just a guess. And I know that, certainly, that there are many other sites out there being attacked. You're seeing different types of patterns, different types of packet contents. We've seen a couple of really stupid attacks where all the attacks have the same bogus source IP address, which, when there's no such machine out there, works almost as well. But, of course, if they all have the same forged source address, you can just filter off everything from that source address, and it's not a problem. So the attacks have varied in cleverness and capability. You also see different volumes of packets from different types of attackers. Some people are obviously dialing in from a small modem connection. Others have a 56K or an ISDN. Interesting. Do you think that publicising this in 2600 and in FRAC has made the problem worse or brought something... Well, it's clearly brought the problem about and made it much, much, much worse than it was before. You'd never heard of these attacks before 2600 and FRAC published. On the other hand, it would have happened sooner or later. And, you know, had you not published the article, or had FRAC not published the article, the authors might well and probably, probably and certainly would have posted their code on the net anyway. So, you know, while I really, really wish it hadn't come out, I, you know, I don't particularly bear a grudge against you or FRAC about it because it would have happened sooner or later. I'm just wondering if this kind of thing had been publicised, say, three or four years ago, do you think we'd be in better shape now? Robert, you're nodding your head vigorously. Well, clearly we'd be in better shape now. It's not completely clear to me what would have happened. You know, one possible interpretation or scenario, I guess, is that, you know, in the old days, there were a lot more clueful people at the providers that were there because the total amount of clue on the internet has not grown or has grown slowly. But the total number of providers, even large providers, has mushroomed dramatically. And what that means is that while all the big providers still have really smart people working for them, there aren't very many of them and they're very, very hard to find. When we talk to the folks at, you know, certain large providers who are trying to trace the packets back through, even in the cases where they were very helpful and willing to help, most of the time we had to teach them what to do with their own equipment in order to help trace the packets back. Does that resemble your experience, the amount of clue on the net is going down? I'm not exactly... I didn't say it was going down. I said it was going up very slowly. But the number of total home number providers and people working in the business has grown so dramatically that the clue per person, on average, has diminished. Right. The percentage of clues is, I guess, not rising the way the number of users is. Exactly. Or the number of providers, which is really the point. Right. I mean, you can make up all sorts of funny acronyms and definitions of, you know, defining clue per square kilometer or clue per person or clue per provider. But I think the point is that it's harder to find good people quickly who can help detect the intruder and trace them back or detect the attacker and trace them back or her back. And that makes it easier for them to get away with it these days. On the other hand, you know, everybody has more balance. If we'd been attacked in the days when we only had a 56, it would have been a serious problem for us, not only because it was damaging our machine's ability to function, but also because there was so much data coming in the attack that it would have severely constrained our ability to do other stuff as well at the same time. And it's very different, you know, when the difference between, say, a provider with a T3 and a provider with a 56K. As time goes on, the capacity of your equipment grows. But, you know, then again, so does the capacity of your attacker. You know, maybe if it had happened three or four years ago, most attackers would have been coming in over 2,400 BPS modems. Also, you know, another aspect to that question is, you know, three or four years ago, there weren't a lot of people out there with, you know, Linux or NetBSD boxes or FreeBSD boxes who could easily execute this sort of attack. Having Unix boxes is a much trickier and more interesting proposition a few years ago. And actually knowing enough to modify the kernels to allow you to forge source addresses was, you know, even rarer. Have the authorities taken an interest in this? Yeah, but they, you know, they're counting on the people who are affected by this to really track down the bad guys. I guess that, you know, if we put the finger on somebody, they'll come and take them in handcuffs, but they're not going to chase them themselves. I mean, it's sort of unfortunate. It's the only business I know of like that. I mean, if you knocked over a bank, the FBI wouldn't tell the bank, well, when your bank tellers go and identify the guy, then we'll go and get him with handcuffs. No, they go and try to figure it out themselves. But realistically, there's no other option here, really. They don't have enough good people. I mean, there aren't enough good people to run the net there almost. Much less, you know, if half of them were off doing law enforcement. It's quite a story, and it's unfortunate that you have to be the focal point of it, but I think... Yeah, well, it is, but... Yeah, as far as an enlightened approach, though, I think you've definitely got that. I mean, imagine this happening to another, I don't want to give, you know, the names of the big companies, but you know who they are. If it happens to them, they're just going to deny it, and they're going to try to blame somebody else. So it probably is already happening to them. Do you think that's... We know for a fact that it is. I mean, we've seen, we know, I mean, much as I don't like it, I don't feel it's my place to deny somebody else anonymity, especially if they've told me about it in confidence. But for a fact that numerous providers have been attacked, including at least two in the New York area. Well, there's the Newsweek article, quotes an anonymous Internet service provider on the West Coast. You have to wonder, you know, why someone wants to stay anonymous for something like this. You know, they... I mean, I'll tell you why. Because when you go public, you suffer for it. Our business will suffer because we're talking about this. There's no question about it. We saw it happen three years ago with the sniffing attacks, and again, we publicized something that nobody on the Internet knew about, and half the people weren't willing to admit even once we had announced it. If we hadn't done it, you know, probably the large majority of those on the Internet right today would be compromised and owned by intruders. As it is, everybody understands that the sniffing attack is now, and mostly is protected, mostly because they're doing the sort of stuff that we actually wrote about in our advisory when this first happened. Right. But despite that, and despite the fact that we did the work and figured out the problem and let everybody know about it, we're still paying the price for talking about it. People still, you know, reporters come to me three years, three and a half years later, and say, oh, Panix, isn't that the site that had this big security hole? And, you know, I just smack my forehead and try and ignore it because there's nothing you can say. Well, Alexis, it's like, you know, not only are you an Internet service provider, but it seems like you're actually participating in the building of what the Net will eventually become. We're trying really hard. I mean, I have to say that, you know, we cannot take the majority of credit here, and I'm really glad to be working with such a really good bunch of people. There are a lot of people all around the Net who are working with us on this and who are doing significant work, maybe more work than we're doing, in terms of actually solving the problem. The biggest solution, the hardest, of course, is, as I said, having every provider prevent their customers from doing forging. But in the meantime, all the major unit expenders out there are working very hard on making it easier for their machines and their operating systems to withstand these sorts of attacks. And, you know, there are a lot of other people scattered about who are just highly expert in this sort of stuff who are giving us a lot of help. I think I should especially mention Avi Friedman from NetAccess, which is a very Panix-like company in Philadelphia, was extremely helpful in this. He actually recognized the exact nature of the attack. I was on the phone with him when I first spotted it. He recognized it first because he'd actually heard about something like it in Philadelphia very recently before then. He worked with me on fixing it. He came up with one of the notions that we implemented to improve the code. Alexis, I'm sorry, I hate to cut you off, but we're down to our last minute. I just wanted to give folks the opportunity to get a hold of you and to find out more about Panix. Can you give us that information? Well, yeah. You can send mail to info at panix.com to get general info about the system. You can send email to staff at panix.com if you want to ask specific questions. That's P-A-N-I-X. That's right. And staff is a C-A-F-F. I would ask people not to send us a lot of mail asking us for details of this attack, mostly because you can find most of what we want to talk about on our web page, just www.panix.com. There actually isn't a lot of detail up there right now, but there will be a lot more, which is just going to be basically reprints of our messages of the day over the last two weeks. That will be up there in the next day or two. And is there a phone number that new users can contact you at? Me directly? Probably not. I'm still trying to catch up on the last two weeks. Or just Panix in general. Panix's phone number in general, 212-741-4400. Okay. Alexis, thank you very much for being with us today. And best of luck in combating this. Thanks. All right. Alexis Rosen, the, I guess, founder, president, runner of Panix.com, under attack by all kinds of evil programs out there. Hopefully we'll figure out a solution. All right. That's our show for tonight. Thanks, everybody, for calling in. Sorry we didn't get to as many phone calls as we would have liked to have. We'll be back again next week. We'll try to make up for that. Emanuel Goldstein for Off The Hook. Good night. The telephone keeps ringing So I ripped it off the wall I cut myself while shaving Now I can't make a call It couldn't get much worse But if they could, they would For Nilly Bond, for the best, expect the worst I hope that's understood For Nilly Bond For Nilly Bond October 12th. Some people call it Columbus Day. Others, the Day of Indigenous Peoples. It's also known as El Dia de la Raza. October 12th, 1996, marks the 504th anniversary of the initial clash between European powers and the indigenous inhabitants of what is now called America. October 12th, 1996, also is the date for the great march on Washington for Latino, immigrant, and poor people's rights, organized by Coordinadora 96. Join Coordinadora 96 for this historic march on Washington, called in response to anti-immigrant policies coming out of Washington and state houses throughout the country. If you want to volunteer in organizing or want bus information, call Coordinadora 96 at 212-505-0001. That's 212-505-0001. And mark the date on your calendar, October 12th, 1996, for the march on Washington.