- How to make new stuff from your piles of obsolete tech
- Why your computer sucks
- 10 recession-proof IT skills
- Juniper execs share network vision
- 9-year-old plots his fifth Microsoft certification
A Latvian ISP linked to online criminal activity has been cut off from the Internet, following complaints from Internet security researchers.
Real Host, based in Riga, Latvia was thought to control command-and-control servers for infected botnet PCs, and had been linked to phishing sites, Web sites that launched attack code at visitors and were also home to malicious "rogue" antivirus products, according to a researcher using the pseudonym Jart Armin, who works on the Hostexploit.com Web site. "This is maybe one of the top European centers of crap," he said in an e-mail interview.
"It was a cesspool of criminal activity," said Paul Ferguson a researcher with Trend Micro.
The ISP was disconnected from the Internet by its upstream provider, Junik, on Monday, after its provider, TeliaSonera told it to stop servicing Real Host or face sanctions Armin said.
Real Host was considered a "bullet proof" hosting provider, that would allow customers to remain online even after they had been linked to malicious activity. It had been linked to the Zeus botnet-making software.
This isn't the first time this type of hosting provider has been knocked offline. In the past year, at least three U.S. ISPs: Atrivo, McColo and 3FN have been unplugged after security researchers built cases against them. Atrivo and McColo were also taken offline by their upstream providers. 3FN was shut down by the U.S. Federal Trade Commission.
But according to Armin, this may be the "first time an international group has achieved this across borders and in Eastern Europe."
In the past, these takedowns have had a serious affect on spam. And while some observers reported a noticeable drop in spam over the weekend, security experts say that this was probably not attributable to the Real Host takedown.
Observers expect to see the criminal activity linked to Real Host resume soon, but they say that the takedown puts some pressure on the bad guys and the networks that provide service to them. "The precedent that's being set right now is that you need to take some responsibility for your network," said Lawrence Baldwin, owner of security research firm Mynetwatchman. "There actually are some consequences now for allowing an obviously heavy concentration of criminal activity on your networks. It's just not going to be accepted anymore."
Partner Content
Simplify Your Branch Infrastructure
Learn how to simplify your branch infrastructure while dramatically increasing app performance with Citrix Branch Repeater.
Download the Free Info Kit
Next-Gen Load Balancing
Free Guide: "Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic" shows you the functionality needed in your next load balancer.
Download the Free Guide
Accelerate Your Web Apps by up to 5x
Free Guide: "The Secret to Getting Maximum Speed from your Web Applications."' Learn how you can deliver Web apps up to 5x faster.
Download the Free Guide
Comments (6)
arghBy Anonymous on August 6, 2009, 5:26 ameffect, not affect.
Reply | Read entire comment
Re: arghBy Anonymous on August 6, 2009, 6:41 amCOMMENTS, not pedantic nitpicking.
Reply | Read entire comment
Brave moveBy Anonymous on August 6, 2009, 8:30 amConsidering the ties to organized crime, this was a gutsy move by the management of the upstream providers. Good for them; hopefully the authorities will back them...
Reply | Read entire comment
There are ways around such thingsBy Anonymous on August 6, 2009, 10:00 amIf you really want to do evil, put your valuable assets anywhere, but access them through secure tunnels from disposable pwned computers worldwide. Yes, there are...
Reply | Read entire comment
DumbBy Anonymous on August 6, 2009, 11:27 pmThis can't work in practice. It takes allot of effort with no real impact on reducing spam-or illegal activity. What little impact it has had if any (I'd argue no...
Reply | Read entire comment
That is almost a complete sentence -- Good Job...By Anonymous on August 10, 2009, 12:34 pmThat is almost a complete sentence -- Good Job. check out verbs, they can help.
Reply | Read entire comment
View all comments