Denial-of-service tool targeting Healthcare.gov site discovered
Source: Ars Technica
Researchers have uncovered software available on the Internet designed to overload the struggling Healthcare.gov website with more traffic than it can handle.
"ObamaCare is an affront to the Constitutional rights of the people," a screenshot from the tool, which was acquired by researchers at Arbor Networks, declares. "We HAVE the right to CIVIL disobedience!"
In a blog post published Thursday, Arbor researcher Marc Eisenbarth said there's no evidence Healthcare.gov has withstood any significant denial-of-service attacks since going live last month. He also said the limited request rate, the lack of significant distribution, and other features of the tool's underlying code made it unlikely that it could play a significant role in taking down the site. The tool is designed to put a strain on the site by repeatedly alternating requests to the https://www.healthcare.gov and https:www.healthcare.gov/contact-us addresses. If enough requests are made over a short period of time, it can overload some of the "layer 7" applications that the site relies on to make timely responses.
Read more: http://arstechnica.com/security/2013/11/new-denial-of-service-attack-aimed-directly-at-healthcare-gov/
I am not surprised
unblock
(56,178 posts)that they haven't found more more potent dos attacks.
thecrow
(5,525 posts)Glad they found it...but will they prosecute whoever did it? I'm sure they covered their trail pretty well.
my questions.. http://www.democraticunderground.com/?com=view_post&forum=1002&pid=3836025
whathehell
(30,456 posts)During one of the more recent elections a bunch of Repukes were charged and convicted of jamming the phones
in democratic headquarters somewhere in New Hampshire.
What WILL be sweet is when the RW nut jobs behind this are Exposed -- I am all but licking my chops and hoping against
hope that they're connected to the Tea Billies in congress and that the administration prosecutes the HELL out of them.
loudsue
(14,087 posts)This is disgusting.
whathehell
(30,456 posts)loudsue
(14,087 posts)who is successful to that end.
Enthusiast
(50,983 posts)This is pretty clear.
whathehell
(30,456 posts)I think SOMEONE would have to leak that out!
Response to thecrow (Reply #20)
panader0 This message was self-deleted by its author.
BlueStreak
(8,377 posts)because they were pretty inept across the board and it seemed there was nobody with overall responsibility for the success of the project.
However, many of the problems that persisted through the first 3 weeks were exactly the symptoms one would expect from a DOS attack, especially if the connections between the various components were across the open Internet. In other words, when pages loaded inconsistently, sometimes showing data, and other times evidently timing out without actually displaying error messages, that type of result could happen if there was a DoS attack aimed at the back end servers.
I understood the idea of a first-day overload or even an overload for the first week. However, this did not explain why we were seeing exactly the same kind of "overload" symptoms 3 weeks into it, even in the middle of the night. That could not possibly have been a human-generated overload, but certainly could have been a DoS load.
My guess is that they didn't make any plans or prepare any safeguards against DoS and didn't really discover attacks for the first few days. But a week into it, I bet they had discovered there were attacks going on. They just don't want to acknowledge that publicly because that might tend to legitimize this for copy-cat perps.
MADem
(135,425 posts)Wait Wut
(8,492 posts)Well, maybe a little surprised that some of these cave dwellers have that kind of knowledge. Not surprised that they'd use it.
Blue_Tires
(57,596 posts)There are a *LOT* of independent hacker teams "for hire" out there if the price is right; no questions asked...The best teams get hired by governments directly (i.e., Syria)...
Wait Wut
(8,492 posts)Ash_F
(5,861 posts)Because they don't have to code the programs themselves. With some initiative, a layman can download the programs, get through the tutorials on how to use them and launch an attack themselves.
That said, a lot of techies consider themselves 'libertarians'.
RKP5637
(67,112 posts)Stargazer99
(3,510 posts)I figured this was going to happen knowing the RW.....although they scream they are the only moral party they sure have a lot of questionable members.
Scuba
(53,475 posts)dipsydoodle
(42,239 posts)was around late '90s. I'd be surprised if it was actually used on this occasion apart from which those using it would relatively easy to trace those using it.
Spitfire of ATJ
(32,723 posts)dipsydoodle
(42,239 posts)Spitfire of ATJ
(32,723 posts)JoeyT
(6,785 posts)but OOB to port 139 doesn't seem to work like it used to, no matter how many times you send it.
Probably because of some socialist plot.
Spitfire of ATJ
(32,723 posts)DeadEyeDyck
(1,504 posts)easy to shield. That is why they went extinct in the late 90s. I would assume that all the exchange sites are running under SSL!
something is missing from this story.
bigdarryl
(13,190 posts)riverbendviewgal
(4,396 posts)I hope.
meegbear
(25,438 posts)raccoon
(32,369 posts)PatrynXX
(5,668 posts)True but unlike peaceful protestors you usually don't get hurt or killed for it. So naturally to be fair going after people for DOS is more legal than zip ties
Springslips
(533 posts)That the ' disobedience' part of "civil disobedience" means that you are willfully, and peacefully breaking the law. If so, then you do not have a 'right' to it, so to speak. After all, Thoreau was in jail when he invented the concept.
Silly teabaggers, progress ideas are for progressives.
onehandle
(51,122 posts)Strip their assets and deport them.
Peacetrain
(24,288 posts)nightscanner59
(802 posts)From the toxic sludge discharged from their georgia-pacific plant at a rate of 450,000 million gallons of dioxin-laden death.
indepat
(20,899 posts)Dopers_Greed
(2,647 posts)Just like the U$ government did to left-wing hacktivists
AAO
(3,300 posts)Kidnap these traitors and toss them in the prison from which they never leave.
I think if we really got together, we could do this. Just disapear there asses. Nobody outside of their family will care where they are nor, shed a tear.
Anyone WIT ME?
displacedtexan
(15,696 posts)The American court system is far from perfect, but a Gitmo approach lowers us to THEIR level. I know you're angry about this, and I don't think you actually believe that "we" should kidnap and torture people, but I agree that someone needs to go to prision for a very long time because of this vicious attack on poor people's ability to get affordable healthcare in this country.
AAO
(3,300 posts)meadowlark5
(2,795 posts)ffr
(23,388 posts)Sounds like those un-American Tea-hadists at it again.
But I hate using the word terrorist as all levels of government are rapidly reclassifying everything as terrorism in order to erode our rights.
SCVDem
(5,103 posts)You can go with the time tested, "ANARCHIST".
Now can we arrest someone?
bigdarryl
(13,190 posts)Any major news outlets covering this or are they still having an ORGASM over Christ Christie ?
Scuba
(53,475 posts)ReRe
(12,188 posts)... their orgasm in the media today is over the disgusting little skit that the rednecks tried to pull off last night down in Nashville, TN or wherever in the hell they have those country hullabaloos.
2naSalit
(102,337 posts)on the homepage and forwarded to all news outlets.
byronius
(7,966 posts)It's why they're the ass-end of humanity, and utterly dependent on the rest of us to save their miserable hides from disappearing altogether.
Worse-than-useless, incompetent leeches.
freshwest
(53,661 posts)Iliyah
(25,111 posts)from all the internal investigation regarding the website?
I'm not surprised either and guess what, you won't hear about this on our informative corporate media.
Thinkingabout
(30,058 posts)Intentionally causing the Benghazi problem, but wait, this may take him through the 2014 election and if the Democrats takes back the House he will not be chairing this committee. I think he can get to the bottom of Benghazi as soon as he finds the WMD's in Iraq.
albino65
(484 posts)My post of October 24:
I know there are a lot of problems with the ACA website, but I am not sure you can count out a coordinated DOS attack by right wing nut jobs. We already know that they use bots and trolls to disrupt discourse on many news forums. I'm also sure that a large number of people were just there "kicking tires " rather than actively seeking health insurance. Also, some of the contractors may not have been giving their best in the run up to roll out due to being disheartened by the controversy and obstructionism by the GOP. If they thought that it was likely that the ACA would fail to launch, they may have seen little prospect in their work. We need to take the example of Kentucky and press our state lawmakers to institute state exchanges. No matter, the media grabs hold of the failures and never the successes.
leftyladyfrommo
(19,982 posts)Sure wouldn't surprise me.
riverbendviewgal
(4,396 posts)traitors.
Pokeemahn
(9 posts)Has anyone noticed that when you google Obamacare or ACA all you get are ultraconservative sites. Anything about it comes up negative. It looks to me like there maybe a concerted effort of technological warfare.
gopiscrap
(24,710 posts)arcane1
(38,613 posts)alfredo
(60,289 posts)PoliticAverse
(26,366 posts)Try it and report what you get back first: http://lmgtfy.com/?q=obamacare
liberal N proud
(61,192 posts)Why are they not attacking those attacking the government web site?
Would this fall under terrorism?
Berlum
(7,044 posts)
watoos
(7,142 posts)for sedition, for this seems to me to fit the definition?
SoapBox
(18,791 posts)And will ABC, CBS, CNN, NBC, NPR, PBS, etc. cover this??????????????????????????????????????
Of course not...but they will continue to bash Obama Care and Obama's failure opening HealthCare.gov.
P.S.........Can someone TWEET this or communicate this to Think Progress? I don't see anything about it over there.
Downtown Hound
(12,618 posts)Do us all a big favor and never fucking open your mouths again about shit you all are totally clueless about. They shut down the fucking government to stop Obamacare. Do you really think they wouldn't try and sabotage the website?
Because if you do, you're an idiot.
greatlaurel
(2,020 posts)Agreed.
SoapBox
(18,791 posts)Whisp
(24,096 posts)The site wasn't working because, ah, yaknow, Obamacare Sucks. Always.
fuck.
dembotoz
(16,922 posts)underpants
(196,286 posts)I asked that several times mostly as a keep-it-in-mind kind of thing
Wernothelpless
(410 posts)Please ....
kestrel91316
(51,666 posts)Hissyspit
(45,790 posts)The question is to what degree has this been a factor.
AAO
(3,300 posts)Whisp
(24,096 posts)This should really show us who is who here. The ones that claim Obama and Obamacare sucks in everything, every day, should have their fucking days numbered here. but no, they slime and spread dissent and lies and support for the baggers and wings.
getting so fucking sick of all this shit.
MynameisBlarney
(2,979 posts)I wouldn't be surprised one bit.
allan01
(1,950 posts)hopr government prosocuters get those so and sos.
Bennyboy
(10,440 posts)SchmerzImArsch
(49 posts)tblue
(16,350 posts)Do you think Repubs wouldn't squeeze every drop of PR blood out of a discovery like this?
Puzzledtraveller
(5,937 posts)discovering this?
whiteroses
(187 posts)The Stranger
(11,297 posts)Weren't we expecting this to happen all along?
Whisp
(24,096 posts)and just blaming it on Obamacare suckage and nothing else...
blank, blank, __________, blankity _________
Puzzledtraveller
(5,937 posts)Of course, China has been using such software to target Japanese MMO's whenever they cracked down on RMT. A lot of RMT is operated in China. I would be much more concerned that with our cyber-intelligence capabilities we would not be capable of detecting such an attack on Healthcare.gov by some Obamacare-hating Cyberteahadists.
DFW
(60,109 posts)Shoot Obama in the knee, and then criticize him for not coming in first in the 100 yard dash.
sendero
(28,552 posts)... RELEASES THE HOUNDS on this one. DOS attacks are difficult to trace, but not impossible. It's time for some right-wing hacktivists to get familiar with the inside of a jail cell.
kelliekat44
(7,759 posts)PoliticAverse
(26,366 posts)Any arrests? Is there an active SS or FBi investigation?
kelliekat44
(7,759 posts)PoliticAverse
(26,366 posts)Puzzledtraveller
(5,937 posts)We are supposed to believe that our elite cyber intelligence apparatus is too ill equipped to handle something like this.
tridim
(45,358 posts)Something none of us will ever see.
And if there is an active investigation we wont know that either.
IronLionZion
(51,166 posts)This tool would only affect load times for the main page. The backend system is complex and has more than enough technical issues on its own.
The effect the DoS attacks have had is very very small.
Coyotl
(15,262 posts)I would think so.
Judi Lynn
(164,122 posts)Paolo123
(297 posts)I like your Latin America posts. I used to live there after college (although I'm old now)
Orsino
(37,428 posts)...in order to keep us from seeing through the FUD. I would have been surprised to learn that no black hats had ever been engaged to DOS the site, whether or not any of the big players co-conspired.
Bobcat
(246 posts)Historically, those who engage in civil disobedience do not try to evade arrest but invite it. Kindly step forward you cowards!
Aldo Leopold
(687 posts)Historic NY
(39,979 posts)ancianita
(43,294 posts)Auntie Bush
(17,528 posts)I have always wondered or suspected they have hired many hundreds or thousands
of people to jam the the site.
Rosa Luxemburg
(28,627 posts)Puzzledtraveller
(5,937 posts)Auntie Bush
(17,528 posts)A ReThug in Mass. went to jail for deliberately jamming the phone lines of the Dem party. (Don't remember the details.) I believe jamming the ACA gov site is even worse so they should be imprisoned also and soon ...making it an example of what will happen if they continue this illegal practice.
Rain Mcloud
(812 posts)Once again they usurp the will of the people to stay in power,just a little longer.
Prophet 451
(9,796 posts)I'd like to but I'm not. I suspected this from teh start.
JackInGreen
(2,975 posts)if someone had an LOIC pointed at healthcare.gov, and it would appear that I was correct.
nikto
(3,284 posts)I have a feeling there's a lot more of it going on then we know.
Maybe it will come out eventually, but probably not soon enough to help.
If rightwing interests can steal 2 elections (2000/2004), they can certainly
find a way to hobble a website.
truthisfreedom
(23,531 posts)Harden it. Harden it until it cannot be stopped.
Sunlei
(22,651 posts)anyone stupid enough to use this kind of simple program will be easy to catch.
CTyankee
(68,124 posts)of course the website was hacked and sabotaged...
Proud Liberal Dem
(24,948 posts)Well, as they say, just because you're paranoid doesn't mean that they're not out to get you! I wonder if it will be discovered that this tool was actually used on the site, generating some of the problems we've seen.
polynomial
(750 posts)HealthCare web sites jammed, sure is! Voting is jammed too!
Government operations is jammed! Making a war is Jammed up! Free speech money to bail outs is Jammed up! The housing title fraud is jammed up! The media is jammed up! Immigration is jammed up! Civil rights is jammed up! Ever since the Republicans have been in control of federal and state governance even the electromagnetic spectrum is jammed up.
Ever wonder in time ago many at the grocery store checking out some of the clerks that really knew the old fashion customer service would ask
Would you like paper or plastic bags to carry your groceries?.
Now no choices.
The Democratic Party should use the same metaphor but give choices in the platform at the next election. To relate health care, voting, a living wage, practical pension plans to affordable retirement, and food industry, education services and especially agriculture to the many low information voters that need to understand the differences in the parties. This can be offered on a simple plastic card to citizens for good Constitutional rights offered on a card or paper to show the confidence and patriotic stand for development into a new system that does not jam the system.
Imagine this so called healthcare sign up debacle could not only disappear but actually expand to a wide range of government services that should be there to perpetuate the American dream. Think about it services for credit cards in the banking system have jammed the entire system over the years telling all Americans exactly where the one percent take a stand. That is to take as much money from the low information citizen as quickly as possible without shame however with an arrogance beyond any time in history loaded with hubris complicit it media mental games.
The credit card system alone shows that the one percent have one value and that is to syphon the money you have or flim flam to steal the tax money through bailouts you already gave. America needs to understand this idea about free speech money to get rid of everyone of those Imam Supreme Court crazies that support such a law.