ISP cut off from Internet after security concerns
A U.S. ISP suspected of aiding cybercriminals in online scams and hosting child pornography was at least partially cut off from the Internet on Tuesday night.
The ISP (Internet service provider), McColo, had been under the watchful eye of computer security analysts for years. It is one of a handful of so-called "bulletproof" hosting providers that provide safe haven online for cybercriminals selling Viagra and fake security software.
ISPs can connect with each other to exchange Internet traffic, a practice known as "peering." Hurricane Electric, an ISP that carried a portion of McColo's traffic, disconnected with McColo on Tuesday night. Global Crossing, an IP (Internet Protocol) network services provider also connected to McColo would not comment.
"All I can tell is we communicate and comply fully with legal authorities, but we do not comment on individual customers and individual incidents," said Richard Larris, senior manager for media relations at Global Crossing.
The shutdown coincides with a damming new report authored by several computer security researchers who detail how McColo and other questionable service providers are linked to spam and cybercrime.
McColo's shutdown "demonstrates that when presented with appropriate evidence of criminal activity, the Internet community can bring about the positive forces necessary to purge it," the analysts wrote.
McColo, whose servers were located within the U.S., at one time hosted up to 40 Web sites with child pornography, the report said.
McColo also played a big role in spam distribution, said Richard Cox, CIO of Spamhaus, which tracks spamming operations. It hosted Web sites that could infect people's computers with malicious software used for sending spam, he said.
Hacked computers then become part of a botnet, or networks of PCs that can be used to send spam or attack other Web sites.
McColo hosted the so-called command-and-control servers for botnets that are used to instruct PCs to send spam. The botnets included Rustock, Srizbi, Pushdo/Cutwail, Ozdok/Mega-D and Gheg, according to the report.
When it received complaints, McColo would shift around the suspect Web sites on its network and try to erase traces of wrongdoing, Cox said.
"Essentially, a lot of these providers know what their customers are doing and try to protect them," Cox said.
Analysts are predicting a drop in spam and botnet activity while McColo is offline. Joe Stewart, director of malware research for SecureWorks, said on Wednesday that he'd received only one spam message from the Rustock botnet, while on a normal day he might get up to 20.
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
On Twitter now
isp
Powered by Twitter
jfruh
Apple syncing patent can't come soon enough
pasmith
New Twitter features borrow from 3rd party clients
Esther Schindler
Open Source Changes the Software Acquisition Process
mikelgan
How to set up continuous podcast play on the new iTunes
David Strom
Five important Windows 7 mobility features
sjvn
Guard your Wi-Fi for your own sake
Sandra Henry-Stocker
Grepping on Whole Words
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.













