Feeds

ICANN cast as online scam enabler

And now a word for our illegal online pharmacy sponsor

The Power of One eBook: Top reasons to choose HP BladeSystem

Note: Officials at LogicBoxes and Directi take strong exception to the reports discussed in this story. Their objections are detailed in this follow-up story.

Two recently issued reports portray the Internet Corporation for Assigned Names and Numbers (ICANN) as a bureaucracy that enables cyber criminals.

In one report (PDF), researchers Jart Armin, James McQuaid and Matt Jonkman detail how one of ICANN's prized sponsors has ties to one of the net's more prolific sources of malware and illegal online pharmacies. It's called LogicBoxes, and over the past two years, ICANN has listed it as a sponsor for meetings that took place in Los Angeles and Delhi, India.

It turns out that LogicBoxes has an association with Atrivo, a network provider that also goes by the name of Intercage. According to the study, a random sampling of 2,600 addresses hosted by Atrivo revealed 7,340 malicious web links, 910 infected websites, 310 malicious binaries, and 113 botnet command and control servers. As an autonomous systems (AS) provider, the Concord, California-based company controls a large number of IP addresses.

The report details how Atrivo works with a rogue's gallery of other companies to enable anonymous sites that punt scareware, malware and online sites pushing Viagra and other sites. Other companies include Hostfresh, EstHost, EstDomains and PrivacyProtect.

In an email to The Register, Atrivo principal Emil Kacperski declined to comment.

A second report issued by an outfit known as Knujon (that's "no junk" spelled backwards) details 48 phantom domain name registrars whose sole purpose seems to be the registration of addresses used in spam and malware campaigns. All of them can be linked back to the Directi Group, which has long been a prolific provider of URLs to scammers.

According to Knujon, the 48 registrars are violating ICANN's own rules requiring them to clearly identify their business name and business address. That's something registrars are reluctant to do when they're spewing out sites as unpopular as these.

ICANN is the government-appointed group that accredits registrars. A spokesman for the group didn't return our calls for comment.

Yes, we realize the net is a big place and it's not possible to know the reputation of every group ICANN accredits or takes money from. But it's not unreasonable to expect the gatekeeper to enforce its own rules, especially given the proliferation of sites pushing spam, malware and other scams. And while ICANN did nothing wrong accepting sponsorship money from LogicBoxes, it's fair to say the the relationship doesn't look good, so long as LogicBoxes continues to keep company with the likes of Directi and Atrivo.

So next time you receive a spam or a popup fraudulently claiming your PC is hosed, think of ICANN. ®

Designing a Defense for Mobile Applications

More from The Register

next story
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.