Feeds

ZyXEL router attack: HUNDREDS of Brit biz bods knocked offline

SYN flood from 'Chinese' hackers wreaks havoc

Business security measures using SSL

Updated Hackers have launched an internet attack which has hobbled the internet connections of at least 100 British businesses.

An unknown group or individual thought to be based in the People's Republic used a SYN flood attack to attack the 600 and 660 models of router from Taiwanese firm ZyXEL.

Sources at ZyXEL and the ISP MDNX confirmed that the attack came from a Chinese IP address.

This denial-of-service attack involves sending a torrent of TCP connection requests from a series of spoofed source addresses. Receiving a large number of forged TCP requests – with the SYN flag in each packet set to request a new connection – causes the target system to grind to a halt as it waits for confirmations that will never arrive.

A source familiar with the matter told The Register that more than 100 businesses had phoned in to complain about failed internet connections.

"These [routers] are legacy models which are six years old and there are many, many of them out there in the wild. The attack is carrier agnostic and affects anyone using the router.”

Another source with detailed knowledge of the matter confirmed the attack and said users could save themselves by closing their router's remote management port.

He said: "We know this attack came from China and used a number of public IP addresses. It seems to be completely random. We don't know why the attacks are coming."

One Twitter user tweeted this yesterday evening:

The Register contacted ZyXEL for comment but have not yet received a response. We'll update this article if we hear anything from the company.

Nobody knows why Chinese hackers chose to launch this attack or even whether they are genuinely based in the country. Do you know any more about this SYN flood assault or have you been affected? Get in touch (click my name at the top of this story for contact details) and let us know. ®

Updated to Add

We should note that the sources we contacted for this story specified only ZyXEL routers as being affected. The only mention of Draytek equipment that we know of in this context came from the Tweet quoted above, which we note has now been withdrawn. Draytek have since contacted us to say that they are unaware of any problem connected with this attack affecting their routers. A Draytek spokesperson added:

We are a completely separate company from ZyXEL, nor do we share any software/hardware platforms.

ZyXEL have also now been in touch to say:

"We're aware of the SYN attack that has been affecting the P66X router models and have been working to resolve any resulting issues.

"Only customers who have remote management open on the routers are affected ... We are informing customers of the steps they need to take in order to address the issue and will be keeping them updated if any further action is required."

Protecting against web application threats using SSL

More from The Register

next story
Brit telcos warn Scots that voting Yes could lead to HEFTY bills
BT and Co: Independence vote likely to mean 'increased costs'
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
Radio hams can encrypt, in emergencies, says Ofcom
Consultation promises new spectrum and hints at relaxed licence conditions
Blockbuster book lays out the first 20 years of the Smartphone Wars
Symbian's David Wood bares all. Not for the faint hearted
Bonking with Apple has POUNDED mobe operators' wallets
... into submission. Weve squeals, ditches payment plans
This flashlight app requires: Your contacts list, identity, access to your camera...
Who us, dodgy? Vast majority of mobile apps fail privacy test
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.