Energy News  
E-Mail "Cluster Bombs" A Disaster Waiting To Happen

tick tick tick tick tick....

Bloomington - Dec 11, 2003
Internet users can be blind-sided by e-mail "cluster bombs" that inundate their inboxes with hundreds or thousands of messages in a short period of time, thereby paralyzing the users' online activities, according to a new report by researchers at Indiana University Bloomington and RSA Laboratories in Bedford, Mass.

IUB computer scientist Filippo Menczer and RSA Laboratories Principal Research Scientist Markus Jakobsson describe in the December 2003 issue of ;login: a weakness in Web sites that makes the e-mail cluster bombs possible. A miscreant could, the authors say, pose as the victim and fill out Web site forms, such as those used to subscribe to a mailing list, using the victim's own e-mail address.

One or two automated messages would hardly overload an e-mail inbox. But Menczer, associate professor of informatics and computer science, said special software called agents, web-crawlers and scripts can be used by the bomber to fill in thousands of forms almost simultaneously, resulting in a "cluster bomb" of unwanted automatic reply e-mail messages to the victim. The attack can also target a victim's cell phone with a sudden, large volume of SMS (short message service) messages.

"This is a potential danger but also a problem that is easy to fix," Menczer said. "We wanted to let people know how to correct the problem before a hacker or malicious person exploits this vulnerability, causing real damage."

The barrage of messages would dominate the bandwidth of an Internet connection, making it difficult or impossible for the victim to access the Internet. This is called a distributed denial-of-service attack, because a large number of Web sites attack a single target.

The attack works because most Web forms do not verify the identity of the people -- or automated software agents -- filling them out. But Menczer said there are some simple things Web site managers can do to prevent attacks.

"Often, subscribing to a Web site results in an automatically generated e-mail message asking the subscriber something like, 'Do you want to subscribe to our Web site?'" Menczer said. "We propose that Web forms be written so that the forms do not cause a message to be sent to subscribers at all. Instead, the form would prompt subscribers to send their own e-mails confirming their interest in subscribing. This would prevent the Web site from being abused in a cluster bomb attack."

Menczer was an assistant professor of management sciences at the University of Iowa's Henry B. Tippie College of Business when the study was initiated. Funding for the study came from an National Science Foundation Career Grant and the Center for Discrete Mathematics and Theoretical Computer Science at Rutgers University.

Community
Email This Article
Comment On This Article

Related Links
Filippo Menczer's faculty page
Markus Jakobsson's faculty page
SpaceDaily
Search SpaceDaily
Subscribe To SpaceDaily Express
Cyberwar - Internet Security News - Systems and Policy Issues



Memory Foam Mattress Review
Newsletters :: SpaceDaily :: SpaceWar :: TerraDaily :: Energy Daily
XML Feeds :: Space News :: Earth News :: War News :: Solar Energy News


US Military Mounts International Psyops Campaign
Washington (AFP) Dec 14, 2005
The US military is mounting a 300 million dollar psychological operations campaign to sway international opinion of the US war on terrorism through messages placed in foreign media, officials said Wednesday.







  • Research Generates Reliable Energy Source During Outages
  • Gas Hydrates Offer New Major Energy Source
  • A Hot Time For Cold Superconductors
  • U.Texas At Austin Flywheel Spins To A Milestone Speed Record

  • Yucca Mountain Site Must Make Use Of Geological Safety Net
  • New Jersey Physicist Uncovers New Information About Plutonium
  • Complex Plant Design Goes Virtual To Save Time And Money
  • Volcanic Hazard At Yucca Mountain Greater Than Previously Thought





  • NASA Uses Remotely Piloted Airplane To Monitor Grapes



  • National Consortium Picks Aviation Technology Test Site
  • Wright Flyer Takes To The Sky In Las Vegas
  • Aurora Builds Low-speed Wind Tunnel
  • Yeager To Retire From Military Flying After October Airshow

  • Boeing Selects Leader for Nuclear Space Systems Program
  • Boeing-Led Team to Study Nuclear-Powered Space Systems
  • Boeing To Build Space-borne Power Generator
  • New High-Purity Plutonium Sources Produced At Los Alamos

  • The content herein, unless otherwise known to be public domain, are Copyright 1995-2006 - SpaceDaily.AFP and UPI Wire Stories are copyright Agence France-Presse and United Press International. ESA PortalReports are copyright European Space Agency. All NASA sourced material is public domain. Additionalcopyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement,agreement or approval of any opinions, statements or information provided by SpaceDaily on any Web page published or hosted by SpaceDaily. Privacy Statement