http://www.theregister.co.uk/2012/07/05/dnschanger_botnet_shutdown/
This story is interesting for a lot of reasons. First the technical details, as non-technical as I can make them….
When you do things on the internet (including the web) there is a process that goes on behind that scenes that you never need to know about unless it breaks (or you’re a computer geek). It’s roughly similar to dialing 411 for a phone call – you tell who you want to talk to, it looks up a phone number, and connects you (and you save the number so you don’t have to ask again)
Well, some clever guys in Estonia figured out ways to trick your computer – extending my analogy, when your computer dials 411 – instead of getting the AT&T 411 system, you got Ed’s phony 411 service in Estonia. Most of the time, it would just pass through the same thing as the real 411, but for some things (like maybe logging in to your bank account), Ed’s fake 411 service would send you to a fake copy of the banking site.
At the peak, the fake DNS (411) service had 4 million computers around the world tricked by what they had done. “Ed” and his buddies were busted, but that left the problem of what do with the 4 million computers that were mindlessly using the fake DNS servers to find computer numbers (called IP numbers).
The FBI and similar agencies have been working with ISPs (like AT&T) to try to notify people that their computers are infected and need to be cleaned up. Monday, the FBI plans to turn off their fake fake DNS servers. There are still an estimated 303,000 computers actively thinking they are being controlled by “ed” and not the FBI.
Testing if your computer is one of the 300,000 is simple.
http://www.dcwg.org/detect/
Has a list of test sites. All they have to do is do a DNS lookup – if the fake FBI server is used, it will point to a page that says “You’re infected”. If your computer using the correct DNS server (usually the one your ISP provided to you), then it points to the write IP number and a message that says “All is Well”.
The whole “DNS lookup” process is one of those things going on behind the scenes that is very potentially sneaky. If for instance, you use the free Google DNS lookup service at 8.8.8.8 (because it is better, faster, etc…) then every single thing you do on the web Google is able to see and log The DNS only sees what you wanted to look up, not what you wanted to do after you get there…. so your browser asks for the IP number for moms.chocolatechipcookies.com, Google sees that. it doesn’t see that within mom’s web site you were looking for /milf/hot-videos/cindy-has-big-boobs.mov – but just gathering where you visit still tells Google a lot about you and about the internet usage
So to be less obtuse, the FBI for quite some time has had the ability to see what those 4,000,000 (now down to 300,000) computers have been accessing. There is no court order in place to let them look at what you’re doing but they are.
If you’ve ever used a wifi hot spot that required you to have an account, you know that’s entirely unnecessary. The fake FBI run DNS server could just have forced your computer to a page (no matter what you typed in) saying “Hello, this is the FBI (or some less shocking entity like CERT). You are seeing this page because your computer is infected with DNSChanger and here is how to solve the problem and make your computer work correctly again – rather than leaving the 300,000 computers talking to the FBI systems for months without the awareness of the owners.
What “Ed” was doing with those 4 million computers was running that is called a “BotNet”- basically an army of 4 million “borrowed” computer and their internet connections all over the world that could be told at the same time to do something – like all request pages from streamingradioguide as fast as they could and then stop and demand that I fork over a large sum of cash or they would turn it on again and put me out of business. Of course, they would never do that cause I don’t have big piles of money and don’t care. But someone like Bank of America would care.