All Posts (6213)

Sort by

Censorship chief escapes lynching for soliciting sex from minor

The director general of the Kano State Film and Censorship Board, Abubakar Rabo Abdulkarim, was nearly lynched over the weekend when a mob attacked him for soliciting sex from an under-aged girl.

Mr. Abdulkarim, the former Hisbah commander was trying to escape from a patrol team which had accosted him when they saw his car parked in a secluded environment - with a young girl inside - when he ran into a motorcyclist. Other members of the Okada union quickly surrounded him and he was only saved a lynching by the police who had been in pursuit of his car.

The censorship board, under his leadership, has waged a scorched earth campaign against actors, musicians and producers in the state for allegedly promoting immorality. As a result, many artistes fled the state and now ply their trade elsewhere..

Mr Abdulkarim, who insisted that the girl he was found with was his niece, said he was not having an affair with her. But when the former enforcer of Sharia law discovered he could not convince the contingent of policemen on night patrol on the propriety of having an under-aged girl in his car at such an odd hour, he panicked. The whole thing looked even more suspicious because for some curious reason he had parked behind a shopping complex along Maiduguri Road that night.

A police source said when the patrol team attempted to arrest Mr Abdulkarim he took flight in his car.

Double trouble

While trying to escape however, he knocked down an official of the Kano History and Culture Bureau who was riding on a motorcycle. This incurred the wrath of Okada riders, who thought that he had knocked down a member of their union and promptly proceeded to give him a thorough beating.

Ironically, it was the patrol team that he had been trying to avoid that finally came to his rescue, although by then the okada riders, who saw he had a girl with him, had damaged the car and were already on the verge of beating him to death.

He was later taken to the Hotoro police division where he was made to write down a statement.

Not a wayward one

When contacted, Mr Abdulkarim said members of the opposition Peoples Democratic Party, and film practitioners, were responsible for his ordeal.

The man, who has been having a running battle with film makers and writers in Kano in his attempt to force them to comply with the Sharia legal code, spoke to NEXT before he travelled to Saudi Arabia for the lesser hajj.

“The girl found in my car was my niece and not a wayward one as insinuated,” he insisted.

Spokesperson of the Kano State police command, Baba Mohammed, said he was not aware of the incident because he was in the hospital at the time. The police commissioner, Mohammed Gana also said he couldn’t speak on the matter because he just returned from Saudi Arabia. He however promised to find out the details from his men at the Hotoro Police Division.

Read more…
24-year-old female student who allegedly hid 32 pellets of substances suspected to be cocaine under her breasts, three in her vagina and anus, on Monday appeared before an Accra Fast Track High Court. Evelyn Payin, a Ghanaian domiciled in Italy was alleged to have told Narcotics Control Board (NACOB) operatives that the drugs were given to her by her boyfriend to be given to someone in Italy for 3,500 dollars fee. Facing charges of attempted exportation of narcotic drugs and possessing drugs without lawful authority, the court presided over by Mr Justice Charles Quist did not take her plea but remanded her into police custody until September 3. Prosecuting, Mr Asiamah Sampong, Principal State Attorney told the court that accused holds an Italian passport number 327573 issued to her on April 2005. Sometime in August, this year, Evelyn was arrested at Kotoka International Airport (KIA) on suspicion that she had narcotic substances on her. Prosecution said accused was billed to travel on board an Alitalia Airlines flight number AZ 845 bound for Italy. He said a search on her body by operatives of NACOB led to the discovery of 32 pellets of substances suspected to be cocaine hidden in a pair of socks, placed in an artificial brazier on her breast. During interrogation, prosecution said Evelyn admitted the offence and added that she had inserted a big pellet in her anus and two pellets in her vagina. She was escorted to NACOB Office and under a 24-hour observation, expelled the three pellets saying they were given to her by her boyfriend Nana Yaw Asumani to be given to someone for 3,500 dollars fee. He said the accused, however, failed to accompany NACOB officials to her boyfriend's residence to be arrested. Prosecution said the drugs with gross weight of 800 grammes had been forwarded to Ghana Standards Board for analytical examination.
Read more…
By now you have probably heard about P-Square’s multi-million Naira
Globacom deal. After months of speculation, the talented duo were
officially announced as Glo Ambassadors last week. During the ceremony,
Peter and Paul were presented with their official Glo ‘jerseys’ and
introduced to the rest of the Glo family which includes other Glo
ambassadors who had their contracts renewed on the same day.

The event was another opportunity for the crop of Globacom ambassadors to reaffirm their commitment to the company for endorsing them and for taking such a commendable step to
lift Nigeria’s entertainment industry to a higher pedestal. P-Square,
the newest addition to the list of Glo ambassadors, described the
endorsement as a welcome recognition of the group’s contribution to the
entertainment industry in Nigeria and indeed Africa, adding that this
would spur the duo to greater achievements in the music industry.

Globacom’s Group Chief Operating Officer, Mr Mohamed Jameel, said that
the engagement of P-Square as brand ambassador and the renewal of the
contract for others showed Globacom’s willingness to always recognize
the vast, shining talents that abound in the country..
“P-Square remains a well focused and popular music group and the youths
of this country and this continent find the group worthy of emulation.
The choice of P-Square to join our brand ambassadors was therefore not
misplaced. We have carefully selected our crop of brand ambassadors and
we believe they represent the very best in their chosen professions,” he
disclosed. “We have been actively projecting enterprising Nigerians who
have excelled in their fields of endeavour. We are of the firm belief
that their faces would help fire the aspirations and dreams of many
youths to reach for their goals and rule their world”, Mr Jameel added.
He also said that the feedback from the public largely influenced the
renewal of the contracts of the ambassadors as there has been wide
acceptance and recognition for the step taken by Globacom to lift the
status of Nigerian stars.

Stars whose contracts were renewed at the event included Rita Dominic, Ramsey Nouah, Desmond Elliot, Jim Iyke, Mike Ezuruonye, Nuhu Aliyu, Kate Henshaw-Nuttal and Ini Edo-Phillip Ehiagwina. Others were
Uche Jombo, Monalisa Chinda, Funke Akindele, Nonso Diobi, Sanni Denja
and Mohammed Yakubu. Also on the bill were Pasuma Wonder, Original Stereoman (Ekwe), Ego Ogbaro, Sammie Okposo and ace comedian,Basketmouth.

Read more…

A Federal High court sitting in Lagos set a N500 million bail on the former head of Intercontinental Bank who faces charges of mismanaging the lender in the run-up to last year's N620 billion sector-wide bailout.

The figure is five times the amount set for the heads of four other lenders rescued alongside Intercontinental.

Erastus Akingbola was sacked by the central bank a year ago along with the four other bank chiefs and charged with graft and money laundering in absentia after leaving for Britain, where he had remained until the start of this month.

The cases against the bank chiefs are seen as a litmus test of Nigeria's ability to prosecute influential figures accused of financial crimes. The country is regularly ranked one of the most corrupt in the world by transparency watchdogs.

Bail conditions included securing three guarantors who own properties in the commercial hub of Lagos with evidence of their tax clearance.

"I think the bail condition is fair having regards to the facts of the case," Rickey Tarfa, a lawyer for Akingbola told reporters outside the Federal High Court in Ikoyi.

The bail was set high because unlike other bank chiefs, Akingbola left the country after last year's bailout.

Tarfa said Akingbola would remain in the custody of the Economic and Financial Crimes Commission (EFCC) until the bail conditions were met.

Read more…

The Federal Capital Territory Police Command on Saturday arrested two members of a gang that abducted Dr. Jhalil Tafawa-Balewa, son of the late prime minister of Nigeria, Abubakar Tafawa Balewa, who was kidnapped on Friday night at the business premises of his wife.

Tafawa-Balewa had gone to visit his wife in the Federal Capital Territory, when two men accosted him and took him away at gunpoint to a hideout in Mpampe area of the city.

He was taken to a hilly area where he managed to escape from his kidnappers. The gang was said to have demanded a N100m ransom from his family.


Photo:Late Father of the Victim

Tafawa-Balewa’s family and friends were already making arrangements to pay the sum to secure his release when he escaped from his kidnappers.

Briefing newsmen in Abuja on Sunday, the FCT Police Commissioner, John Haruna, explained that a suspected member of the gang, Adamu Adamu, who was arrested when he came to collect the ransom, led the police to their hideout where another suspect was apprehended.

He suffered gunshot wounds and was taken to the hospital for treatment. Two other suspects are being sought, he added.

Tafawa-Balewa stated that the gang took him away in a Honda car and seized his wallet and wristwatch. The car was recovered in Minna, Niger State where it was taken to after the operation.

Speaking with newsmen, Tafawa-Balewa said, “It was raining when they took me away, so I had no idea where they took me to. But I know that we ended up on a mountain. But when I got an opportunity to escape, I took it.

When I came out, I saw policemen searching everywhere, I didn’t know they were looking for me.”

Read more…

Police Checkpoints Banned

The Nigeria Police has banned checkpoints across the country following several fatal accidents caused by the checkpoints mounted by the police.

P.M.NEWS gathered that the directive to that effect was given over the weekend by the Inspector-General of Police (IGP), Mr. Ogbonna Onovo, who ordered that police commissioners in all the 36 states of the federation must implement the order immediately.


Inspector-General of Police (IGP), Mr. Ogbonna Onovo.

In response to the directive, the Commissioner of Police, Lagos State Command, Mr. Marvel Akpoyibo, went on air to announce the directive, ordering all policemen in his command to leave the checkpoints immediately.

A police source in Lagos told P.M.NEWS under confidentiality that all area commands and divisional police officers have been directed to ensure that the order is carried out at all their duty posts.

As at this morning, P.M.NEWS discovered that the most checkpoints often mounted early in the morning to extort money from motorists in Lagos had disappeared..

Only traffic wardens and LASTMA officials were seen controlling traffic.

There was a multiple accident at Isheri area of Lagos State where over 30 people were burnt to death at police checkpoint.
Read more…




click to expand image
Inspector General of Police, Mr. Ogbonna Onovo

THERE was pandemonium in Iwofe Area of Port Harcourt on Sunday when a navalrating shot a police constable to death after a heated argument over agirlfriend.

The police constable, who was identified as Osaro Osame, was said to be on a special duty at Saipem, an oilservicing company, before he was killed.

PUNCH METRO gathered that Osame, who was in company of a lady, had engaged the naval rating in an altercation over the woman.

Angered by the constable’s audacity, the naval rating (name withheld) brought out a rifle and shot Osame at close range.

Those around the area, according to an eyewitness, took to their heels whenthey heard the sound of a gunshot after the disagreement between thetwo security agents.

The police constable, according to an eyewitness died on the spot while the naval rating was arrested after the incident.

“The sound of the gun really made people to be afraid. Those who werecurious after they heard the gunshot went straight to the scene of theincident to see things for themselves,” an eyewitness said.

Confirming the incident, the Rivers State Police Public Relations Officer, Dr.Rita Inoma-Abbey, said the incident took place at about 1.30am onSunday.

Disclosing that the naval rating was arrested by the Navy Command, Inoma-Abbey said the suspect would soon be handedover to the state police command.

She said, “One police constable, Osaro Osame of the 45 Police Mobile Force on a special dutyat Saipem, Port Harcourt was shot dead by a naval rating at about 0130hours today (Sunday).

“The deceased left camp in company with a lady. It is highly suspected that the lady may be the cause ofthe misunderstanding between the naval rating and the deceased.”

Inoma-Abbey said the lady, who was suspected to causing rift that led to the policeman’s death, was in police custody.

She said the policeman’s corpse had been deposited in a mortuary, addingthat the Criminal Investigation Department of the state police commandhad begun investigation into the incident.

Read more…

2011: Obasanjo may dump Jonathan

The relationship between the Chairman of the Board of Trustees of the Peoples Democratic Party, Chief Olusegun Obasanjo, and President
Goodluck Jonathan may have come under severe threat.

Saturday Punch gathered from authoritative sources on Thursday that Obasanjo, a former President of the country who had hitherto supported Jonathan to
run for the presidency next year, was considering a change of
allegiance in favour of another presidential aspirant from the northern
part of the country.


Photo:From Yaradua to Jonathan to Who ? The Fox called OBJ rules
It was learnt that Obasanjo had started yielding to pressure from the camp of the presidential aspirant who before now had persistently mounted pressure on him for his
support.

A reliable source, who spoke to our correspondent on condition of anonymity, said that Obasanjo had decided to shift his allegiance to the presidential candidate from the North,
contrary to the impression he has been creating in the public lately.
It was further learnt that the former President has held three secret
meetings with the presidential aspirant who is also pursuing his
ambition on the platform of the Peoples Democratic Party.

The source said the relationship between Obasanjo and Jonathan came under threat after some appointments the President made recently.

The former president, who is widely believed to have some influence on Jonathan, was said to be uncomfortable with some of the
appointments,including that of Lt. Gen. Theophilus Danjuma (retd) who
was appointed as the Chairman of the Presidential Advisory Committee.

The relationship between the two retired generals had fallen apart when Obasanjo revoked one of the oil wells allocated to Danjuma by the
regime of the late dictator, Gen. Sani Abacha.

It was further gathered that Obasanjo introduced some companies to Jonathan for some high profile jobs in the oil sector, which were not honoured.

Saturday Punch gathered that for some undisclosed reasons, the President did not accede to the demand of the PDP BOT Chairman who was said to be unhappy
with the development.

It was learnt that an angered Obasanjo had commenced discreet discussions with the candidate.

Obasanjo was said to have told his close confidants that he was making a U-turn on Jonathan because the President was not listening to him. The source
added that the new beneficiary of Obasanjo’s support had continually
reminded him of the relationship between them and how his efforts had
culminated in his emergence as the President in 1999.

It was gathered that Obasanjo was reconsidering the aspirant’s plea on the premise that he owed him a lot and would not lose anything if he threw
his weight behind him.

However, this turn of event was said to have created a big rift among key players in the Obasanjo camp.

It was learnt that while people like Dr. Doyin Okupe are seriously opposed to a deal with Obasanjo’s new favourite candidate, politicians like the
Osun State Governor, Prince Olagunsoye Oyinlola, are irrevocably
committed to the aspirant’s agenda.

President Jonathan’s Special Adviser on National Assembly Matters and Co-ordinator of his presidential campaign, Senator Muhammed Aba-Aji,
however, said he doubted the claim that Obasanjo could sway his support
for Jonathan in favour of another presidential aspirant.

He said, “I doubt it very much. Obasanjo is supporting us 100 per cent. He is 100 per cent pro-Jonathan. He is committed to the Jonathan project.
In fact, we are relying on him to deliver the five states in the
South-West and other states to us. He is our leader; we also rely on
his influence in some other states. He is more than committed. It is
mischief makers who are at work. We should discountenance false rumour.
It is baseless. In fact, our opponents are already jittery because of
the level of acceptance that the President has garnered across the
country and beyond.”

But speaking with one of our correspondents shortly after returning from Kenya on Friday night, Obasanjo said it would be inappropriate

for him as the Chairman, Board of Trustees of the PDP to support any of the presidential aspirants of the party before

the party’s primaries.

He said he would only

be able to lend his open support for the party’s candidate after the

party’s primaries.

The former president, who spoke through his Media Consultant, Mr.

Adeoba Ojekunle, said, “The BOT chairman is the father of all party members and

aspirants in the party. It is inappropriate for the BOT chairman to

support any of the contestants in the party. The issue is not who he

supports but who the party chooses. He can only begin to support the

party’s candidate after the party’s primaries. By the way, the party

has not elected its candidate and so, how can we begin to speculate

who the BOT chairman is supporting? “In any case, the leaders of the South-West zone have not spoken on

their stand on who to support for the PDP presidential candidate. The

BOT Chairman is the father of everybody in the party.”

Read more…

Sunday Sermon: THE DAYS OF NOAH

AS IT WAS IN THE DAYS OF NOAH
A. The “Days of Noah” - Luke 17:26-27 And as it was in the days of Noe, so shall it be also in the days of the Son of man. They did eat, they drank, they married wives, they were given in marriage, until the day that Noe entered into the ark, and the flood came, and destroyed them all.
B. Those will be the most wicked and spiritually careless days ever
C. The “Days of Noah” that Jesus referred to were not the days before the rapture, but the days preceding His second coming
-think of how evil and careless this world will become after the rapture
D. We are in the days leading up to those days and many Christians are getting caught up in it
E. Noah was a “Just man”, “Perfect in his generation” and “walked with God”
-signs of last days - hearts of many grow cold, evil men and seducers become worse, perilous times
F. We are encouraged by Noah to live a godly life in an ungodly world.

III. NOAH BROUGHT REST TO THE LAND
A. The meaning of Noah’s name - Gen 5:28-29 And Lamech lived an hundred eighty and two years, and begat a son: And he called his name Noah, saying, This same shall comfort us concerning our work and toil of our hands, because of the ground which the LORD hath cursed.
B. Noah’s life brought a rest to the earth from the curse of sin which would have destroyed humanity
C. Noah is a type of Christ .
-1 Pet 3:21 The like figure whereunto even baptism doth also now save us (not the putting away of the filth of the flesh, but the answer of a good conscience toward God,) by the resurrection of Jesus Christ:
D. Just as Noah’s life brought a rest to the earth from sin, Christ brings rest to the soul of man
E. Every time the church reaches a soul with Christ, that soul gains a rest from the destruction of sin

IV. NOAH DIDN’T GIVE UP
A. God told Noah to build an ark - 540’L x 90’W x 54’H
B. The ark had to be built to God’s specific details without power tools and precut, treated lumber
C. During this time Noah was mocked, ridiculed, called crazy and insane, etc (it had never rained)
D. For over 100 years Noah labored, not quitting, not getting discouraged and only 8 people were saved
E. Noah’s work encourages us to be faithful to what called us called us to do, don’t give up
-we may be ridiculed and
mocked for what we believe and for what the Word of God teaches but we must be faithful to it
-Jude 1:17-18 But, beloved, remember ye the words which were spoken before of the apostles of our Lord Jesus Christ; How that they told you there should be mockers in the last time, who should walk after their own ungodly lusts.
-2 Pet 3:3-4 Knowing this first, that there shall come in the last days scoffers, walking after their own lusts, And saying, Where is the promise of his coming? for since the fathers fell asleep, all things continue as they were from the beginning of the creation.
F. Noah didn’t quit, because he believed what God told him
-Heb 11:7 By faith Noah, being warned of God of things not seen as yet, moved with fear, prepared an ark to the saving of his house; by the which he condemned the world, and became heir of the righteousness which is by faith.

V. CONCLUSIONA. Don’t give in to the spiritually careless attitude of the world
B. That’s what happened in the days leading up to Noah
C. The sons of God, morally pure people, began to give in to the spirit of the age (1-4)
D. Just as Noah built a vessel that enabled his family to escape the judgment of God, Christ is building a vessel that will escape the judgment that is to come
-1 Cor 3:9 For we are labourers together with God:...
-we are working on a vessel that will escape the judgment to come
E. Keep on working for God, it will pay off in the end
Read more…
A new family of bots is responsible for nearly 200 distributeddenial-of-service attacks targeting websites in China, the UnitedStates, South Korea and Germany, according to researchers at securityfirm Arbor Networks

The bot family, which has been dubbed "YoyoDDoS" after the hostname of one of its initial command-and-control (C&C)servers, was first detected in March. To date, Arbor Networks hasprocessed more than 70 variants from the family and identified at least34 C&C servers, all but three of which are located in China.

DDoS attacks use large numbers of compromised PCs to flood a targeted website withtraffic with the goal of knocking it offline. Out of the 180 YoyoDDoSattacks that have been identified, 126 of them targeted IP addresses inChina, while 32 targeted victims in the United States, nine in SouthKorea, and five in Germany.

Several different online merchants have been targeted, including sites selling auto parts and cosmetics,Edwards said. Several gaming and gambling sites also were attacked,along with a website-hosting provider, a music forum and a personalblog..

“It is not targeted at a specific industry,” said Edwards, a former FBI special agent assigned to the Detroit CybercrimeSquad. “Its more like a general tool, and if somebody wants to take asite down for a certain reason, a lot of time they use this YoyoDDos.”

The attacks typically last between a few hours to two days, he added.Several sites have been attacked continuously for 24 to 48 hours.

Researchers at Arbor Networks said they do not know how many computers have beeninfected with the bot malware, but they believe there are at least threeor four independent YoyoDDoS botnets being controlled by independentoperators.

If this is the case, the code to create the bot malware may be circulating in the cybercrminal underground, Edwards said.

The bot malware, which Edwards said is not especially sophisticated, couldmake its way onto a user's PC via malicious links or attachments inemails. After instillation, the bot connects to the C&C server andreports back details about the victim host, including the make, modeland speed of the processor and the operating system service pack level.Additionally, every time an infected computer is started, the malwaremakes contact with the C&C server.

The bot family uses four different types of DDoS attacks – HTTP, UDP, SYN and ICMP – all ofwhich flood a victim with different types of traffic, Edwards said. Ifan attack is launched with a certain type of traffic, and the victim hasa firewall or another security device that blocks it, another attackmode can be used.

“I do know that it is being actively used based on the number of attacks we are logging,” Edwards said. “We arestill logging attacks and finding [bot malware] specimens we haven'tseen.”

Read more…

Kokoro shows off its latest android Actroid F

Geminoid F, the uncannily lifelike fembot we saw in April, is back in a new PR vid from Kokoro, a Tokyo-based entertainment company that collaborates with Osaka University'sHiroshi Ishiguro in the creation of androids both feminine and creepy.

Geminoid F was so named because it's a nearly exact replica of a human female model, seen here. In the new video, the robot calls itself "Actroid F," as it has joined the ranks of other Actroid robots produced by Kokoro.

The air servo-powered fembots can be rented for trade shows and other events. While Actroid F can move its eyes, mouth, head, and back, it can also act as a telepresence robot. Cameras and face-tracking software follow a remote operator so facial expressions and head movements are reproduced in the robot in a master-slave relationship via Internet link.

Actroid F has minimal servomotors to save on cost, and it can't walk. But Kokoro reportedly announced plans to sell 50 units to museums and hospitals for some $110,000 apiece, aiming for them to serve in roles such as receptionist, patient attendant, or guide. The company has said patients have reacted favorably in a hospital trial.

ATR Intelligent Robotics and Communication Laboratories, backed by the government, companies, and academia, also collaborated in Actroid F's development, one of many robot projects Japan has funded as it tries to develop next-generation machines to meet social needs..

Read more…
These are some pictures of the location pix of 'One Night Stand' which premiers at AY Live, Thisday Dome, this Sunday, 29th, 2010.
Genevieve is the host! Get ready for the unexpected!

This is c

heap publicity Genevieve ! Dbanj was rumoured to have kokomastered you then bank W became capable . now it is A.Y the Joker , Gen please get a man ! we know its entertainment but, leave dis for the young actresses to mess themselves up !


Read more…














click to expand image
Broadcast rights: HiTV, DSTV in battle for subscribers’ attention

HiTV‘s recent loss of the exclusive broadcast rights for the Barclays PremierLeague to DSTV has deepened the rivalry between the two major satelliteTV service providers. SAMSON ECHENIM and UDEME EKWERE capture theinside story and the lamentation of subscribers who have had to switchoften to where the action is



When Mr. John Ado, a civil servant, got

married a few years ago, the first thing he desperately wanted was aDigital Satellite Television (also known as DSTV). He got it throughconsistent saving after two years. As a lover of football, he could notafford to miss the exciting Barclay sponsored European PremiershipLeague. He had to take a soft loan to install a HITV ditch, which hadthe broadcast right.

A year after, Ado is thinking of suspending his subscription pact with HITV. He is also planning toreturn to DSTV, following the award of broadcast right to the EnglishPremiership League.

With high energy and strong desire to be on top of competition, HITV had two years ago offered unbelievablesum of $100m, representing nearly 70 per cent increase, from the $35m,which DSTV used to offer, for the right to broadcast EPL in Nigeria.

But the table has suddenly turned against it. HITV can no longer fulfill that. The right has been returned to DSTV.

Now HITV is adopting multiple counter strategies, including slashingsubscription fee by over 45 per cent, to remain in business as soccerloving Nigerian subscribers massively shift to DSTV, after it failed tosecure the EPL right.

The Barclays Premier League is the biggest continuous annual sporting event in the world, watched byover 2.5 billion fans in the world and broadcast to more than 500million homes, according to available company data.

According to information obtained from HITV website, which was posted on August9, the drama of right became intense on July 19, deadline for HITV topay up.

Having won the right and had earlier paid $40m, HITV was to get bank guarantee for the balance of $75m on July 23, whenit got a ”rude shock and disappointing” announcement by DSTV of itsacquisition of the right on July 22.

The Managing Director and Chief Executive Officer of Hi Media, owners of the pay TV,Mr. Toyin Subair, had blamed the ongoing reforms of the Central Bank ofNigeria for the loss, which he said affected HITV bankers swiftness inmeeting the July 19 deadline.

However, all that is now history. The first indigenous pay TV is making frantic efforts atensuring that it continues to, at least, control a significant portionof the market size, while analysts are of the opinion that thedevelopment does not necessarily spell doom for the company.

When one of our correspondents visited HITV, he was told the company‘spublic relations officer and the CEO were not available. Calls latermade to their mobile telephones were not responding.

A statement on the company‘s website, however, quoted Subair as saying,however, that HITV was fortunate to have, over the past couple ofyears, moved away from building its business model around the BarclaysPremier League.

”Although we lost the rights, we have over the years grown our brand with other premium content for all. Iwant to correct the impression that HITV is all about the EnglishPremier League. While we pride ourselves as number one in the area ofsports content, especially football, HITV is purely an entertainmentPay TV company with lots of other entertainment content for the viewingdelight of its numerous subscribers,” he said.

Although HITV still maintains sports content such as the UEFA Champions League,Carling Cup, Europa Cup and Italian Serie A, soccer lovers are troopingout and hooking up with DSTV, according to findings by ourcorrespondents.

For instance, a housewife, Mrs. Mary Ehinanya, said her husband watched HITV just because of the EPL. Nowthat the EPL is no more on HITV, the family‘s next line of action iseasily guessed.

She said, ”Even the other games HITV shows are usually not live, and so, we will not miss it at all, we willjust subscribe to DSTV which we stopped subscribing to following theirloss of the license a few years back.

Mr. Julius Akposhare, who lives in Ikorodu, said he managed to pay the N6,000subscription for HITV just because of the Premiership League, butdoubted paying again even with the reduction to N3,500 per month,following the loss of licence.

”That was the only reason why I had HITV, you know DSTV was more expensive. But I havespoken to my neighbours who subscribes to DSTV, and we have agreed thatI will connect to it. There is a way we can do it, then I will givethem some money so that they can join and be paying for the DSTV, thatis the way we will manage the situation,” he said.

For Mr. Jibril Layiwola, a sports analyst, the fact that HITV lost thelicence will not make much difference, even though he said there wasnot much to HITV outside EPL in terms of sports.

HITV insisted in the online statement that it had an array of channels andthat it would continue to acquire more to cater for all categories ofviewers.

”We are bringing in 10 more new channels in a couple of weeks. For kids, there is Hi Kids, Kids Co and Nickelodeon.For movies, we have Hi Movies, Hi Mix, among others and for news thereis BBC, Sky News, Al Jazeera and Hi News, Amuludun, Biscon and TVC,among others, which take care of local programming.

”For entertainment, Hi Nolly is one of the best movie channels one can getin this part of the world and plans are on to ensure that all the filmsyou watch on Hi Nolly are all new films. We now have a new channelsmanager who is doing the best she can to make this dream a reality.”

A major innovation is the replacement of its music channel, Nigezie withOne Music, which came into effect on August 1, as the pay TV pledged itwould continue to grow business model and invest in all opportunities,which bring entertainment and information to Nigerians.

”We are aware of the ongoing reforms in the banking sector and there was notime that HITV blamed the CBN for the loss of the EPL rights, thereforms will be of benefit to all of us and our children in the future,so that is clear.”

”Hi Nolly and One Music signals are being seen in 10 African countries as well as Europe, America andCanada. ”Both Hi Nolly and One Music signals are seen in Ghana, Uganda,Kenya, Tanzania, Rwanda, Burundi, Zambia, Malawi, Sudan and Eritrea onWannachi platform and in South Africa we are on Top TV.”

”We are going ahead with the plan, so now our valued subscribers canwatch premium sport, movies and enjoy music at a far reduced price.Nigerians deserve to enjoy quality programmes at a price that won‘tkill them, we would have reduced the price before even if we had thePremiership right because the plan has been hatched for some monthsnow,” he said.

Also, on fears of loss of job, a HITV employee, who spoke with our correspondent on Thursday, on condition ofanonymity, said the company had no plans to lay off workers. Heexpressed strong optimism that the company would continue to remain inbusiness, adding that the EPL right loss was not enough to threaten itsexistence.

An avid HITV follower, who is also a banker, Mr. Tijani Lawanson, said the news that HITV lost the right to beam theEnglish Premier League to Nigerians for the next European footballseason would not make much difference to him.

He said being a subscriber to both DSTV and HITV, the loss of the licence byHITV, simply means that he would have to focus more on watching DSTV.

Read more…

Mourinho in La Liga debut





click to expand image
Mourinho

Barca‘s arch-rivals Real Madrid will travel to Real Mallorca tomorrow for JoseMourinho‘s first competitive game since replacing Manuel Pellegrini atthe helm.

His side have been solid if unspectacular in warm-up games as he has experimented with line-ups and formations.

Of the new recruits, Argentina winger Angel Di Maria has caught the eyewith two goals in the last two games, but Mourinho‘s biggest problem isin defence.

With Raul Albiol, Pepe and Ezequiel Garay all injured Sergio Ramos and Ricardo Carvalho will probably act as a standin centre back pairing.

Financially troubled Mallorca are also unveiling a new coach, former Danish international Michael Laudrup.

He has a tough task to replicate last season‘s fifth-place finish underGregorio Manzano, the club relying heavily on their youth system tobolster their squad.

Valencia start a new era without Spain duo Villa and David Silva, who had to be sold over the summer tohelp reduce crippling debts despite achieving a Champions League place.

They open their campaign away to Malaga today without injured new striker Roberto Soldado.

Malaga are marked out as a side to watch after being bought by a member of the Qatari royal family in June.

They have appointed former Porto boss Jesualdo Ferreira to head up their new project, and have brought in seven new players.

The three promoted clubs all face tough opening-day encounters. RealSociedad are at home to Villarreal tomorrow while Hercules and Levantehost Athletic Bilbao and Sevilla respectively today.

Read more…









click to expand image
INI EDO

Nollywood actress, Ini Edo-Ehiagwina hasn‘t been in a good mood these past days.Life and Beat gathered that the pretty actress has virtually drawn thebattle lines with an online journal published by an entertainmentjournalist that is currently working with a popular soft-sell magazinein Lagos.

The online journal, which draws the contents of its publications from Nollywood, is said to have recently reported thatIni was caught having carnal knowledge of another actress, Tonto Dike.

In her reaction to the publication, the actress had claimed that there wasno iota of truth in it. Sources close to her said she described it ascheap blackmail aimed at smearing her name with dirt on one hand and onthe other hand, at extorting money from her.

Ini, they revealed, is determined not to fall prey this time and has sincedirected her lawyers to sue the offending journal and its publisher.

Although Ini‘s friend and fellow actress, Tonto Dike was mentioned in theallegedly offensive publication, she has not said anything about it.

Read more…









click to expand image
L-R: Adeduro and David

The Lagos State Chapter of the National Association of Nigerian TheatreArts Practitioners (NANTAP) was thrown into mourning as three of itsmembers perished in a car accident that occurred in Lagos on Sunday,August 22, 2010.

The deceased, namely, Miss. Joju Adeduro, Miss. Kathryn David, and Miss Getrude Anyichie were returningfrom an event in the morning when the vehicle conveying them had ahead-on collision with a speeding Toyota Camry (number withheld).

None of the three ladies survived the accident, while the driver of their vehicle and another passenger suffered injuries.

Both Joju Adeduro and Kathryn David were said to have been very activemembers of the association. They were actually fully involved in theproduction of Lagos NANTAP‘s first movie titled Labalaba Nse Bi Eye,while Getrude Anichie distinguished herself as an actress before herdeath.

According to the Chairman of the state chapter of NANTAP, Mr. Mufu Onifade, burial arrangements and a special gatheringin honour of the departed will take place soon.

Read more…

How to make a crocodile smile: Swim in a pool full of deadly salties with just a perspex cage for protection

Tourists to this unusual theme park are sure to get some holiday snaps with a difference.

Inspired by the popularity of cage shark-diving, a tourist attraction has opened that allows adrenalin junkies the chance to swim with killer crocodiles.

And, as these incredible pictures show, participants can get up close and personal with one of the worlds deadliest creatures.

Definitely no running, ducking bombing or petting in this pool: Face to face with one of the 125 stone monsters

Definitely no running, ducking bombing or petting in this pool: Face to face with one of the 125 stone monsters

All that separates thrill-seekers from the huge saltwater crocodiles is a five-inch thick perspex box that has, we are assured, undergone 'extensive' safety testing.

Fearless participants climb into the clear container - nicknamed the Cage of Death - which is suspended on a monorail track that runs above four crocodile enclosures.

Two grated doors lock into position on the top of the 10ft tall box which is then lowered into the water and comes to rest 2ft beneath the surface.

To ensure that the paying customers get their money's worth, chunks of meat are tied to the bottom of the cage. The crocodiles instantly drawn to it when it enters the water.

The results vary from the crocs 'eye-balling' the swimmer, rubbing against the cage or going into a full on 'aggressive attack' against it.

Snappy snaps: Holiday photos from this resort will be just a little different

Snappy snaps: Holiday photos from this resort will be just a little different

Customers pay about £100 to spend 20 minutes swimming alongside the crocs; the largest of the beasts measures a whopping 18ft and weighs over 125 stone,

One of the mighty reptiles at the Crocosaurus Cove park in Darwin, Australia, is named Burt. Film buffs might remember him from the first Crocodile Dundee movie - he's the one who nearly ate Linda Koslowski's character.

Sallie Gregory, spokeswoman for the park, said: 'Many people find the opportunity of getting to within a few inches from the jaws of these crocodiles exhilarating.'

'People often get activity ranging from an aggressive attack to a casual eye-balling and swim past where the crocs are so close that they rub against the cage.'

'Most of the women who take part say they are happy just to watch the crocodiles while guys tend to want the action and attack.'

Smile please: Two thrill-seeking tourists get up close and personal with one of the saltwater crocodiles at the Crocosaurus Cove park in Darwin, Australia

Smile please: Two thrill-seeking tourists get up close and personal with one of the saltwater crocodiles at the Crocosaurus Cove park in Darwin, Australia

She added: 'One of our directors who has extensive experience with crocodiles wanted a concept that allowed people to get up close to these ultimate predators in a safe environment.'

'The cage runs on a overhead monorail system, suspended over the enclosures and is lowered into up to four separate enclosures as part of the 20 minute experience.'

'The perspex is about 135mm thick and extensive testing in both the manufacturing and the way the crocodiles would react to the cage were carried out prior to the testing team entering the cage.'

The 'Cage Of Death' has been extensively tested for safety. With one of these prehistoric killers just inches away, one might hope so..

The 'Cage Of Death' has been extensively tested for safety. With one of these prehistoric killers just inches away, one might hope so..

'The top of the cage has two grated doors to stop anything entering the cage and a back up motor and separate chain operates to ensure that in the event of a malfunction, the cage can continue to operate.'

'The cage generally allows about two feet from the surface of the water though this can be adjusted if people are not strong swimmers and would prefer to keep their head above water.'

Among the crocodiles people can swim alongside are the mating pair of Houdini and Bess as well as Chopper, Denzel and of course movie star Burt.

But one of the most popular crocs is Wendell - he's the biggest and is named after muscular Australian rugby star Wendell Sailor.

Crocodile attacks in the wild are quite rare these days. However, during the Japanese army's retreat from Ramree Island in February 1945, saltwater crocodiles are thought to have been responsible for the deaths of 400 Japanese soldiers. .

British troops encircled the swampland through which the Japanese were retreating, resigning the Japanese to a night in a mangrove swamp which was home to thousands of saltwater crocodiles.

The Ramree crocodile attacks are listed as 'The Greatest Disaster Suffered from Animals' in The Guinness Book of Records

Saltwater crocodiles are the largest reptiles on the planet. Their main habitat is northern Australia and New Guinea, Indonesia and Borneo. They have been known to kill and eat horses, water buffalo, and even sharks as well as the occasional human.



Read more…

To deal with a problem, the first thing we have to do is to understand the problem. This means that we have to be able to measure all meaningful aspects of the problem. If we consider the problem of online fraud, it is encouraging that there has been substantial progress in understanding phishing and how malware is used to steal credentials, documents and money. But, strikingly, almost nothing is known about Nigerian scams (also known as advance fee fraud and 419 scams - 419 is a section under the Nigerian Criminal Code Act that prohibits obtaining goods by false pretences). This makes it harder to defend against this increasingly common type of fraud, and almost impossible to predict the extent to which it may become worse onwards.Nigerian Scams

We designed and performed an experiment that allows us to take the pulse on Nigerian scammers. Are the scammers really from Nigeria, you may begin to ask? What do they want, and how do they get it? What are their strengths, what are their weaknesses? Are they at the peak of their success, or should we fear that they can become dramatically better at what they are doing? What can organizations do to secure themselves and their users?.

Here is the experiment in a nutshell. Imagine a camera that sells for $750 new, and I offer one for sale on Craigslist for $250. Only used for a few weeks, in perfect condition. Good deal, right? But what if I instead were to ask $750 (or more) for it used? Not so hot, you might say. It makes more sense for you to buy it in the store. You would not bother contacting me.

But fraudsters would.

They may contact me and ask to buy it - even at a premium. They will tell me where to ship it, and they will send me a payment. Or rather: something that looks like a payment to a would-be victim, who would not realize that it really was not a payment until after the camera was shipped.

We used the technique of offering too expensive merchandise to find fraudsters without bothering honest people. In fact, we used it to make the fraudsters find us, while avoiding everybody else. Then we acted as would-be victims, and paid attention to what happened.

Here are some of our findings:

Nigerian scams are aptly named. Indeed, almost all of the fraudsters we interacted with wanted us to ship our merchandise to an address in Nigeria. Knowing this may help a little in designing countermeasures, whether legal or technical.

Most Nigerian scammers "pay" using PayPal. Then they send an email that looks a lot like a PayPal payment notification. But, interestingly, they do not spoof emails. If they were, which would be very easy, they would no doubt increase their yield.

Some Nigerian scammers "pay" using Western Union. Then they send a confirmation code that lets the seller pick up the money - but with some digits starred out. "When you send me the tracking number, I will send you the missing part, and you can pick up the payment."

Some Nigerian scammers "pay" using Credit Cards. They request the victim's credit card details so that they can "transfer" the money to his or her account.

Nigerian scammers are bullies. As a would-be victim has agreed to sell, but then expresses second thoughts, the scammer becomes mean and threatening. He sends angry emails in all-caps; tells the would-be victim that he or she will be blacklisted or reported; he even sends a notification from a payment provider, stating that the would-be victim's account has been revoked. (This can only be undone by responding to the notification with your password.)

Nigerian scammers know what they want. They want fancy cameras, but do not care as much for laptops, and do not give a darn about refrigerators and other bulky electronic appliances. It makes sense: The merchandise needs to be shipped to them, and then be resold in Nigeria.

Knowing that the scammers remain in business, we can infer that they are reasonably successful. In fact, we see more and more Nigerian scams. So we can conclude that there are enough people who are not very careful, and that bullying them pays off. This is not about people lacking technological skills, it is about them not thinking critically. User awareness and education campaigns could change that.

Of course, Nigerian scams are not limited to Craigslist, nor to frauds in which they try to obtain people's cameras for free. Our experiment only gives us a glimpse at one particular type of scam at one particular point in time. But it gives us hope that it is possible to create a taxonomy of scams and scammers, and develop tools and campaigns that hurt their bottom line.

Read more…

In this post we (UNIXY) are going to share our experience fending off a large Distributed Denial of Service (DDoS) attack for a client. Generally, Website owners deal with DDoSattacks on their own. There are equipment and solutions vendors cater tothese owners and guarantee protection against these kind of attacks upto a certain threshold. The cost of hiring these vendors can range fromthousands to hundreds of thousand or millions of dollars depending onthe severity of the attack.

Our goal was to build a solution with the least amount of funds possible. This solution is scalable and can handle the worst attacks.The client’s dedicated server is not a special server but a simple quadcore Xeon managed server running the LAMP stack.The DDoS riposte described in this article can scale to stop a 10Gbpsattack or more. The good news is this solution does not require changinganything on the dedicated serveritself of the constellation. The server could be running just about anysoftware stack. This configuration will work just fine with almost allcases effortlessly..

  • Distributed Denial of Service – The Social

Before we delve into the glorious technical details, there is an important aspect of DDoS attacks that one should know about; that is thesocial dynamics that lead to the attack. The more one understands aboutthe the social aspect of a DDoS attack the easier it becomes to preventor stop it. Because once a DDoS has started, priorities shift quitedramatically and rational for making wise decisions becomes flawed.

DDoS comic

DDoS comic

DDoS attacks do not occur randomly. They are targeted and come with a motive. The motive could be revenge but most of the time the motive isfinancial. The individual or groups that conduct the DDoS attacks aremost of the time hired to complete the job. They have the resources andknow-how to orchestrate the attack while hoping to avoid getting caughtby the authorities. They have no emotional attachment to the DDoS attackitself; they have no hard feelings towards the victim. They just getpaid for what they do and nonchalantly, but meticulously, execute.

As explained, DDoS attacks are preceded by an email, post, or phone call, from the individual or group with interest, to the victim. It isalways recommended to treat strangers you meet online or offlineprofessionally and politely. The smallest altercation can lead to anegative reaction, which can escalate actions. In the face of anonymousthreats against your business or organization, remain calm and composed.

DDoS Offer in Forum

DDoS Offer in Forum

There are public markets online (please don’t ask for links) where wannabe DDoS perpetrators get to hire the attackers. Pricing varies from$5/hr to $10 for a simple non-distributed DoS attack. A DDoS, however,tends to be more expensive depending on the sheer amount of data orpackets that needs to be delivered at the target. It can range from$20/hr to $100/hr. The word used to in the circles in lieu of DDoS is to“drop;” meaning to drop a certain Web site or network off the Internet.It really means to either overwhelm the target with enough traffic thatthe equipment fails or to force upstream providers to “null route” thedestination IP at the network level. The end result is that the IP getsdropped from the routing tables and the server to stop responding to allrequests.

The fact that DDoS is not cheap has got to be comforting to an extent. It means that it is only a matter of time before the DDoS“client” runs out of cash. This in itself is encouraging. Keep that inmind should you begin to lose patience. Perseverance is omnipotent.Denial of service attacks are considered a crime and are punishable byFederal law in the US and by the police in the UK. As we will explain inthe technical part of this article, DDoS attacks are almost impossibleto trace to back to the individual or group that are orchestrating theattack. Because of the distributed nature, it requires cooperation fromseveral network engineers that work for upstream providers.

Distributed Denial of Service – The Technicals

First things first, What is a DoS? what is the difference between a DoS and DDoS? A Denial of Service (DoS) is an attack originating fromone source or one system that results in the service in question beingunavailable to its legitimate users. It denies its very users accesseither because the service runs out of available resources or has beentricked to deny access to legitimate users. For example, a DoS attack ona Web server can cause it to run out of resources and stop respondingto requests. A DDoS, on the other hand, is a more sophisticated attacksince the attack originates from hundreds or thousands or nodes.

A DDoS attack is almost impossible to trace back to the source due to its distributed nature. DDoS orchestrators call the nodes andcontroller system a “bot.” With a few commands, the bot owner caninstruct infected nodes from around the world to attack a target. Thebot systems are hosted and controlled via the Internet Relay Chat(IRC) system or via a direct connection port connection. The nodes usedto attack the target are made of compromised Windows and Linux nodesfrom around the world.

Before we present our solution, we need to discuss the two types of DDoS attacks that exist. On one hand you have attacks arebandwidth-based and seek to saturate the connectivity link. On the otherhand, you have attacks that are packet-based and seek to saturate theprocessing capability of the equipment. In other words, they seek tooverwhelm the processing power of the CPU and memory or fabricof the routers or switches. All equipment has hard limits when it comesto their ability to handle a certain number of packets per second.Routers and switches are no exception.

Capacity of networking equipment - Mbps vs pps

Capacity of networking equipment - Mbps vs pps

For example, take the above specification for a Cisco 6500 firewall. Each module is able to handle 5Gbps or 2.8 million pps. This firewall sure looks like it can handle a 5Gbpsattack. Great! However, should there be a packet-based DDoS attack, onewould only need a 1.5Gbps payload to saturate it. That’s 2.8 million pps* 64 Bytes = 1.5Gbps. So bandwidth capacity means nothing by itself andsmall packets can cause havoc.

Our client was facing a 2Gbps DDoS attack that is packet based. It sought to force routing equipment along the way to start droppinglegitimate packets. This caused the upstream to null route the IP toalleviate the burden on other customers that are behind the link. Thisis the typical reaction from all upstreams as they seek to protect theirmany other customers from feeling the pinch of the attack. We weregiven one last chance to “fix” things before the IP could be routed backin. Here is how we were able to fend off the attack and keep the serverrunning.

We have deployed what we call a “constellation” of reverse proxy VM or VPS nodes running the high performance Web server Nginx. The VM nodes werepurchased from several providers given they are located at separatefacilities. Essentially, we are off-loading and “splitting” both packetprocessing and bandwidth consumption across several data centerfacilities (physical routers & carriers).

Nginx constellation

Nginx constellation

The configuration of the Nginx nodes is a typical reverse proxy configuration with the usual extra kernel security configuration. So fora 2Gbps attack and with 20 VM nodes, the bandwidth consumption per nodeis a maximum of 2GBps / 20 = 100Mbps. That’s a 100Mbps load per VMnode, which is reasonable enough and is below the threshold for gettingone’s IP null routed by the provider. One could add more and more Nginxnodes to the constellation without issues.

So how is 20 VM nodes going to be affordable? VM prices have dropped dramatically over the last year. For the above configuration, a VM cancost between $5/mo and $10/mo. That’s an average of $8*20 = $160/Mo.Knowing that most DDoS attackers have the attention span of a gold fish,the $160 is all you need to send your attacker and his accomplicepacking.

Total cost for averting a 2Gbps attack

Let’s talk more about the Nginx constellation configuration. The Nginx front-end nodes will run in proxymode caching static files and requests. The more aggressive the DDoSthe higher the time-to-live for cache objects should be. This preventsthe Nginx nodes from proxy-passing requests to the quad core node.Although, if the main node has idle CPU and plenty of memory it wouldn’thurt to put it to good use to alleviate the burden on the Nginx frontnodes. Your domain’s A records is going to be the IP of the Nginx frontnodes configured in round robin fashion. DNS round robin has itsshortcomings in terms of not having control over how long (bad) recordsget cached by resolvers around the world. But in this case, it does notmatter much. Just be sure to set high TTL for the records so your DNSserver does not collapse under the enormous volume.

Nginx DDoS Constellation

Nginx DDoS Constellation

There are tons of online tutorials that go over the installation of Nginx as a reverse proxy so be sure to read up on it. But we will listsome of the peculiar settings that are needed to handle a large scaleDDoS. Of importance is the number of Nginx worker processes and workerconnections. Those values will need to adjusted gradually and higher tohandle different kind of attacks depending the VM resource allocation.But you should set them at least as high as the following:

worker_processes 8;
events {
.
.
worker_connections 4096; # Be sure to set ulimit -n 4096 or more
.
.
}

Keep in mind that one still needs to gear up for the event by setting kernel and system variables on the Nginx nodes. Simple things likeper-IP rate limiting, flooding rate limits, and syn cookies should beenabled without a question. Here are some measures you can implement:

net.ipv4.tcp_syncookies = 1
# source validation / reversed path
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
kernel.pid_max = 65536
net.ipv4.ip_local_port_range = 9000 65000

Recap.

In brief, here are the elements that constitute our solution:

  • Nginx reverse proxy constellation
  • DNS round robin records
  • Security at the Nginx front end level
  • Know the social and technical dynamics behind DDoS attacks


Read more…

How to Defend Against DDoS Attacks

A distributed denial of service attack is every business’s worst nightmare. One minute, everything is ticking along as normal. The next, your infrastructure is hit by a tsunami of spurious traffic from across the Internet. Legitimate users find themselves locked out, your ability to do business online grinds to a halt, and there's not a great deal you can do about it – unless you prepare ahead of time.

Nowadays, it is frighteningly easy for attackers to execute a DDoS attack. Botnets comprised of thousands of compromised PCs can be rented cheaply, and software capable of automating attacks can be acquired readily on the underground market. Attacks peaking at tens of gigabits per second have been recorded, and the size of peak attacks grows each year.1 A modest attack can be bought for less than a thousand dollars.2 It’s also quite possible for your site to become collateral damage in an attack against a third party you know nothing about. Witness Twitter, one of the Internet's most highly trafficked sites, which found itself knocked offline for hours last August due to a politically motivated attack launched against a single user.3Preventing Denial of Service Attacks

While some evidence shows that massive brute force DDoS attacks are falling out of favor among financially motivated criminal enterprises, there are few signs of a decline in DDoS more generally.4 DDoS attacks are so hard to stop that it's not unheard of for some companies to surrender to extortion attempts, quietly handing their attackers tens or hundreds of thousands of dollars in protection money in order to make the problem go away.5

Short of paying out, it's extremely difficult to completely prevent a determined DDoS attack. But there are four general measures organizations can take, both during system design and live operation, to mitigate the risk of genuine users and customers suffering disruption during an attack. Successful defenses involve using all four techniques:

1. Over-provisioning

Many DDoS attacks are brute force in nature, and over-provisioning is a brute force defense. Your opponent simply needs to throw enough traffic at you to overwhelm your capacity. You can reduce his chances of success and limit the impact on your users by provisioning for far more traffic than you would expect to receive during normal operation. You do not necessarily need to provision for a 40Gbps attack – not all attackers have botnet arsenals that large – but you should aim to prepare for traffic many multiples of what you experience in normal operations..

Some people, when designing their networks, have a tendency to provision for their highest anticipated level of genuine traffic. An e-commerce site, for example, might provide enough capacity for a seasonal sales peak. This will rarely be sufficient to fend off a good-sized DDoS attack. If normal business means 60,000 visits per day, expect a DDoS attack to easily send that much traffic your way in ONE minute. That translates to 86 million “visits” in a single 24-hour attack. A site only provisioned for 60,000 visits will quickly fall to its knees.

A good rule of thumb when building out your hardware infrastructure is to provision for ten times normal peak traffic. Work out the most amount of traffic you've ever had, multiply it by ten, and deploy sufficient hardware to cope with at least that level of activity.

Similar rules apply to bandwidth, so you must ensure that your contract is flexible enough to permit traffic coming into your systems to “burst” to many times the normal volume. You don't want your connectivity provider to shut down all traffic to your site in order to prevent collateral damage to its other customers. Work out the largest amount of bandwidth your site has ever consumed under normal circumstances, then check that your contracts would allow a sustained burst of ten times that amount. Keep in mind that handling that much traffic will take a hefty bite out of your checkbook, too.

2. Remote/redundant monitoring

If up-time is important to you, chances are you already have systems in place to monitor the performance and availability of your site. But in-house monitoring systems can be of limited utility if they're under a DDoS attack as well. If a system designed to alert you when the network experiences problems sits behind the same bottleneck as the site it is monitoring, the alert probably won't make it to your phone or in-box in a timely fashion.

When you're under attack, it helps to know that you are under attack – and quickly. A more reliable alternative is to subscribe to a third-party service that monitors your site around the clock from dozens of other places on the Internet, evaluating its responsiveness from a genuine end-user perspective and providing alerts to your phone when problems are found.

3. Dump the logs

Your Web server logs can't tell the difference between a genuine visitor and a botnet node. Both visits will usually be recorded in the same way. Even if your server is provisioned correctly and is able to recover from a DDoS attack flood, if its logs stack up, you can often add insult to injury if your server fails because the logs became too large. While the log data could possibly be used for forensic purposes after the attack is over, its value is relatively limited. It's far more important that servers are able to respond to genuine users during the attack.

If you find log files growing large quite quickly, you're faced with the choice between keeping the data and losing the server, or losing the data and keeping the server. If your Web server is mission critical and large log files are preventing you from recovering, your choice should be clear: dump the logs.

4. Know the people at your providers

While it is technically possible to locally configure network hardware to drop some malicious packets, ideally you'll want the unwanted traffic throttled as close to the source as possible. This means that coordination with your upstream providers is a must.

Unfortunately, if your opponent has done his reconnaissance properly, he will launch his attack at the most inconvenient time possible. There's a good chance that the text message alerting you to an incoming DDoS will arrive at 1am on a Saturday morning, when both you and your regular ISP points of contact are off for the weekend.

The normal support numbers you know to call might go to voice-mail, the night-shift staff may not have the expertise or authority to help, and automated ticketing systems may not be as comprehensively attended as they are during business hours. If you can't find anyone in a position to help you, you're then faced with the prospect of two or three days of compromised performance or outright downtime.

In these circumstances it’s essential to have the direct telephone numbers of clued-in people at your ISP's network operations center. If you know how to contact the right person to help shut down the attack, regardless of the hour, you'll experience far fewer headaches when a DDoS strikes.

It's a truism that most security vulnerabilities are people problems. Fortunately, that sometimes also applies to the solutions.

DDoS attacks are here to stay – after all, they are cheap to setup and easy to implement. By appropriately deploying plans in these four areas (provisioning, monitoring, log management and escalation) you should be able to hold your own against all but the most determined and aggressive attackers.

Read more…

Blog Topics by Tags

  • in (506)
  • to (479)
  • of (339)
  • ! (213)
  • as (166)
  • is (157)
  • a (156)

Monthly Archives