Microsoft admits technical error in IP takeover, but No-IP still down

No-IP claims Microsoft doesn't appear to be very good at DNS

Microsoft admitted Tuesday it made a technical error after it commandeered part of an Internet service's network in order to shut down a botnet, but the Nevada-based company says its services are still down.

A federal court in Reno granted Microsoft an ex-parte restraining order that allowed it to take control of 22 domains run by No-IP, a DNS (Domain Name Service) provider owned by Vitalwerks, which was served the order on Monday.

Microsoft alleged the domains were being abused by cybercriminals to manage and distribute malware. It was the tenth time Microsoft has turned to the courts to take sweeping action against botnets, or networks of hacked computers.

Although No-IP was not accused of wrongdoing, Microsoft maintained the company had not done enough to stop abuse on its networks. Microsoft's intention by seizing the domains was to block only the computers using No-IP's services that were being used as part of a botnet.

But "due to a technical error, however, some customers whose devices were not infected by the malware experienced a temporary loss of service," according to an email statement from David Finn, executive director and associate general counsel of Microsoft's Digital Crimes Unit.

"We regret any inconvenience these customers experienced," Finn wrote via email on Tuesday.

He claimed that No-IP's services were restored at 6 a.m. Pacific Time Tuesday. No-IP spokeswoman Natalie Goguen wrote via email that Microsoft made a technical change on Tuesday to forward legitimate traffic back to No-IP, but "it didn't do anything."

"Although they seem to be trying to take corrective measures, DNS is hard, and they don't seem to be very good at it," she wrote.

When queried, a Microsoft spokeswoman pointed to a tweet by No-IP that said it was under DDoS (distributed denial-of-service) attack. Goguen responded that No-IP's website was under attack but it did not affect its DNS infrastructure.

No-IP provides a free service that allows a customer's domain name to always point back to their computer even if an ISP assigns a different IP address to a computer when it comes online. It does that by offering subdomains for 22 main domain names it owns.

The IP address of a customer's subdomain is updated as the computer's IP address changes. Records in the DNS (Domain Name System) are then updated.

In its civil suit, Microsoft alleged two foreign nationals, Mohamed Benabdellah of Algeria and Naser Al Mutairi of Kuwait, used No-IP's service to facilitate the management of malware that steals sensitive data from people's computers.

No-IP's service "provides computers that move from IP address to IP address a stable domain name for malware-infected computers to contact," according to the lawsuit.

No-IP maintains that it has worked with companies that reported abuse but "unfortunately, Microsoft never contacted us or asked us to block any subdomains," according to a blog post on Monday.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags securityMicrosoftcybercrimelegalCriminalVitalwerks

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Cool Tech

Breitling Superocean Heritage Chronographe 44

Learn more >

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?