NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business / Companies / Telecommunications

Juha Saarinen: XT time all over again?

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
8 Sep, 2014 12:10 AM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Hollywood star Jennifer Lawrence. Did the weekend's Spark shutdown really come from local users wanting to look at hacked pictures of her? Photo / AP

Hollywood star Jennifer Lawrence. Did the weekend's Spark shutdown really come from local users wanting to look at hacked pictures of her? Photo / AP

Juha Saarinen
Opinion by Juha Saarinen
Tech writer for NZ Herald.
Learn more

It was XT time all over again as much of New Zealand internet went down on Friday evening and continued to have problems over the weekend.

I didn't notice anything amiss, but then I'm not a customer of Spark.

Spark said that the issue is due to a handful of customers wanting to ogle nude pictures of Jennifer Lawrence as delivered by phishing emails, but which in actual fact installs some unnamed malware used for a denial of service attack - or, sending large amounts of data or requests, which overwhelms servers trying to keep up.

There's been speculation that it was a Domain Name System (DNS) amplification attack that created huge amounts of traffic.

These attacks abuse the Domain Name System machines that translate numeric addresses like 8.8.4.4 to a host name like google-public-dns-b.google.com which is a bit easier for humans to remember.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Without going into too much technical detail, amplification or reflection attacks as the name implies allows an attacker to send several small queries to servers, demanding a large response with lots of data.

What's more, it's easy to fake the address that the response should go to.

The long and short of this is that with relatively simple means, an attacker can use a relatively low-speed network connection, like ADSL2+ with a maximum of 1 megabit/s upstream, and send fifty or more times the amount of traffic to a victim system.

Spark hasn't so far provided any technical detail on what happened, but as the rest of its network appeared to be working, it's unlikely that a DNS amplification attack was the culprit.

First, despite the amplification factor being large, you need more than just a handful of machines to swamp a modern network with large amounts of capacity.

Discover more

Opinion

Juha Saarinen: C-Level technocrats? No thanks

17 Jul 11:54 PM
Opinion

Juha Saarinen: Knocking off Nokia

23 Jul 01:57 AM
Opinion

Juha Saarinen: Telecom vs Chorus

25 Jul 12:22 AM
Opinion

Juha Saarinen: Aussies clamp down on dastardly downloaders

30 Jul 12:00 AM

Second, if Spark was sending out large amounts of data overseas for three days as a spokesperson for the company said, it would've been noticed by international monitoring services like the Digital Attack Map nothing out of the ordinary appears to have been recorded however.

A Spark techie described on the Geekzone forum the telco's DNS infrastructure as being "load balanced in different geographic locations; each instance is connected to the core network by two different paths and each DNS server is connected to the redundant switch (and router) infrastructure by multiple bonded GigE [Gigabit Ethernet network] interfaces."

Advertisement
Advertise with NZME.

Translation: that's a serious set up with lots of network capacity. Are we to believe that "a handful" of malware infected users were able to overwhelm that, for three whole days?

An outage notification message sent to providers connected to Spark's network talks about "a total of five domain addresses" having been blacklisted by the telco as part of its technical fix for the problem, along with blocking of certain inbound traffic to its broadband network gateways.

Furthermore, the notification mentions that Spark's Global Gateway international network would continue to identify and block "offending source IP addresses". Both measures suggests that the fault was caused by external factors, and not customers on Spark's own network.

Whatever it was that caused the problems, three days' of service disruption despites the Spark techies' valiant efforts to set things right is not a good look for the country's largest internet provider.

Spark should take a look at its processes around responses to issues like this one, and ensure that they're more flexible and faster when problems such as the recent lot happen.

For instance, during the weekend outage, the telco issued a workaround that involves changing the internet Protocol addresses for the DNS servers on its network - this isn't too hard to do for people with technical nous, but it's not so easy for everyone else.

Advertisement
Advertise with NZME.

Having customers changing their DNS entries from the original ones that are automatically allocated when the broadband connection starts up could come back and bite Spark however.

Now that the attack has subsided, Spark now has further support headaches as it would like users to switch back to automatic allocation of DNS servers:

If you changed your DNS settings to Google's we advise you to change back and switch to auto. Details here: http://t.co/CQdQsdiyNs 2/2

Also, given that both the broadband network and Spark's 3G/4G mobile data service are affected by the issue, publishing details about the work around on a web page that won't load with the existing DNS settings seems a suboptimal way to disseminate information.

For the sake of Spark's customers, I hope the "mini XT" event over the weekend is a wake-up call for the incumbent that there are parts of its network that aren't robust enough and needs a makeover.

Blaming customers and "cyber criminals" for problems that appear to be caused by issues on Spark's own network isn't the way to go however.

Tweets by @SparkNZ

Ballmer's 'Blue Screen of Death'
Ballmer's 'Blue Screen of Death'

Blue screen of Ballmer

Advertisement
Advertise with NZME.

From the truth will out department: it wasn't a nameless Microsoft developer that wrote the text for the famous Blue Screen of Death (BSoD) in ye olde Windows 3.1.

It can now be revealed that the BSoD author was... Steve Ballmer, in 1992.

Microsoft blogger and principal software engineer Raymond Chen said Ballmer didn't like the original text and a few days later, came back with a version that went into the early version of Windows almost word for word.

Chen doesn't say what the original text was, or if Ballmer went on to write more error messages.

Steve-o is of course no longer with Microsoft, having left the chief executive job, hopped off the company board and become Mr Basket Ballmer as the new owner of the LA Clippers team.

He will be missed.

Advertisement
Advertise with NZME.
Save

    Share this article

Latest from Telecommunications

World

Trump gives TikTok 90 more days to find buyer, again delayed ban

19 Jun 05:53 PM
Business|companies

One NZ expands Starlink partnership to Internet of Things

15 Jun 09:34 PM
Premium
Stock takes

Stock Takes: Why NZ's largest firms are suddenly ripe for takeover talks

12 Jun 09:00 PM

Help for those helping hardest-hit

sponsored
Advertisement
Advertise with NZME.

Latest from Telecommunications

Trump gives TikTok 90 more days to find buyer, again delayed ban

Trump gives TikTok 90 more days to find buyer, again delayed ban

19 Jun 05:53 PM

ByteDance is in talks with US investors to reduce its share in TikTok.

One NZ expands Starlink partnership to Internet of Things

One NZ expands Starlink partnership to Internet of Things

15 Jun 09:34 PM
Premium
Stock Takes: Why NZ's largest firms are suddenly ripe for takeover talks

Stock Takes: Why NZ's largest firms are suddenly ripe for takeover talks

12 Jun 09:00 PM
Premium
Tech Insider: A $529 phone, bought in March, can only make 3G calls; IRD’s AI warning; Musk’s pain is Beck’s gain; a self-employed Wellington man scores a $16K Google Cloud refund

Tech Insider: A $529 phone, bought in March, can only make 3G calls; IRD’s AI warning; Musk’s pain is Beck’s gain; a self-employed Wellington man scores a $16K Google Cloud refund

10 Jun 03:14 AM
How a Timaru mum of three budding chefs stretched her grocery shop
sponsored

How a Timaru mum of three budding chefs stretched her grocery shop

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP