Contact Me By Email

Showing posts with label Denial-of-service attack. Show all posts
Showing posts with label Denial-of-service attack. Show all posts

Saturday, March 05, 2011

Cyberattack in South Korea Hits 40 Web Sites - NYTimes.com

The coat of arms of South KoreaImage via WikipediaCyberattack in South Korea Hits 40 Web Sites - NYTimes.com

SEOUL, South Korea — Forty Web sites in South Korea were attacked by a computer virus on Friday, including the official sites of the presidential Blue House, the Foreign Ministry, the country’s biggest bank, the country’s two largest search engines, a major online auction house and some American and Korean military sites.

It was not immediately clear who was behind the attack, but the National Police Agency is investigating the assault, which was discovered by AhnLab, an Internet security firm in Seoul.

Computer analysts said the problems amounted to a so-called denial of service attack, in which multiple computers infected by a software virus try to access targeted Web sites simultaneously. That can overwhelm the sites with a surge of traffic that crashes their servers.

WordPress, one of the largest blog-hosting sites on the Internet, was attacked this way on Thursday, the company said.

A South Korean government official said Friday that there had been “no major damage at all” to computer systems at the Blue House, the executive office and official residence of South Korea’s president.

“We were attacked, but it was defended,” the official said, noting that the Blue House and other agencies had installed security countermeasures after a major cyberattack on South Korean government sites in July 2009. He said the effect of that attack had been “quite chaotic.”

An AhnLab spokesman, Song Chang-min, said the two attacks had similarities, including the targeted sites. AhnLab discovered the virus on Thursday and quickly distributed a free antivirus solution for downloading.

“This wasn’t as serious as 2009, but it still makes servers go down,” Mr. Song said. “Some Web sites going down for even a minute or two, especially commercial sites, can be a big problem. It can be critical.”

Saturday, December 11, 2010

WikiLeaks Attacks Illegal Says Internet Society - PCWorld

WikiLeaks Attacks Illegal Says Internet Society - PCWorld


Takedown attempts against WikiLeaks undermine what the Internet stands for, says the nonprofit group dedicated to open use of the Internet.

Dec 11, 2010 9:11 am
Takedown attempts against WikiLeaks undermine what the Internet stands for, and those responsible should be tracked down and prosecuted, says the Internet Society, a nonprofit group dedicated to the open use of the Internet.
Could Wikileaks spawn troubles for the IT industry?

In its December newsletter, ISOC says it recognizes that WikiLeaks' posting of diplomatic cables is a worry to some, but knocking the site offline is illegal.
"Unless and until appropriate laws are brought to bear to take the wikileaks.org domain down legally, technical solutions should be sought to reestablish its proper presence," ISOC says, "and appropriate actions taken to pursue and prosecute entities (if any) that acted maliciously to take it off the air."
Wikileaks has suffered distributed DoS attacks and in response supporters of WikiLeaks have launched DDoS attacks of their own against Visa, Mastercard, and Amazon.com.
"The Internet Society is founded upon key principles of free expression and non discrimination that are essential to preserve the openness and utility of the Internet," ISOC writes. "We believe that this incident dramatically illustrates that those principles are currently at risk.
"Free expression should not be restricted by governmental or private controls over computer hardware or software, telecommunications infrastructure, or other essential components of the Internet."
WikiLeaks has managed to continue posting the leaked documents and fresh ones with help from mirror sites around the world.
ISOC notes that due to the very resilient design of the Internet, the attempts to keep WikiLeaks offline have failed, but they have had a negative effect on the Internet in general.
The cooperation among several organizations has ensured that the impact on the Wikileaks organizational website has not prevented all access to Wikileaks material," ISOC says. "This further underscores that the removal of a domain is an ineffective tool to suppress communication, merely serving to undermine the integrity of the global Internet and its operation."

Friday, December 03, 2010

WikiLeaks fights to stay online after US company withdraws domain name | Media | guardian.co.uk

WikiLeaks fights to stay online after US company withdraws domain name | Media | guardian.co.uk

Everydns.net says attack against leaks site endangered other customers' service – effectively pushing site off the web

The US was today accused of opening up a dramatic new front against WikiLeaks, effectively "killing" its web address just days after Amazon pulled the site from its servers following political pressure.

The whistleblowers' website went offline for the third time in a week this morning, in the biggest threat to its online presence yet.

Joe Lieberman, chairman of the Senate's committee on homeland security, earlier this week called for any organisation helping sustain WikiLeaks to "immediately terminate" its relationship with them.

On Friday morning, WikiLeaks and the cache of secret diplomatic documents that have proved to be a scourge for governments around the world were only accessible through a string of digits known as a DNS address. The site later re-emerged with a Swiss domain, WikiLeaks.ch.

Julian Assange this morning said the development is an example of the "privatisation of state censorship" in the US and is a "serious problem."

"These attacks will not stop our mission, but should be setting off alarm bells about the rule of law in the United States," he warned.

The California-based internet hosting provider that dropped WikiLeaks at 3am GMT on Friday (10PM EST Thursday), Everydns, says it did so to prevent its other 500,000 customers of being affected by the intense cyber attacks targeted at WikiLeaks.

The site this morning said it had "move[d] to Switzerland", announcing a new domain name – wikileaks.ch, with the Swiss suffix. However, the new address still only points to an IP address, suggesting WikiLeaks has been unable to quickly find a new hosting provider.

The Wikileaks.ch domain name, which only surfaced on Friday morning, is being served by the Swiss Pirate Party. And the routing to it is still being done by everydns.

Late yesterday evening Tableau Software, a company which published data visualisations, pulled one of its images picturing the WikiLeaks diplomatic cables at the request of Senator Lieberman. Writing on the company's blog, Elissa Fink said: "Our decision to remove the data from our servers came in response to a public request by Senator Joe Lieberman, who chairs the Senate Homeland Security Committee, when he called for organisations hosting WikiLeaks to terminate their relationship with the website."

Mark Stephens, the London-based lawyer acting on behalf of Assange, wrote on Twitter after the shutdown: "Pressure appears to have been applied to close the WikiLeaks domain name."

Andre Rickardsson, an expert on computer security at Sweden's Bitsec Consulting, told Reuters: "I don't believe for a second that this has been done by everydns themselves. I think they've been under pressure," he said, apparently referring to US authorities.

A new Germany-based WikiLeaks domain – wikileaks.dd19.de – also appeared on Friday morning, with its data apparently hosted in California. People have also taken to setting up alternative domain names that point to the WikiLeaks address. Robin Fenwick, a UK-based web services director, this morning launched Wikileeks.org.uk – a "joke domain" that points to the WikiLeaks DNS address.

In a statement on its website, the free everydns.net service said that the "distributed denial of service" (DDOS) attacks by unknown hackers – who are trying to knock WikiLeaks off the net – meant that the leaks site was interfering with the service being provided to other users. That in turn meant that WikiLeaks had broken everydns.net's terms of service, and it cut the site off at 3am GMT on Friday (10PM EST Thursday).

DNS services translate a website name, such as guardian.co.uk, into machine-readable "IP quads" – in that case 77.91.249.30, so that http://77.91.249.30 will show the Guardian site. If the DNS fails, the site is only reachable via IP address – but WikiLeaks has not yet provided one via Twitter or other means.

Everydns.net said that the attacks – which have been going on all week, and led the site to temporarily host its services on Amazon's more resilient EC2 "cloud computing" service – "threaten the stability of the EveryDNS.net infrastructure, which enables access to almost 500,000 other websites".

WikiLeaks was given 24 hours' notice of the termination, and everydns said: "Any downtime of the wikileaks.org website has resulted from its failure to use another hosted DNS service provider."

The move comes after several days of WikiLeaks coming under a determined DDOS attack, apparently from hackers friendly to the point of view of the US government, which has disparaged the site's leaking of thousands of US diplomatic cables.

US companies have also come under intense political pressure to remove any connection to, or support for, WikiLeaks. Amazon ended its hosting of the cables on its EC2 cloud computer service earlier this week, but last night insisted in a blogpost that its decision was not due to pressure from Senator Joe Lieberman, who has called for the removal of the data – and who has influenced at least one other US company to withdraw support for WikiLeaks data.

In a blogpost late on Thursday, Amazon said reports that government inquiries prompted it to remove the data were "inaccurate".

Amazon said:

"[Amazon Web Services] does not pre-screen its customers, but it does have terms of service that must be followed. WikiLeaks was not following them. There were several parts they were violating. For example, our terms of service state that "you represent and warrant that you own or otherwise control all of the rights to the content… that use of the content you supply does not violate this policy and will not cause injury to any person or entity". It's clear that WikiLeaks doesn't own or otherwise control all the rights to this classified content. Further, it is not credible that the extraordinary volume of 250,000 classified documents that WikiLeaks is publishing could have been carefully redacted in such a way as to ensure that they weren't putting innocent people in jeopardy."

It noted that:

"When companies or people go about securing and storing large quantities of data that isn't rightfully theirs, and publishing this data without ensuring it won't injure others, it's a violation of our terms of service, and folks need to go operate elsewhere."

But as commentators have pointed out, that stance is contradicted by the fact that Amazon has previously hosted the "war logs" from WikiLeaks which contained data about the US wars in Afghanistan and Iraq.

Connecting to WikiLeaks is presently not possible until it gets a new DNS service. WikiLeaks itself said on Twitter that the ending of DNS services was allegedly due to "claimed mass attacks" and called for further donations to "keep us strong".
Enhanced by Zemanta