<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: cyberattacks]]></title>
    <link>http://securityratty.com/tag/cyberattacks</link>
    <description></description>
    <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The DDoS Attack Against Bobbear.co.uk]]></title>
      <link>http://securityratty.com/article/290801c330ee41caec63af5966719ea1</link>
      <guid>http://securityratty.com/article/290801c330ee41caec63af5966719ea1</guid>
      <description><![CDATA[When you get the &quot;privilage&quot; of getting DDoS-ed by a high profile DDoS for hire service used primarily by cybercriminals attacking other cybercriminals, you're officially doing hell of a good job...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SSNmn4J-fjI/AAAAAAAACeM/iaTooLo_YGA/s1600-h/ddos_for_hire_bobbear.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SSNmn4J-fjI/AAAAAAAACeM/iaTooLo_YGA/s200/ddos_for_hire_bobbear.png" /></a>When you get the "privilage" of <a href="http://blogs.zdnet.com/security/?p=2188">getting DDoS-ed by a high profile DDoS for hire service</a> used primarily by cybercriminals attacking other cybercriminals, you're officially doing hell of a good job exposing <a href="http://www.bobbear.co.uk/">money laundering scams</a>.<br />
<br />
The attached screenshot demonstrates how even the relatively more sophisticated countersurveillance approaches taken by a high profile DDoS for hire service can be, and were in fact bypassed, ending up in a real-time peek at how they've dedicated 4 out of their 10 BlackEnergy botnets to Bobbear exclusively.<br />
<br />
Perhaps for the first time ever, I come across a related DoS service offered by the very same vendor - <b>insider sabotage on demand given they have their own people in a particular company/ISP in question</b>. Makes you think twice before considering a minor network glitch what could easily turn into a coordinated insider attack requested by a third-party. Moreover, now that I've also established the connection between this DDoS for hire service and one of the command and control locations (all active and online) of one of the botnets used in the <a href="http://blogs.zdnet.com/security/?p=1670">Russia vs Georgia cyberattack</a>, the <a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">concept of engineering cyber warfare tensions</a> once again proves to be <a href="http://ddanchev.blogspot.com/2008/08/whos-behind-georgia-cyber-attacks.html">a fully realistic one</a>. <br />
<br />
<b>Related posts:</b><br />
<a href="http://blogs.zdnet.com/security/?p=1095">A U.S military botnet in the works</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/ddos-attack-graphs-from-russia-vs.html">DDoS Attack Graphs from Russia vs Georgia's Cyberattacks</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">Botnet on Demand Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT Through Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">Corporate Espionage Through Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">The DDoS Attack Against CNN.com</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A New DDoS Malware Kit in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">Electronic Jihad v3.0 - What Cyber Jihad Isn't</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vAULN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vAULN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ReZlN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ReZlN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Xyy4n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Xyy4n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jkNqn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jkNqn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R21XN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R21XN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vKYRN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vKYRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Mwlxn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Mwlxn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/458461988" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 05:35:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ddos">ddos</category>
      <category domain="http://securityratty.com/tag/ddos attack">ddos attack</category>
      <category domain="http://securityratty.com/tag/ddos-ed">ddos-ed</category>
      <category domain="http://securityratty.com/tag/ddos malware kit">ddos malware kit</category>
      <category domain="http://securityratty.com/tag/ddos attack graphs">ddos attack graphs</category>
      <category domain="http://securityratty.com/tag/hire service">hire service</category>
      <category domain="http://securityratty.com/tag/profile ddos">profile ddos</category>
      <category domain="http://securityratty.com/tag/botnets">botnets</category>
      <category domain="http://securityratty.com/tag/blackenergy botnets">blackenergy botnets</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/458461988/ddos-attack-against-bobbearcouk.html">The DDoS Attack Against Bobbear.co.uk</source>
    </item>
    <item>
      <title><![CDATA[Expert to Obama: Time to Reboot Cyber Security]]></title>
      <link>http://securityratty.com/article/5acc7618798e1355bef187e9a55dc36a</link>
      <guid>http://securityratty.com/article/5acc7618798e1355bef187e9a55dc36a</guid>
      <description><![CDATA[With everything from businesses to the military dependent on computer networks, the Obama White House needs a coherent strategy for coping with cyberattacks. The third installment of the Danger Room...]]></description>
      <content:encoded><![CDATA[With everything from businesses to the military dependent on computer networks, the Obama White House needs a coherent strategy for coping with cyberattacks. The third installment of the Danger Room Debriefs series on security issues facing the new administration features John Arquilla, professor of defense strategies at the U.S. Naval Postgraduate School.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=f67f581a119fe5c150a7c15d303e6e48" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=f67f581a119fe5c150a7c15d303e6e48" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=yNq8N"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=yNq8N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=hifWn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=hifWn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=nBBFn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=nBBFn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Opm0N"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Opm0N" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=1LX2N"><img src="http://feeds.wired.com/~f/wired/politics/security?i=1LX2N" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=2PHJn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=2PHJn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=0xBjn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=0xBjn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=zztjN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=zztjN" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/457543682" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/457543684" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 02:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/obama white house">obama white house</category>
      <category domain="http://securityratty.com/tag/security issues">security issues</category>
      <category domain="http://securityratty.com/tag/defense strategies">defense strategies</category>
      <category domain="http://securityratty.com/tag/coherent strategy">coherent strategy</category>
      <category domain="http://securityratty.com/tag/computer networks">computer networks</category>
      <category domain="http://securityratty.com/tag/military dependent">military dependent</category>
      <category domain="http://securityratty.com/tag/debriefs series">debriefs series</category>
      <category domain="http://securityratty.com/tag/professor">professor</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/457543684/unsolicited-a-3.html">Expert to Obama: Time to Reboot Cyber Security</source>
    </item>
    <item>
      <title><![CDATA[Real-Time OSINT vs Historical OSINT in Russia/Georgia Cyberattacks]]></title>
      <link>http://securityratty.com/article/20a44f5ecd81be809dacc26141c04b6b</link>
      <guid>http://securityratty.com/article/20a44f5ecd81be809dacc26141c04b6b</guid>
      <description><![CDATA[The original real-time OSINT analysis of the Russian cyberattacks against Georgia conducted on the 11th of August, not only closed the Russia vs Georgia cyberwar case for me personally, but also, once...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SPfiGY9ParI/AAAAAAAACT4/qFAdE-rdQZs/s1600-h/georgia_ddos13.JPG.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SPfiGY9ParI/AAAAAAAACT4/9N9uGXoRSB4/s200-R/georgia_ddos13.JPG.png" /></a>The original <a href="http://blogs.zdnet.com/security/?p=1670">real-time OSINT analysis of the Russian cyberattacks against Georgia</a> conducted on the 11th of August, not only closed the Russia vs Georgia cyberwar case for me personally, but also, once again proved that real-time OSINT is invaluable compared to <a href="http://www.scribd.com/doc/6967393/Project-Grey-Goose-Phase-I-Report">historical OSINT using a commercial social network visualization/data mining tool</a> which cannot and will never be able to access the Dark Web, accessible only through real-time <a href="http://ddanchev.blogspot.com/2006/09/cyber-intelligence-cyberint.html">CYBERINT practices</a>.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SPyTGJhYQJI/AAAAAAAACUI/P3h69SzYPm8/s1600-h/georgia_ddos_botnet_cc.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SPyTGJhYQJI/AAAAAAAACUI/LwvYHvdpiFQ/s200-R/georgia_ddos_botnet_cc.png" /></a>The value of real-time OSINT in such <a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">people's information warfare cyberattacks</a> -- with <a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">Chinese hacktivists</a> perfectly aware of the <a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">meaning of the phrase</a> -- relies on the relatively lower operational security (OPSEC) the initiators of a particular campaign apply at the beginning, so that it would scale faster and attract more participants. What the Russian government was doing is fueling the (cyber) fire - literally, since all it takes for a collectivist socienty's cyber militia to organize, is a "call for action" which was taking place at the majority of forums, with the posters of these messages apparently using a spamming application to achieve better efficiency.<br />
<br />
<a href="http://intelfusion.net/wordpress/?p=430">The results</a> from 56 days of <a href="http://intelfusion.net/wordpress/?p=398">Project Grey Goose</a> in action got published last week, a project <a href="http://ddanchev.blogspot.com/2008/09/summarizing-augusts-threatscape.html">I discussed back in August</a>, point out to the bottom of the food chain in the entire campaign - <b>stopgeorgia.ru</b> :<br />
<br />
<a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SPfkXQ-08xI/AAAAAAAACUA/qd9xv7kt2Qw/s1600-h/georgia_ddos8.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SPfkXQ-08xI/AAAAAAAACUA/dnYU_GbeEnw/s200-R/georgia_ddos8.JPG" /></a>"<i>Furthermore, coming up with <a href="http://intelfusion.net/wordpress/?p=398">Social Network analysis of the cyberattacks</a> would produce nothing more but a few fancy graphs of over enthusiastic Russian netizen's distributing the static list of the targets. The real conversations, as always, are <a href="http://blogs.nyu.edu/blogs/agc282/zia/2008/08/intelfusions_sna_of_russian_cy.html">happening in the "Dark Web" limiting the possibilities for open source intelligence</a> using a data mining software. Things changed, OPSEC is slowly emerging as a concept among malicious parties, whenever some of the "calls for action" in the DDoS attacks were posted at mainstream forums, they were immediately removed so that they don't show up in such academic initiatives</i>"<br />
<br />
So what's the bottom line? Nothing that I haven't already pointed out back in August : "<a href="http://voices.washingtonpost.com/securityfix/2008/10/report_russian_hacker_forums_f.html">Report: Russian Hacker Forums Fueled Georgia Cyber Attacks</a>" :<br />
<br />
"<i>But experts say evidence suggests that Russian officials did little to discourage the online assault, which was coordinated through a Russian online forum that appeared to have been prepped with target lists and details about Georgian Web site vulnerabilities well before the two countries engaged in a brief but deadly ground, sea and air war."</i>  <br />
<br />
<a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9117439&amp;source=NLT_PM&amp;nlid=8">Some more comments</a> :<br />
<br />
"<i>Just because there was no smoking gun doesn't mean there's no connection," said Jeff Carr, the principal investigator of Project Grey Goose, a group of around 15 computer security, technology and intelligence experts that investigated the August attacks against Georgia. "I can't imagine that this came together sporadically," he said. "I don't think that a disorganized group can coalesce in 24 hours with its own processes in place. That just doesn't make sense.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SPyW6yXyA5I/AAAAAAAACUQ/roWip-fqbeE/s1600-h/georgia_packet_clearing_house.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SPyW6yXyA5I/AAAAAAAACUQ/7oAwAggiAKE/s200-R/georgia_packet_clearing_house.jpg" /></a>It wouldn't make sense if this was the first time Russian hacktivists are maintaining the same rhythm as real-life events - <a href="http://blogs.zdnet.com/security/?p=1408">which of course isn't</a>.<br />
<br />
Moreover, exactly what would have constituted a "smoking gun" proving that the Russian government was involved in the campaign, remains unknown -- I'm still sticking to my comment regarding <a href="http://georgiaupdate.gov.ge/doc/10006744/CYBERWAR-%20fd_2_new.pdf">the web site defacement creative</a>. If they truly wanted to compromise themselves, they would have cut Georgia off the Internet, at least from the perspective offered by this graph courtesy of the <a href="http://www.pch.net/">Packet Clearing House</a> speaking for their dependability on Russian ISPs. <br />
<br />
As for <a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">the script kiddies</a> at <b>stopgeorgia.ru</b>, <a href="http://74.125.39.104/search?hl=en&amp;q=cache%3Astopgeorgia.ru%2F%3Fpg%3Dser&amp;aq=f&amp;oq=">they were informed enough to feature my research into their "negative public comments section"</a>. To sum up - the "DoS battle stations operational in the name of the "<i><a href="http://www.alexandrasamuel.com/dissertation/pdfs/Samuel-Hacktivism-entire.pdf">Please, input your cause</a></i>" mentality is always going to be there.<b><br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BxRfM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BxRfM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iUQ7M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iUQ7M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9vGjm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9vGjm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=85DIm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=85DIm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mX8FM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mX8FM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XswSM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XswSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wZ9Jm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wZ9Jm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/426491766" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 05:58:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/cyberattacks">cyberattacks</category>
      <category domain="http://securityratty.com/tag/cyber">cyber</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/real-time osint">real-time osint</category>
      <category domain="http://securityratty.com/tag/project">project</category>
      <category domain="http://securityratty.com/tag/project grey goose">project grey goose</category>
      <category domain="http://securityratty.com/tag/forums">forums</category>
      <category domain="http://securityratty.com/tag/cut georgia">cut georgia</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/426491766/real-time-osint-vs-historical-osint-in.html">Real-Time OSINT vs Historical OSINT in Russia/Georgia Cyberattacks</source>
    </item>
    <item>
      <title><![CDATA[Georgian cyberattacks suggest Russian involvement, say researchers]]></title>
      <link>http://securityratty.com/article/85726b2410d9fd5b92e7815fbc10ed1f</link>
      <guid>http://securityratty.com/article/85726b2410d9fd5b92e7815fbc10ed1f</guid>
      <description><![CDATA[The hackers who launched cyberattacks against the one-time Soviet republic of Georgia in August probably had links to the Russian government, though evidence remains scarce, according to a report on...]]></description>
      <content:encoded><![CDATA[The hackers who launched cyberattacks against the one-time Soviet republic of Georgia in August probably had links to the Russian government, though evidence remains scarce, according to a report on the attacks.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f38324534b27016d0a323ddda3b09f7b:rU6qffy2l3fI%2BN4wVgUumnqUJlaW3AshTQqpQ7ZVNwiLVQPNS%2Bk5%2Fy%2FqTZ8jAVqM35UAiRA%2Fh59y'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7232c8fb31acbf4efaf5cd37cdac8371:6qwNiJqTXGLjxq5KSyc1PC6RUyOHVdiClbLHTKYgY4ERBE14ImdKNz7N9CUPaHqKhSKsWYbLXE7mRA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:18a4e9be5eadf5b96200fea04a2c1aef:xBiG%2B3aAu%2BU9kz7DWLsTWtYvCRi%2BDq8l1n7cDtHsMw6QFocaIHDoNSXYNbu00O7SGWBzLOgzuXlkXA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6d8d0e3ce01f301e1347d69cf4709317:eyWYAAQiUWN%2FDL3v9CEms0MKfRQmg5SPlbG457yJ7h9A1xpsksO%2FR1ToukaUni3nWebbiQj92SExYQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=c693462edfa499abde57d3c3c9e586a4"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=c693462edfa499abde57d3c3c9e586a4"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=c693462edfa499abde57d3c3c9e586a4" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/evidence remains scarce">evidence remains scarce</category>
      <category domain="http://securityratty.com/tag/one-time soviet republic">one-time soviet republic</category>
      <category domain="http://securityratty.com/tag/cyberattacks">cyberattacks</category>
      <category domain="http://securityratty.com/tag/russian government">russian government</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/august">august</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=c693462edfa499abde57d3c3c9e586a4">Georgian cyberattacks suggest Russian involvement, say researchers</source>
    </item>
    <item>
      <title><![CDATA[Experts: Georgian cyberattacks suggest Russian involvement]]></title>
      <link>http://securityratty.com/article/abb52ade1e924d125a1385af4dac00b3</link>
      <guid>http://securityratty.com/article/abb52ade1e924d125a1385af4dac00b3</guid>
      <description><![CDATA[The hackers who launched cyberattacks against the former Soviet republic of Georgia two months ago probably had links to the Russian government, even though no hard evidence has been uncovered of...]]></description>
      <content:encoded><![CDATA[The hackers who launched cyberattacks against the former Soviet republic of Georgia two months ago probably had links to the Russian government, even though no hard evidence has been uncovered of official involvement, a report by an all-volunteer group of experts said Friday.]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hard evidence">hard evidence</category>
      <category domain="http://securityratty.com/tag/official involvement">official involvement</category>
      <category domain="http://securityratty.com/tag/months ago">months ago</category>
      <category domain="http://securityratty.com/tag/cyberattacks">cyberattacks</category>
      <category domain="http://securityratty.com/tag/russian government">russian government</category>
      <category domain="http://securityratty.com/tag/experts">experts</category>
      <category domain="http://securityratty.com/tag/soviet republic">soviet republic</category>
      <category domain="http://securityratty.com/tag/friday">friday</category>
      <category domain="http://securityratty.com/tag/all-volunteer">all-volunteer</category>
      <source url="http://www.networkworld.com/news/2008/101708-experts-georgian-cyberattacks-suggest-russian.html?fsrc=rss-security">Experts: Georgian cyberattacks suggest Russian involvement</source>
    </item>
    <item>
      <title><![CDATA[DDoS Attack Graphs from Russia vs Georgia's Cyberattacks]]></title>
      <link>http://securityratty.com/article/dc1b9df0e6d3f3f43b5c110a78a3be89</link>
      <guid>http://securityratty.com/article/dc1b9df0e6d3f3f43b5c110a78a3be89</guid>
      <description><![CDATA[Part of Georgia's information warfare campaign aiming to minimize the bandwidth impact on its de-facto media platforms such as the web site of their Ministry of Foreign Affairs, I've just received a...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SPZIdRd6kMI/AAAAAAAACTA/fkKSEaSfIXc/s1600-h/ddos_attack_graph_georgia_russia.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SPZIdRd6kMI/AAAAAAAACTA/KRKwlE_hA04/s200-R/ddos_attack_graph_georgia_russia.JPG" /></a>Part of <a href="http://www.mediachannel.org/wordpress/2008/08/14/the-cnn-effect-georgia-schools-russia-in-information-warfare/">Georgia's information warfare campaign</a> aiming to minimize the bandwidth impact on its de-facto media platforms such as the web site of&nbsp; their Ministry of Foreign Affairs, <a href="http://georgiaupdate.gov.ge/doc/10006744/CYBERWAR-%20fd_2_new.pdf">I've just received a report</a> part of Georgia's "<i>Russian Invasion of Georgia</i>" series entitled "<i>Russian Cyberwar on Georgia</i>", which is quoting me on page 4 in regard to the "too good to be courtesy of <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9112443&amp;taxonomyId=82&amp;intsrc=kc_top">Russia's cyber militia</a>" creative that appeared on the defaced Georgian President's web site. The report also includes DDoS attack graphs and related details worth going through : <br />
<br />
"<i>The last large cyberattack took place on 27 August. After that, there have been no serious attacks on Georgian cyberspace. By that is meant that minor attacks are still continuing but these are indistinguishable from regular traffic and can certainly be attributed to regular civilians. On 27 August, at approximately 16:18 (GMT +3) a DDoS attack against the Georgian websites was launched. The main target was the Georgian Ministry of Foreign Affairs. The attacks peaked at approx 0,5 million network packets per second, and up to 200–250 Mbits per second in bandwidth (see attached graphs). The graphs represent a 5-minute average: actual peaks were higher.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SPZI1-qp3kI/AAAAAAAACTI/-xuWJWJj9gg/s1600-h/ddos_attack_graph_georgia_russia1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SPZI1-qp3kI/AAAAAAAACTI/Fef2CL-KlH4/s200-R/ddos_attack_graph_georgia_russia1.JPG" /></a><i>The attacks mainly consisted of HTTP queries to the http://mfa.gov.ge website. These were requests for the main page script with randomly generated parameters. These requests were generated to overload the web server in a way where every single request would need significant CPU time. The initial wave of the attack disrupted services for some Georgian websites. The services became slow and unresponsive. This was due to the load on the servers by these requests. As you see from the graphs above the attacks started to wind down after most of the attackers were successfully blocked. The latest attack may have been initiated as a response to the media coverage on the Russian cyber attacks.</i>"<br />
<br />
In case you're interested in more factual evidence about what was happening at the particular moment in time, go through the following assessment - "<a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a>", as well as through the following posts - "<a href="http://ddanchev.blogspot.com/2008/08/russia-vs-georgia-cyber-attack.html">The Russia vs Georgia Cyber Attack</a>"; "<a href="http://ddanchev.blogspot.com/2008/08/whos-behind-georgia-cyber-attacks.html">Who's Behind the Georgia Cyber Attacks?</a>"; "<a href="http://blogs.zdnet.com/security/?p=1533">Georgia President’s web site under DDoS attack from Russian hackers</a>".<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OctdM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OctdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YNEdM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YNEdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i8cZm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i8cZm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Qfnnm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Qfnnm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gCSDM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gCSDM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TEWEM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TEWEM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=SVKNm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=SVKNm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/421908026" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 11:01:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/georgia cyber attack">georgia cyber attack</category>
      <category domain="http://securityratty.com/tag/ddos attack">ddos attack</category>
      <category domain="http://securityratty.com/tag/russian cyber attacks">russian cyber attacks</category>
      <category domain="http://securityratty.com/tag/graphs">graphs</category>
      <category domain="http://securityratty.com/tag/russia">russia</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/421908026/ddos-attack-graphs-from-russia-vs.html">DDoS Attack Graphs from Russia vs Georgia's Cyberattacks</source>
    </item>
    <item>
      <title><![CDATA[Information Assurance Education: A Work In Progress]]></title>
      <link>http://securityratty.com/article/cd2b253bc91e0e99b5809e677391c0cd</link>
      <guid>http://securityratty.com/article/cd2b253bc91e0e99b5809e677391c0cd</guid>
      <description><![CDATA[The recognition that we need improved computer security education has increased over the past several years. Recent cyberattacks in Georgia and Estonia exemplify the new threats faced by economies...]]></description>
      <content:encoded><![CDATA[The recognition that we need improved computer security education has increased over the past several years. Recent cyberattacks in Georgia and Estonia exemplify the new threats faced by economies that rely on the Internet. Thus, more people see the need to protect cyberspace—which translates into improving computer security in all aspects of computer use—as crucial for everyone, not merely for those who work with technology. In this column, we reflect on emerging opportunities and challenges in instruction as well as the need for increasing the partnerships among industry, government, and academia to foster mutual understanding of challenges and joint participation in solutions.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=7d1fe7bdf14bc24c805d7320845ac7e9" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=7d1fe7bdf14bc24c805d7320845ac7e9" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer security education">computer security education</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/computer useas crucial">computer useas crucial</category>
      <category domain="http://securityratty.com/tag/joint participation">joint participation</category>
      <category domain="http://securityratty.com/tag/protect cyberspacewhich">protect cyberspacewhich</category>
      <category domain="http://securityratty.com/tag/challenges">challenges</category>
      <category domain="http://securityratty.com/tag/foster mutual">foster mutual</category>
      <category domain="http://securityratty.com/tag/threats faced">threats faced</category>
      <category domain="http://securityratty.com/tag/recent cyberattacks">recent cyberattacks</category>
      <source url="http://www.pheedo.com/click.phdo?i=7d1fe7bdf14bc24c805d7320845ac7e9">Information Assurance Education: A Work In Progress</source>
    </item>
    <item>
      <title><![CDATA[Two Europeans charged in U.S. over DDoS attacks]]></title>
      <link>http://securityratty.com/article/50344ed7143e5c88fdce42097172b5ee</link>
      <guid>http://securityratty.com/article/50344ed7143e5c88fdce42097172b5ee</guid>
      <description><![CDATA[Two European men have been indicted for allegedly orchestrating cyberattacks against two Web sites, a continuation of the first successful U.S. investigation ever into distributed denial-of-service...]]></description>
      <content:encoded><![CDATA[Two European men have been indicted for allegedly orchestrating cyberattacks against two Web sites, a continuation of the first successful U.S. investigation ever into distributed denial-of-service attacks, according to the U.S. Department of Justice.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=17978?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=17978?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/cyberattacks">cyberattacks</category>
      <category domain="http://securityratty.com/tag/successful">successful</category>
      <category domain="http://securityratty.com/tag/continuation">continuation</category>
      <category domain="http://securityratty.com/tag/justice">justice</category>
      <category domain="http://securityratty.com/tag/european">european</category>
      <category domain="http://securityratty.com/tag/investigation">investigation</category>
      <source url="http://www.networkworld.com/news/2008/100308-two-europeans-charged-in-us.html?fsrc=rss-security">Two Europeans charged in U.S. over DDoS attacks</source>
    </item>
    <item>
      <title><![CDATA[Many computer users lack basic security precautions, survey says]]></title>
      <link>http://securityratty.com/article/9902eac4654dc6a709d53538753b3ae2</link>
      <guid>http://securityratty.com/article/9902eac4654dc6a709d53538753b3ae2</guid>
      <description><![CDATA[Although businesses and government agencies are getting better at cybersecurity, many U.S. computer users still fail to take basic precautions to protect against cyberattacks, a survey...]]></description>
      <content:encoded><![CDATA[Although businesses and government agencies are getting better at cybersecurity, many U.S. computer users still fail to take basic precautions to protect against cyberattacks, a survey says.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c30a021b0bbdbf538fe867d430519874:O6ex%2BXGUCg%2FGoYyNOiqXkbTM9rvrl8XznijuOQS7KZTNJ433zT2E8UkFn0J6QR9w2DBGnnJ1D91u'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d9feb4f4901a8e19cc0a2976a0e90326:cmK5ysI6WVRYh0kL48m3bGA46Wda9SL5eqKb1Z%2FOOl5JGKoOw8xZmcE8YRO2fx30JqEbQk%2Be1c3GLA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ca60d9b4946c37552db2a67411365e69:iQVkaDXGEjk3Z9FQfP0XD4pPpHnWYCSYY8apKbfxENA%2Bnzmq2q8l6YTLUYlzvCkNdX2oKjOULjRRMg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f34ba24fa4071a4ff4d75864eab6ebac:1L9%2F5fqoLjDcKGOY0e3eW42AUxHurayn3ezAit5yJft2Wh7TSE0%2Byl3y16SerN%2B%2BQ5lniGSzg4W83Q%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=a977ddde3abe58a168b096ba5bb27da3" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a977ddde3abe58a168b096ba5bb27da3" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer users">computer users</category>
      <category domain="http://securityratty.com/tag/basic precautions">basic precautions</category>
      <category domain="http://securityratty.com/tag/government agencies">government agencies</category>
      <category domain="http://securityratty.com/tag/survey">survey</category>
      <category domain="http://securityratty.com/tag/fail">fail</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <category domain="http://securityratty.com/tag/cyberattacks">cyberattacks</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <category domain="http://securityratty.com/tag/cybersecurity">cybersecurity</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=a977ddde3abe58a168b096ba5bb27da3">Many computer users lack basic security precautions, survey says</source>
    </item>
    <item>
      <title><![CDATA[Survey: Many computer users lack basic security precautions]]></title>
      <link>http://securityratty.com/article/6bc2869a235c6efc6b34c541bfb781aa</link>
      <guid>http://securityratty.com/article/6bc2869a235c6efc6b34c541bfb781aa</guid>
      <description><![CDATA[Cybersecurity efforts in the U.S. government and many businesses are improving, but many individual computer users still don't take basic precautions against cyberattacks, cybersecurity experts said...]]></description>
      <content:encoded><![CDATA[Cybersecurity efforts in the U.S. government and many businesses are improving, but many individual computer users still don't take basic precautions against cyberattacks, cybersecurity experts said Thursday.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=314?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=314?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/individual computer users">individual computer users</category>
      <category domain="http://securityratty.com/tag/basic precautions">basic precautions</category>
      <category domain="http://securityratty.com/tag/cybersecurity experts">cybersecurity experts</category>
      <category domain="http://securityratty.com/tag/cybersecurity efforts">cybersecurity efforts</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <category domain="http://securityratty.com/tag/cyberattacks">cyberattacks</category>
      <category domain="http://securityratty.com/tag/thursday">thursday</category>
      <source url="http://www.networkworld.com/news/2008/100208-survey-many-computer-users-lack.html?fsrc=rss-security">Survey: Many computer users lack basic security precautions</source>
    </item>
  </channel>
</rss>
