<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Tikun Olam Suffers DOS Attack After Exposing Former IDF Torturer</title>
	<atom:link href="http://www.richardsilverstein.com/tikun_olam/2010/07/29/israeli-hackers-attack-tikun-olam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.richardsilverstein.com/tikun_olam/2010/07/29/israeli-hackers-attack-tikun-olam/</link>
	<description>Essays on politics, culture and ideas about Israeli-Arab peace and world music</description>
	<lastBuildDate>Sun, 12 Feb 2012 22:52:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: medawar</title>
		<link>http://www.richardsilverstein.com/tikun_olam/2010/07/29/israeli-hackers-attack-tikun-olam/comment-page-1/#comment-138341</link>
		<dc:creator>medawar</dc:creator>
		<pubDate>Mon, 02 Aug 2010 10:16:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.richardsilverstein.com/tikun_olam/?p=14743#comment-138341</guid>
		<description>Nearly all the attacks are made possible by the probably needless complexity of the software environment on what are, after all, meant to be personal computers.

But I speak as one who had to be convinced of the need for CPM, having learned on machine-code-only machines with just a &quot;monitor&quot; programme in EPROM somewhere.

A DNS attack is a different thing from a DoS attack: in the latter they are just using many machines (usually, other people&#039;s machines infected with a virus) to swamp the site, although this usually involves attempts to send commands or requests that tie up a lot of the site&#039;s time or crash its server in some way.

A DNS attack is when the DNS databases that let your machine find Richard&#039;s site, are hacked so they direct your computer to a different server, which has a copy of his content on, but which records your comments and more particularly, your IP, for future reference. That&#039;s not so bad, but such fake sites are also normally designed to fire malware back at your computer to drag information out of it, or to send on malware to everyone in your address book and so forth.

So a DNS attack is more malicious, and more subtle, than a DoS attack.

The Firestarter firewall for Ubuntu machines reacts instantly to any change in the DNS server your ISP is using during a session. This is good.</description>
		<content:encoded><![CDATA[<p>Nearly all the attacks are made possible by the probably needless complexity of the software environment on what are, after all, meant to be personal computers.</p>
<p>But I speak as one who had to be convinced of the need for CPM, having learned on machine-code-only machines with just a &#8220;monitor&#8221; programme in EPROM somewhere.</p>
<p>A DNS attack is a different thing from a DoS attack: in the latter they are just using many machines (usually, other people&#8217;s machines infected with a virus) to swamp the site, although this usually involves attempts to send commands or requests that tie up a lot of the site&#8217;s time or crash its server in some way.</p>
<p>A DNS attack is when the DNS databases that let your machine find Richard&#8217;s site, are hacked so they direct your computer to a different server, which has a copy of his content on, but which records your comments and more particularly, your IP, for future reference. That&#8217;s not so bad, but such fake sites are also normally designed to fire malware back at your computer to drag information out of it, or to send on malware to everyone in your address book and so forth.</p>
<p>So a DNS attack is more malicious, and more subtle, than a DoS attack.</p>
<p>The Firestarter firewall for Ubuntu machines reacts instantly to any change in the DNS server your ISP is using during a session. This is good.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Silverstein</title>
		<link>http://www.richardsilverstein.com/tikun_olam/2010/07/29/israeli-hackers-attack-tikun-olam/comment-page-1/#comment-138309</link>
		<dc:creator>Richard Silverstein</dc:creator>
		<pubDate>Mon, 02 Aug 2010 04:35:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.richardsilverstein.com/tikun_olam/?p=14743#comment-138309</guid>
		<description>Duly noted.  I come from the DOS age as well.  But I&#039;ve never suffered a DoS attack, so the lingo is a bit new to me.</description>
		<content:encoded><![CDATA[<p>Duly noted.  I come from the DOS age as well.  But I&#8217;ve never suffered a DoS attack, so the lingo is a bit new to me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ruth</title>
		<link>http://www.richardsilverstein.com/tikun_olam/2010/07/29/israeli-hackers-attack-tikun-olam/comment-page-1/#comment-138296</link>
		<dc:creator>Ruth</dc:creator>
		<pubDate>Mon, 02 Aug 2010 00:12:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.richardsilverstein.com/tikun_olam/?p=14743#comment-138296</guid>
		<description>Could you make that DoS?  It&#039;s very confusing for us oldtimers who used DOS (Disk Operating System) before Windows... For a bit there I thought someone had revived DOS or I was in the wrong century.</description>
		<content:encoded><![CDATA[<p>Could you make that DoS?  It&#8217;s very confusing for us oldtimers who used DOS (Disk Operating System) before Windows&#8230; For a bit there I thought someone had revived DOS or I was in the wrong century.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Medawar</title>
		<link>http://www.richardsilverstein.com/tikun_olam/2010/07/29/israeli-hackers-attack-tikun-olam/comment-page-1/#comment-138289</link>
		<dc:creator>Medawar</dc:creator>
		<pubDate>Sun, 01 Aug 2010 16:13:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.richardsilverstein.com/tikun_olam/?p=14743#comment-138289</guid>
		<description>Indymedia UK, meanwhile, does the same thing on behalf of the powers that wannabe.</description>
		<content:encoded><![CDATA[<p>Indymedia UK, meanwhile, does the same thing on behalf of the powers that wannabe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Silverstein</title>
		<link>http://www.richardsilverstein.com/tikun_olam/2010/07/29/israeli-hackers-attack-tikun-olam/comment-page-1/#comment-138270</link>
		<dc:creator>Richard Silverstein</dc:creator>
		<pubDate>Sun, 01 Aug 2010 07:48:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.richardsilverstein.com/tikun_olam/?p=14743#comment-138270</guid>
		<description>No one is blocked at least not for the reason given in that msg.  The error message is generic and didn&#039;t describe the reality of the situation which was a DOS attack.</description>
		<content:encoded><![CDATA[<p>No one is blocked at least not for the reason given in that msg.  The error message is generic and didn&#8217;t describe the reality of the situation which was a DOS attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Silverstein</title>
		<link>http://www.richardsilverstein.com/tikun_olam/2010/07/29/israeli-hackers-attack-tikun-olam/comment-page-1/#comment-138269</link>
		<dc:creator>Richard Silverstein</dc:creator>
		<pubDate>Sun, 01 Aug 2010 07:47:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.richardsilverstein.com/tikun_olam/?p=14743#comment-138269</guid>
		<description>Relax, most of the insults were directed at me, not you.  But if you start digging up good original info that embarrasses the powers that be then you too can be smeared in the pages of Rotter.</description>
		<content:encoded><![CDATA[<p>Relax, most of the insults were directed at me, not you.  But if you start digging up good original info that embarrasses the powers that be then you too can be smeared in the pages of Rotter.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Silverstein</title>
		<link>http://www.richardsilverstein.com/tikun_olam/2010/07/29/israeli-hackers-attack-tikun-olam/comment-page-1/#comment-138267</link>
		<dc:creator>Richard Silverstein</dc:creator>
		<pubDate>Sun, 01 Aug 2010 07:43:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.richardsilverstein.com/tikun_olam/?p=14743#comment-138267</guid>
		<description>An incomplete IP address doesn&#039;t help us much even though I understand this is how things work in England (not here or in Israel I gather where we have full IPs).  A Rotter member posted in that thread that the IP address 212.143.134.129 belongs to the Israel Broadcasting Authority.  This may have to do with the fact that many journalists are researching the story and all these referrals appear to be an attack, but aren&#039;t.</description>
		<content:encoded><![CDATA[<p>An incomplete IP address doesn&#8217;t help us much even though I understand this is how things work in England (not here or in Israel I gather where we have full IPs).  A Rotter member posted in that thread that the IP address 212.143.134.129 belongs to the Israel Broadcasting Authority.  This may have to do with the fact that many journalists are researching the story and all these referrals appear to be an attack, but aren&#8217;t.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: medawar</title>
		<link>http://www.richardsilverstein.com/tikun_olam/2010/07/29/israeli-hackers-attack-tikun-olam/comment-page-1/#comment-138262</link>
		<dc:creator>medawar</dc:creator>
		<pubDate>Sun, 01 Aug 2010 06:30:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.richardsilverstein.com/tikun_olam/?p=14743#comment-138262</guid>
		<description>The attack on you followed a link being put on rotter.net, my conclusion is that there&#039;s a computer scanning the internet for &quot;Doran Zahavi&quot; and putting the links up on rotter.net far automatically, or least it&#039;s fully automatic on Saturday mornings. (Happened MUCH too fast to be someone surfing and finding it by chance!)

The IP is incomplete because sitemeter doesn&#039;t tell non-law-enforcement people that last group (at least not in the UK, due to data protection act.) But it allows you the ISP and location.
There&#039;s no question that if you give the relevant sitemeter page to the FBI, NETCU or SOCA, they can get the whole IP from the ISPs it went through to get there, though they won&#039;t discuss the details.

Once rotter.net had my post, it then put up all the comments I posted here, again, automatically within a few seconds. It didn&#039;t catch on to other posts of mine on the same subject, that didn&#039;t contain &quot;Doron Zahavi&quot; until one of the RSS subscribers came back and manually surfed through my site.

So, about nine tenths of it is robotic. 
What happened to my site wasn&#039;t exactly an attack, just the consequence of the RSS feeds going to a lot of people whose computers all verified the link at the same time.
But whatever put your site down was evidently more than this. (The RSS effect doesn&#039;t last for very long.)

Also, yesterday, when you were inactive, there were several occasions throughout the day when DNS servers in both the UK and Canada briefly lost their ability to find your site. Your tech person needs to watch this, because a DNS attack would imply an aspiration to put up a clone of this site and harvest the FULL IPs of all your regular readers and comment-writers.</description>
		<content:encoded><![CDATA[<p>The attack on you followed a link being put on rotter.net, my conclusion is that there&#8217;s a computer scanning the internet for &#8220;Doran Zahavi&#8221; and putting the links up on rotter.net far automatically, or least it&#8217;s fully automatic on Saturday mornings. (Happened MUCH too fast to be someone surfing and finding it by chance!)</p>
<p>The IP is incomplete because sitemeter doesn&#8217;t tell non-law-enforcement people that last group (at least not in the UK, due to data protection act.) But it allows you the ISP and location.<br />
There&#8217;s no question that if you give the relevant sitemeter page to the FBI, NETCU or SOCA, they can get the whole IP from the ISPs it went through to get there, though they won&#8217;t discuss the details.</p>
<p>Once rotter.net had my post, it then put up all the comments I posted here, again, automatically within a few seconds. It didn&#8217;t catch on to other posts of mine on the same subject, that didn&#8217;t contain &#8220;Doron Zahavi&#8221; until one of the RSS subscribers came back and manually surfed through my site.</p>
<p>So, about nine tenths of it is robotic.<br />
What happened to my site wasn&#8217;t exactly an attack, just the consequence of the RSS feeds going to a lot of people whose computers all verified the link at the same time.<br />
But whatever put your site down was evidently more than this. (The RSS effect doesn&#8217;t last for very long.)</p>
<p>Also, yesterday, when you were inactive, there were several occasions throughout the day when DNS servers in both the UK and Canada briefly lost their ability to find your site. Your tech person needs to watch this, because a DNS attack would imply an aspiration to put up a clone of this site and harvest the FULL IPs of all your regular readers and comment-writers.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Served from: www.richardsilverstein.com @ 2012-02-12 15:23:26 by W3 Total Cache -->
