<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SocialB &#187; security</title>
	<atom:link href="http://whitneymayparker.com/blog/index.php/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://whitneymayparker.com/blog</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Fri, 02 Apr 2010 22:51:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Network Solutions Websites Suffer Wide-Spread Hack</title>
		<link>http://whitneymayparker.com/blog/index.php/2010/01/network-solutions-websites-suffer-wide-spread-hack/</link>
		<comments>http://whitneymayparker.com/blog/index.php/2010/01/network-solutions-websites-suffer-wide-spread-hack/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 00:09:56 +0000</pubDate>
		<dc:creator>Whitney</dc:creator>
				<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[website hosting]]></category>
		<category><![CDATA[Network Solutions]]></category>
		<category><![CDATA[Turkish hackers]]></category>

		<guid isPermaLink="false">http://whitneymayparker.com/blog/?p=43</guid>
		<description><![CDATA[Diplomatic row between Israel and Turkey may have sparked the cyber attack, which has targeted a large number of Israeli and Western websites This weekend an unknown number of websites hosted by the widely-used Network Solutions hosting provider were &#8220;hacked&#8221; by a group claiming support for the Palestinian cause. Websites that were targeted had their [...]]]></description>
			<content:encoded><![CDATA[<h2>Diplomatic row between Israel and Turkey may have sparked the cyber attack, which has targeted a large number of Israeli and Western websites</h2>
<p><img class="floatleft prettyBox" title="Hacked Website Image Capture " src="http://mustell.ath.cx/images/capture.png" alt="Hacked Website Image Capture" width="404" height="227" />This weekend an unknown number of websites hosted by the widely-used Network Solutions hosting provider were &#8220;hacked&#8221; by a group claiming support for the Palestinian cause. Websites that were targeted had their homepages replaced with a very simple website (sometimes called &#8220;defacing&#8221;), generally they were black, with some flags, and messages in both Turkish and English. Some have pictures, and I saw several variations like the one to the left. There are some speculative reports that there is &#8220;drive-by malware&#8221; installed on these pages that will automatically try to download when you visit the site, so be cautious about visiting sites hosted by Network Solutions in the coming weeks!</p>
<p>Unfortunately, Network Solutions does not seem to be out in front of the problem, although they have posted an announcement to their telephone helpline and to their technical support forum telling customers how to restore their website to a saved back up and change all of their passwords. My suspicion however, is that weak passwords are not the root cause of the problem.  On one of my client&#8217;s websites, we changed the passwords four times in less than three days, and the site has continued to be hacked repeatedly throughout the last three days. (<em>Disclaimer: I would not recommend Network Solutions as a host to any client. My preferred hosts remain: Rochen, GoDaddy and Rackspace.</em>)</p>
<p>The Associated Press ran a story earlier today noting that the London-based Jewish Chronicle was also attacked this weekend by what appears to be the same group of Turkish hackers. Here&#8217;s the story that ran today (emphasis is my own):</p>
<blockquote><p>Britain&#8217;s flagship Jewish newspaper has been attacked by Turkish-speaking hackers.<em>Jewish Chronicle </em>Editor Stephen Pollard says his paper&#8217;s Web site was replaced by anti-Semitic messages for several hours.</p>
<p>The site was still unavailable early Monday. A previous version of the site cached by Google ( GOOG &#8211; news &#8211; people ) showed a Palestinian flag and anti-Semitic statements in Turkish and English.</p>
<p><em><strong>Pollard said the attack could be related to the diplomatic feud that erupted between Israel and Turkey last week.</strong></em></p>
<p><em><strong>The Turkish government was outraged when Israel&#8217;s deputy foreign minister denied their ambassador a handshake and forced him to sit on a low sofa as the cameras rolled. Israel has since apologized.</strong></em></p></blockquote>
<p><em>The Jerusalem Post</em> added the following commentary:</p>
<blockquote><p>Replete with anti-Semitic conspiracy theories combined with hard-core jihadi rhetoric, the Turkish &#8220;Palestinian Mujaheeds&#8221; group responsible for bringing down the Web site of Britain&#8217;s <em>Jewish Chronicle</em> on Sunday can be seen as part of a growing network of sophisticated and coordinated Islamist hackers.</p>
<div>
<div>
<p><img style="float: left; margin-right: 10px;" title="The Website of the Jewish..." src="http://www.jpost.com/servlet/Satellite?blobcol=urlimage&amp;blobheader=image%2Fjpeg&amp;blobheadername1=Cache-Control&amp;blobheadervalue1=max-age%3D420&amp;blobkey=id&amp;blobtable=JPImage&amp;blobwhere=1263147918256&amp;cachecontrol=5%3A0%3A0+*%2F*%2F*&amp;ssbinary=true" border="1" alt="The Website of the Jewish..." width="248" height="164" /></p>
<div>
<p>The Website of the <em>Jewish Chronicle</em> as it looked on Monday morning.</p>
</div>
</div>
</div>
<p>Turkish hackers are notorious for playing a major role in coordinated international Web attacks, which usually come in response to international incidents perceived as affronts by the hackers.</p>
<p>&#8220;Aren&#8217;t you ashamed of giving tolerance to the Jewish who is the main actor of wars [sic],&#8221; read the message by the Palestinian Mujaheeds on the <em>Chronicle</em>&#8216;s Web site.</p>
<p>&#8220;The beginning is Allah, the end is Allah,&#8221; the message said. After Operation Cast Lead in Gaza last year, Turkish hackers took part in a coordinated assault on Israeli and Western Web sites.</p>
<p>This type of attack is more sophisticated than a denial of service attack, in which Trojan programs planted in the computers of unsuspecting Web users direct their hosts to flood a targeted Web address with traffic, overwhelming the server and knocking it offline for a period of time.</p></blockquote>
<p><em>The Jewish Chronicle </em>is also hosted on the Network Solutions servers, according to the Whois registry. Another Jewish news website, Jerusalemonline.com was affected last week, although their site is hosted at GoDaddy.com. I&#8217;m unaware of any other sites hosted by GoDaddy.com that have been affected.</p>
<p>* Update : Network Solutions says &#8220;hundreds&#8221; of their sites were affected (<a href="http://www.krebsonsecurity.com/2010/01/hundreds-of-network-solutions-sites-hacked/">read Brian Krebs here</a>), hosted on their shared Unix servers using a &#8220;file inclusion&#8221; technique.</p>
<p>* Unrelated? : There&#8217;s a great deal of international hacking in the news this week &#8212; <a href="http://www.nytimes.com/2010/01/19/technology/companies/19google.html">Google e-mail accounts owned by U.S. journalists were hacked in China</a>;  <a href="http://www.telegraph.co.uk/news/worldnews/asia/china/7033319/Chinese-search-engine-Baidu-sues-US-company-over-hacking-attack.html">China&#8217;s search engine Baidu is suing the U.S. webhost Register.com for a supposed Iranian cyber attack against the website</a> (<a href="http://www.worldbulletin.net/news_detail.php?id=51526">the same &#8220;Iranian Cyber Army&#8221; attack that knocked out Twitter in December</a>); and <a href="http://www.asianetindia.com/news/china-claims-victims-hackers_121258.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KeralaOnline+%28Kerala+Online%29">India is complaining about China&#8217;s cyber attacks against their government computers</a>.</p>
<p><em> If any one out there thinks the age of net-warfare isn&#8217;t upon us, think again!</em></p>
<p><img src="file:///C:/Users/Whitney/AppData/Local/Temp/moz-screenshot.png" alt="" /></p>
]]></content:encoded>
			<wfw:commentRss>http://whitneymayparker.com/blog/index.php/2010/01/network-solutions-websites-suffer-wide-spread-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

