01/02/2009

ATTENTION (and tips) ; Jewish and Israeli sites under Cyber attack

The Jawa Report: Pro-Jewish Blogger Account Hacked By Hamas

Ynet news website hacked by “cyber-terrorist” « Aliyah! Step-by ...

http://www.zahal.org/zahal_forum/viewtopic.php?p=735&...

www.nlp-israel.com/default.asp?pn=/index.asp (google for Rm0T@HotmaiL.CoM)

nizozot.shablool.org.il/index.asp

len8

more to follow as zone-h.org is not available we will try to update you on the situation as much as Googling makes it possible (and Google is always too late for that matter).

If you are pro Israel or have links to that site or have a jewish content you MUST expect to be attacked and eventually hacked. Be sure to keep clean backups and de-activate all interactive functions on your site (forums, comments, eventually even site-search) Also be sure that you have the latest version of your OS, your serverware and your website modules (ALL OF THEM). If you are not sure, you go to google and do this - "the version of the software" exploit - for example "apache 3.2" exploit and you will see the attacks and workarounds to defend yourself. If you are a bigger site you MUST do a test yourself with METASPLOIT. This will be the tool by excellence that will be used against you.

You can also limit the danger by excluding IP adresses from countries that you don't want to do business with or didn't have any trustful connections from. If you didn't have any connections from users (not hackers or attackers) from an arabic country or from Korea, Turkey, romania, chile or other countries, than why should you accept them today.

If you are a hoster for israeli or jewish sites you should install a reverse proxy before it and limit all traffic to port 80 and drop all other traffic, point final. Your reverse proxy should be a closed down box like a nokia, eventually with a firewall with application and anti-DDOS modules.

If I was an ISP in Israel I would start blocking the incoming attack traffic at my side.

There is a war going on and you are part of it. You are throwing bombs, they are attacking your cyber-infrastructure with virtual bombs. Cyberwar is here again.

13:34 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment