Feeds

Scientology website shielded against DDoS attack

After the storm

Protecting users from Firesheep and other Sidejacking attacks with SSL

Updated The Church of Scientology has restored it website to normal after a campaign of denial of service attacks prompted it to use DDoS mitigation service Prolexic.

Web sites associated with the Church of Scientology were intermittently unavailable last week after an internet group calling itself Anonymous declared war on the controversial organisation.

Anonymous justified its actions by alleging the Church of Scientology has misused copyright and trademark law in censoring criticism against the church. The campaign was sparked off by the church's attempts to remove a promotional video featuring Scientologist Tom Cruise from YouTube. The clip shows a video from Cruise's Freedom Medal ceremony from late 2004 in which the actor speaks with (frankly scary) intensity about the responsibilities of being a Scientologist. After the Church of Scientology lodged a copyright infringement complaint, YouTube pulled the video, but the material has since resurfaced on Gawker.com.

As well as directing sympathisers to use denial of service software, Anonymous is calling on its members to make nuisance calls, host Scientology documents the Church claims as protected by copyright, and fax black pages to the Church's fax machines in an effort to waste ink. Longer established critics of Scientology have criticised the actions of Anonymous as counterproductive.

Wired reports that miscommunication between hactivists briefly resulted in a Dutch school web site becoming a target of attack on Friday.

The progress of the attack was closely monitored by network security tools firm Arbor Networks. Dr Jose Nazario, senior security engineer at Arbor Networks, said threats to attack the websites associated with the Church of Scientology were acted out.

The waves of ongoing attacks witnessed by Arbor lasted an average of 30 minutes consuming an average of 168 Mbps and peaking out at 220 Mbps.

"This is on the high side of an attack, but significantly smaller than the largest ones we commonly see nowadays," writes Nazario. "The attacks used in this case are common, garden variety DDoS attacks."

Danny McPherson, chief research officer at Arbor, added that the attacks were ongoing though diminishing in intensity. He stated that the ferocity of the attacks was on the same level as those thrown against Estonia last year. The technical sophistication applied to the attacks is fairly basic. Networks of compromised machines are being used in some cases, he added.

"The attacks are mostly brute force flooding. Some of the attacks start and stop from a bank of machines at exactly the same time so there have definitely been bots employed," McPherson told El Reg.

In response to the attacks, the Church of Scientology moved its systems over to a managed service run by security firm Prolexic, Netcraft reports.

The Church of Scientology has issued statements suggesting that controversy over the Tom Cruise video had increased traffic to its Web site. It has also said that the video was taken out of context. It did not comment directly on last week's denial of service attacks.

As the Church previously announced, the pirated and edited excerpts of Mr. Cruise were contained in an official Church event in 2004, an event attended by 5,000 Scientologists and their guests and further available for viewing in any Church of Scientology world over. Having presented these selective and out-of-context excerpts with the intent of creating both controversy and ridicule, nevertheless resulted in people searching for an visiting Church of Scientology websites as evidenced by “most searched for” lists of various search engines. Those wishing to find out the Church of Scientology’s views and to gain context of the video have the right to search official Church websites if they so desire.

A search on YouTube reveals other clips from the now famous Scientology Freedom Medal ceremony of 2004 remain available, whilst controversy about the affair has sparked several satirical responses of variable quality. ®

The next step in data security

More from The Register

next story
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
'Speargun' program is fantasy, says cable operator
We just might notice if you cut our cables
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.