Feeds

Scientology website shielded against DDoS attack

After the storm

SANS - Survey on application security programs

Updated The Church of Scientology has restored it website to normal after a campaign of denial of service attacks prompted it to use DDoS mitigation service Prolexic.

Web sites associated with the Church of Scientology were intermittently unavailable last week after an internet group calling itself Anonymous declared war on the controversial organisation.

Anonymous justified its actions by alleging the Church of Scientology has misused copyright and trademark law in censoring criticism against the church. The campaign was sparked off by the church's attempts to remove a promotional video featuring Scientologist Tom Cruise from YouTube. The clip shows a video from Cruise's Freedom Medal ceremony from late 2004 in which the actor speaks with (frankly scary) intensity about the responsibilities of being a Scientologist. After the Church of Scientology lodged a copyright infringement complaint, YouTube pulled the video, but the material has since resurfaced on Gawker.com.

As well as directing sympathisers to use denial of service software, Anonymous is calling on its members to make nuisance calls, host Scientology documents the Church claims as protected by copyright, and fax black pages to the Church's fax machines in an effort to waste ink. Longer established critics of Scientology have criticised the actions of Anonymous as counterproductive.

Wired reports that miscommunication between hactivists briefly resulted in a Dutch school web site becoming a target of attack on Friday.

The progress of the attack was closely monitored by network security tools firm Arbor Networks. Dr Jose Nazario, senior security engineer at Arbor Networks, said threats to attack the websites associated with the Church of Scientology were acted out.

The waves of ongoing attacks witnessed by Arbor lasted an average of 30 minutes consuming an average of 168 Mbps and peaking out at 220 Mbps.

"This is on the high side of an attack, but significantly smaller than the largest ones we commonly see nowadays," writes Nazario. "The attacks used in this case are common, garden variety DDoS attacks."

Danny McPherson, chief research officer at Arbor, added that the attacks were ongoing though diminishing in intensity. He stated that the ferocity of the attacks was on the same level as those thrown against Estonia last year. The technical sophistication applied to the attacks is fairly basic. Networks of compromised machines are being used in some cases, he added.

"The attacks are mostly brute force flooding. Some of the attacks start and stop from a bank of machines at exactly the same time so there have definitely been bots employed," McPherson told El Reg.

In response to the attacks, the Church of Scientology moved its systems over to a managed service run by security firm Prolexic, Netcraft reports.

The Church of Scientology has issued statements suggesting that controversy over the Tom Cruise video had increased traffic to its Web site. It has also said that the video was taken out of context. It did not comment directly on last week's denial of service attacks.

As the Church previously announced, the pirated and edited excerpts of Mr. Cruise were contained in an official Church event in 2004, an event attended by 5,000 Scientologists and their guests and further available for viewing in any Church of Scientology world over. Having presented these selective and out-of-context excerpts with the intent of creating both controversy and ridicule, nevertheless resulted in people searching for an visiting Church of Scientology websites as evidenced by “most searched for” lists of various search engines. Those wishing to find out the Church of Scientology’s views and to gain context of the video have the right to search official Church websites if they so desire.

A search on YouTube reveals other clips from the now famous Scientology Freedom Medal ceremony of 2004 remain available, whilst controversy about the affair has sparked several satirical responses of variable quality. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.