Feeds

WikiLeaks urged to stop hosting on Russian blackhat ISP

Virtual mafia state, indeed

Securing Web Applications Made Simple and Scalable

Security watchers have urged Wikileaks to stop hosting its material with a "bulletproof" Russian ISP believed to primarily cater to, or be controlled by, Russian cyber criminals.

Wikileaks.org now points to a mirror of the site, mirror.wikileaks.info, hosted by Webalta, a blackhat ISP linked to a company called Heihachi Ltd, according to Spamhaus. The .org URL has been WikiLeaks' main web address since its launch in 2006.

"Spamhaus regards the Russian Webalta (also known as Wahome) host as being "blackhat" - a known cybercrime host from whose IP space Spamhaus only sees spamming, malware/virus hosting, phishing and other cybercriminal activities," the anti-spam organisation said on Tuesday evening.

The warning follows similar concerns raised by Trend Micro, which also runs a spam-blocking list.

Both firms said that whatever political view one takes of the ongoing WikiLeaks saga, the site's administrators should take more care over the company it keeps.

Ironically, the judgment of an investigator that Vladimir Putin's Russia is a "virtual mafia state" has been one of the highest-profile disclosures from the US embassy cables so far released by Wikileaks.

"The fact that recently some unknown person or persons decided to put a Wikileaks mirror on IP address 92.241.190.202 should raise an alarm; how was it placed there and by whom," said Spamhaus.

"Our concern is that any Wikileaks archive posted on a site that is hosted in Webalta space might be infected with malware... Spamhaus takes no political stand on the Wikileaks affair."

Trend Micro said: "We don't know whether wikileaks.org has perhaps been compromised or whether WikiLeaks is knowingly getting services from a blackhat provider.

"To give you an idea, here are some illustrious neighbors: paypal-securitycenter.com, carders.kz, idchecking.ir (phishing), and postbank-sicherung.com."

The wikileaks.org domain was offline for a week after the plug was pulled by its DNS provider EVERYdns.net. It reappeared on Friday after being registered with another US DNS outfit, Dynadot. ®

Application security programs and practises

More from The Register

next story
ONE EMAIL costs mining company $300 MEEELION
Environmental activist walks free after hoax sent share price over a cliff
Arrr: Freetard-bothering Digital Economy Act tied up, thrown in the hold
Ministry of Fun confirms: Yes, we're busy doing nothing
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
Apple smacked with privacy sueball over Location Services
Class action launched on behalf of 100 million iPhone owners
US judge: YES, cops or feds so can slurp an ENTIRE Gmail account
Crooks don't have folders labelled 'drug records', opines NY beak
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.