<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: PRI Website Target of Cyber-Aggression</title>
	<atom:link href="http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/feed/" rel="self" type="application/rss+xml" />
	<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/</link>
	<description>Permaculture News, Commentary and Worldwide Projects.</description>
	<lastBuildDate>Tue, 22 May 2012 06:34:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Peter</title>
		<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/#comment-46768</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Tue, 27 Apr 2010 23:20:53 +0000</pubDate>
		<guid isPermaLink="false">http://permaculture.org.au/?p=2939#comment-46768</guid>
		<description>There is a lot of activity in the recent weeks with defacement groups attacking servers in Australia. This is the ANZAC weekend activity:
http://www.networkworld.com/news/2010/042710-cereal-hacker-on-defacement.html

In the security world we consider it low-hanging fruit and not serious but when you get it done to you there is a personal reaction and attachment to the event so you are right in feeling the way you do but in the larger world of security attacks its not a huge deal.

You are well served in having the backup, just spend some time when you get it and read up on &quot;hardening&quot; the various packages and operating systems you are using on the server and eliminate most of the easy-to-fix and low-hanging-fruit areas most kids and groups try to use to get in. Thats all you can do unless you want to start buying network security appliances to monitor traffic real time and take various defined actions if any triggers are set off. This expense and time involvement is usually reserved to larger organisations so you can look at first hardening the configuration settings of what you are using in your kit and then look at any open source software that can provide some of the features of the network security appliances to run along with the rest of the site.


Cheers,
Peter</description>
		<content:encoded><![CDATA[<p>There is a lot of activity in the recent weeks with defacement groups attacking servers in Australia. This is the ANZAC weekend activity:<br />
<a href="http://www.networkworld.com/news/2010/042710-cereal-hacker-on-defacement.html" rel="nofollow">http://www.networkworld.com/news/2010/042710-cereal-hacker-on-defacement.html</a></p>
<p>In the security world we consider it low-hanging fruit and not serious but when you get it done to you there is a personal reaction and attachment to the event so you are right in feeling the way you do but in the larger world of security attacks its not a huge deal.</p>
<p>You are well served in having the backup, just spend some time when you get it and read up on &#8220;hardening&#8221; the various packages and operating systems you are using on the server and eliminate most of the easy-to-fix and low-hanging-fruit areas most kids and groups try to use to get in. Thats all you can do unless you want to start buying network security appliances to monitor traffic real time and take various defined actions if any triggers are set off. This expense and time involvement is usually reserved to larger organisations so you can look at first hardening the configuration settings of what you are using in your kit and then look at any open source software that can provide some of the features of the network security appliances to run along with the rest of the site.</p>
<p>Cheers,<br />
Peter</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Burns</title>
		<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/#comment-46731</link>
		<dc:creator>Michael Burns</dc:creator>
		<pubDate>Tue, 27 Apr 2010 14:01:40 +0000</pubDate>
		<guid isPermaLink="false">http://permaculture.org.au/?p=2939#comment-46731</guid>
		<description>I wonder if these are the same hackers who attacked the mutualaid.org server the last few weeks. The Finger Lakes Permaculture email list was lost. We are looking for our subscribers and directing them to http://flxpermaculture.net to reconnect with us.

-Michael Burns</description>
		<content:encoded><![CDATA[<p>I wonder if these are the same hackers who attacked the mutualaid.org server the last few weeks. The Finger Lakes Permaculture email list was lost. We are looking for our subscribers and directing them to <a href="http://flxpermaculture.net" rel="nofollow">http://flxpermaculture.net</a> to reconnect with us.</p>
<p>-Michael Burns</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Butchasteve</title>
		<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/#comment-46716</link>
		<dc:creator>Butchasteve</dc:creator>
		<pubDate>Tue, 27 Apr 2010 08:14:33 +0000</pubDate>
		<guid isPermaLink="false">http://permaculture.org.au/?p=2939#comment-46716</guid>
		<description>Hopefully its just a random attack rather than one aimed at the philosophy of the site itself. I mean, how could anyone be angry with the idea of permaculture? Probably just some pimply basement dwelling computer troll auditioning for a job at microsoft.</description>
		<content:encoded><![CDATA[<p>Hopefully its just a random attack rather than one aimed at the philosophy of the site itself. I mean, how could anyone be angry with the idea of permaculture? Probably just some pimply basement dwelling computer troll auditioning for a job at microsoft.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: michaelangelica</title>
		<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/#comment-46711</link>
		<dc:creator>michaelangelica</dc:creator>
		<pubDate>Tue, 27 Apr 2010 07:42:32 +0000</pubDate>
		<guid isPermaLink="false">http://permaculture.org.au/?p=2939#comment-46711</guid>
		<description>I am amazed that anyone would feel that threatened enough by permaculture forums to hack us.
But this has happened twice now in recent history.

Maybe we should promote &quot;Buy Nothing Day&quot; a bit more and watch the system disintegrate? ;)</description>
		<content:encoded><![CDATA[<p>I am amazed that anyone would feel that threatened enough by permaculture forums to hack us.<br />
But this has happened twice now in recent history.</p>
<p>Maybe we should promote &#8220;Buy Nothing Day&#8221; a bit more and watch the system disintegrate? <img src='http://permaculture.org.au/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matt luthi</title>
		<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/#comment-46705</link>
		<dc:creator>matt luthi</dc:creator>
		<pubDate>Tue, 27 Apr 2010 06:10:16 +0000</pubDate>
		<guid isPermaLink="false">http://permaculture.org.au/?p=2939#comment-46705</guid>
		<description>Thank god you had a working backup stored on another server. This site is invaluable.

Regards,
Matt</description>
		<content:encoded><![CDATA[<p>Thank god you had a working backup stored on another server. This site is invaluable.</p>
<p>Regards,<br />
Matt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Smith</title>
		<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/#comment-46700</link>
		<dc:creator>Eric Smith</dc:creator>
		<pubDate>Tue, 27 Apr 2010 04:51:31 +0000</pubDate>
		<guid isPermaLink="false">http://permaculture.org.au/?p=2939#comment-46700</guid>
		<description>Shyte, just read your reply above Craig... They hit the server. Heck!!!!!!!!!!!!!!</description>
		<content:encoded><![CDATA[<p>Shyte, just read your reply above Craig&#8230; They hit the server. Heck!!!!!!!!!!!!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Smith</title>
		<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/#comment-46698</link>
		<dc:creator>Eric Smith</dc:creator>
		<pubDate>Tue, 27 Apr 2010 04:48:23 +0000</pubDate>
		<guid isPermaLink="false">http://permaculture.org.au/?p=2939#comment-46698</guid>
		<description>Dang! I take some time off and when i get back everythings in a mess. To all coding kiddies and spammers... no parties while the mods are on holidays ;o)

I&#039;m waiting patiently with the rest of you... well waiting any way ;o)</description>
		<content:encoded><![CDATA[<p>Dang! I take some time off and when i get back everythings in a mess. To all coding kiddies and spammers&#8230; no parties while the mods are on holidays ;o)</p>
<p>I&#8217;m waiting patiently with the rest of you&#8230; well waiting any way ;o)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eco4560</title>
		<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/#comment-46687</link>
		<dc:creator>Eco4560</dc:creator>
		<pubDate>Tue, 27 Apr 2010 01:42:29 +0000</pubDate>
		<guid isPermaLink="false">http://permaculture.org.au/?p=2939#comment-46687</guid>
		<description>Nasty stuff. 
I&#039;m missing all my updates from Purple Pear and Mischief! Hope it gets fixed soon, and a big thanks to the team who is working to keep us all on line and in contact.</description>
		<content:encoded><![CDATA[<p>Nasty stuff.<br />
I&#8217;m missing all my updates from Purple Pear and Mischief! Hope it gets fixed soon, and a big thanks to the team who is working to keep us all on line and in contact.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Mackintosh</title>
		<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/#comment-46677</link>
		<dc:creator>Craig Mackintosh</dc:creator>
		<pubDate>Mon, 26 Apr 2010 22:38:38 +0000</pubDate>
		<guid isPermaLink="false">http://permaculture.org.au/?p=2939#comment-46677</guid>
		<description>Sorry Peter - but there&#039;s a bit more to it than that. It was a determined, prolonged attack over the course of several days. We&#039;re not talking just software code access, we&#039;re talking gaining root access at partition level and complete destruction of all data.

&gt;&gt;Anyone with actual skills would have gotten a lot further... 

I don&#039;t know how much further they could have got... 

&gt;&gt;and would have done it without being detected.

Excuse my tired sense of humour here, but there&#039;s no way they can destroy our hard drive without us noticing.

I did mention in the post above, Peter, that they destroyed our server. It&#039;s nothing to do with the forum, the main site, or other.</description>
		<content:encoded><![CDATA[<p>Sorry Peter &#8211; but there&#8217;s a bit more to it than that. It was a determined, prolonged attack over the course of several days. We&#8217;re not talking just software code access, we&#8217;re talking gaining root access at partition level and complete destruction of all data.</p>
<p>>>Anyone with actual skills would have gotten a lot further&#8230; </p>
<p>I don&#8217;t know how much further they could have got&#8230; </p>
<p>>>and would have done it without being detected.</p>
<p>Excuse my tired sense of humour here, but there&#8217;s no way they can destroy our hard drive without us noticing.</p>
<p>I did mention in the post above, Peter, that they destroyed our server. It&#8217;s nothing to do with the forum, the main site, or other.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter</title>
		<link>http://permaculture.org.au/2010/04/26/pri-website-target-of-cyber-aggression/#comment-46675</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Mon, 26 Apr 2010 22:03:21 +0000</pubDate>
		<guid isPermaLink="false">http://permaculture.org.au/?p=2939#comment-46675</guid>
		<description>Craig,

I don&#039;t feel PRI is the focus of the attack for it&#039;s permaculture. Most likely just script kiddies using tools that take advantage of out-of-the-box php code ore default deployments of software not locked down to any level. Forums are usually the weak point for injection techniques or modied urls probing weaknesses.

Anyone with actual skills would have gotten a lot further and would have done it without being detected.

Cheers,
Peter</description>
		<content:encoded><![CDATA[<p>Craig,</p>
<p>I don&#8217;t feel PRI is the focus of the attack for it&#8217;s permaculture. Most likely just script kiddies using tools that take advantage of out-of-the-box php code ore default deployments of software not locked down to any level. Forums are usually the weak point for injection techniques or modied urls probing weaknesses.</p>
<p>Anyone with actual skills would have gotten a lot further and would have done it without being detected.</p>
<p>Cheers,<br />
Peter</p>
]]></content:encoded>
	</item>
</channel>
</rss>

