Log in

View Full Version : Server Attack Foiled


Jason Dunn
01-24-2005, 07:30 PM
If you were wondering what happened to our server this morning, it was under attack. 870 different computers were pounding our server with a <a href="http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513">known phpBB exploit</a> that we patched back in December. Unfortunately, the solution provided by the phpBB team didn't do anything to prevent the phpBB install in question from being overloaded with the requests. We've blocked the attacking computer in question and modified phpBB to essentially ignore such requests. Thanks to <a href="http://www.dejavusoftware.com">Jorj</a> and <a href="http://www.fabriziofiandanese.com">Fabrizio</a> for rescuing our server from the abyss. :-)You know, this makes me wonder at what point the issue of personal liability comes into question - if my computer is attacking your computer, even if I don't know it, shouldn't I be liable for that in some way? If my dog attacks someone, I'm held responsible. If a piece of my roof falls off and kills someone, I'm responsible. I wonder if we'll start to see some legal action against users, or against software companies, related to issues like this?

Mike Temporale
01-24-2005, 07:47 PM
Thanks to Jorj (http://www.dejavusoftware.com) and Fabrizio (http://www.fabriziofiandanese.com) for rescuing our server from the abyss. :-)

:werenotworthy:

You know, this makes me wonder at what point the issue of personal liability comes into question - if my computer is attacking your computer, even if I don't know it, shouldn't I be liable for that in some way?

Interesting question... At some point, sure. I wonder what it will take before we start to see companies take this kind of action. I think, you would have to prove that the owner neglected to preform routine security updates.

spunkkat
01-24-2005, 10:08 PM
I think it should be a law now, if we don't start to police people who do not uphold their civic &amp; web duty to have anti-virus &amp; such... why should "we" pay for someone else's lack of caring? P.S. Tanx for reactivating my account so fast!!!

Jerry Raia
01-25-2005, 08:59 AM
Thanks to Jorj (http://www.dejavusoftware.com) and Fabrizio (http://www.fabriziofiandanese.com) for rescuing our server from the abyss. :-)

:werenotworthy:

You know, this makes me wonder at what point the issue of personal liability comes into question - if my computer is attacking your computer, even if I don't know it, shouldn't I be liable for that in some way?

Interesting question... At some point, sure. I wonder what it will take before we start to see companies take this kind of action. I think, you would have to prove that the owner neglected to preform routine security updates.

Don't know how one could prove that without being invasive. One of the great things about the internet is the freedom of it. Along with that comes the abuse. If you tighten up too much on the abuse you may strangle the freedom too.

jimfee
04-17-2005, 10:57 AM
You will always have a section of lazy slobs that allow themselves to be co-opted for this type of attack. The only way to ensure they are not successful is to have a security team in place, which you seem to have. The only way to have a security team in place is to provide them some kind of security in return. How about a donation link, I don’t want this resource to go away. Some of my favorite boards have gone the way of "this domain is available for sale" lately.