Tuesday, December 9, 2008

The Mirror Question

Defacement mirrors have been around for a long time and the question of whether mirroring encourages defacements has been around for just as long. The basic argument is that defacement mirrors encourage defacement by allowing the attackers to look "cool" and compete to be the most prolific defacers (in terms of high profile targets and numbers of defacements etc...). A recent post on the SecuriTeam blog got me thinking about it again, particularly about how I use these mirrors in my research.

Attrition started mirroring defacements in 1995 but stopped doing so in 2001 (as did Safemode) leaving Alldas as the largest mirror. Alldas eventually stopped mirroring as well leaving Zone-h as only major active mirror (there are still some smaller ones and some specialized (usually regional) ones). The mirrors closed for a variety of reasons such as the increase in defacements and burn out on the part of the volunteers who run the mirrors. But another key issue is that the mirrors themselves come under attack. Attrition has been defaced and subjected to Denial of Service attacks and Alldas was also defaced and suffered sustained ddos attacks. Zone-H has been defaced in the past. Zone-H has also thought about stopping their mirror, but continues to mirror.

Early on Attrition was blamed for encouraging defacements. Their response (and here) was:


# Odds are we have berated and insulted most defacers for their activities - we've questioned them, encouraged them to STOP, etc.
# We are not the only mirror. If we close up shop, the other mirrors will pick up our role...


Zone-H has a similar response:

Our usual answer to this claim is that Zone-H is not the first mirror archive website, others appeared before it, others will be after it. And the first defacement mirror website, appeared AFTER defacements became very popular.
But sure, a lot of defacers are using Zone-H archive capability just to satisfy their ego-driven needs, using Zone-H as a stage for their own lack of personality or social skills.


Since I am most interested in politically motivated, targeted attacks I find the defacement mirrors useful for a variety of reasons. When servers are defaced (particular high profile targets) there is often an immediate assumption of some kind of god-like haxoring skills or government/military involvement on the part of the attackers. Since the attacks are interpreted contextually (dissident group X has been repressed by government X for years or "cyber war has erupted between count and country y) the source behind the attacks and their abilities are often a forgone conclusion. Whenever a defacement I am interested in occurs the first thing I do is look it up in the defacement mirrors.

Do the attackers have other defacements? Are any of their previous defacements politically motivated, are they random(ish)? The fact that they even report the defacement to a mirror is often an indication that the group is in the defacement "scene" not part of a "cyber war" or "cyber crackdown." What information can be gleaned from the defacement, names, groups, email addresses, IRC channels, similarity in the code etc...?

Have the targets been defaced before? If a web site has bee defaced many times (sometimes even through the same method) it is a good indication that security was lax rather than that the attackers possessed some amazing skillz. Just because a site is a "gov" or "mil" and it gets defaced is not surprising when you look it up in a defacement mirror only to find that it had been defaced in the past.

The mirrors help provide texture to analysis of defacements and are a valuable resource. Recently the so-called "India/Pakistan Cyberwar" has received a good deal of media attention. However, a quick browse through zone-h showed that it was more of a defacement "flare-up" than a "cyber war". These mirrors continue to be a valuable resource.

Monday, December 8, 2008

Wikipedia, Cleanfeed & Filtering

IWF classified a Wikipedia page as containing a pornographic image of a child. As a result UK ISP's that participate in the cleanfeed program are now blocking access to the Wikipedia page of the band the Scorpions because of a controversial album cover that is potentially child pornography and thus illegal under UK law. The IWF states:

A Wikipedia web page, was reported through the IWF’s online reporting mechanism in December 2008. As with all child sexual abuse reports received by our Hotline analysts, the image was assessed according to the UK Sentencing Guidelines Council (page 109). The content was considered to be a potentially illegal indecent image of a child under the age of 18, but hosted outside the UK. The IWF does not issue takedown notices to ISPs or hosting companies outside the UK, but we did advise one of our partner Hotlines abroad and our law enforcement partner agency of our assessment. The specific URL (individual webpage) was then added to the list provided to ISPs and other companies in the online sector to protect their customers from inadvertent exposure to a potentially illegal indecent image of a child.


But why didn't they just block access to the specific URL of the offending image? Instead they block the entire page, the text (and other images) of which are completely legal. There is no technical reason why they cannot block URLs to specific offending images in exactly the same way as they can block a specific Wikipedia page and not the entire Wikipedia site.

The IWF collects URLs that are potentially illegal for containing child pornography and sends them to participating ISP's in the U.K. as part of the cleanfeed program. The ISPs then block access to these URLs. These URLs may be shared with other agencies through the IN HOPE network and possibly with commercial filtering companies as well. Canada has a similar cleanfeed program in which Cyberip collects the potentially illegal URLs and send them to Canadian ISPs who then block access to them. One of the main why cleanfeed has been successful and replicated in oher countries is that it was supposed to elegantly avoid the pitfall of overblocking, the key objection that was consistently raised civil libertarians and others with respect to filtering. This is why filtering at the URL level is so important: one offending page can be blocked while the rest of the site remains available.

One of the questions I've often raised (in the Canadian context) concerns what precisely is blocked. We know that cleanfeed systems can block at the URL level, so why block access to the web page containing the offending image and not the the URL to the offending image itself? There is no technical reason for not doing so. If IWF added the URL to the specific offending image embedded in the Scorpions Wikipedia page the text of the article, which is perfectly legal, along with all the other legal images would still be available. Only the one offending image would have been blocked.

For a system that was designed to not overblock I find it hard to understand why they don't the specific offending images. If an entire website was devoted to showing images of child abuse then it would be understandable, but Wikipedia?