Georgia accuses Russia of coordinated cyberattack

By Tom Espiner, ZDNet UK
Tuesday, August 12, 2008 11:02 AM

The Georgian embassy in the United Kingdom has accused forces within Russia of launching a coordinated cyberattack against Georgian Web sites, to coincide with military operations in the breakaway region of South Ossetia.

Speaking to ZDNet Asia's sister site ZDNet UK on Monday, a Georgian embassy spokesperson said that Web sites had been unavailable over the weekend, claiming this was due to Russian denial-of-service attacks.

"All Georgian Web sites have been blocked," said the spokesperson. "Georgia is working on redirecting Web traffic."

At the time of writing, the Ministry of Defense of Georgia Web site was unavailable for viewing from the United Kingdom. Both the Georgian presidential Web site and the Ministry of Foreign Affairs of Georgia Web site were available, but the spokesperson said this was due to Georgian redirection work.

"They are new [Web sites]," said the spokesperson. "It was impossible two days ago [to access them]."

However, the spokesperson admitted that, as yet, Georgia could not confirm that Russia had been responsible, as the causes were still "under investigation". "Who else might it be though?" asked the spokesperson.

The Russian embassy in London said it had no information regarding cyberattacks against Georgia, but insisted there had been no military attack against Georgia. "I'd like to draw attention to a misunderstanding," said a Russian embassy spokesperson. "There is no Russian [military] attack. There is peace enforcement in South Ossetia."

According to a post on the Web site of the president of Poland, Lech Kaczynski, the Russian government blocked Georgian Web sites to coincide with "military aggression".

"Along with military aggression, the Russian Federation is blocking Georgian Internet portals," read a statement on the Polish presidential Web site. "On request of the president of Georgia, the president of the Republic of Poland has provided the Web site of the president of Poland for dissemination of information."

One of the statements made by the Georgian government on the Polish presidential website accused the Russians of bombing the port of Poti on the Black Sea, "far from South Ossetia", and of sending warships into the area.

"[Poti] serves as a vital energy-transit route to Europe," read the statement. "Over the past 48 hours, Russian forces have killed over 100 Georgian civilians and soldiers, after targeting residential complexes in Georgia, as well as airports, bases, and other vital infrastructure."

The RBN Web site, which normally attempts to track the activities of the criminal Russia Business Network, kept a running commentary of technical developments over the weekend.

On Saturday, the RBN blog, which is run by security researcher Jart Armin, claimed there was a "full cyber-siege" of Georgia. The RBN blog post claimed that the Russia-based servers AS12389 Rostelecom, AS8342 Rtcomm and AS8359 Comstar were controlling all traffic to Georgia's key servers.

According to the blog, German hackers managed to route traffic directly to Georgia through Deutsche Telekom's AS3320 DTAG server for "a few hours" on Saturday, but this traffic was intercepted and rerouted through AS8359 Comstar, which is located in Moscow.

The RBN Web site also warned users not to trust any Web sites that appeared to be maintained by the Georgian government but did not have any statements about the weekend's hostilities, as these had likely been intercepted and altered.

Security organization the Shadowserver Foundation reported in an update to an earlier blog post that it was also seeing cyberattacks directed against ".ge" sites, with the Georgian presidential and Web sites being hit with HTTP floods. Shadowserver reported that the command-and-control server being used to launch the attacks was located in Turkey.

In July, Shadowserver security volunteer Steven Adair reported that the president of Georgia's Web site had suffered a denial of service attack following a build-up of hostilities between Russia and Georgia over South Ossetia.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Windows Server 2008 iSCSI multiple connected session modes

Enterprise Servers & Storage

For administrators using Windows Server 2008's iSCSI initiator, selecting the right connection policy is critical. Rick Vanover explains the options for the ease-of-entry storage protocol.


Read more »


 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




NUS Enterprise: An 'incubator without walls'

Blog thumbnail

Almost everyone has had dreams of owning their own shop, but most of us know also that it takes a fair amount of resources to open a new business, and..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web