• IP addresses are NOT logged in this forum so there's no point asking. Please note that this forum is full of homophobes, racists, lunatics, schizophrenics & absolute nut jobs with a smattering of geniuses, Chinese chauvinists, Moderate Muslims and last but not least a couple of "know-it-alls" constantly sprouting their dubious wisdom. If you believe that content generated by unsavory characters might cause you offense PLEASE LEAVE NOW! Sammyboy Admin and Staff are not responsible for your hurt feelings should you choose to read any of the content here.

    The OTHER forum is HERE so please stop asking.

154th Sabo Temasek Review Website!

makapaaa

Alfrescian (Inf)
Asset
<TABLE id=msgUN border=0 cellSpacing=3 cellPadding=0 width="100%"><TBODY><TR><TD id=msgUNsubj vAlign=top>Coffeeshop Chit Chat - TR caught STP Prostitutes redhanded</TD><TD id=msgunetc noWrap align=right>
icon.aspx
Subscribe </TD></TR></TBODY></TABLE><TABLE class=msgtable cellSpacing=0 cellPadding=0 width="96%"><TBODY><TR><TD class=msg vAlign=top><TABLE border=0 cellSpacing=0 cellPadding=0 width="100%"><TBODY><TR class=msghead><TD class=msgbfr1 width="1%"> </TD><TD><TABLE border=0 cellSpacing=0 cellPadding=0><TBODY><TR class=msghead><TD class=msgF width="1%" noWrap align=right>From: </TD><TD class=msgFname width="68%" noWrap>Fkapore <NOBR></NOBR> </TD><TD class=msgDate width="30%" noWrap align=right>Nov-2 1:59 pm </TD></TR><TR class=msghead><TD class=msgT height=20 width="1%" noWrap align=right>To: </TD><TD class=msgTname width="68%" noWrap>ALL <NOBR></NOBR></TD><TD class=msgNum noWrap align=right> (1 of 18) </TD></TR></TBODY></TABLE></TD></TR><TR><TD class=msgleft rowSpan=4 width="1%"> </TD><TD class=wintiny noWrap align=right>23694.1 </TD></TR><TR><TD height=8></TD></TR><TR><TD class=msgtxt>SPH IP address caught “grabbing” content from Temasek Review server

November 2, 2009 by admin01
Filed under Top News

Leave a comment


From our Correspondent
The Temasek Review site was down for almost 8 hours on 30 October 2009 from a massive DDOS or distributed denial of service attack. (read the details here)
* A DDOS attack is an attempt to make a computer resource unavailable to its intended users. One common method of attack involves saturating the target (victim) machine with external communications requests, such that it cannot respond to legitimate traffic, or responds so slowly as to be rendered effectively unavailable.
* An IP address is a numerical label that is assigned to devices participating in a computer network utilizing the internet protocol for communication between its nodes which helps in host and location identification. To check your own IP, just go to [URL="http://whatismyipaddress.com/"]http://whatismyipaddress.com[/URL] and it will reveal your IP address in an instance. IP addresses are usually displayed in human-readable notations, such as 208.77.188.166.
On or about 31st October 2009, around 0200 hours to 1st November 0400 hours, while our system administrator was doing a routine check on the server and firewall, he noticed a flurry of network communication requests coming from one single IP address concurrently which caused our server’s load to increase tremendously.
Attached below is a snapshot of the apache-server status log which shows the IP addresses which have been accessing our site.
sphgrab.jpg

As you can see from the above snapshot, all but two of the IP addresses came from the same source – 203.116.231.234 which was traced back to Singapore Press Holdings as per [URL="http://whois.domaintools.com/203.116.231.234"]http://whois.domaintools.com/203.116.231.234[/URL]
</TD></TR></TBODY></TABLE></TD></TR></TBODY></TABLE>
 

makapaaa

Alfrescian (Inf)
Asset
sphddos585.jpg

The IP address belonging to SPH appeared to be accessing our entire site indiscriminately, reading even our archived contents from as early as 2008. (boxed in red)
The actual number is much higher and cannot be revealed in its entirety here due to its length.
From the log, it seems to suggest that whoever doing that is using a Web Grabber Software with the aim of getting all the content from our site since a single web browser is unlikely to be reading our entire site all at a go.
Fortunately, our new anti-DDOS firewall managed to stop these requests to prevent them from loading the server thus causing it to slow down. A shared server with limited bandwidth would have crashed.
The situation is akin to somebody making a thousand phone calls one after another continuously to your handphone which will jam your line and prevent other people from reaching you, not quite unlike a DDOS attack.
We would like to ask SPH the following questions:
1. Who is the culprit using a SPH-owned computer to “grab” our content from as early as March 2008 when the postings can be viewed from our site in the public domain?
2. Why is he/she doing copying our site in its entirety? Is it for his/her personal reading at his/her own pleasure or is it for some other more insidious purposes?
3. What is he/she going to with the content from our site? Will it be plagiarized and reproduced elsewhere at a later date?
If SPH journalists are really interested to learn more about Temasek Review, they can email us to request a copy of our backlog files which will save them the trouble of “grabbing” the content directly from the server.
By doing so covertly without asking for our permission and flooding our server with so many network communications request at one go, it will slow down the site, retard the loading speed of the pages and can potentially cause the server to crash (though highly unlikely in our new dedicated server).
Is this how SPH operates, under a cloak of secrecy? Or is it a response to our increasing readership?
Though our server has been “strengthened” following the last DDOS attack, we are very concerned about possible “intrusions” like this again from SPH or other government agencies which will increase our server load unnecessarily such that it may not be able to respond during periods where the traffic may doubled or even tripled.
We sincerely urge SPH to come forward and explain their actions publicly not only to us, but to the entire blogosphere as well. We will be most willing to sit down and listen to what they have to say over a cup of tea and resolve the issue together to achieve a win-win situation for both parties.
However, if it chooses to remain recalcitrant and continue their unwanted and unwelcome “intrusions” to undermine our site, then we will have no choice but to escalate the matter up to the relevant authorities.
We would like to remind the SPH journalists involved of Section 7 of the Computer Misuse Act (CAP 50A):
7. —(1) Any person who, knowingly and without authority or lawful excuse —


<DL>(a) interferes with, or interrupts or obstructs the lawful use of, a computer; or</DL><DL>(b) impedes or prevents access to, or impairs the usefulness or effectiveness of, any program or data stored in a computer,</DL>shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $10,000 or to imprisonment for a term not exceeding 3 years or to both and, in the case of a second or subsequent conviction, to a fine not exceeding $20,000 or to imprisonment for a term not exceeding 5 years or to both.
 
Top