Slashdot Log In
Russia Accused of Cyber-War Against Estonia
Posted by
kdawson
on Thu May 17, 2007 09:19 AM
from the deniability dept.
from the deniability dept.
earthlingpink writes about the ongoing DDoSing of Estonia. The Guardian is reporting that Russia stands accused of engaging in a three-week-long series of cyber-attacks. Government, banking, and media websites have been targeted. It is unclear whether the attacks are sanctioned or initiated by the Russian Government, but Estonian authorities believe that to be the case. NATO has sent security experts to Tallinn to help beef up defenses. The Estonian defense minister said, "At present, NATO does not define cyber-attacks as a clear military action. This means that the provisions of... collective self-defense, will not automatically be extended to the attacked country... this matter needs to be resolved in the near future."
Related Stories
[+]
The Real Impact of the Estonian Cyberattack 172 comments
An anonymous reader writes "News.com offers up an interview with Arbor Networks' senior security researcher Jose Nazario. He takes stock of the denial-of-service attack against the Baltic nation of Estonia, and considers the somewhat disturbing wider implications from the event. 'You look around the globe, and there's basically no limit to the amount of skirmishes between well-connected countries that could get incredibly emotional for the population at large. In this case, it has disrupted the Estonian government's ability to work online, it has disrupted a lot of its resources and attention. In that respect, it's been effective. It hasn't brought the government to a crippling halt, but has essentially been effective as a protest tool. People will probably look at this and say, That works. I think we're going to continue to do this kind of thing. Depending on the target within the government, it could be very visible, or it could not be very visible.'"
[+]
US Prepares for Eventual Cyberwar 223 comments
The New York Times is reporting on preparations in the works by the US government to prep for a 'cyberwar'. Precautionary measures are being taken to guard against concerted attacks by politically-minded (or well-paid) hackers looking to cause havoc. Though they outline scenarios where mass damage is the desired outcome (such as remotely opening a dam's gates to flood cities), most expect such conflicts to be more subtle. Parts of the internet, for example, may be unreachable or unreliable for certain countries. Regardless, the article suggests we've already seen our first low-level cyberwar in Estonia: "The cyberattacks in Estonia were apparently sparked by tensions over the country's plan to remove Soviet-era war memorials. Estonian officials initially blamed Russia for the attacks, suggesting that its state-run computer networks blocked online access to banks and government offices. The Kremlin denied the accusations. And Estonian officials ultimately accepted the idea that perhaps this attack was the work of tech-savvy activists, or 'hactivists,' who have been mounting similar attacks against just about everyone for several years."
[+]
Government-Sponsored Cyberattacks on the Rise 96 comments
jbrodkin writes "A new McAfee report finds that 120 countries, notably the United States and China, are regularly launching Web-based espionage campaigns. Government-sponsored cyber attacks against enemy countries are becoming more common, targeting critical systems including electricity, air traffic control, financial markets and government computer networks. This year, Russia allegedly attacked Estonian government news and bank servers, while China was accused of hacking into the Pentagon. A McAfee researcher says this trend will accelerate, noting 'it's easier to attack government X's database than it is to nuke their troops.'"
[+]
Politics: DoS Attacks on Estonia Were Launched by Student 184 comments
As_I_Please alerts us to the fact that a 20-year-old Estonian student has been fined for participating in DoS attacks against various Estonian political and governmental websites last May. The situation was notable because it escalated tensions between Estonia and Russia when the latter was accused of initiating the 'cyber-attack'. Quoting:
"The fact that a single student was able to trigger such events is particularly ominous when you consider just how many potential flashpoints exist between various countries all over the world. The DoS attack against Estonia is an excellent example of how a cyberattack carried out by a 20-year-old student in response to real-life events further exacerbated an existing problem between two nations."
[+]
The Secret China-U.S. Hacking War? 107 comments
bored-at-IETF-ntp-session writes "In an article at eWeek Larry Seltzer examines the supposed hacking war between the US and China. He surmises 'Even if you can't prove that the government was involved ... it still bears some responsibility'. He quotes Gadi Evron who advised the Estonians during the Russian attacks. 'I can confirm targeted attacks with sophisticated technologies have been launched against obvious enemies of China ... Who is behind these attacks can't be easily said, but it can be an American cyber-criminal, a Nigerian spammer or the Chinese themselves.' Seltzer concluded 'It's just another espionage tool, and no more or less moral than others we've used in the past.'" This a subject we've also previously discussed.
[+]
News: Expert Dissects Estonian Cyber-War 1 comment
Stony Stevenson points out an iTnews summary of a security researcher's account of the cyber-attacks on Estonia last year. The full report [PDF] is also available. We've discussed this internet-based conflict in the past. From the report:
"In the days leading up to the attack, numerous clues pointed to a large-scale operation that was being planned online. Russian-language Internet discussion forums were abuzz with preparations for an online attack. Three days before the expected onslaught, Estonia planned to release the news of the coming strike in hopes that European media attention would oblige the EU to pressure the Kremlin to intervene, whether or not the attacks emanated from the Russian authorities."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.

I can confirm (Score:5, Funny)
As an American-Estonian (1/3 Estonian on my Mother's side), I can confirm that Russia has been attacking my programming project, making it impossible to debug. And THAT boss is why the project isn't done yet! What can I do when all of Russia is against me?
Where did I hear about this attack? Uh.. slashd... an on-line news source specializing in technical news of course!
Re:I can confirm (Score:5, Funny)
How can you be ONE THIRD something? I'd understand 1/2 or 1/4 or 1/8 (etc.)
Or, perhaps, you're 1/3 SWEDISH. }:->
(I know I'd be downmodded for this, but I HAD to say it)
Parent
Re:I can confirm (Score:5, Funny)
Parent
Re:I can confirm (Score:4, Funny)
Ménage à trois?
Parent
Russia or Russians? (Score:3, Insightful)
Re:Russia or Russians? (Score:5, Informative)
It didn't make US news, of course, but Estonia just had some of the first riots in their capital, Talin. Lately, the Estonian government has been removing Soviet war memorials because, well, they partly respresented the Soviets ruling their country. Just like the Russians have been doing in Moscow, they remove them all and have a single statue garden (they are historical, after all).
However, when they removed one statue of a Soviet soldier in a cemetary, thousands of Russians living in Estonia started protesting. Now, maybe the Russian population just liked that particular statue, but there were rumors that Russian agents were stirring up trouble just to stir up trouble.
Russia's been flexing its muscles across Eastern Europe again. They've been punishing "bad" countries which disobey them. First the riots (which were suspected to be caused by Moscow), now cyber attacks. Neither are outright military moves, but they sure as hell get the message across.
Combined with the recent crackdown on free media and opposition in Russia, it sounds like life might get interesting in 5 years. It seems that, with America's short attention span focused on Iraq, Russia has been putting the pieces in place to recapture former glory.
Do you think that after 50 years that Boris the Soviet simply retired to the countryside? Or has he just been waiting patient for the right opportunity?
Maybe I just haven't had enough coffee this morning to make the conspiracy theories go away.
Parent
Re:Russia or Russians? (Score:5, Insightful)
Parent
Re:Russia or Russians? (Score:5, Interesting)
Parent
Re:Yuschenko and the CIA revolution? (Score:4, Informative)
Parent
The real outcome of the attacks (Score:3, Interesting)
How would you you fight a DDoS attack and make sure all non-bot users have access?
reminds of (Score:5, Insightful)
before 9/11 in early 2001, a chinese jet fighter bumped a us spy plane it was trying to harass away. the chinese fighter crashed and the pilot was never found, and the spy plane was forced to make an emergency landing on hainan island, where the chinese stripped the plane of equipment and then returned the crew to the usa
what happened for a few tense weeks was a lot of nationalistic chest thumping by chinese and american hackers: chinese hackers defacing poorly patched american servers, everything from small businesses to government systems, and american hackers defacing chinese servers: schools and government (i remember this well as i had a box that was hacked: my home page was replaced with a chinese flag and a "fuck usa", heh)
the point is, it's probably not official, it's probably by an independent group of weakly organized russian hackers upset due to nationalistic pride
the trigger for them is that statue that estonia got rid of in tallinn, which russians probably view as thousands of dead soldiers in the defense of estonia from the nazis, and estonia being ungrateful, and estonians viewing as an example of soviet domination, and a symbol of the past cold war era, and russians trying to retain their dominance
regardless, i expect some pissed off estonian hackers soon to plaster "in soviet russia, estonia hackers hack you!" all over pravda.ru, or something
hello brawling estonians and russians (Score:5, Funny)
please be accusing each other's mothers of various acts of bestiality and extreme promiscuity, and do not go lightly on the creative threats of violence, including skewering the eyes with pokers, and the twisting of testicles in various farm machinery. proper english grammar is optional, in fact, it is better if your english grammar is nonexistent
ok, my popcorn is ready, any russian want to respond to the above estonian?
go!
Parent
Re:dude (Score:4, Insightful)
Since you remind about holocaust, remember gulag. Millions of people from Baltic states died there. And deportations started one year before Germany attacked SSSR.
Americans haven't occupied France and Belgium for 45 years. Russians haven't liberated Estonia. In 1944 Estonia one occupant was replaced by other. If Sadam's statue is erected in Kuwait, do people of Kuwait have to leave it in front of emir's palace after Iraqies are gone. Did Russians had to leave Stalin next to Lenin in Mausoleum after 1953.
Parent
Actually this has happened before, to the USA (Score:5, Informative)
Cut Russia off the net (Score:5, Interesting)
Most of the botnets in the world are controlled by Russian mafia. The rest of the world is spending an insane amount of time, money and effort defending against these attacks that orginate 90% from one part of the world. It's like criminally created welfare program, and we're all paying.
Re:Cut Russia off the net (Score:5, Insightful)
So if we cut their IP blocks off from the world beacuse of botnets, what other excuses could we use? Well, China supports terrorism, so lets cut them off too. And both Koreas. And the entire middle east. Etc.
Also, the hackers would end up proxying through another set of IPs and getting to where they need to be anyway. And could write up their bots to do the same.
That said, don't use technical solutions for social problems. The problem is the governments of the countries in question don't care. They can deny involvement but still watch their enemies writhe. It should be treated as if a stream of foreign nationals marched out of their country and into ours, guns drawn. And that their government is doing nothing to stop them.
Parent
Re:Common Sense (Score:5, Insightful)
You haven't got a clue.
A DDOS attack is basically an attempt to saturate the capacity of the target. The "distributed" part means that it is difficult to screen out the attackers because the machines are on so many different subnets. The flaws that a DDOS relies on are not in the attacked systems, but in the attacking ones which have been compromised and have had software installed that makes them a "bot". A network of these "bots" are then coordinated by the attacker.
And if you think that shutting down the websites of pretty much every government institution, bank and commercial enterprise in a highly connected country like Estonia amounts to "a few eggs thrown over the fence" then just think what it would do your nations economy.
Parent
Re:Common Sense (Score:4, Informative)
For the love of freedom, just patch the boxes and shut up!
You just don't get it do you? A DDOS is not indicative of a flaw in the systems under attack, it is using the regular means of access to the systems (HTTP requests mostly) but doing it on a massive scale from machines around the world taht have been compromised. Or are you suggesting that Estonian sysadmins perform the impossible and patch all these lousy Windows boxes on various ISP accounts around the world?
Unless you've experienced a large scale DDOS or read the detailed summary of how one was handled then all I can suggest is looking at some descriptions of what a DDOS is. Wikipedia is a good start. Our Payment Service Provider received a blackmail threat a couple of years ago, and then experienced a massive ten day long DDOS attack. Once it was over they provided us with a very detailed account of the attack. What impressed me was the sheer number of machines used in the attack and how evenly spread around the world they were. Trying to contact the relevant sysadmins or ISPs for these machines was simply not feasible.
Parent
Re:Common Sense (Score:5, Interesting)
But that doesn't make cyber attack bullshit. That's like saying that land invasions are a made up boogeyman because they depend on flaws like "not having a giant impregnable wall surrounding your country." DDoS attacks, in particular, are problematic. A given target has no way to prevent zombied machines from participating in the attack.
Besides which, a DDoS attack is just a bandwidth race. If my home PC were to be attacked like this, there's nothing I, personally, can do about it. My router won't pass any of the packets to my machine, but if there's 6 Mbps worth of incoming traffic, even if I drop it at the router, I still can't get much legit traffic through. I can call my provider, and see if they can stop it upstream, but then it's just a comparison of the bandwidth at the DSLAM to the bandwidth of the attacker. The only thing to hope for is that, somewhere up the chain, you can reach a node with enough bandwidth that the attacker can't overwhelm it. When you start getting up into backbone territory, this isn't a problem.
But - if we hypothesize for the moment an actual planned assault by a country - odds are pretty good that the US DoD, for example, has more bandwidth than Iran.
Parent
Re:They forgot something. (Score:5, Informative)
Vandalized? Moved to cemetery where it belongs.
Estonia is seen as a neo-fascist regime by Russia, and in my opinion, rightly so
Russia is seen as imperialist regime by Estonia, and in my opinion, rightly so
you can't deny over 30% of your population [estimate of Russian population in Estonia] the most basic rights, including citizenship
You learn the language, pass one exam and voila - the citizenship is yours.
and education for children based on their nationality, and be seen otherwise.
We have schools for Russian-speaking children where most of the subjects are taught in Russian. Unbelievable, yes?
Of course, Europe and the United States ignore this issue.
And Russians ignore the reality. I'm sorry if you do not agree.
Parent
Re:They forgot something. (Score:5, Informative)
Nope the starting point of this was the relocation of a large statue of a Soviet soldier from central Tallinn to a Soviet Army military cemetery on the outskirts of the city. The Estonians were occupied twice by the Soviet Union, once at the beginning of World War II and again at the end. The second occupation was billed as a liberation of Estonia by the Soviets, but both times large numbers of Estonians were deported to labour camps in the east of the Soviet Union, many to never return. As a result, the statue came to symbolise the occupation of Estonia, and it was felt it should not be in the centre of the countries capital.
During the Soviet era, a large number of ethnic Russians were settled in Estonia and a program of Russification carried out that tried to extinguish Estonian language and culture. This was a common policy across the Soviet Union, as it was seen as a way of preventing a future break up of the union. The Putin government plays on the tensions amongst these former Soviet populations as a way of reasserting Russias importance in the region.
The bodies that are often mentioned in the news reports are actually located some distance from the original site of the statue. They have been located (there was no sign of their presence above ground) under a tram stop and road junction. Excavation was carried out, and the coffins relocated to the same cemetery as the statue. This is in accordance with war graves agreements that are part of internation law.
Parent
Re:They forgot something. (Score:5, Insightful)
Let me give you another perspective on this. You can decide whether or not you want to stick to your guns here. Are you by any chance married to a Russian woman? Because if you are, that will certainly inhibit your ability to see the other side.
Estonia was under Russian control until 1918. It remained an independent nation until 1940, when the USSR invaded it. Germany occupied it from 1941 to 1944. During the 1 year or so of Soviet occupation prior to the Nazi invation, the Soviets did such nice things as kill the intellectuals and forcibly conscript Estonians into the Red Army. I can't say it's any wonder that as in Ukraine (where Stalin and his henchmen had killed and starved to death millions of Ukrainians in the 1930s), the locals viewed the Nazis as liberators and then found out that they were just as bad if not worse as the Soviets. Do note that the USA never recognized the Soviet occupation of Estonia, Latvia and Lithuania. NEVER. It's important to know that for over 50 years, official US policy was that the occupation of these 3 countries was illegal.
After WWII ended, Estonia was screwed. They were part of the Soviet Union. The Soviets moved hundreds of thousands of Russian speaking immigrants into Estonia in an attempt to "Russify" it and to dilute Estonian nationalism. Estonian freedom fighters fought a small scale guerilla war against the USSR into the early 1950s when they finally gave up and realized it was hopeless.
During the USSR period, Russian was the official language in education. It was possible to have education in whatever the local language was (Krushchev made some changes that allowed this), but there was a catch - if you wanted to get a good job, you absolutely had to speak Russian well. Given that Russian and Estonian are about as closely related as English is to Polish, you might understand that Estonian parents had no choice but to send their kids to Russian language schools so as to give them the best chance to prosper in the USSR.
Cut to 1991 when Estonia gets its independence. They now have a rather large Russian speaking population who they were forced to accept by a government that no longer exist. These people have never assimilated into Estonian society. In fact, they were encouraged immigrate there specifically to dilute Estonia's sense of national identity and to turn them into "good little Soviet subjects". These immigrants have never bothered to learn the Estonian language since Russian was the official language of the government prior to 1991. Now you have all these people who say "Screw you! We want to speak Russian!" in a country where the majority of citizens speak the local language, Estonian. They demand that everything be done in Russian so they can understand it. The Estonians never wanted to speak Russian to begin with, so they are promoting the use of their national language. Now you have about 26% of the population who refuses to "get with the program", demands that their language be given equal footing with the national tongue and even worse, feels that things were a lot better back when they were in charge and the stupid locals were taking orders from them. So given that Estonia never wanted the Soviets/Russians there to begin with and the Soviets weren't exactly enlightened when they ran the show, can you really blame them for not being real happy with Russia today? By the way, ethnic Russians can become Estonian citizens, but they have to take
Parent
Re:Why Is This In Politics??!!! (Score:5, Insightful)
The politics section originally started out I believe a year or two ago to cover the election and resulting aftermath of "ZOMG BUSH GOT LESS VOTES!" type story. It has since become a more rounded section and carries stories from all over the world under it's banner, because you know "Stuff that matters" is quite often political.
I mean when people start having wars via the Internet (as this rather implies is happening in some twisted form) it starts to effect us geeks as well. So we discuss it on Slashdot and because it's political based they used the politics banner.
I feel sorry for you if you can't see that the FAQ maybe outdated and this has been this way for a good few months (maybe 12+) now, so decide to grind your axe on a stone that's been here longer than you probably have (Anoncow has no ID so I can't tell from your number, but I have to assume you're new if you don't understand the politics section).
Parent
Re:Why Is This In Politics??!!! (Score:5, Funny)
Parent
Re:Oh yeah? (Score:5, Funny)
That's why in Hunt for Red October, Sean Connery says "ping -c 1 sub.navy.mil" (or simply "One ping only")
That joke worked so well in my head :-(
Parent