Blue Security Denies It's At Fault In Blog Outage - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


Blue Security Denies It's At Fault In Blog Outage

In another twist to this tale of denial-of-service attacks, spammers, and anti-spam security, the CEO of one security firm staunchly defends his company.

Blue Security's chief executive Friday denied that the server he repointed at a TypePad blog earlier this week brought along a denial of service attack that caused that blogging service, and others hosted by Six Apart, to crash.

"When we changed the domain name server to point to TypePad, there was no traffic flowing into our corporate server at," said Eran Reshef, Blue Security's CEO.

"I'm one of the victims here," Reshef said.

The dispute over the whats and hows and whens of the incident, which dropped Six Apart's TypePad, LiveJournal, and MessagePad blogging services offline for approximately 8 hours late Tuesday and early Wednesday U.S. time, was fueled Thursday by analysts who said Reshef's story didn't add up.

Friday, Reshef acknowledged that some of his company's servers had been subjected to a large denial-of-service (DoS) attacks for days, but said those were operational, or back-end, servers, and not connected to his anti-spam company's front door at Earlier, he had denied that any DoS was underway.

"I just discovered that today," he said.

"There was no DoS on the corporate server," when he repointed the URL to a dusted-off blog on TypePad's domain to get out the word that the site was unavailable outside Israel, where Blue Security is based.

Reshef had earlier said that a Russian spammer, dubbed "PharmaMaster," had bribed a worker at a "major ISP" to reroute Internet traffic so that no page requests reached Blue Security's Web site from outside the country. Friday, Reshef said that further investigation now led him to believe that a "blackhole filter," a technology often applied in DoS defenses, was maliciously used to block incoming traffic.

Reshef provided TechWeb with copies of Blue Security's Web logs that showed a drop in access from locales outside Israel over an hour and 45 minute span. During the last 7 minutes of that log, only 28 percent of the site accesses originated outside Israel.

"It wasn't the best decision to reroute traffic to TypePad," Reshelf said. But he again defended the repointing, saying that if he had suspected the attacker would follow Blue Security to the TypePad blog, he would have done things differently. "I would have just put out a press release," he said.

Reshef said that TypePad readers were able to add comments to the blog for at least 30 minutes after Blue Security repointed its servers. Blue Security redirected its site to TypePad at 11:20 p.m. (GMT) on Tuesday, May 2, he said. But comments were posted from 11:27 to 11:57 p.m., at which point the string broke, not to be resumed for more than two hours. Six Apart said this week that the DoS attack began at approximately 4:00 p.m. PDT (midnight GMT, May 3), or about 40 minutes after Blue Security said their site was redirected.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
1 of 2
Comment  | 
Print  | 
More Insights
The State of Cloud Computing - Fall 2020
The State of Cloud Computing - Fall 2020
Download this report to compare how cloud usage and spending patterns have changed in 2020, and how respondents think they'll evolve over the next two years.
10 Ways to Transition Traditional IT Talent to Cloud Talent
Lisa Morgan, Freelance Writer,  11/23/2020
What Comes Next for the COVID-19 Computing Consortium
Joao-Pierre S. Ruth, Senior Writer,  11/24/2020
Top 10 Data and Analytics Trends for 2021
Jessica Davis, Senior Editor, Enterprise Apps,  11/13/2020
Register for InformationWeek Newsletters
Current Issue
Why Chatbots Are So Popular Right Now
In this IT Trend Report, you will learn more about why chatbots are gaining traction within businesses, particularly while a pandemic is impacting the world.
White Papers
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll