I'm not familiar with Amazon's content policies, but I couldn't see Amazon wanting this stuff hosted on their servers.
http://blogs.wsj.com/digits/2010/11/29/wikileaks-using-amazo...
11–20 of 70 posts
I'm not familiar with Amazon's content policies, but I couldn't see Amazon wanting this stuff hosted on their servers.
http://blogs.wsj.com/digits/2010/11/29/wikileaks-using-amazo...
This is very interesting. If Wikileaks does in fact become designated a terrorist organization by the US, then it seems Amazon will have to shut them down or run the risk of providing them "material aid". The same would be true of any other cloud provider... are there any sizable cloud providers outside the US?
The overheated rhetoric spewing from some politicians notwithstanding, I can hope that no court of law will be persuaded that there can be a terrorist organization without weapons, indeed without violence of any kind. (Even if Assange has committed some violent crime on his own -- and I am not saying he has -- this is clearly not the purpose of the organization.)
Why don't they invest some of the donation money in P2P DNS and start hosting the site as torrent ? Many people would be happy to seed.
They could try popularizing Freenet (which is already existing and is a fairly stable technology), but, again, I'd guess they probably have their hands full of other tasks already.
WikiLeaks hosts torrents. For example see the link "Click here to download full site in single archive" at the bottom of http://cablegate.wikileaks.org/. And, I believe, the content is already copied to (and being discussed at) Freenet and other similiar P2P networks.
08:57:41.211436 IP managed.unixy.net.49467 > ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http: S 1398247905:1398247905(0) win 5840
08:57:41.264403 IP ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http > managed.unixy.net.49467: S 1288073904:1288073904(0) ack 1398247906 win 16384
08:57:41.264424 IP managed.unixy.net.49467 > ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http: . ack 1 win 5840
08:57:41.318642 IP ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http > managed.unixy.net.49467: R 1288073905:1288073905(0) win 16384
The Reset packet sent from the EC2 node to the initiating node is a probe to identified non-existent nodes (spoofed). Notice in the above handshake that the initiating node didn't send a packet-response to the Reset. On the second consecutive attempt though all appears well (because the EC2 node added the initiating node to the ACL).
08:57:42.961708 IP managed.unixy.net.49468 > ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http: S 1394481180:1394481180(0) win 5840
08:57:43.016547 IP ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http > managed.unixy.net.49468: S 1406181195:1406181195(0) ack 1394481181 win 5792 08:57:43.016564 IP managed.unixy.net.49468 > ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http: . ack 1 win 46
08:57:51.100914 IP managed.unixy.net.49468 > ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http: P 1:18(17) ack 1 win 46
08:57:51.180674 IP ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http > managed.unixy.net.49468: . ack 18 win 724 08:57:56.206546 IP managed.unixy.net.49468 > ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http: P 18:39(21) ack 1 win 46
08:57:56.261630 IP ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http > managed.unixy.net.49468: . ack 39 win 724
08:57:56.678942 IP managed.unixy.net.49468 > ec2-184-72-37-90.us-west-1.compute.amazonaws.com.http: P 39:41(2) ack 1 win 46
But I wonder just how long they'll be able to evade the attack.
Regards
Shouldn't we really be trying to get to the bottom of who is behind this DDoS attack? If Wikileaks is said to be a terrorist organisation, isn't this an act of war?
This is very interesting. If Wikileaks does in fact become designated a terrorist organization by the US, then it seems Amazon will have to shut them down or run the risk of providing them "material aid". The same would be true of any other cloud provider... are there any sizable cloud providers outside the US?
It looks like it's hosted in the US (ec2-184-72-37-90.us-west-1.compute.amazonaws.com). Also, the front end proxy is doing some heavy filtering to weed out the cheap hit-and-run nodes participating in the DDoS but still accepts legitimate browser-based requests (persistent). Notice how a Reset (R) is sent right away on the first try: 08:57:41.211436 IP managed.unixy.net.49467 > ec2-184-72-37-90.us-west-1.compute.amaz…