Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

internet.commerce
Be a Commerce Partner

Imprinted Promotions
Corporate Gifts
Laptop Batteries
Computer Hardware
Calling Cards
Web Hosting Directory
Promotional Products
Memory Upgrades
KVM Switches
Compare Prices
Home Improvement
Shop
Online Shopping
Computer Deals

The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

 
  Rethinking the Datacenter
Sponsored by HP
Today's datacenters need to increase utilization, get control over power and cooling costs, and align with business objectives. Download this eBook to learn about the challenges facing the data center in a world where digital information is growing at a torrid pace and costs are being held in check. Learn more. »
 
  Putting the Green into IT
Sponsored by HP
Electricity use in data centers is skyrocketing, sending energy bills through the roof, creating environmental concerns and generating negative publicity. "Going Green" means looking to technologies like virtualization, energy-efficient chips and racks, and implementing policies that extend beyond the data center. Learn more. »
 
  Managing the Modern Network
Sponsored by HP
In a global economy where information crosses the globe in an instant, and where Web-based applications power business, it's more important than ever to ensure your network is safe from threats and optimized to deliver the data your business needs. »
 
  Evaluating Software as a Service for Your Business
Sponsored by Webroot
Is Software as a Service just hype, or is something really going on here? See if your company can benefit as SaaS tries to change the face of the enterprise. »
 
  Is Your Disaster Recovery Plan Good Enough?
Sponsored by HP
Preparing for a disaster is more often than not part of the storage planning process, and it is one of the most difficult tasks, since it includes local hardware and software, networking equipment, and a test plan. Learn how to get disaster recovery right. »
 

Current Newswire:

The Convenience of Proprietary Software (From a Purchasing Angle)

Please Welcome Digistan

Ubuntu's Pipe Dream: True Free Software Syncronicity

Nothing New Under the Sun. Or Red Hat, or FSF, or OSI, or...

Open-Source Security Idiots

Microsoft's Quiet War Against GNU/Linux on Motherboards

Reflections on Open Source Commerce, Part 2

Novell Readies Silverlight Clone for Linux

A Tale of Four Kernels

Gentoo Foundation Reinstated, Gentoo Council Goes Out with a Fizzle

Senior Unix Engineer
I T Search
US-NE-Kimball

Justtechjobs.com Post A Job | Post A Resume
:Update: ESR Confirms DoS Attack; Hacker to End Attack
Update: ESR Confirms DoS Attack; Hacker to End Attack
Aug 25, 2003, 05 :00 UTC (99 Talkback[s]) (50208 reads)

(Other stories by Eric S. Raymond)

ESR Confirms DoS Attack; Hacker to End Attack

By Eric S. Raymond
President
Open Source Initiative

I have just received confirmation that there was indeed a DoS attack on SCO's network, a rather sophisticated one organized by an experienced Internet engineer. The person responsible has agreed to terminate the attack in response to my earlier request[1], but it will not actually end until the timers on his 'bots run out.

I don't actually know who the attacker is, and don't want to; the person who phoned me was not him, but an associate -- what spies call a cut-out. It is clear that the attacker was no script kiddie; he was able to come up with a subtle, selective attack that only took out a subset of sites on the subnet that hosts SCO and looked like a site outage from the outside.

I had been hoping, and actually expecting, that the attacker would turn out to be some adolescent cracker with no real connection to the open-source community other than a willingness to stand down when one of its leaders asked. But no; I was told enough about his background and how he did it to be pretty sure he is one of us -- and I am ashamed for all of us.

This attack was wrong, and it was dangerous to our goals. I realize the provocation was extreme; since March SCO has threatened, grossly insulted, and attacked our community and everything we've worked for. I'm certainly not without sympathy for the person who did this.

Nevertheless...we must *never* make this mistake again, whether against SCO or any other predator. When we use criminal means to fight them, no matter what the provocation is, we bring ourselves down to the level of the thieves and liars now running SCO. That is unethical, and bad tactics to boot.

Public opinion matters, it even influences judges. We must do right, and we must be *seen* to do right, in order to win against SCO and the bigger, nastier foe pulling their strings. In an info-war like this, truth is the most potent weapon, but a reputation for virtue and honesty runs a close second. Don't be the one to throw ours away!

One more request. Please try to keep the conspiracy theorizing under control, at least in public forums. Yes, SCO is behaving much like a sock puppet of Microsoft now, but we have neither any evidence of conspiracy prior to the lawsuit there nor any need to suppose it to explain either company's behavior. Overheated speculation about how long they've been plotting this just makes us look paranoid. Stick to the facts; Microsoft, a convicted predatory monopolist, is funding a lawsuit against its only serious competition to the tune of more than six megabucks, and their money is the only real income SCO has. That's quite enough without the speculation.

Rebel Alliance provisional command...uh...thanks you for your cooperation. There will be further dispatches shortly. Keep watching the skies...

[1] http://lwn.net/Articles/46229/

Let SCO Hang Itself

The confrontation between SCO and the open-source community has now escalated to open war. I suppose, in retrospect, that this was inevitable once SCO announced its intention to sue on a theory that would make all open-source licenses invalid. And we all know who's lurking like Emperor Palpatine behind Darl Vader, funding his lawsuit to the tune of at least $6,000,000[1] even if not otherwise pulling his strings.

SCO/Caldera's site is being hit by a massive denial-of-service attack today. The timing, the scuttlebutt on Slashdot and elsewhere, and the contents of my mailbox all suggest strongly that the DOS attack was triggered by Darl McBride's slanderous interview[2] accusing the community of being IBM's sock puppets, and my response[3] to it.

It appears that my response articulated what many of us have been feeling for months as SCO's public rantings grew ever wilder and more destructive. McBride's personal accusations against me bother me very little, but I am nevertheless honored and humbled by the heartfelt support many of you have emailed. A good number of you seem to want to elect me your war-leader in this crisis -- maybe it's time for me to dust off that Obi-Wan Kenobi costume the SVLUG people made for me to wear on the original Windows Refund Day :-). I will strive to be worthy of your trust.

With whatever authority I have, I ask that the DOS attack cease immediately. Please stand down now. We have better ways to win this fight.

There are at least three reasons running a denial-of-service against SCO is a bad idea:

First: We're the good guys. But that doesn't matter if we aren't seen to be the good guys. We cannot fight our war using vandalism and trespass and the suppression of speech, or SCO will paint us as crackers and maybe win. Let's keep the moral high ground here.

Second: We have other tools that are more powerful. We have an astonishingly strong set of facts on our side. SCO has been caught in multiple lies, wholesale IP violations, and defamatory statements. The way to destroy them is with legal weapons. We can do that.

Third: SCO is its own worst enemy. Every time its spokespeople open their mouths, they dig their company's grave a little deeper. Consider their statements at SCOforum and what followed. We're in an even stronger position than we were three days ago.

We want them raving in public. It helps us. Everything they say is more rope to hang them with in a courtroom, but they're too trapped in their own propaganda-based strategy to do the smart thing and shut up. Their problem is that the moment they stop FUDding long enough for people to get a clear-eyed look at the facts[4] their credibility will evaporate and their stock price will crash hard. Even all the legions of Microsoft's press shills, captive analysts, and astroturfers won't be able to rescue them.

Stop the DOS attack. Let SCO speak out and hang itself.

Right now, the most helpful thing you can do is collect SCO's published statements and show how they have repeatedly contradicted themselves and lied about the facts. I've received some genuinely useful stuff by email describing factual and legal vulnerabilities that the research team[5] here at Alliance HQ didn't spot on its own -- papers like Greg Lehey's analysis[6] of the code SCO revealed at SCOforum showing that they must have stripped BSD copyrights out of their kernel tree. The reports indicating reason to believe that there is probably GPLed code in Unixware's Linux Personality Module were helpful too.

One of our big advantages over SCO is distributed brainpower. There are a lot of us, and we have excellent Internet-research skills. Want to strike a blow against SCO? Help convict them using their own public statements, their own 10Ks and 10Qs, all the press coverage, the material that's in their web and FTP sites. Collate. Assemble dossiers. The facts are with us, so gather and use the facts. All cheesy Star Wars references aside, this is info-war. Truth -- believable and provable truth -- is the weapon.

This is why sites like the IWeThey SCOvsIBM page[7] and WeLoveTheSCOInformationMinister[8] aren't just good clean fun; they're valuable references to help lawyers demonstrate SCO's record of bad faith, lies, and massive intellectual-property theft. Do more of that; in particular. the IWeThey wiki badly needs updating and better cross-references. These things will be used to defeat SCO -- and sooner than you probably think.

I'm organizing a conference call early this coming week among a few key leaders to decide on the next stage of our response. Have patience. There is a plan developing, which I can't talk about because the element of surprise is part of it. We will counterattack at a time and place of our choosing and we will win.

Rebel Alliance provisional command, over and out... :-)

[1] http://www.infoworld.com/article/03/08/08/31OPcringely_1.html

[2] http://www.nwfusion.com/news/2003/0825scoatta.html

[3] http://www.catb.org/esr/writings/mcbride.html

[4] http://www.opensource.org/sco-vs-ibm.html

[5] The research team: myself, Rob Landley, and Catherine Raymond, esq.

[6] http://www.lemis.com/grog/SCO/code-comparison.html

[7] http://twiki.iwethey.org/twiki/bin/view/Main/SCOvsIBM

[8] http://www.anerispress.com/wltsim/
--

Eric S. Raymond

Related Stories:
OSI President Responds to SCO's DoS Claims(May 07, 2003)
PR: FBI Investigating DDoS Attack, SCO Suspects Link to Linux Community(May 06, 2003)
CNET News: Net Attack Crushes SCO Web Site(May 03, 2003)


Index Mode   |   Flat Mode   |   Thread Mode   |   Thread Flat  
  Talkback(s) Name  and Date
One other explanation could be Darl shut ...   Are we sure its a DOS attack?   
Uno Engborg
Aug 24, 2003, 12:55:12
 
Eric has once again spoken like a true l ...   BADA_BING!   
christian kuzmanic
Aug 24, 2003, 13:27:58
 
>"Second: We have other tools that are m ...   Contrary to all evidence microsoft did win too   
wb
Aug 24, 2003, 13:36:06
 
Since SCO is not getting any new custome ...   It doesn't hurt sco at all   
Brad
Aug 24, 2003, 13:45:24
 
This article is perhaps even more ignora ...   Eric Raymond's Assumption that the DOS on SCO   
Hayl
Aug 24, 2003, 13:45:47
 
From the article:There is a plan develop ...   This is promising   
stwrtpj
Aug 24, 2003, 13:57:50
 
 I think it is irresponsible of ESR to a ...   Innocent until proven guilty   
Abe
Aug 24, 2003, 14:04:10
 
Use the Source Luke! Honest to God, this ...   Red Leader Stay on Target!   
Simplicissimus
Aug 24, 2003, 14:23:12
 
You have stated that there is a possibil ...   SCO behind DDOS on sco.com   
Norman MAdden
Aug 24, 2003, 14:26:05
 
Can someone get some MRTG graphs from th ...   DOS?   
Christopher Curtis
Aug 24, 2003, 14:26:13
 
Good day;    While some rightfully anger ...   Maybe not the OSS folks doing the DoS..   
Jeff Cobb
Aug 24, 2003, 14:26:49
 
so those f%¤&#g punks in redmond are inv ...   6 miljon for a license?   
Albert Elfv
Aug 24, 2003, 15:14:18
 
Some are reporting evidence that there i ...   DOS? RUSure?   
robT
Aug 24, 2003, 15:25:58
 
Stop the Dos attack it just gives Darl a ...   I agree   
K. P.
Aug 24, 2003, 15:31:13
 
if the DOS stops (assuming it exists at  ...   watch out   
geoff lane
Aug 24, 2003, 15:43:25
 
I think it's SCO DOSing themselves i ...   My conspiracy theory   
gazonk
Aug 24, 2003, 16:00:37
 
FWIW, I did find a mention now at grokla ...   Re: DOS?   
Christopher Curtis
Aug 24, 2003, 16:35:00
 
Do "we" really know that this is "our" d ...   Is it really   
drew Roberts
Aug 24, 2003, 17:18:40
 
This is only speculation, but what if th ...   Are you sure it's coming from Linux users?   
Ursus Orribilus
Aug 24, 2003, 17:38:29
 
The key question is, is the attack reall ...   Is there really a DOS attack?   
Anil Wang
Aug 24, 2003, 17:45:47
 
For one I can see that there are those t ...   DOS Attacks   
Jim
Aug 24, 2003, 17:48:41
 
I forgot to mention in my previous post  ...   Addendum:   
Ursus Orribilus
Aug 24, 2003, 17:50:14
 
I can access www.canopy.com just fine. C ...   Why then can I still reach out to www.canopy.com&#   
Kurt Pfeifle
Aug 24, 2003, 17:51:47
 
Mr. Raymond:With all due respect, I thin ...   Who says it's our side?   
Michael A. Hobson
Aug 24, 2003, 17:53:47
 
According to this link:  http://radiocom ...   Not a DOS attack?   
Derik
Aug 24, 2003, 18:23:53
 
...this may seem like a bit of a stretch ...   Just a second here...   
Penguinisto
Aug 24, 2003, 19:14:16
 
*IF* certain individuals on the internet ...   Irresponsible comments from ESR   
Anonymous
Aug 24, 2003, 19:23:13
 
While I believe that the community is un ...   Hmm. Okay.   
Paul Dorman
Aug 24, 2003, 19:34:44
 
Nice letter overall, but I can't hel ...   *sigh*   
sdfsdf
Aug 24, 2003, 20:15:45
 
>SCO-scum may or may not have been hit w ...   To Eric   
blacklight
Aug 24, 2003, 20:23:03
 
MuParadigm has taken the time to do a tr ...   DDOS are you sure   
Charles Esson
Aug 24, 2003, 21:03:44
 
> >"Second: We have other tools that are ...   Re: Contrary to all evidence microsoft did win too   
christian kuzmanic
Aug 24, 2003, 21:08:10
 
sco.com, caldera.com, and calderasystems ...   why not DOS email server   
whg
Aug 24, 2003, 21:36:31
 
> Can someone get some MRTG graphs from  ...   Re: DOS?   
Bojan Smojver
Aug 24, 2003, 21:39:12
 
 http://news.netcraft.com/archives/2003/ ...   Netcraft   
Yo
Aug 24, 2003, 22:15:38
 
> Can someone get some MRTG graphs from  ...   Re: DOS?   
Daniel
Aug 24, 2003, 22:22:39
 
> One other explanation could be Darl sh ...   Re: Are we sure its a DOS attack?   
Wogster
Aug 24, 2003, 22:32:58
 
Anyone else having problems getting to m ...   Microsoft   
Nick
Aug 24, 2003, 22:56:51
 
Maybe the FBI confiscated SCO's webs ...   possible SCO Federal raid   
Norman Madden
Aug 24, 2003, 22:58:41
 
Perhaps ESR should have put emphasis on  ...   Emphasis on the "If"   
J. Buckle
Aug 24, 2003, 23:12:48
 
Eric,All this could be a masquerade tryi ...   Caution .... Beware !!!   
cyzedx
Aug 24, 2003, 23:18:27
 
Eric, if you are going to do something:  ...   To Eric - II   
blacklight
Aug 25, 2003, 00:40:56
 
...as McBride is suffering from a Denial ...   Quite appropriate...   
LackeyOfIBM
Aug 25, 2003, 00:46:54
 
Well, they must be. They're behind e ...   IBM are DDoSing The SCO Group   
Leon Brooks
Aug 25, 2003, 00:47:54
 
It would make a bizarre kind of sense if ...   Perhaps someone put that webserver through a shred   
Leon Brooks
Aug 25, 2003, 01:00:10
 
Very good catch. SCO continues to play a ...   Re: Why then can I still reach out to www.canopy.c   
Blue Knight
Aug 25, 2003, 01:02:50
 
> Amazingly, it seems that www.sco.com a ...   Re: Re: DOS?   
Bojan Smojver
Aug 25, 2003, 02:22:32
 
> If you are moving in for the kill, do  ...   Re: To Eric - II   
Bojan Smojver
Aug 25, 2003, 02:24:17
 
Maybe someone sent SCO a "cease to exist ...   Re: Quite appropriate...   
Norman Madden
Aug 25, 2003, 02:49:02
 
"Who knows if they even still employ any ...   Re: Re: DOS?   
Norman Madden
Aug 25, 2003, 02:59:34
 
Once again, it is time for Eric to promo ...   Eric, get lost!   
Ruiz
Aug 25, 2003, 03:00:13
 
``I bet they don't come back ...   Re: DDOS are you sure   
Richard N. Turner
Aug 25, 2003, 03:40:12
 
While I appreciate the work that ESR doe ...   ESR: Self-Appointed Leader?   
XYZ
Aug 25, 2003, 06:13:51
 
  Why not take responsiblility for the " ...   While you are at it.   
yoseph t.
Aug 25, 2003, 06:46:10
 
ESR is such a windbag. If anything he ma ...   ESR is the only embarassment I see around here   
Schmo
Aug 25, 2003, 07:16:34
 
I have a bad feeling over this one - hea ...   This could be baaa-aaad   
SteveOC
Aug 25, 2003, 07:36:13
 
Oooh, I am such a bad man.  I approve of ...   It's a good thing   
Mikel Kirk
Aug 25, 2003, 07:59:02
 
> if the Bush administration thinks      ...   Re: Re: Contrary to all evidence microsoft did win   
R.L.
Aug 25, 2003, 08:37:16
 
All that noise looks like there is no ot ...   work   
Sergey
Aug 25, 2003, 09:20:08
 
well, this is just great.  so now, with  ...   jeezus, eric, will you shut the hell up?   
rday
Aug 25, 2003, 11:08:31
 
> Apache is released under the Apache So ...   Re: Re: Re: DOS?   
Daniel
Aug 25, 2003, 11:37:10
 
As you can clearly see, MS in involved i ...   MS involvment prooved   
ac
Aug 25, 2003, 11:45:30
 
I Agree. There are much more important t ...   re: work   
Jim
Aug 25, 2003, 11:54:13
 
> Microsoft.com now pops out a home page ...   Re: This could be baaa-aaad   
Bojan Smojver
Aug 25, 2003, 12:33:41
 
Why don't you get lost?  God, man, c ...   Re: Eric, get lost!   
Chad
Aug 25, 2003, 12:34:23
 
You and all the other ESR bashing idiots ...   Re: jeezus, eric, will you shut the hell up?   
Chad
Aug 25, 2003, 12:37:03
 
Then go.......who's stopping you?  ...   Re: ESR is the only embarassment I see around here   
Chad
Aug 25, 2003, 12:38:30
 
In any case, it is grossly irresponsible ...   Re: Irresponsible comments from ESR   
AC
Aug 25, 2003, 12:56:56
 
Honestly ESR, since you don't know a ...   Any Proof?   
drew Roberts
Aug 25, 2003, 13:27:12
 
> I was told enough about his background ...   I'm not buying it   
Anil Wang
Aug 25, 2003, 13:36:32
 
"Public opinion matters, it even influen ...   Do the right thing   
ken
Aug 25, 2003, 14:00:36
 
I see no good from the DoS, even though  ...   Wdo benefits?   
Ed Craig
Aug 25, 2003, 14:05:42
 
Why is Eric Raymond still making sweepin ...   Eric Raymond is STILL making generalizations   
Hayl
Aug 25, 2003, 14:43:18
 
I have long enough to be more scared (ge ...   Re: Re: Eric, get lost!   
blacklight
Aug 25, 2003, 14:55:44
 
>First: many of those of us use SCO-scum ...   Re: Wdo benefits   
blacklight
Aug 25, 2003, 15:17:26
 
> Why don't you get lost?  God, man, ...   Re: Re: Eric, get lost!   
Derik
Aug 25, 2003, 15:25:56
 
Me too I am not buying it. Besides, prov ...   Re: I'm not buying it   
R.L.
Aug 25, 2003, 15:38:51
 
Among the chief criticisms of SCO's  ...   Show us the proof, and the justice   
Fra. 219
Aug 25, 2003, 15:46:25
 
> I have long enough to be more scared ( ...   Re: Re: Re: Eric, get lost!   
Alvin Davis
Aug 25, 2003, 15:49:36
 
It is a well known tactic - to attack yo ...   SCO DoS-ed themselves   
ongeboren
Aug 25, 2003, 15:53:51
 
What are we to make of the fact that SCO ...   SCO *Still* Down   
Daniel
Aug 25, 2003, 16:05:05
 
We need to tell ESR to shut up.  The tim ...   Stupid and dangerous.   
Jerry Rian
Aug 25, 2003, 16:05:59
 
I don't understand why you would ass ...   That was really bad judgement, Eric   
codez
Aug 25, 2003, 16:17:54
 
I'd just like to add my voice.I cons ...   Re: Re: Irresponsible comments from ESR   
Steve Bergman
Aug 25, 2003, 16:22:58
 
I know it was a joke, but the bit about  ...   "provisional command"   
Joe Buck
Aug 25, 2003, 16:28:23
 
Who the hell elected ESR as our leader?  ...   What leader?   
Monkey boy
Aug 25, 2003, 16:39:27
 
Hey Stranger !it seems you haven't m ...   Re: Eric, get lost!   
cyzedx
Aug 25, 2003, 17:03:24
 
well, I was amused by ESR comments, but  ...   hum   
GuyCLO~
Aug 25, 2003, 17:40:55
 
This is the problem: I don't know Er ...   Re: Re: Eric, get lost!   
blacklight
Aug 25, 2003, 17:56:30
 
  ESR why are you incriminating ourselve ...   "he is one of us " ?!?!   
luke skywalker
Aug 25, 2003, 17:58:39
 
> well, I was amused by ESR comments, bu ...   Re: hum   
Anil Wang
Aug 25, 2003, 19:10:03
 
This DoS story is just as faked as the " ...   Yes, he's our McBride (was   
brit
Aug 25, 2003, 21:02:09
 
http://radio.weblogs. com/0120124/2003/0 ...   Go and Have a look at Groklaw Aug25   
Charles Esson
Aug 25, 2003, 22:13:57
 
The fact that ESR was the one that coine ...   Re: Re: Re: Eric, get lost!   
erik
Aug 25, 2003, 22:53:47
 
>>ESR has two good skills. When he sets  ...   Re: Re: Re: Eric, get lost!   
copy_chief
Aug 26, 2003, 01:10:31
 
> The fact that ESR was the one that coi ...   Re: Re: Re: Re: Eric, get lost!   
schmo
Aug 26, 2003, 02:36:42
 
... is hosted with ... TADA! IBM (Sequen ...   The SCO site that still works...   
Bojan Smojver
Aug 26, 2003, 08:59:36
 
It would be *SO* much more "professional ...   stripslashes   
Benjamin Smith
Aug 31, 2003, 07:03:17
 
Is there a solution on DoS attack in lin ...   Is there a solution on DoS attack in linux   
Rahul
Jul 17, 2004, 05:08:54
 
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address: