Friday, November 6, 2009 14:49
Attack on Temasek Review: not Straits Times
In Main Stories • 2,671 views • 24 Comments
Well, the truth is no warning was needed; but perhaps a little more understanding of the Internet by TR.
For, as at least one TR reader pointed out in the discussion the followed on the site, IP addresses by themselves do not prove anything. In fact IP spoofing is a common tactic used in a DOS attack and with information available readily. TR should have known that SPH is as easy prey as anyone.
***
Our NIPS vendor’s technical staff member, who checked 7 days worth of data and found no DOS activity originating from SPH concluded: “My opinion of the situation is Temasek Review released the article with very little research into what happened on its server.”
It is an expert opinion; but if opinions don’t count, here are the facts: Contrary to TRs allegations, neither did anyone in SPH try to “grab” TR material in a way that would load its server; nor did any SPH staffer launch any attack on the server.
Read the rest of the write-up at the Straits Times blog.
Read also: TR’s Rebuttal to SPH
Related posts:
24 Comments
Online Shmonline
Online Shmonline
Utopia
If you ask Burma Junta if they ever murder innocent people, they will tell they never kill innocent people, with definition of “innocent” using their own dictionary. If you ask SPH, a very mouthpiece of incumbent party whose leaders are friend friend, business partners with Junta, what will you get ? Credibility, honesty integrity, rule of law , justice, truth and reality ? Or honest mistake ?
Utopia
Geoffrey,
you wrote
“For, as at least one TR reader pointed out in the discussion the followed on the site, IP addresses by themselves do not prove anything. In fact IP spoofing is a common tactic used in a DOS attack and with information available readily ,TR should have known that SPH is as easy prey as anyone.”
You, as someone working in SPH, can’t be serious to use a anonymous commenter to augment your argument ? I thought SPH editors say and publish “word of wisdow” many a times that commenters have no credibility, and do you need me to remind you ? So why are you using TR reader to point out the technicality ?
In addition, we, as readers here, are not interested in that particular reader’s remark, rather we are interested whether you accept the TR Reader’s as the reason. Please don’t make use of scapegoat like Law Minister SHAM who use a particular writer to augment “Singapore is not a country but a city” if you not prepare to believe likewise in that scapegoat’s word. So do you, as a representative of SPH, believe that TR Reader’s remark is the reason or not ?
Next, whether you are proven right or wrong are you willing to do put your job and SPH’s reputation on the line for the truth just like TR did so ? Are you willing to issue a apology from yourself and on behalf of SPH just like TR promises to do so ?
In other words, no cheap stunt when proven wrong to put the blame on the TR’s reader whom you derive the reason from or the vendors/SPH_Employee responsible for your enquiry . No more Wong Can’t Sing’s stunt.
If so, wish you both TR and SPH good luck.
On TR’s site
‘back to SPH by our data center and showed it getting our content from as early as 2008.
SPH claimed that their logs showed otherwise:
“SPH logs also determined that no one from the company tried to access material from 2008, as claimed by TR.”
There can only be two possibilities:
1. The SPH logs did not include the period between 31st October 2009, 2200 hours and 1st November 2009, 0100 hours.
2. Our system administrator, who is a China national, falsified the server log.
Our hosting company is RTG Asia, an outshore VPS and dedicated server provider. Our system administrator is its employee.
Will a Chinese system administrator have any vested interests in TR or SPH? What will he stand to gain by hurling false accusations against SPH?
There is a discrepancy between what SPH said and what was revealed on our log.
If it is proven beyond doubt that the data shown on our log is false and no SPH IP address was “grabbing” our site content during the stipulated period of time, we will offer an UNRESERVED APOLOGY to SPH on Temasek Review under its “TOP NEWS” section immediately.
We will also lodge a formal complaint to our hosting company and terminate their services without any delay.
It is now between SPH and RTG Asia. We are as interested as anybody else to find out the truth.
SPH should come clean about what happen exactly and show us REAL PROOF of their log instead of relying on half-baked arguments and inconsistent data to mislead the public.”
Utopia
By the way, I strip off all references of web addresses in last comment otherwise very likely to place into moderation.
delo
whatever lah SPH, you should have not even officially replied. this only makes you look weak and vulnerable, even if you didn’t actually do it.
singaporedaddy
Good Afternoon,
I don’t see the wisdom of raising this matter in either TRs or SPHs blog – and there is a very simple reason why; there currently exist 147 definitions of what is and is not a DDOS attack; and if one even includes both inbound and outbound DDOS attacks; the number of interpretations is multiplied significantly – even the best subject matter experts in this area remain divided on what is and is not a DDOS attack.
So it’s conceivable; both TR and SPH may not even be using the same terms of reference to discuss this matter. I really don’t see this as something that can be resolved by simply revealing info concerning server logs; if anything it will only confuse the vast majority of readers as they do not have either the inclination or knowledge (including myself) to make an informed decision concerning this matter.
Our concern is strategic; that is to say; we do not believe the internet is an effective platform to resolve this dispute – at best it will just sharpen the climate of fear further thus militating against free and responsible online discourse; at worst, it will be seized upon by eager beaver bureaucrats who are only to willing to use this as an excuse to roll out yet another set of draconian online rules, guidelines and legislation, which we are certain will have an adverse effect on growing the economic interest of the internet.
It would serve the interest of all parties immeasurably if both SPH and TR disengage from continuing their cat fight online WITH IMMEDIATE EFFECT and try to resolve their differences in a real world quorum – we believe this would not only preserve the social harmony in the internet; but it would also allow both parties to resolve their objects of disagreement in a more amicable and congenial setting – besides from what I am able to glean from all this; no one here is really interested in this petulant cat fight – if anything it can only serve as a distraction to more important subjects currently discussed in this excellent blog and elsewhere in greater blog-o-sphere.
We hope that both SPH and TR will consider the broader implications of what we have pointed out and more importantly respect the interest of most netizens – just as the sun does not revolve around both of you; neither does the celestial properties of the internet – they remain rightly quite indifferent, I am afraid.
Meanwhile I remain yours most reliably
SD (Internet Liaison officer of the brotherhood)
This is a diplomatic communiqué from Primus Aldentes Prime ( broadcast on all channels) – DC 234-0026 EP Doberman.
Client-Server
But an Independent body is required to investigate the DOS attack.
Imagine an IT Vendor prove that DOS originate from their CLIENT, SPH’s location?
I wonder could this happen?
Jeremi Au Yang
TR need to send in its representative IT networking expert ,certified black belt ethical hacker to verify and see the evidence which claims that the DDOS did not come from there.
Or should TR just accept their expanation without asking for solid evidence that proves beyond reasonable doubt?
xisd
Jeremy, go and ask singaporedaddy aka Sergei / did he tell you. He also happens to doube as the Osfront laison officer. He regularly signs off death warrants authorizing shut downs of gaming forums whenever they misbehave in Russia. He and his pet ASDF gansters. These are the Gestapo or the SS of the brotherhood. They will kick in doors, seal off the premises and start interrogating everyone whenever a site is nuked. The Russians live in constant fear of them. So I will not be surprised if they are probably the only ones who know what is really happening here. Otherwise why would they want to keep everything under cling film? Use your brain!
Robox
Doesn’t the very pose that Geoffrey Pereira adopts for the picture in his blog scream: “I AM PAP APPROVED” – “Who the hell are YOU”?
btan
The people who initiate and continue to conduct DoS attacks on TR are nothing but a coward and an enemy to freedom of expression.
small voices
Why dont you just cut through the fog of war between wayang and strait times and tell us what is really happening SD? With these two clowns trading blows in the WWW it is giving us all a very big headache. I really dont know who or what to believe any longer!
vipersonic
Read TR’s rebuttal to sph’s article – http://www.temasekreview.com/2009/11/06/a-rebuttal-to-sphs/
I think everybody should support what TR is doing to SPH.
Big Brother’’s propaganda machine stands in its ugly nakedness.
Looks like the PAPies apparatuschiks are are now cowering when the brights lights are focused on them, revealing all their warts and sores for the whole world to see.
Keep up the good work TR, we are all for you.
des
SPH = Singapore PAP Holdings
Fiona Chan Bai Bai
But then hor, if it goes to the courts, u know that the decision would be announced from a JUDGE’s mouth, right?
Hutchison Sconana
The server hit resides in CHINA.
As such, this should be settled in China courts.
But i would prefer in internation court or the Hague.
hahaha
Interesting
Not directly related to this topic but I found this interesting. Compare:
http://www.temasekreview.com/2009/11/08/sph-an-insiders-confession/
and
http://i-speak.blogdrive.com/archive/157.html
bladerunner
How dangerous a threat do you think this episode is to rpg Singdad? Dont be insulted by this direct line of questioning. I have always respected the brotherhood, so it is only natural that our cosca and many others come to you to seek wisdom on this matter. Even you must know this is a stone in our shoe. Although we can understand why you need to play it down. We have been talking amongst ourselves. Some feel, if it is like this, it may be a better idea to go somewhere else. We ask only that you share with us all whether we can make the journey safely and happily. This is not to much to ask.
rolleyes
Hi guys, this’s just a little chat carried over from TR. I won’t partake anymore in this silly issue on a grabbing “DDOS” after this comment.
TR’s been giving brash replies to commenters and even censoring some comments. I guess they’ve recently stirred some hornet’s nest everywhere (they seriously need more editorial oversight than shooting articles off-the-cuff) and that made them paranoid thinking everyone is their enemy.
Obviously, TR is a fierce advocate of free speech. And among that, voicing doubts is the basis of checks and balance. This works both ways. You comment about people, people also comment about you. If TR really honour their conviction to this, they should also learn to manage it in a civil detached way.
In his latest reply to me, the admin questions why they should even answer to anonymous posters ( that’s me =) ) who doubt their version of truth. Then I answer – TR’s open letter to SPH is also anonymous. In fact, TR is not even a legal entity, whereas Geoffrey is a real person. TR has put his picture within their sights on their homepage. So, you see: TR – anonymous poster with no legal identity; while Geoffrey – real-life person with picture splashed openly on their site. That answers TR’s own question.
I find TR admin overly emotional. Comments on a site like TR are to be expected since the articles are so lop-sided. He needs to be civil and open, even under duress. He’s representing not just himself. If that can be, what need has he to censor free speech which is against his principle? To hide the truth? To project a squeaky picture with no blots?
Anyway, I miss wayang. I quit TR.
bladerunner II
Apart from this which I found threadbare to say the very least.
Today we all still in the dark! We dont even know whether there was actually a DOSS attack. Or even who launched it. If there wasnt a DOSS attack why was this elaborate cry wolf story hatched. Most worrying, we do not know whether it is safe to continue sinking money, time and resources into a place that is so uncertain and fraught with dangers.
More should have been done by the tribal elders to bring TR to account for their actions. Much more.
bladerunner II
Perhaps you should go and ask the headman in your tribe SD what others will think when they see that TR is just let off with a smack?
SD how many people do you think are here. Silently watching and thinking what I am thinking right now?
singaporedaddy
Good Afternoon Memphisto et al
How are you all? May I begin by first offering my profuse apologies for the delay in replying (is this the place to even have such a conversation Memphisto?). You and the other tribes should remain calm – please understand we have always valued your friendship, as we do with TR; you could say friendship is the only thing that really matters to us; without friendship, there is no community; without community, there can be no fellowship and without fellowship there can be no such thing as peace and without peace; we can never prosper – do we understand each other?
You on the other hand must also understand there are limits to what we can realistic achieve here; we will certainly try to reason with them; but the time is not right; but always remember we have no right to stop people from saying this or that in the internet; but we can ALL certainly choose how we may wish to react to all these strange developments to draw either an intelligent or stupid conclusion.
To me the only thing that matters is the four houses of the guilds have all agreed unanimously after numerous discussions with us that there was NEVER any DDos attack on temasek review – why did TR represent otherwise? Irrelevant. What is their motivation? Irrelevant. Is SPH or TR telling the truth? Irrelevant again – we don’t go into other peoples houses uninvited and tell them how to run their household.
As I said, the only thing that matters to us is the copper gilded certainty that there was never any DDos attack on TR; it never even happened so much as once – so everything is as it should be – my friends let me try to put it into perspective, if the guilds are not losing any sleep over this matter and they have much more to lose – why are the rest of you so restless?
SD

Ahh yes, the old, “He said, she said” starts!
While IP spoofing may have occurred, with someone masquerading a PC at SPH, WHY would they bother? More importantly, when there are bigger fish to fry, why would someone want to take TR offline unless they were competing for the same public space found on Google News pages. Only ST appears to possess this likely intent.
This is quite serious. Everytime TR faces a Denial of Service (DoS) attack, Google takes note and pushes their articles from it’s News Summary page because their pages are not accessible. Fortunately, their online infrastructure is getting better and such DoS (it’s not DDOS because it appears to be just one machine doing the pinging) attacks can be mitigated by a dedicated router.
Any chance of that? Should get in touch with Steve Gibson of the GRC.com. He’s dealt with cracker wannabes before. Also, quite a few guys in the IT Sec sphere here in Singapore who can help.