Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Given the nature of both organizations are not too tech-savvy, I wouldn't be surprised if the sites in question were running an unpatched version of Apache and were susceptible to this:

http://www.infoq.com/news/2011/08/apache-killer

But that is pure speculation. What I'm trying to say is there are far more tools than LOIC to pull of a DDOS attack.



riaa.org, mpaa.org, and universalmusic.com I could see being unpatched, but I would have thought justice.gov would have to be patched for compliance reasons.


That's a logical point. But compliance with what? All I can find after a quick google search is National Institue of Technology GUIDELINES, and the only laws mentioned seem to deal with user privacy.

In fact, the only compliance regulations I know of with government sites have to do with accessibility.

[EDIT] Wait, I might be wrong. The DoD guide seems to cite quite a few regs, some of which may apply to the Justice department. Too bad I can't check their site :P

http://www.defense.gov/webmasters/policy/dod_web_policy_1207...



> but I would have thought justice.gov would have to be patched for compliance reasons.

I don't think that's true. I'd imagine the server behind justice.gov has no connectivity to anything important for compliance reasons, so patching it isn't really a big deal.

Relevant xkcd: http://xkcd.com/932/


I'd be surprised, if I had the funds these organizations do and I knew I would be a likely be a target for this kind of thing I'd at least hire a security consultant to check these things over for me.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: