RSS 2.0 Follow Us!

Related Posts

Cyber Disenfranchisement: Lieberman Hacked on Primary Day

John on August 8, 2006 at 10:49 am

[Welcome Michelle Malkin readers.]

Lieberman vs. Lamont is the most high profile contest of the 2006 election season. Daily Kos and the NY Times are supporting Lieberman’s challenger because of Lieberman’s support for the war.

Today is the primary that decides who will get the Democratic nod. Here’s what you see if you go to www.joe2006.com right now:

lieberman.jpg

The site has been hacked by persons unknown, but I think we all know whose behind this last minute dirty trick. Lieberman’s campaign is calling for an investigation:

Lieberman campaign manager Sean Smith said the campaign has contacted the Connecticut attorney general’s office and asked for a criminal investigation by state and federal authorities…”Voters cannot go to our Web site. They cannot access information,” Smith said. “It is a deliberate attempt to disenfranchise voters.”

I guess the “Kos kids” weren’t convinced they could win a fair fight. Of course Ned Lamont still doesn’t know anything about blogs, so he definitely wouldn’t know anything about this.

Someone needs to go to jail for this.

Update: On his front page Kos speculates that Lieberman’s campaign forgot to pay the bills:

Can you believe that Lieberman’s site is still down? I wonder if they’re still trying to blame “bloggers” for their inability to pay their bills.

He then responds to Lieberman’s campaign issuing a statement saying it was a DDoS attack. Of course, Kos thinks it might be a cover-up:

It doesn’t pass the smell test — DoS attacks wouldn’t bring down a site for 18 hours (or however long their site has been down). So it could be their hosting provider is either covering for the Lieberman campaign, or perhaps more likely, it is simply incompetent…I’m doing a bit of digging of my own on this one.

Right…and OJ is looking for the real killers.

Update 2: A quick roundup of news. First, the Connecticut attorney general has received the Lieberman campaign complaint and will be investigating the hacking. Meanwhile Lieberman adviser Dan Gerstein has acknowledged that they have no hard proof any Netroots people were behind the DDoS attack.

Over at Wonkette, the suspicion is that Lieberman’s host was simply overwhelmed by last minute visitors prior to the election. According to this post:

Joe Lieberman is paying $15/month to host his website, and has a 10GB hosting limit. This is basically the equivalent of trying to host a Katherine Harris photo gallery on Geocities. DoS nothing, an Instapundit link would’ve crashed the site.

First, I’m not sure how they know that. Second, a 10GB hosting limit? They must be talking size, not bandwidth. I pay about $7 a month and I have something like 400 GB of bandwidth, which is quite a bit unless you’re distributing lots of video or large audio files. If Joe is paying double (again, assuming that’s even accurate), he could easily have plenty of bandwidth to keep the site going. Absent more information, I’m not buying the Wonkette line.

Update 3: Kos is the source of the hosting info at Wonkette. Kos says Lieberman does indeed have a 10GB bandwidth limit. If so, that’s pretty small. However, most hosting companies don’t cut your service when you reach the limit. If you go over the limit, you get a big bill the following month.

Kos also has an update saying Lieberman was hosted on a box with 73 other sites. If so, I think that tips the balance toward an avalance of visitors crashing the site. A site expecting thousands of hits an hour needs a dedicated server. Lieberman’s people should have known better. No response from them, but for the moment I’m going to assume Kos has a reliable source.

It kills me to have to apologize to Kos, but it’s looking like he’s in the clear on this one. Then again, he was speculating that Lieberman forgot to pay his bills. Looks like we were both wrong. If more info comes out either way, I’ll post it.

Update 4: Well, I call them as I see them and this situation is changing fast. A commenter below posted a link to this Kos diary which seems to suggest there was a Lieberman specific attack:

The site is setup on a single vulnerable server, with, apparently, no backup plan. At best, completely incompetent. At worst, downright Rovian. But since another site is running fine, on the same server, it’s downright bizarre that they couldn’t fix Joe’s site in the last 18+ hours – it’s obviously not a bandwidth (DoS or limitation) issue. It appears the party line is that the site was affected by a “SQL Injection” attack. Whether this was done via the open and non-firewalled MySQL port on the single linux server, or via poor form validation, we’ll never know (if it was done at all).

So, bad hosting plan aside, it does appear Lieberman may have been hacked. Once again, the netroots suspect a conspiracy:

A quick look at this from a semi-competent admin (myself) brings me to one of two conclusions. 1) The admin(s) of this site are TOTALLY incompetent, or 2) this server was made vulnerable on purpose, in order to attract or make possible a DoS attack, which could then be used to generate negative publicity and sympathy.

Now who is leaping to wild assumtions? I know what an injection attack is but whether or not it’s traceable is getting beyond my depth. Anyone out there that can comment knowlegeably?

I’ll say this. If it was a Lieberman specific injection attack, chances are good it was a web-savvy Lamont sympathizer and not the host administrator.

Update 5: Over at NRO, Stephen Spruiell has an update from the campaign:

I just called Marion Steinfels, the communications director for Lieberman campaign, to ask her what she thought of Lamont comments (see here and here) about the website situation. She told me, “We know exactly what happened. There was a coordinated attack on our website — which we’ve explained in several statements that we’ve sent out today.” As to the idea that Ned Lamont knows that his supporters are not involved, she said, “Did he contact every blogger that supports his campaign and every person in the state of Connecticut and America that’s given money to his campaign? I’m not even sure what to say about that, it’s so ridiculous.”

[Thursday update including refutations of Kos's claims and the latest on the investigation is here. - John]

Category: Blogs & New Media |

10 Comments

  1. Casey Tompkins

    Kos says “It doesn’t pass the smell test — DoS attacks wouldn’t bring down a site for 18 hours.”

    I guess Kos didn’t hear about the Protein Wisdom DDOS attack which kept the site down for several days, hm?

    Yeah, there’s a smell around here, all right…

    August 8, 2006 @ 12:18 pm
  2. Robert Crawford

    DDoS attacks have taken sites down for days at a time, so 18 hours isn’t surprising. Kos is blowing smoke, trying to deflect from his brownshirts.

    August 8, 2006 @ 12:27 pm
  3. Brett

    If you notice the under construction page is on a mybasecamp domain server whereas Lieberman’s site is hosted on theplanet servers (looked up via whois). hmmm….

    August 8, 2006 @ 1:12 pm
  4. MirCat

    DoS attacks keep a person from connecting to a server/connection/whatever by bogging it down. As Brett states, his page is being diverted to a different server. So either Joe’s page was hacked, erased, and main page with a redirect was put in its place; or Joe’s hosting company’s DNS server was hacked; redirecting it that way.

    What I don’t understand is why is it taking so long to fix. Joe’s people could simply upload a back up (if they were smart enough to back it up in the first place). If it was the DNS it would take the hosting company like 30 seconds to fix.

    SO: The hosting company is staffed with morons OR Joe hired morons OR the hosting company itself is rooting for Lamont (making them morons) OR All of the above.

    - The Cat

    August 8, 2006 @ 1:46 pm
  5. A Moderate from South Dakota » Hacked?

    [...] Hacked? By sdmoderate It seems Senator Joe Lieberman’s campaign site has been having issues the past day or so which has brought out the Lieberman apologists and even the Lieberman camp is crying foul ( I’d link to Lieberman’s site but as of this writing, it is still down). [...]

    August 8, 2006 @ 2:09 pm
  6. Scrapiron

    Will the state AG charge them with terrorism? Maybe 20 years in the slammer would streighten out a lot of left wingers. Na, a left winger would never go to jail, insane people are confined in mental health facilities.

    August 8, 2006 @ 2:18 pm
  7. Fred

    Was any donor and credit card info stolen? Kos is saying that the site was attacked via SQL injection (See http://www.dailykos.com/story/2006/8/8/144119/5628). SQL injection is typically used to steal info from a Web site and not to shut down a site.

    August 8, 2006 @ 2:21 pm
  8. Sean O'Doherty

    A simple explination is:

    http://server1.myhostcamp.com/suspended.page/

    They exceeded bandwidth…

    August 8, 2006 @ 4:40 pm
  9. John

    Not likely. I had a site which, like the Lieberman site, was hosted on a privately owned server (along with dozens of other small sites) at Rackspace. My bandwidth limit was 2 GB per month. Suddenly one month we hit something like 30 GB, more than was allowed for the whole box.

    Here’s the thing: The server never went down. Next month we got our regular bill, plus a $400 surcharge for exceeding the limit. But it didn’t crash the server and we were never cut off. This host may have different rules than rackspace, but if it was a bandwidth problem Lieberman’s people could just write a check and up it. That would take a few minutes. The site has been down for a day.

    Now, the traffic could have exceeded what the server was capable of handling, but if that were the case, other sites on the same box would be out as well. As the Kos diarist noted above, that doesn’t seem to be the case. So at this point I’m once again leaning towards some type of malicious intent.

    Time will tell. This has become to high profile for their not to be answers at some point.

    August 8, 2006 @ 4:54 pm
  10. mitemous » Blog Archive » Joe Lieberman’s Website (juicy technical details)

    [...] http://michellemalkin.com/archives/005684.htm http://www.dailykos.com/story/2006/8/8/144119/5628 http://hotair.com/archives/the-blog/2006/08/08/zero-hour-lieberman-vs-lamont/ http://www.verumserum.com/?p=478 http://www.sdmoderate.com/2006/08/08/hacked/ I can confirm that the site is currently hosted at The Planet (just looked it up in the routing table).  This is one of the largest and most well known providers in Dallas.  They have 4 datacenters (including one inside the Dallas Infomart), and bandwidth is plentiful enough to handle a DDoS at the network level.  The network admins are probably some of the most competent in the business–I know because I have a couple production servers with them.  [...]

    August 8, 2006 @ 5:44 pm

Leave a reply

  1. You will post the following soon.
    Go ahead and start typing.