Security Watch: Squatters Jumping Claims To Domain Names

Team Evil vs. Israel

In early July 2006, as hostilities flared up between Israel and Palestinians in the Gaza strip, an attack was initiated on servers belonging to Israeli and pro-Israeli organizations by a Moroccan hacking group named "Team Evil."

A forensic analysis by Beyond Security's beSIRT team succeeded in disrupting the servers and defacing some of them. The attack shows that best practices are often crucial in protecting critical resources.

The major opening for Team Evil was the fact that Internet-facing applications on the servers were not kept up to date with the most recent security patches. This gave the attackers publicly-known avenues for attack.

In some cases, applications that were compromised were run with excessive privileges, with the result that other parts of the system were vulnerable.



Comment on this article
Be the first to comment on this article.
Upcoming eSeminars

Data Protection Virtual Tradeshow
Cameron Crotty 50x50

Available On-Demand
Join Cameron Crotty and experts as they explore best practices and solutions needed to maintain a secure flow of data.
Available On-Demand
Security 2.0: Controlling Complexity
with Cameron Crotty. Sponsored by Symantec
Available On-Demand
Backup Exec 11d - The Gold Standard in Windows Data Recovery
with Frank Derfler. Sponsored by Symantec
Advertisement