Dark Christianity
dark_christian
.::: .::..:.::.:.

May 2008
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31

dogemperor [userpic]
American Family Association launches DDoS on Philadelphia city mail system?

There has been a *very* interesting thread on SPAM-L, a mailinglist dedicated to fighting network abuse, regarding an American Family Association astroturfing campaign which ended up launching a distributed denial of service attack against the City of Philadelphia's email servers--specifically as a method of protesting Philadelphia's announcement they will charge the Boy Scouts local council rent for use of city meeting facilities (the city allows nonprofits otherwise in compliance with city laws to use facilities, but the city's Fairness ordinance also explicitly prohibits giving this treatment to groups that discriminate against others on the basis of religion or sexual orientation--both of which the BSA does).

The chaos seems to have started on October 24, when the mail system was brought to a screeching halt:

Philadelphia - An outcry over the city's demand of $200,000 in rent from the Boy Scouts threatened to crash the city's e-mail system this weekend.

Terry Phillis, Mayor John Street's Chief Information Officer in charge of the Mayor's Office of Information Services, confirmed he was forced to remove 150,000 Boy Scout-related e-mails from the city's e-mail system.
"We were deluged," Mr. Phillis confirmed. "We pulled the messages off so they wouldn't take the system down. It had to be done to protect system integrity."

Mr. Phillis said he believes there was a chain mail campaign to send correspondence to city officials on the issue.

"There was an active campaign to let City Council know they were against what happened," Mr. Phillis stated.
The city notified the Boy Scouts' Cradle of Liberty Council they must either adopt city non-discrimination policies, pay the market value rent of $200,000 a year, or abandon the headquarters Boy Scouts built and have occupied since 1927.

Per the article, at least one councilman received upwards of 1000 emails himself, and a similar volume seems to have been received by most of the city aldermen; the Postini mail filtering system was nearly overwhelmed by the sheer volume of email (which the system apparently flagged as spam).

Where this gets of particular interest to Dark Christianity is that the massive mailbombing of City of Philadelphia aldermen seems to have been the result of an astroturfing campaign by the AFA of Pennsylvania--the same group who formerly had Michael Marcavage as its head (and whose group Repent America essentially originated as a lobbying wing/sister org of AFA-PA, in much the same manner of relationship of Freedom's Heritage Forum, AFA-KY, and Frank Simon); Marcavage is known, among other things, for ongoing campaigns to disrupt "Gay Day" held by the Philadelphia Phillies.

And the AFA-PA seems to have coordinated with the national AFA to launch the astroturfing--one which resulted in the sending over 300,000 nearly identical emails including nearly 120,000 from one individual and nearly 200,000 from the AFA itself (which managed to trip the spam filters):
Philadelphia - A near-crash of city computers last month was a far more deliberate and pernicious event than previously believed, city officials said on Thursday.

City computers were attacked by hundreds of thousands of e-mails most of which were sent from the server of a notoriously aggressive conservative religious group proselytizing an anti-homosexual agenda.

Terry Phillis, the city's technology director, confirmed Thursday close to 300,000 e-mails, almost all of them supporting the local Boy Scouts' Cradle of Liberty Council, blasted city computers the weekend of Oct. 20, 21, and 22.
. . .
Mr. Phillis has compiled the e-mails that nearly overwhelmed his computer system into three categories. He said 11,262 Boy Scout related e-mails were delivered. The majority of the correspondence was addressed to Mayor John Street, Council President Anna Verna, and Councilwoman Blondell Reynolds Brown.

Mr. Phillis said by way of example nearly 47,000 messages were directed to Mrs. Verna on Oct. 20.
A second group of 118,181 e-mails were taken off the system and deleted by a flustered technician. The fact that such an enormous number of e-mails had been deleted was not known when Mr. Phillis first publicly spoke about the e-mail deluge last week. He said in the future chain e-mails like these would not be deleted. Instead, they will be put in place that will take the e-mails off the computer and set them aside for examination and possible delivery later.

The final category, 167,008 e-mails, were sent back never delivered because they came from the same computer address. The city's Postini spam filtering security system is programmed to automatically fend off computer attacks by returning large volumes of e-mails sent from the same source. The originating address in this case, Mr. Phillis said, belongs to the American Family Association (AFA).

The AFA is a well-known conservative Christian group working from Tupelo, Miss.

Sandy Roberts, AFA's public relations director, was contacted for comment. She referred the call to Randy Sharp, whom, she said,directed the action aimed at the City of Philadelphia. Mr. Sharp did not return the calls.

Disturbingly, there are signs--including info from an ex-AFA employee who left the organisation over its increasingly anti-LGBT stance--that this may have been part of a deliberate denial-of-service by proxy:
A former employee of AFA told The Bulletin the AFA has a mailing list of nearly 3 million members.

"Its bread and butter is the Internet," the source stated. "They send out action alerts to their millions of members with the intent of getting those members to contact the target. They get their members to flood these corporations and city governments with e-mails. The objective is to disrupt service."
Among the corporations attacked by the AFA are the Ford Motor Company and Disney - and apparently the City of Philadelphia.

"They target these groups," the source confirmed. "They use the Internet as a weapon in the culture wars. It's an effective weapon. It gets people heard."

The source confirmed the AFA started out as an anti-smut group but has increasingly focused on an anti-homosexual agenda to raise money and bring attention to their message.

Curiouser and curiouser...

A third newspaper article--now apparently revised, but the original version of which was published on SPAM-L--implicates AFA even more decisively:
COMPUTER ATTACK: The American Family Association of Tupelo, MS, headed by United Methodist clergyman Donald Wildmon, was apparently behind an Oct. 20-22 email barrage that nearly crashed the City of Philadelphia's computer system, according to the Philadelphia Bulletin.

City computers were hit by some 300,000 e-mails, most of which were traced back to the AFA computer system, said Terry Phillis, the city's technology director. Almost all of the emails supported the local Boy Scouts' Cradle of Liberty Council. Philadelphia officials have directed the Boy Scouts to comply with the city's non-discrimination policy by renouncing the National Boy Scouts' stance against accepting openly
gay members, or lose their right to use city-owned facilities. AFA representatives refused to comment on the attack.

Of note--whilst this is one of the first documented cases of astroturfing that crosses the line to a distributed denial of service attack in the email sense--this is neither the first DDoS nor the first astroturfing/"letterspamming" by a dominionist group. Calvary Chapel (and something like eight separate front companies) became positively infamous for app-spamming for "distant translator" applications to such a degree that the FCC has had to put a freeze on all new applications while it sorts out the over 13,000 apps that Calvary Chapel-linked groups put in (in some cases, involving multiple frontgroups simultaneously putting in multiple applications for distant translators of radio stations that were receiving the *same* feed through Calvary Satellite Network); another example of "letter-bombing" of this sort is the Parent's Television Council, a dominionist pro-censorship group known to be behind literally 99.9 percent of indecency complaints to the FCC (some for things as innocuous as someone saying "damn" before the watershed hour, or women in bikinis).

There is quite the active debate going on at SPAM-L on whether this sort of behaviour should be considered a bona fide form of network abuse (so far, the consensus is trending towards "yes"; there is precedent for this, including "make money fast" and 419 scams being considered a special type of spam (aka "the same thing lots and lots of times"), and deliberate attempts at automated trolling (for example, Hipcrime on Usenet) have also set a precedent for considering this abusive).

At least one commentator has even noted that there is a possibility AFA could be liable under federal laws prohibiting denial of service (via perhaps a novel interpretation of computer crimes laws as well as laws prohibiting incitement to riot; as the poster noted, "Incitement to commit actions which amount to DoS is likely enough for the movers and shakers to be indicted") and has noted a potential precedent used in a different "incitement to DDoS" case (namely, that of Colin Francis McCrae, who attempted a similar extortion DDoS against a UK county police department). Very interestingly to me, much of the discussion is explicitly taking into account the history of astroturfing by dominionist groups in general and noting that this tactic is being used *precisely* because of its abusiveness.

A minor historical note: Just because there's a lively discussion on what is being considered as "religiospam" by the net.abuse community doesn't mean that this is the first religious spam.

Far from it.

In fact, the first recorded large Usenet spam (aside from variants of "Make Money Fast", which have been ongoing pretty much continuously since 1988 or so, and a few smaller spams; the first organised Usenet spam seems to have been a variant of the 419 schemes that plague email nowadays dating from 1988, and the first known email spam dated back from 1978 from the now-borged-into-HP Digital Computers (this was, in fact, so long ago that Internet sites did not yet have .com/.net/.org addresses, still using NCP rather than TCP/IP which was still in development; the changeover to TCP/IP for the Internet would not occur until the mid-80s, and Usenet did not yet exist) was in fact a religiospam of the sort that should be very familiar to most of the readers here.

The first documented "big" Usenet spam was a largescale spam sent to practically the entire Usenet of the time--6000+ separate discussion forums--claiming that the Rapture was imminent (Clarence Thomas IV--no relation to the Supreme Court Justice--was an employee of a Seventh Day Adventist college who was fired after the incident). The spam--which is actually in part archived--was interesting in part because it contained many claims that sound much more like Assemblies theology than Seventh Day Adventist--among other things, the claim that the US had gone away from "God's Constitution" as noted in Exodus, a heavy promotion of "spiritual warfare" theology of the neopente sort (and claims straight out of Hal Lindsey's "The Late, Great Planet Earth"), and ending up with posting the (Protestant) version of the Ten Commandments as "God's Constitution"--very interestingly and eerily similar to claims made by folks promoting Roy Moore's political campaigns, among others. (In retrospect, I have to wonder of Thomas was part of either a group attempting to steeplejack the Seventh-Day Adventists or had been recruited by dominionists; the SDA has actually been surprisingly vocal (for a conservative evangelical Christian group) in protesting the "America is a Christian Nation" historical revisionism promoted by Wallbuilders et al.)