Slashdot Mirror


Gambling Sites Battle DDoS Attacks

the-dark-kangaroo writes "Gambling sites are fighting back against extortion from hackers using Distributed Denial of Service (DDoS) attacks. According to the report released by the BBC many of these attacks are coming from infected home PCs which have succumbed to a worm or virus. The gambling sites are bringing in reinforcements: Pipex, Cisco and security firm Energis are creating 'intelligent' traffic monitoring systems to help stop these attacks."

60 of 296 comments (clear)

  1. I try and try.. by XaXXon · · Score: 3, Interesting

    But I just can't feel too sorry for them.

    I mean, I know it's wrong, but when you get into that business I'm sure this isn't really that uncommon. Gambling is a shady 'business' in the first place, so if you have to deal with other shady people to keep it going, then them's the breaks, buddy.

    1. Re:I try and try.. by LordNightwalker · · Score: 5, Insightful

      Yah, and I'd feel sorry for them if they'd play nice and stop writing worms to crawl blogs and paste poker spam in the comments. You wouldn't believe the amount of spam I had to clear from my blog comment area already. Imagine my surprise when I saw the same poker spam in the comments of every single post in my blog on some computer graphics project I'm working on... Feel sorry for them? Not really.

      --
      Install windows on my workstation? You crazy? Got any idea how much I paid for the damn thing?
    2. Re:I try and try.. by really? · · Score: 3, Insightful

      Two wrongs=right?? To each his own I guess.

      --

      "Consistency is contrary to nature, contrary to life. The only completely consistent people are the dead." A. Huxley
    3. Re:I try and try.. by John+Seminal · · Score: 3, Insightful
      But I just can't feel too sorry for them. I mean, I know it's wrong, but when you get into that business I'm sure this isn't really that uncommon. Gambling is a shady 'business' in the first place, so if you have to deal with other shady people to keep it going, then them's the breaks, buddy.

      Would you prefer to deal with a bookie or a regulated buisness? At least the on-line gambling websites have to pay taxes.

      --

      Rosco: "If brains were gunpowder, Enos couldn't blow his nose."

    4. Re:I try and try.. by really? · · Score: 5, Insightful

      Why is gambling a shady biz? I don't gamble myself, but as long as they don't come to my house and force me to gamble, I don't see the shady part.
      Tax on those poor at math? Perhaps. But, why shady?

      --

      "Consistency is contrary to nature, contrary to life. The only completely consistent people are the dead." A. Huxley
    5. Re:I try and try.. by legoburner · · Score: 4, Informative

      Though a lot of online casinos do that*, not all do that and it is somewhat unfair to lump all of them in as deserving of the dDoSes.

      Some interesting stats about online gambling:
      - Those dDoSes hit 2GB/sec. More than Energis' internal network can cope with.
      - The primary dDoSers (some russian guys) were caught and arrested last year, there was a /. story about it too
      - The mafia have been involved with some US sites, but I know of at least one that got shut down when the entire board of the company got arrested
      - The WTO is trying to make the US ban on Internet gambling illegal
      - The biggest online casino is israeli-founded/based www.888.com who do multiple billion per month in turnover. You can get house win from that by taking off about 98-99.5%. (turnover counts every value of every spin of a slot machine or every wager, remove the odds of winning % for the house win)

      In conclusion, the world does not have the same laws as the US (gambling is perfectly fine in the UK for instance) and some people run responsible gambling sites and still have to put up with all the tiring crap from crackers and dDoSers.

      * technically it is their affiliates who do it through affiliate programs, but same difference, they are all guilty and could crack down on it if they wanted.

    6. Re:I try and try.. by queenb**ch · · Score: 2

      Personally, I don't feel sorry for them at all. It seems like just desserts to me since they are responsible for a LARGE portion of the spyware that we end up removing from PC's on a regular basis.

      My reply to them is WAAAAAA!!! We (the internet community) asked you not to do a bunch of things which were "bad" (spam and spyware). You went ahead and did the "bad" things and now someone who is "badder" is doing "bad" things to you and you want us to help you.

      Hmmmm...let me think about this - help the spamming spywaring jackesses - no, not today.....eat sh**, die, turn green, and bloat. I think that about covers it. Asking us to be upset about the possible demise of gambling on the internet, with the problems you have caused, is like asking someone to be upset because their hemmorhoid has suddenly and painlessly fallen off.

      In addition, I fail to see what benefit you provide anyone. Someone mentioned taxes. Most of the gambling sites are located in a few countries in Central America (like Belize) where the money is usually paid to a corrupt goverment that uses it to more efficiently repress the local population. There is strong evidence that the cocaine cartels are involved.

      2 cents,

      Queen B

      --
      HDGary secures my bank :/
    7. Re:I try and try.. by WIAKywbfatw · · Score: 4, Insightful

      Sorry but you're displaying your ignorance. Gambling is legal in most societies, and in some (eg, Hong Kong) it's a common activity that the majority of the population enjoy.

      Betting on the result of a sporting event, or anything else, via a legally authorised bookmaker is no more shady than having a cup of coffee.

      Just because you have this image of gambling that seems to be more to do with smoke-filled secret back rooms where you have to know the password and the guy behind the bar to get in than legitimate, publicly-traded and -scrutinied businesses that doesn't make it a reality.

      The gambling sites being DDOSed aren't run by crooks, they're the legitimate and legal online presences of bricks-and-mortar bookmakers as well as internet gambling start-ups.

      --

      "Accept that some days you are the pigeon, and some days you are the statue." - David Brent, Wernham Hogg
    8. Re:I try and try.. by Anonymous Coward · · Score: 3, Funny

      Dude, you just set variable Two wrongs equal to right. You just turned morality on its head.

    9. Re:I try and try.. by 91degrees · · Score: 2, Informative

      It seems like just desserts to me since they are responsible for a LARGE portion of the spyware that we end up removing from PC's on a regular basis.

      Some of them aren't. A lot of them run a perfectly legitimate business advertising through tradiaiton means.

      In addition, I fail to see what benefit you provide anyone. Someone mentioned taxes. Most of the gambling sites are located in a few countries in Central America (like Belize) where the money is usually paid to a corrupt goverment that uses it to more efficiently repress the local population. There is strong evidence that the cocaine cartels are involved.

      This is because the US is so hard on gambling. The crime organisations get involved. The ones mentioned in the article seem to be UK sites. Gambling pays a decent amount to the treasury, and it tightly regulated by the government.

    10. Re:I try and try.. by WIAKywbfatw · · Score: 4, Insightful

      Casinos seem morally irresponsible to me, letting people run up debt to the point where they put a burdon on society in order to make a profit. I'm sure this is an argument for another place at another time, but that's how I feel.

      I'm sorry, but in the US couldn't you apply that label to hospitals too? Medical bills that run into 5 or 6 figures aren't uncommon and it's a sad fact that the biggest factor in personal bankrupcy in the US is unpaid (and, more importantly, unpayable) medical bills.

      And, out of interest, where do you draw the line at what is and what isn't gambling? Is playing the lottery gambling? And in a so-called "free" society, shouldn't you be able to do what you want with your hard-earned cash? Does anyone really have the right to tell you how you can and can't use it to entertain (and possibly enrich) yourself if you're not hurting anyone else in the process?

      To be honest, I'm not in favour of unchecked gambling, but then I'm not in favour of unchecked alcohol abuse either, but you don't see church and state bringing the roof down on that ballgame, do you?

      --

      "Accept that some days you are the pigeon, and some days you are the statue." - David Brent, Wernham Hogg
    11. Re:I try and try.. by Technician · · Score: 2, Interesting

      I look at it as a zero sum gain industry. It only re-distributes wealth. It has no wealth creation or real value growth. Many industries such as farming take labor and make a product. Other than entertainment value, gambling has no product. All gambeling money is re-distributed with no net gain. That's the thing I have against the state lottery or state video poker. The state provides no product and just takes the suckers money.

      I would rather see the state earn money by providing services such as affordable broadband such as in Washington State. The state is providing $40/month broadband with telephone and 5 Gig bandwidth. It beats video poker.

      --
      The truth shall set you free!
    12. Re:I try and try.. by grammar+fascist · · Score: 2, Informative

      Medical bills that run into 5 or 6 figures aren't uncommon and it's a sad fact that the biggest factor in personal bankrupcy in the US is unpaid (and, more importantly, unpayable) medical bills.

      I'd like you to cite a source for that. I googled for it and found a few charts, most of them indicating loss of job as the #1 cause.

      --
      I got my Linux laptop at System76.
    13. Re:I try and try.. by Zooka · · Score: 5, Informative

      "This is pure BS. Poeple who try to lump Gambling in with true addictions such as drugs and smoking are simply wrong. There is no physical addiction with gambling. You won't go through withdrawl if...."

      Your understanding of "addiction" is lacking. While physical dependency on a substance is indeed not the 'exact same thing' as an uncontrollable psychological compulsion, they both CORRECTLY fall under the same general definition of "addiction".

      In other words, your opinion that physical addiction is the only "true addiction"... is simply wrong.

      http://en.wikipedia.org/wiki/Addiction

    14. Re:I try and try.. by vandan · · Score: 4, Insightful
      Sorry but you're displaying your ignorance. Gambling is legal in most societies ...


      Sorry but you're displaying your arrogance. Just because something is legal doesn't mean it is ethical. I could give you plenty of examples, but I'll leave it up to people's imagination.

      Betting on the result of a sporting event, or anything else, via a legally authorised bookmaker is no more shady than having a cup of coffee.


      What sort of a dim-witted comparison is that? Gambling devastates many people's lives. That makes people who push their gambling 'services' onto us 'shady'. Having a cup of coffee has nothing to do with it.

      Just because you have this image of gambling that seems to be more to do with smoke-filled secret back rooms where you have to know the password and the guy behind the bar to get in than legitimate, publicly-traded and -scrutinied businesses that doesn't make it a reality.


      You don't need smoke-filled, secret rooms or passwords to have a shady business. You just need to have a deficient conscience, or excess greed, and an online gambling site. Then you sit back and wait for the poor suckers to 'click', 'click', 'click', 'click', 'click', 'click', 'click'. People don't rock up to a gambling establishment and try their luck once. They stay their until they're out of money. You can disagree with me if you like, but every time I go to a casino ( get dragged their by workmates once a year or so ), the above is what I witness.

      The gambling sites being DDOSed aren't run by crooks, they're the legitimate and legal online presences of bricks-and-mortar bookmakers


      I don't think so. People running gambling sites are far more likely to be dodgy than those in a physical establishment. It's far easier to police a 'real' gambling business than a virtual one, especially since a virtual one can hide it's location and reside in a place that has no regulation.

      Also, I get a fucking shitload of SPAM from gambling sites. Right away that says to me that the people running the sites are far from innocent, law-abiding citizens.

      You seem to try to make the point throughout your post that because something is legal, that somehow blesses the activity. I suppose the opposite of this is that everything which is illegal is patently evil. Both points are absolutely ridiculous. There are plenty of things which are legal which are evil:

      - selling carcinogen-soaked cigarettes
      - selling alcohol
      - selling weapons
      - having a monopoly ( esp. a media monopoly )

      Likewise, there are plenty of things which are illegal which are quite harmless ... possibly even good ... and should be legal:

      - recreational drugs
      - not voting if there's no-one worth voting for ( Australia )
      - being a member of the Iraqi resistance

      I'm pretty sure that I'd get disagreement on all of the above points. This reinforces my argument that:

      - you should never use the law to enforce ethical behaviour in private matters
      - you should never use an activity's legal status as an indicator of it's ethical status

      Back to the topic of the actual article ... I don't really relate to the DDOSers ( they're probably just other gambling sites or spammers who haven't been paid for their advertising services ), but I couldn't give a toss about the online gambling sites.
    15. Re:I try and try.. by csteinle · · Score: 2, Insightful

      So, selling alcohol is "evil", but recreational drug use is morally acceptable. What? Way to go on the consistent argument there.

    16. Re:I try and try.. by Sircus · · Score: 3, Insightful

      You also don't see "Fly with us! We'll cram you into a tiny seat, next to a fat guy, have former-prison-warder-host(esses) serve you luke-warm food at 3-hour intervals and play a film with anything even potentially offensive cut from it!" ads for airlines. You see wide, open spaces, people sleeping like babies and beautiful hostesses caring for people's every need.

      It's common practice to advertise an image of something which bears no relation to reality.

      --
      PenguiNet: the (shareware) Windows SSH client
    17. Re:I try and try.. by azaris · · Score: 3, Insightful

      I look at it as a zero sum gain industry. It only re-distributes wealth. It has no wealth creation or real value growth.

      Well duh. Most industries today create nothing tangible. Think all of the services you can buy that generate no physical substance. Wash your car for $10, nothing of value is generated. In fact, the act of washing a car consumes large amounts of natural resources in the form of energy consumed and detergents that must be recovered before they are released into the natural water reserves. Does this mean we should abolish all carwashes?

      The economy isn't really about creating goods for consumption. Yes, those things are important for sustaining people but in reality as long as there is sufficient natural resources being converted to goods, the rest of the society can just spend their time trading money from one hand to another in exchange for services like gambling. Like it or not, it IS a part of the economy and provides livelyhood for hundreds of thousands.

      Many industries such as farming take labor and make a product. Other than entertainment value, gambling has no product.

      You can probably come up with a dozen other industries that similarly offer only entertainment.

      All gambeling money is re-distributed with no net gain. That's the thing I have against the state lottery or state video poker. The state provides no product and just takes the suckers money.

      You can justify all you want, but the truth is that any objection against gambling is purely moral. I'm always amazed at how ass-backward conservative Slashdot is when it comes to things like gambling, but I guess that's the US mentality of "gambling evil" at work.

      I would rather see the state earn money by providing services such as affordable broadband such as in Washington State. The state is providing $40/month broadband with telephone and 5 Gig bandwidth. It beats video poker.

      Did it ever occur to you that maybe the proceeds from the state lottery are used to subsidize such projects? Duh indeed.

    18. Re:I try and try.. by pk2000 · · Score: 3, Interesting

      The most overlooked form of gambling is insurance. You place a bet that your house will catch fire. If it doesn't then you loose your bet. If it does you win!! But your winnings are actually less than the value of the damage.

    19. Re:I try and try.. by TheClassic · · Score: 2

      The gambling sites don't write worms to paste poker spam anymore than freeipods.com does. Its the people who are trying to take advantage of affiliate programs who do it.

  2. Great Idea by IInventedTheInternet · · Score: 5, Funny


    A moment of silence for the kneecaps of the virus writers if/when discovered.

    1. Re:Great Idea by bsharitt · · Score: 2, Funny

      No, the people behind online gambling are more devious than that. They'll use hundreds of bots to spam the virus writers websites with gambling related links.

  3. Where's my violin? by mizhi · · Score: 3, Insightful

    I know these gambling sites are legitimate companies, but it seems the worms that most people get are advertising either porno shops or gambling shops.

    It's difficult for me to feel sorry for gambling sites getting DDoSed.

    --
    Humorless sig goes here.
  4. Legal issues? by britneys+9th+husband · · Score: 5, Interesting

    Ok, I'm not sure about those other companies that were mentioned, but Cisco is a U.S. company. And internet gambling is illegal in the United States. Now, don't get me wrong, I don't give a shit whether people gamble on the internet, and I see the anti-internet-gambling laws as having as much to do with protecting monopolies as anything else.

    Now that I've said that, how is this not a legal issue for Cisco? Surely the FBI, DEA, and assorted other federal agencies would be all over Cisco if they were helping Colombian drug cartels in any way whatsoever. How do they "get away" with it? Aren't they essentially aiding and abetting what in the U.S. is considered a criminal enterprise? I mean, as an individual I can go place bets at some offshore casino and fly under the radar, but a big company like Cisco is going to have a hard time doing that, especially if their help is on the front page of Slashdot and other news sources.

    --
    Hear recorded Slashdot headlines on your phone! New service beta testing. Just call (248) 434-5508
    1. Re:Legal issues? by LordNightwalker · · Score: 5, Insightful

      Cisco is just working on solutions against DDOS attacks; it's not Cisco's responsibility if that technology is used to protect the Pentagon or some online gambling site. Following your logic, Cisco is already in trouble because those online gambling companies already use Cisco hardware in their setup... And so is Dell, 'coz they made the PCs used by the casino staff, and so is the company who made the bricks for the building their HQ is located in etc...

      See how ridiculous it gets if you stop to think about it? ;)

      --
      Install windows on my workstation? You crazy? Got any idea how much I paid for the damn thing?
    2. Re:Legal issues? by wildBoar · · Score: 3, Insightful

      The Colombian cartels are illegal in their own countries as well as in the US, the internet Gambling operations are legitimate companies operating in compliance with their local laws.

      It is a big difference.

      I'm afraid despite all attempts (wishes) to the contrary the US can't apply any law it likes on any country in the world.

      Well, not without invading it first ;-)

    3. Re:Legal issues? by nrlightfoot · · Score: 3, Informative

      As far as I'm aware the law commonly cited as making internet gambling illegal in the US is dubiously applied to the internet, and not likely to stand up as covering internet gambling if tested in court. As far as I know there is no legal precedent for the legality of internet gambling. There are however, states which have blanket laws prohibiting any gambling, and then they make specific exeptions to the law for casinos and lotteries and such.

      --
      what sig?
  5. Filtering doesn't save incoming bandwidth by A1kmm · · Score: 3, Insightful

    The bottleneck is probably bandwidth, not CPU. A network of drones can send traffic in the GBit/s range, and even if these packets are not replied to and the CPU and memory resources can cope, a lot of damage will still be caused.

    The only way to make this work is to block traffic at a site far enough back to cope with the level of traffic(and the size of botnets will only grow, so even a reasonably large network company could be knocked out).

    --
    X-Has-Sig: yes
    1. Re:Filtering doesn't save incoming bandwidth by Oddly_Drac · · Score: 2, Insightful

      "The only way to make this work is to block traffic at a site far enough back to cope with the level of traffic"

      And build a list of IP addresses to allow the botnets' ISPs to cut their accounts until they speak to someone about not being a Typhoid Mary.

      In fact, it's getting close to the time when we should be doing this.

      --
      Oddly Draconis
      Too cynical to live, too stubborn to die.
  6. NAT by Underholdning · · Score: 4, Interesting

    I wonder if the ISP's will continue selling solutions where the PC is connected directly to the internet. We've all seen the tests. It takes less than 5 minutes for a Windows PC to be taken over (or 0wned as they say). But - a simple router with NAT helps immensly. Would it help if the ISP's were forced to only sell internet access with at least a router?

    1. Re:NAT by ZorbaTHut · · Score: 3, Insightful

      Oh, yeah. That'd be great. Instead of having to squeeze the public services I want behind a single IP, I'd just be screwed. That's a real step up.

      Encouraged? Sure. Forced? I like having my open static IP, thanks.

      --
      Breaking Into the Industry - A development log about starting a game studio.
    2. Re:NAT by Anne+Thwacks · · Score: 3, Interesting
      What would really help is Microsoft being forced to sell software that is reasonably fit for the purpose for which it is sold. I seem to recall they mention that Windows is meant for use with the internet - that surely implies that it ought not to be 0wned in 5 minutes.

      In the UK, and most probably Europe, it is a very serious offence to sell goods unfit for the purpose for which they are advertised.

      Lock them up and throw away the key. Mwa, ha, ha haaar!

      --
      Sent from my ASR33 using ASCII
    3. Re:NAT by bani · · Score: 2, Interesting

      how about fines if your pc is found to be infected and participating in ddos?

      that would sure help encourage you to keep your pc clean.

      otherwise, nobody is going to bother lifting a finger protecting their windoze boxen. which is the situation now. and look at the results.

  7. Devils advocate... by John+Seminal · · Score: 5, Insightful
    Many extortionists are targeting net-based betting firms and threatening to cripple their websites with deluges of data unless a ransom is paid.

    Okay, I understand that we're talking about gambling websites. But these same methods can be used to take down just about any website. Society makes the final call on what is legal and illegal. Some might say the hackers are using their ethics to take down a vice. But if that was the hackers goal, why ask for money? Second, the tax revenue gambling generates often goes to schools. By taking them down, it would seem harm is being done in unexpected places. Politicans are responsible for planning funding, and if a bubble bursts, the community is in trouble.

    Second, do we want one, or a small group of people, telling society what they can and can't do? What if a group of Jehova's Witnesses hackers decided to remove ALL porn off the web. People would freak out. One man's utopia is another mans hell.

    --

    Rosco: "If brains were gunpowder, Enos couldn't blow his nose."

    1. Re:Devils advocate... by d1v1d3byz3r0 · · Score: 4, Informative

      Gambling revenue, in this case, would not be going to schools as the revenue is not within states jurisdiction. To my knowledge, online gambling sites are illegal to be hosted in the states. So the money is going directly into the pockets of some guy with a Carribean bank account.

  8. Prevention? by peasleer · · Score: 3, Interesting

    I know Linux based servers have the ability to limit the amount of damage a DOS/DDOS can do. I do it with my server: run daemons as their own user and limit the amount of resources they can use, both CPU and memory. That way, the system may get bogged down, but will never suffer a complete failure from a DOS attack. I am curious as to why some larger sites like the gambling networks aren't using such preventative measures. Are they not effective against larger attacks?

    --
    Mythos : Logos :: Slashdot : Intelligence
    1. Re:Prevention? by gtoomey · · Score: 2, Insightful

      Working out whats network traffic is valid becomes the issue. eg you cant easily differentiate between a valid http request and one from a zombie. If you thousands of requests/second then the site may be effectively unreachable.

    2. Re:Prevention? by jwdb · · Score: 4, Informative

      As someone stated in an earlier comment, the biggest problem is bandwidth. Your CPU may be able to handle the traffic, but when you've got a botnet spanning thousands of computers, sending you traffic in the Gb/sec range, even a serious backbone connection will begin to stutter.

      Jw

  9. Hackers by jnguy · · Score: 5, Insightful

    Why are a bunch of script kiddies being called hackers again?

    1. Re:Hackers by DingerX · · Score: 2, Insightful

      I think the hacker line is a troll man. Just call script kiddies/crackers/wire defrauders/pirates "hackers" and you automatically generate 25 indignant posts on slashdot from folks like us who remember when hacking meant turning a spare cassette port into an audio device, and a 1200-baud touchscreen vector graphics terminal was a hotrod.

      Anyway, yeah, I'm surprised online gambling hasn't been hit earlier: here you have a huge industry that relies on a single technology for all its business, and is completely unregulated. But in such an environment, cyberextortion can be a dangerous game, since unregulated companies can always fall back on "brick and mortar" security. (That is, throw bricks through your window and mortar your house) And most societies in the world have excellent non-governmental agencies who specialize in protection and kneecaps already. A few hits, a little publicity, and problem solved.

      In other words, the way to extort money is to promise protection from dDOS attacks. The ones who end up getting the dough will be those who do, whether the name is Cisco or Gotti.

  10. The root of the problem by KiloByte · · Score: 2, Insightful

    Can't we finally cut the problem at its roots? And the roots are a criminally insecure poor-excuse-for-an-OS.

    If your car notoriously breaks causing harm to other users of the road, you won't get your car's paper prolonged. If a company keeps producing cars that damage other users of the roads, that company has to replace/fix all the cars sold. Now, tell me why exactly Microsoft can get away with selling software that's harmful for the community at large?

    --
    The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
    1. Re:The root of the problem by Spy+Hunter · · Score: 2, Insightful
      Because the Internet is not controlled and maintained by the government like the road system is. (Purposely, I might add, and with many benefits. If the government controlled the Internet it would be much different than it is today. It would probably suck.) That is why your analogy is flawed.

      The market must act as the force that keeps Microsoft honest. Why the market has not done so is an interesting question. My theory is that since Windows *is* the computer for most people, any problems with Microsoft software are simply blamed on computers in general and seen as unavoidable. Though if you look at interest in Linux, a large chunk has been due to the perception that it is more secure. So there have been some effects. Apple also benefits from this, to a lesser extent I believe.

      --
      main(c,r){for(r=32;r;) printf(++c>31?c=!r--,"\n":c<r?" ":~c&r?" `":" #");}
  11. online poker by davids-world.com · · Score: 2, Funny

    How sad.

    I fear this 'online poker' guy is getting attacked, too, in which case we would miss out on all the great spam comments in our blogs. Wouldn't that be a sad, sad world?

  12. Legality and Cause by robdavy · · Score: 5, Interesting

    Firstly, the legality issue is weird to me. I come from the UK were licensed gambling (be it online or in real life) is perfectly legal. I find it rather ammusing that a whole State would ban something like gambling. Anyway, people seem to think that the reason a site dies during a DDoS attack is CPU usage. It's not. It's not related to the servers at all (at least not in the case of big attacks) We were recently hit by a DDoS attack (don't ask) and we were having our 100mb uplink saturated. That's where the problem occured. Our 13 machines could cope with the requests - the pipe couldn't. Even if we went to a Gig uplink (which was considered), they'd simply saturate that. A few hundred compromised machines on DSL/Cable can easily do that. Scary stuff I must admit.

  13. Go after the botnets... by xenobyte · · Score: 2, Interesting

    The only real way to combat DDoS through botnets is to go after the owners of the botnets... No, I'm not talking about the hackers that created or controls the botnets; taking one down only opens up a slot for someone else. No, I'm talking about the owners of the PC's that comprise the botnets. Making it a crime to participate in botnets, knowingly or not. Make people TURN OFF their PC's if they're not 200% certain they're patched and firewalled as much as possible, or face billion dollar fines and lengthy prison terms. If this forces the really lame poeple to stay off the net, so much the better.

    Complain about Microsoft and others making insecure software as much as you like, but it really comes down to stupid people not living up to their obligations as netizens. I mean, you don't just buy a car and then go driving. You need a license which involves tests, you need to renew your license in time. You need to pay some fees and you need to maintain your car mechanically. And you need to follow the rules of the road or face some form of punishment.

    There will never be such a thing as a secure OS, made by Microsoft or others. There will always be the possibility for problems and unless we let the manufacturer remotely go in and patch their machines (yeah, right!), it will have to be the owner that must take care of it.

    As simple morals and recommendations clearly doesn't make people do what they're told, we have to to add the 'or else!' clause, in the form of punishments for those slacking off and ignoring the updates.

    --
    "For every complex problem, there is a solution that is simple, neat, and wrong." -- H.L. Mencken (1880-1956) --
    1. Re:Go after the botnets... by ajs318 · · Score: 2, Interesting

      A car driver is liable if their brakes fail. This is why Third Party insurance is compulsory -- you can't be sued for money you haven't got.

      However, a technological solution might actually be better in this case. It's not like spam, which is meant for human beings and hard for a machine to determine accurately. DDoS attacks are just streams of packets. Threatening hanging and flogging only works against people who take notice of what you say and who you have a reasonable chance of catching. Nailing stuff down works against everyone.

      Could we build routers capable of blocking DDoS attacks? IPV4 addresses are 32 bits long so, to keep a very simple track of which ones were permitted and which weren't, you would need to address 4Gb of memory, or 512MB. That is certainly within the bounds of doability. Double it just so you can block outgoing as well as incoming traffic. Any address seen pushing suspected malicious packets gets blocked for awhile, then unblocked. Anyone getting blocked often enough gets a friendly word from their ISP.

      --
      Je fume. Tu fumes. Nous fûmes!
  14. Blame the right person for that by michaelhood · · Score: 2, Informative
    These are not the gambling sites that do this. These are affiliates. The gambling sites very much frown on spam, which is why some of them won't even accept traffic from e-mail, and other sources that is likely to be spam. But it's quite difficult for them to police traffic sources from tens of thousands of affiliates.

    From the PartyPoker Affiliate Agreement:

    2.13 "Spam" or "Unsolicited Promotions" means emails or any other messages that are circulated by you, directly or indirectly, including messages that are posted on newsgroups, chatboards and other types of online forums and which: 1). are directed at people who have not consented nor confirmed that they wish to receive promotional messages from you; 2). contain false or misleading statements; 3), do not truthfully identify the source or the originating IP Address; or 3). do not provide the recipient with an option to easily "Remove" them from receiving future mailings or promotions.
    1. Re:Blame the right person for that by geminidomino · · Score: 2, Insightful

      Yeah, because we know they'd NEVER have an AUP like that just for show.

      If they don't immediately terminate spamming affiliates,they are knowingly profitting from the spam. If the actually PAY OUT to the spammer, then they are condoning it.

      This tends to be the case, or else it wouldn't be a problem.

  15. Re:NAT won't help by olla+podriga · · Score: 2, Insightful

    NAT won't help at all. Most malware comes through mail, browser vulnerabilities or users that click on everthing without thinking (while logged in as admin of course). Besides, with forced NAT, people would start complaining that their favourite P2P or online game won't work.

  16. We need some "Killer" viruses by Choroisothiazolinone · · Score: 2, Interesting

    Part of the problem these days is most virii involve smtp spam and trojan horse bot's - both of which your average punter can live with and won't notice. What I'd like to see is more viruses of the smoke your hardrive and blow up your monitor kind. People would be damn careful about popups, AV products and firewalls if this were the case.

  17. ISPs by gilesjuk · · Score: 2, Insightful

    It should be part of your ISPs AUP that you take precautions to prevent your computer becoming infected. In fact I would suggest that it be made possible that you aren't allowed a net account unless you pay for anti-virus software as part of the signup process (if using Windows).

    Everyone I know who is using Windows is getting sick of all the viruses and junk, It tires me to hear about it and I'm now at the stage where I say "put up with it or let me install Linux". At some point the pain level will grow such that they will want to try Linux.

  18. Zzz's Casino by offpath3 · · Score: 3, Funny
    You can see them going alphabetically through the list with the gambling sites, trying one after another.

    We here at Zzz's Casino guarantee no interuption to our service due to DDoS attacks.

  19. Good job, Virus Writers! by Anonymous Coward · · Score: 2, Funny

    Now when they learn how to hack into
    their cement shoes under 100 feet of water,
    I'll be even more impressed!

  20. Alternative Theory by Salamander · · Score: 5, Interesting

    On my website 90% of the comment spam was from online poker sites. That added up to hundreds of messages per day that I had to delete, and I know many others had similar experiences. I know I was thinking that they deserve a lesson, and maybe some folks decided to teach them one. While I don't necessarily approve of the method, I fully understand the impulse. Many online gambling sites are run by pricks; I won't shed a tear for them and their self-inflicted troubles any more than I would for the RIAA/MPAA.

    --
    Slashdot - News for Herds. Stuff that Splatters.
  21. Give me a break... by t0mass · · Score: 2, Informative

    Since when DDoS attacks are considered as hacking?
    Every idiot with internet access can make a DoS attack, and not everyone with access is a hacker.

  22. Hate It by CypherXero · · Score: 3, Insightful

    I've gotten SO MUCH spam on my blog and via e-mail about online poker, that I HATE poker now, and I've never even played it. If the gambling sites are worried about DDoS, tell those bastards to stop pissing off the rest of the world.

  23. What scares me is that you are wrong. by hummassa · · Score: 2, Informative

    You know, if you bash the queen, the next premier (this one is a friend) and the royal family enough in the media, you can even quote "the horrible things the royal family made to stay in power in the last 400? years"... hehehe. and voila, let's invade GB, they have WMDs, they have an evil secret police they use to crush the freedom fighters in Northern Ireland. Next, US invades Ireland too, for harbouring freedom fighters... errm terrorists.

    You see, I myself don't feel a lot safe, because the US government/media sees our president as a drinking communist who is building nukes, too, even if it's all far from the truth.

    --
    It's better to be the foot on the boot than the face on the pavement. ~~ tkx Kadin2048
  24. Addiction by nuggz · · Score: 4, Interesting

    I don't care about addictions.
    It just means the affected person must put out even more effort to overcome it.

    Just because some people are sex addicts doesn't mean I shouldn't be allowed to sleep with my wife. (or yours for that matter)

  25. How about the ISPs by phorm · · Score: 2, Interesting

    I think a big probably is not only the "clueless users" as it were, but the ISPs who put them online. They advertise all the wonders of the modern internet (blazing speeds, media downloads, etc) with complete lack of reference to such problems.

    Some ISPs do offer firewall/antivirus services, though most I've seen either suck or cost an additional fee.

    But the thing is, it's probably not that difficult to tell if the users on your ISP are owned. And the ISP can disconnect those users until they are patched, or at the very least stick them on a limited subnet wherein they can download patches/fixed but not continue to contribute to the degredation of the internet.

    The problem is that the ISPs are following the money trail and ignoring all these problems. Cutting off a "bad" customer is risking loss of capital... nevermind the cumulative money-loss effect that ISPs share in hosting spambots, cracked machines ,etc

  26. US-Centric Shortsightedness by billstewart · · Score: 2, Insightful
    They're not going after the online casinos because they're opposed to vice - many of the extortionists appear to be Russian mafias, who are perfectly happy to have vice around as long as they get a piece of the action. They're going after the online casinos because they're cranking a lot of money, and they depend on the internet, and their internet connections are easily attacked, and the attacks are relatively untraceable.

    You're thinking about this as a US couch potato that believes that what your government tells you applies to the rest of the world, or even to your part of the world. Stop that silliness.... In most of the world, gambling is a legal activity, though many governments require licenses for gambling houses. Tax revenue from gambling is simply tax revenue, like any other business tax revenue. The connection to schools is popularly used in the US when state lotteries are trying to convince the public that there's some moral difference between gambling with the state vs. gambling with your local bookie, which lets them continue the hypocrisy of banning the local bookie's operations.

    If you don't like small groups of people telling society what they can and can't do, work on changing your government. The US Feds have tried to stop Internet gambling, and any interstate gambling activities, and are relatively successful at it within the US, and many states are pretty aggressive about it as well. Senator John Kyl is one of the worst offenders. Then there's this drug prohibition thing, which is designed to fund gangs and terrorism and cause government corruption around the world, and the US has bullied a lot of other countries and even the UN into treaties agreeing to let the US politicians' idea of good vs. bad drugs be enforced on everybody else. And then there was that sting a few years ago where the US Feds got some California pornographer to mail videotapes to Tennessee so they could bust them for obscenity, because "community standards" in Tennessee are different than in California.

    --

    Bill Stewart
    New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks