Taking on an Online Extortionist
An anonymous reader writes "When an online exortionist comes a knocking, threatining a DDoS, do you pay or fight? For many, paying may seem like a sensible option when compared to going out of buisness. CSO Magazine has a riveting article about how an online gambling site and a DDoS specialist teamed up to take on such an extortionist. When everybody else was rolling over and paying, this company risked its very existence to fight back. From the article: '"The attack went to 1.5Gb, with bursts up to 3Gb. It wasn't targeted at one thing. It was going to routers, DNS servers, mail servers, websites. It was like a battlefield, where there's an explosion over here, then over there, then it's quiet, then another explosion somewhere else," says Lyon. "They threw everything they had at us. I was just in shock."'"
Very long but very interesting. Glad to see they caught some of them. They mentioned a hacked icq account.. That just seemed odd to me since ICQ accounts are free.. Anyone know what they were talking about?
There exists some positive integer N that you are the Nth person to read this signature.
It makes me wonder if this new anti-DDoS company can somehow establish relationships with ISPs to track back the zombies and get them shut down more quickly? Seems that would be the sanest and most effective tool -- take away the bots. No bots -- no botnet -- no attacks.
John
Glad to see someone standing up to these thugs. I remember a few years ago, the ISP that I admin'd hosted the connection for http://www.defcon.org/. We had someone start a Smurf attack from the Con, targetting our inbound T3's. We were able to track it down, and actually snatch him out of his seat right there at the con. He promptly apologized (I think, he only spoke german, IIRC). The look on his face was priceless. Oh, did I mentioned that me, and everyone else at the company carry Glock 19's? Yeah, we didn't have any more problems for the rest of the con. Everyone was on their best behaviour. A bunch of fine, upstanding individuals. :)
I've always wondered...when a site is slashdotted, it implies that the site has been hit by high referrals from slashdot, causing it to become slow or go down totally.
But how does slashdot itself cope with the high traffic?
Actually, in relation to that, what happens when your spamfilter marks such an email as spam. I guess you can say that's a major false positive.
Some ISPs are doing customer-level ingres filtering -- e.g. if the "other end" of the cable modem gets a packet whose src address is not that of the cable modem, drop it on the floor, it's forged.
The ease of infecting home XP systems remotely means you sometimes find teenagers with tens of thousands of zombie computers at their control. They can sell them to spammers, too.
The ease of doing massive DDoS attacks is why I stopped running an IRC server, and also stopped a research project I was doing related to inter-protocol messaging. It wasn't worth the hassle.
Fighting back is hard if you don't know who to fight, but in the case of extortion, (1) document everything on paper, (2) keep timestamped printed IRC logs of all conversations, and full email printouts; (3) ask some other people to print copies of their IRC logs when appropriate. Then contact the RCMP (or if you are in the USA, the FBI, but in the USA you need to show financial damage of $5,000 or more). Don't wait until it's all over before contacting them.
Good luck!
Liam
Live barefoot!
free engravings/woodcuts
Speaking of mentions on Slashdot, has anyone else ever seen an article wherein someone was portrayed as such a complete shining genius? Anybody else find this even slightly suspicious?
My little site.
The thing with these DOS extortionist is that unlike the mafia or other groups they do not protect you from other extortinist. If you pay them thay can stop their attact, but if someone else try to attack you they cannot do anyting.
But like I said, he's cleaned up his act in recent months, so I no longer have a beef with him. Some folks, on the other hand, still hold this against him--which isn't an entirely unreasonable position to take.
Obliteracy: Words with explosions
MAILSERVER: Error, mailbox does not exist
Not saying it would necessarily work, and as it was probably sent to a published address, would at best delay the threat while lowering the extortionist's expectation of your ability to defend your network.
09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
Dane-geld
:)
(A.D. 980-1016)
IT IS always a temptation to an armed and agile nation,
To call upon a neighbour and to say:--
"We invaded you last night--we are quite prepared to fight,
Unless you pay us cash to go away."
And that is called asking for Dane-geld,
And the people who ask it explain
That you've only to pay 'em the Dane-geld
And then you'll get rid of the Dane!
It is always a temptation to a rich and lazy nation,
To puff and look important and to say:--
"Though we know we should defeat you, we have not the time to meet you.
We will therefore pay you cash to go away."
And that is called paying the Dane-geld;
But we've proved it again and again,
That if once you have paid him the Dane-geld
You never get rid of the Dane.
It is wrong to put temptation in the path of any nation,
For fear they should succumb and go astray,
So when you are requested to pay up or be molested,
You will find it better policy to says:--
"We never pay any one Dane-geld,
No matter how trifling the cost,
For the end of that game is oppression and shame,
And the nation that plays it is lost!"
- Rudyard Kipling
Anyone willing to try their hand at "updating" this to fit online extortion? This could be lots of fun
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
xkcd.com - a webcomic of mathematics, love, and language.
Is it just me, or is the author none-too-subtly suggesting at the end of what seems a pretty flattering article that the one who engineered the defence is in collusion with the exortionists, and that paying him for help is essentially paying a protection fee? The turnabout in tone is so abrupt it seems like the last few paragraphs were written by a different person.
The only thing I'm reminded of is the telling of a guy who sought palindrome ICQ account numbers with email addresses from XS4ALL assigned to them, of which the email accounts had expired. Apparently he found a few, and through XS4ALL, he would re-create these expired email accounts, then have the old password sent to him. A weird collectible, and probably not the story you were looking for. :-)
Take off every 'ZIG' !!
did anyone else notice that this is a november 2003 article?
Starting Feb 2004, my site was hit by a powerful DDoS attack. It knocked out my web server and it nearly took out my web host's switch in the data center. I never got any demands or letters or figured out who caused it.
Anonymizer.net tried to help me by putting my domain behind a series of rotating proxy servers. Their whole network crashed after 6 hours and they had to stop helping me.
Finally my web host hit on the right idea. I set up a half dozen virtual private servers (VPS) at Globalservers.com (same company that hosts about.com and freeservers) and my host installed a proxy server on each one called twhttpd and set them all to route traffic to and from my web server at his data center.
Then I set up an account at ZoneEdit and added all the IPs for the proxy servers with a failover system. Every time the bastards knocked out one of the proxy servers, ZoneEdit would detect that the server was borked and switch to another one. With the load reduced, the dead proxy came back on its own a few minutes later.
After about 6 months of this, they finally gave up and I won.
Only on
When they fire that warning shot, you dump all the attacking IPs to a log and circulate the list to AHBL, Spamhaus, CBL etc so that the extortionist's zombie network is now worth half of what it was before. Zombies are only worth anything if they are novel. And you tell the extortionist that for each additional shot, their botnet monetary value will decrease by 10% or whatever.
And some pretty questionable ones:
"I do not agree that the dog in a manger has the final right to the manger even though he may have lain there for a very long time. I do not admit that right. I do not admit for instance, that a great wrong has been done to the Red Indians of America or the black people of Australia. I do not admit that a wrong has been done to these people by the fact that a stronger race, a higher-grade race, a more worldly wise race to put it that way, has come in and taken their place."
He also had no problem with using gas to put down uprisings by colonized indigenous peoples. I'm not saying he's a saint, just pointing out that popular leaders tend to get viewed through a rose colored filter.
"History will be kind to me, for I intend to write it"
--Winston Churchill
What would happen if he had changed the dns of his website, to, i dunno, say the ip address of fbi.gov? The criminals would then be dossing fbi.gov and the fbi would immediately notice. If it wasn't a dns-based attack, it should be relatively easy to route all incoming traffic to another ip address.
I wonder if the guy that was originally being dossed would get in trouble for it.
Why read the article when I can just make up a snap judgement?
_Selling_ material was how we justified it to an isolationist Congress and population. Actually, we _lent_ most of what went over because England was running out of money. And we didn't want it back once the war was over.
Plus several squadrons worth of American figher pilots went over to help before we declared war.
Plus our navy was fighting an unofficial war with the German U-boats for about a year before we went to war while we escorted the convoys heading from Canada to England.
FYI, we're just as grateful to England for remaining a friend ever since. Although personally I wish your government would try to hold mine in check rather than just going along with everything Bush does. Your government may be our friend but I don't think your people like us very much at this point.
Only on
Because he knew England didn't have the manpower for an amphibious landing in France or Germany. They'd sent troops to France, but the incompetency of the French High Command in the face of Blitzkreig forced the Dunkirk evacuation.
That's where the line about "the New World coming to rescue the Old" comes in -- Churchill knew he couldn't invade France until the US entered the war. He knew that was likely by early '42, i.e., about two years after that speech. If Pearl Harbor hadn't happen, Roosevelt was prepared to make German attacks on American shipping a casus belli.
Did they teach you the history of WW II, or are you just being obnoxious?
Your friendly neighborhood nitpicker
How ironic that a story about fighting DDoS attacks can't be read due to the Slashdot effect.
The Russians were actually allied with Germany, and would have taken no significant part in the war if Hitler had not decided that he wantesd Russia as part of his empire, and decided to attack them.
Just a little historical note, both sides were going to renege on that alliance/truce. Except the germans though they could gain the upper hand by a decisive pre-emptive attack. Their intelligence reported russia was marshalling it's forces to attack germany.
They got bod down in russia in winter and they got crushed byt the combined might of the cold and the ruskies.
"There are more things in heaven and earth, Horatio, than are dreamt of in your philosophy."
It's AMAZING, but you have to supply the electricity which will add up to a fair amount for a real pc vs. a little appliance thingy. Got a spare laptop with a borked screen or something? You could probably pick one up for a song at RePC or a similar outfit.