CastleCops.com Hit With Reputation-Based Attacks
An anonymous reader writes "The all-volunteer based online fraud fighting group CastleCops.com is currently the target of ongoing reputation-based attacks in which criminals use phished PayPal accounts to donate thousands of dollars to CastleCops from dozens of victims. This attack appears to be in response to a recent series of failed denial-of-service attacks against the CastleCops, Web site. From the story: 'A few donations were for as little as $1, while other fake donations ranged as high as $2,800. To the victims of the stolen PayPal accounts, it looks as if CastleCops is the one stealing their money, when in reality, it's the attackers. Also, the fraudulent activity seeks to ruin their relationship with PayPal.' In a comment left on Washingtonpost.com's Security Fix blog, CastleCops co-founder Paul Laudanksi says while the group's site remains under a heavy DDoS attack, it is currently down due to a hardware failure, not the attack itself."
First comment!
CastleCops needs to start treating what they are doing more like a business and less like a hobby.
"I'd rather be a lightning rod than a seismometer." -Ken Kesey
Eh, sounds about right... I thought to myself.
It is no longer uncommon to be uncommon.
that the attacks were done with spam-obtained accounts. IMO the users shouldn't be refunded - they deserve that for being stupid and clicking "here!" on those e-mails.
With CastleCops.com as a honeypot, ISPs could be contacted to the origin of the DDoS attacks, PayPal could do some investigating of their own as to the IP origins of donations and do something about this stuff.
Fer Bob's sakes, this isn't 2001 anymore, when are these companies and perhaps goverment going to make some strides in shutting down bots and zombies?
A feeling of having made the same mistake before: Deja Foobar
How did we arrive at such a completely fucked-up state of affairs, where organized gangs from Russia control what is (arguably) the most powerful supercomputer in existence? How is it that cyber-criminals are able to act with such total impunity? Am I the only person who doesn't understand how this is being ignored amid all the noise about "the war on terror"?
In Soviet Russia, phishers send you money..
Seriously. Is decency at such a low ebb that people have to stoop to attacking victim services and defense organizations? Seriously. Maybe if these people put half the time and energy they did into stealing they could actually get a real job and sleep well for a change instead of ripping people off all the time.
:-)
And while they're at it, they could stop sporging sci.crypt and other groups. That'd be nice.
Someday, I'll have a real sig.
A few years ago, I got hit with a Joe Job. Someone sent out spam to a very large list, pretending to be me, advertising a service I actually provided then. The email was badly spelled, made the emphasis very unprofessional, and linked to my site. The goal, and maybe the result, was to make me look like an ignorant, asshole spammer. They paaid to do this, though not a lot I imagine. This seems to be a very similar kind of attack.
My Photography - http://ian-x.com
The Deathlings (comic) - http://thedeathlings.com
It costs the ISP's money to turn off a customer's account ... and then deal with the customer calling and swearing that HIS computer is not the problem.
The ISP's are NOT going to spend the money UNLESS they're facing larger fines if they do not do so.
Not to mention that the ISP's usually don't hire the best and brightest out there. I don't believe they could tell the difference between the slashdot effect and a DDoS. How many of the people here would be happy to find out that their they've been cut off because their machines were participating in a "DDoS" of some website? When all they were doing is hitting a site with a story with HUGE graphics?
fraud is the biggest problem of paypal. here we have an anti fraud org under attack by fraudsters.
paypal under ebay is not stupid as the old paypal to not understand the importance of this, and not defend the enemy of its enemy.
Read radical news here
"Slashdot - News and Chat Sites Deviant". (Click "homepage" link above for details).
You know... A while back I rambled on about lazy ass engineers who have the capability to stop botnet DDoS traffic. Went unanswered, some mumbled those with the capabilities to stop it did nothing. As for the financial fraud occurring, its unfortunate but will likely be resolved too. Its a shame when people go out of their way to make things better only to be trampled upon. Kudos to Castlecop's team for their resiliency. As for the network engineers who peruse this site, this could one day be you too. Think about that before you decide to just brush away calls for assistance when dealing with botnets and attacks.
Infiltrated dot Net
The Republican Party made a generous donation to the Black Panthers.
You know it makes sense, a little reminder from jointm1k.
when are these companies and perhaps goverment going to make some strides in shutting down bots and zombies?
It's up to you. Botnets allow this kind of activity and there really is no way to trace the communications back to the source without reverting to POTS. Even then, those with enough power and skill can go undetected. OS diversification will help. Elimination of the weaker OS will do more. You can demand your freedom, that the government quit subsidizing non free software and change the way you and your business do things. The only one of the above you know will work is what you do for yourself.
DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
Paypal can add an option for your donation account to verify by phone before accepting the charge. This way you call every donator to confirm their donation (and probably thank them) before their credit card is charged.
HTML is obsolete. It's time for a new, simpler and richer markup language.
for making it on the news. If it wasn't for you I wouldn't have know CastleCops.com excisted. Extra attention you didn't want.
by TheSpoom (715771) Uncaring Linux user here. I have nothing to add to this but please continue. *munches popcorn*
"the group's site remains under a heavy DDoS attack"
Doesn't this always happen when a site is mentioned on Slashdot?
network engineers who i've asked to help track these ddos's have been extremely helpful. but if anyone here isn't peering with isc and/or donating transit, and you'd like to, and you're located in 1735 lundy, 529 bryant, or 200 paul, then please drop me a note off-line. vixie@isc.org
I couldn't agree more. Paypal is a yoke.
The internet is essentially currently ruled by the might-as-right school. Thus, the necessity of "vigilante" groups like CastleCops, and their own destruction at the hands of gangsters in control of botnets.
Until national governments get serious about bad actors in their countries (China and Russia, I'm looking at you), we won't have real justice on the net.
And then, once we do, we'll need to make sure our national governments keep it reasonable.
Gah. Maybe anarchy is better.
expandfairuse.org
I have always been fascinated with DDoS attack. The ability to attack a single target from various computers has made me grown knowing the importance of network security. And the target that can stand the test of DDoS is even fascinating. If it is as acclaimed, then, my heartiest congrates to CastleCops! And PayPal..just a reminder. Please be aware that PayPal is not a bank. So it doesn't have any kind of obligations to follow any of the rules and regulations of a bank. Which means it is not entitled, to refund any credits lost. Within e-bay, it's safe enough. Out of e-bay, fraudelent is almost unavoidable.
"Two things are infinite: the universe and human stupidity; and I'm not sure about the universe."