MediaDefender's BitTorrent-Based DOS Takes Down Revision3
Sandman1971 writes "Over the long Memorial Day weekend, Revision3 was the target of a malicious Denial Of Service Attack which brought R3 to its knees. After investigating the matter, it was discovered that the source of the attacks came from MediaDefender, the famed company hired by the MPAA and RIAA to try and stop the spread of illegal file sharing. The kicker? Revision3 was taken down for running a bittorent tracker to distribute its own legal content."
I take it you didn't RTFA; the FBI is currently investigating the issue with R3's assistance.
According to this, it's on the way.
Again, please RTFA Coward. The torrents on Revision3's servers were their own content, but one R3 member found a torrent named something like RAMBO_axxo on their tracker on May 25 and reported it to the admins. They immediately took it down and then found the backdoor that MediaDefender had been using to post fake torrent hashes on their servers. Once the backdoor was closed, MediaDefender's servers began the DOS attack as an automatic response. Louderback says that the FBI is already investigating. I expect the EFF will get involved as well as this story develops.
They have a 9 gigabit connection dedicated to launching illegal DoS attacks. I wish I was joking.
The story is all over the place now. You can read about it at CNET at http://news.cnet.com/coops-corner/?tag=cnetfd.blogs
as well as Valleywag http://valleywag.com/393955/revision3-ceo-antipiracy-group-attacked-our-network
I was able to grab the blog post:
As many of you know, Revision3's servers were brought down over the Memorial Day weekend by a denial of service attack. It's an all too common occurrence these days. But this one wasn't your normal cybercrime - there's a chilling twist at the end. Here's what happened, and why we're even more concerned today, after it's over, than we were on Saturday when it started.
It all started with just a simple "hi". Now "hi" can be the sweetest word in the world, breathlessly whispered into your ear by a long-lost lover, or squealed out by your bouncy toddler at the end of the day. But taken to excess - like by a cranky 3-year old-it gets downright annoying. Now imagine a room full of hyperactive toddlers, hot off of a three hour Juicy-Juice bender, incessantly shrieking "hi" over and over again, and you begin to understand what our poor servers went through this past weekend.
On the internet, computers say hi with a special type of packet, called "SYN". A conversation between devices typically requires just one short SYN packet exchange, before moving on to larger messages containing real data. And most of the traffic cops on the internet - routers, firewalls and load balancers - are designed to mostly handle those larger messages. So a flood of SYN packets, just like a room full of hyperactive screaming toddlers, can cause all sorts of problems.
For adults, it's typically an inability to cope, followed either by quickly fleeing the room, or orchestrating a massive Teletubbies intervention. Since they lack both legs and a ready supply of plushies, internet devices usually just shut down.
That's what happened to us. Another device on the internet flooded one of our servers with an overdose of SYN packets, and it shut down - bringing the rest of Revision3 with it. In webspeak it's called a Denial of Service attack - aka DoS - and it happens when one machine overwhelms another with too many packets, or messages, too quickly. The receiving machine attempts to deal with all that traffic, but in the end just gives up. (Note the photo of our server equipment responding to the DoS Attack)
In its coverage Tuesday CNet asked the question, "Now who would want to attack Revision3?" Who indeed? So we set out to find out. Internet attacks leave lots of evidence. In this case it was pretty easy to see exactly what our shadowy attacker was so upset about. It turns out that those zillions of SYN packets were addressed to one particular port, or doorway, on one of our web servers: 20000. Interestingly enough, that's the port we use for our Bittorrent tracking server. It seems that someone was trying to destroy our bittorrent distribution network.
Let me take a step back and describe how Revision3 uses Bittorrent, aka BT. The BT protocol is a peer to peer scheme for sharing large files like music, programs and video. By harnessing the peer power of many computers, we can easily and cheaply distribute our huge HD-quality video shows for a lot less money. To get started, the person sharing that large file first creates a small file called a "torrent", which contains metadata, along with which server will act as the conductor, coordinating the sharing. That server is called the tracking server, or "tracker". You can read much more about Bittorrent at Wikipedia, if you really want to understand how it works.
Revision3 runs a tracker expressly designed to coordinate the sharing and downloading of our shows. It's a completely legitimate business practice, similar to how ESPN puts out a guide that tells viewers how to tune into its network on DirecTV, Dish, Comcast and Time Warner, or a mall might publish a map of its stores.
But someone, or some company, apparently took offense to Revision3 using Bittorrent to distribute its own slate of shows. Who could that be?
Along with where it's bound, every internet packet has a return address. Often, particularly in cases like this, it's forged - or spoofed. But interestingly enough, whoev
According to CNET article http://news.cnet.com/coops-corner/?tag=cnetfd.blogs "At this point, Revision3 says it's not planning to file a lawsuit. Not because it doesn't have a case but pursuing a court remedy would likely cost a lot of money."
In theory, there's no difference between theory and practice; in practice there is.
I hate to feed the trolls, but just felt someone should point out for those who don't use Revision3 that this is incorrect, they produce original shows, such as Diggnation. (as far as i am aware, they do not have any user uploaded content or any non-original content at all)
Now it's possible that there was a 3rd party somewhere in there forging packet headers and inflating the number of packets sent, but that seems unlikely.
A DoS violates Federal Criminal Law. Copyright is generally a Civil statute and is prosecuted via lawsuits.
What MediaDefender did is therefore being investigated under criminal law.
http://en.wikipedia.org/wiki/NET_Act The United States No Electronic Theft Act (NET Act), a federal law passed in 1997, provides for criminal prosecution of individuals who engage in copyright infringement, even when there is no monetary profit or commercial benefit from the infringement. Maximum penalties can be five years in prison and up to $250,000 in fines. The NET Act also raised statutory damages by 50%.
2461 Santa Monica Blvd., D-520
Santa Monica, CA 90404
PHONE: (310) 956-3300
FAX: (310) 956-3391
Start your letter writing and phone calling campaign against Media Defender now.
For the lazy. Seems they run vmware. Maybe slashdot would like to say 'hi' to them at port 950.
129.47.130.104
129.47.130.155
129.47.130.53
129.47.131.106
129.47.131.208
129.47.132.160
129.47.132.211
129.47.132.58
129.47.132.7
129.47.133.10
129.47.133.112
129.47.133.163
129.47.248.125
129.47.248.207
129.47.248.2
38.103.50.152
38.107.160.10
38.107.160.12
38.107.160.13
38.107.160.14
38.107.160.15
38.107.160.18
38.107.160.19
38.107.160.22
38.107.160.23
38.107.160.24
38.107.160.25
38.107.160.3
38.107.160.6
38.107.160.8
38.107.161.68
38.107.161.71
38.107.161.72
38.107.161.74
38.107.161.75
38.107.161.76
38.107.161.79
38.107.161.80
38.107.161.81
38.107.161.82
38.107.161.83
38.107.161.84
Well here in Canada alot of police officers choose not to enforce the pot smoking laws. So far this hasn't led to a massive breakdown in law & order or police abuse, just a bunch of relaxed police officers and pot smokers. Yep ignoring that law sure seems to have worked out pretty well, maybe we can try a few more in the near future.
I may agree with what you say, but I will defend to the death your right to face the consequences of saying it.
I actually went to the site to see what they had, and I didn't see anything there that was not their own content. It looks like some pretty interesting stuff, too. Would you like to provide a cite of anything that can be found there that is not theirs? If not, just admit that you don't know what you're talking about and refrain from further comment.
Not quite. MD's two most important tools are fake torrents and DoS attacks, both to be used only against what they deem immoral^Willegal.
:]
Probably, Rev3's tracker somehow made the list of evil trackers, only to be "attacked" by the first, inexpensive measure: Injecting fake torrents. MD's goal being to dilute the quality of one tracker's torrents to uselessness. Since Rev3's tracker doesn't communicate tracked torrents back to a web site, nobody noticed or downloaded the fakes and everything was good with the exclusion of some wasted cpu cycles and memory on Rev3's side.
Now after Rev3 changed the tracker's policy to no longer accept random injections, MD's system probably recognized it's first measure to be failing and escalated behaviour to the next stage. A purty DDoSing of the torrent, obviously illegal under federal law.
Since this appears to be their software's standard behaviour, blame will probably be shifted on some dumb programmer who merely executed orders from higher-up scum within MediaDefrauder. I demand the heads of all of MD as well as the RIAA and MPAA on silver platters. Also, pepper sauce.