Live data from Hacker News

German police raid DDoS-friendly host FlyHosting

krebsonsecurity.com

1–10 of 48 posts

Re: German police raid DDoS-friendly host FlyHosting

#2
> FlyHosting, a dark web offering

And then:

> An ad for FlyHosting posted by the the user “bnt” on the now-defunct cybercrime forum BreachForums

So we have a dark web 'offering' advertising on a clearnet forum. This is a conflict of interests IMHO. You're either fully operating on the darkweb or you're not. Clearnet e-crime sites are famously de-anonymized. It just takes a payment from PayPal registered in your legal name to buy hosting services, and boom: you've been decloaked by the authorities.

Re: German police raid DDoS-friendly host FlyHosting

#3
Looks like RIPE is revoking their ASN:

  $ whois -h whois.ripe.net AS202437
  [...]
  aut-num:        AS202437
  as-name:        FLYHOSTING
  remarks:        -------------------------------------------------------------
  remarks:        This internet resource will be deregistered by 9 June 2023.
  remarks:        -------------------------------------------------------------
  [...]
  last-modified:  2023-03-31T13:34:39Z
There's no equivalent remark on their IP space (185.132.53.0/24 and 2a0f:9400:6119::/48) yet.

Re: German police raid DDoS-friendly host FlyHosting

#6

Looks like RIPE is revoking their ASN: $ whois -h whois.ripe.net AS202437 [...] aut-num: AS202437 as-name: FLYHOSTING remarks: ------------------------------------------------------------- remarks: This internet resource will be deregistered by 9 June 2023. remarks: ------------------------------------------------------------- [...] last-modified: 2023-03-31T13:34:39Z There's no equivalent remark on their IP space (1…

Does anyone know what standards / processes are for de-peering, or as in this case, revoking ASN entirely, of rogue networks?

The notion of ignoring networks (ASNs) which have predominantly hostile traffic at the BGP level has been bandied about for a long time, but so far as I know, most network operators are exceedingly reluctant to do this, absent a few, mostly political, instances. Israel and its Arab neighbours come to mind, my understanding is that direct network connections are limited, or at least were historically. There are a few other cases largely between hostile nations.

Would RIPE be acting on the request of German legal authorities and/or courts, or on some other basis? And how would this be determined?

Re: German police raid DDoS-friendly host FlyHosting

#7

Looks like RIPE is revoking their ASN: $ whois -h whois.ripe.net AS202437 [...] aut-num: AS202437 as-name: FLYHOSTING remarks: ------------------------------------------------------------- remarks: This internet resource will be deregistered by 9 June 2023. remarks: ------------------------------------------------------------- [...] last-modified: 2023-03-31T13:34:39Z There's no equivalent remark on their IP space (1…

Does anyone know what standards / processes are for de-peering, or as in this case, revoking ASN entirely, of rogue networks? The notion of ignoring networks (ASNs) which have predominantly hostile traffic at the BGP level has been bandied about for a long time, but so far as I know, most network operators are exceedingly reluctant to do this, absent a few, mostly political, instances. Israel and its Arab neighbours…

small hosting operators usually have few actual paid IP transit upstreams (2 or 3 max), which can credibly disconnect them based on criminal activity.

they also usually have a small number of actual manually-configured peers and if they're a member of an IX, they use the routeservers instead. Very easy for an IX to disconnect a criminal entity.

disconnecting a HUGE network that has a large portion of abusive traffic is much harder, like trying to bgp blackhole some major ISPs in China.

Re: German police raid DDoS-friendly host FlyHosting

#8
I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

Re: German police raid DDoS-friendly host FlyHosting

#9

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

yknow customers usually get away

whats funnier is those who run these booter sites then ACCEPTS payment with paypal. dios mio

Re: German police raid DDoS-friendly host FlyHosting

#10

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

Isn't almost any online payment method trivially trackable?

Bitcoin (and most other cryptocoins) needs a bit of effort to grovel the public transaction history, and XMR does things that supposedly make that not really work at all, but other than that...

Post reply on HN