Live data from Hacker News

German police raid DDoS-friendly host FlyHosting

krebsonsecurity.com

11–20 of 48 posts

Re: German police raid DDoS-friendly host FlyHosting

#11

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

What identity verification does paypal actually do? I'd assume (potentially incorrectly) that criminals using it were doing so under an assumed (or stolen) identity so the account wouldn't lead back to them.

Which would limit what you could do with the money, but isn't that true of any crime related money?

Re: German police raid DDoS-friendly host FlyHosting

#12
post #11

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

What identity verification does paypal actually do? I'd assume (potentially incorrectly) that criminals using it were doing so under an assumed (or stolen) identity so the account wouldn't lead back to them. Which would limit what you could do with the money, but isn't that true of any crime related money?

PayPal has a banking license it does a pretty full KYC in most places or relies on others that do.

Outside of cash transfer services which often also require an ID on both ends albeit that is often easier to fake there aren’t ways to transfer money anonymously.

So companies use either alternative settlement methods such as crypto or gift cards or what is also quite common twin settlement.

You want a VPC? We’ll give you one for free just buy a 3 months VPN service from our sister company.

Basically the idea here is to split the records across as many platforms as possible and have as much separation as possible from payments and actual usage.

Re: German police raid DDoS-friendly host FlyHosting

#14

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

Isn't almost any online payment method trivially trackable? Bitcoin (and most other cryptocoins) needs a bit of effort to grovel the public transaction history, and XMR does things that supposedly make that not really work at all, but other than that...

[flagged]

Re: German police raid DDoS-friendly host FlyHosting

#16
post #14

Earlier quoted context omitted.

Isn't almost any online payment method trivially trackable? Bitcoin (and most other cryptocoins) needs a bit of effort to grovel the public transaction history, and XMR does things that supposedly make that not really work at all, but other than that...

[flagged]

But how do you find the prostitute?

Re: German police raid DDoS-friendly host FlyHosting

#19

Looks like RIPE is revoking their ASN: $ whois -h whois.ripe.net AS202437 [...] aut-num: AS202437 as-name: FLYHOSTING remarks: ------------------------------------------------------------- remarks: This internet resource will be deregistered by 9 June 2023. remarks: ------------------------------------------------------------- [...] last-modified: 2023-03-31T13:34:39Z There's no equivalent remark on their IP space (1…

Does anyone know what standards / processes are for de-peering, or as in this case, revoking ASN entirely, of rogue networks? The notion of ignoring networks (ASNs) which have predominantly hostile traffic at the BGP level has been bandied about for a long time, but so far as I know, most network operators are exceedingly reluctant to do this, absent a few, mostly political, instances. Israel and its Arab neighbours…

For small ASNs wanting new connections it's getting pretty common for peers to require a RPKI/ROA (a cryptographic verification system used to automatically configure what advertisements are accepted based on what resources your RIR says you have and what you crypto sign on how you want to advertise them) instead of a LOA (letter of authorization, a document they can put on file saying what you intend to advertise). With this your RIR becomes the trust anchor (and signer, if you don't want to deal with delegation) so a revocation of the resources by the RIR should automatically result in your advertisements being rejected by your peering points in most cases like this going forward.

This is getting uptake because instead of the pitch to operators being "help validate internet advertisements" it's "now you don't have to manually configure accept policies or worry about misconfigured advertisements from clients".

https://www.arin.net/resources/manage/rpki/troubleshooting/#...

Re: German police raid DDoS-friendly host FlyHosting

#20
> The U.K.’s National Crime Agency announced last week that it’s been busy setting up phony DDoS-for-hire websites that seek to collect information on users, remind them that launching DDoS attacks is illegal, and generally increase the level of paranoia for people looking to hire such services.

This... might actually be effective.

One major reason I stopped using Kazaa/LimeWire back in the day was growing fear (and experience) with files being laced with malware.

Throw out enough landmines to make someone think every service could be a trap... seems smart.

Post reply on HN