Earlier quoted context omitted.
A malicious tracker, or a peer if using DHT, can claim an IP, the victim, is active in the swarm and has valuable bits of the torrent. Then torrent clients will try to connect to the victim. The attack is pretty clever, being indirect it is hard to trace and because bittorrent allows arbitrary ports you can hit a specific ip & port pair. The one downside is the victims can be sure it is a bittorrent DDOS by checking…
or a peer if using DHT Please confirm my understanding: this would be by inserting yourself into the DHT with an address near/equal to a target high-volume torrent, so that you're frequently queried by clients looking for peers? If so, I guess it could be possible in some cases to identify the peers who initiated the attack. The non-malicious peers attempting to make BitTorrent connections to your server will provide…
Basecamp was under network attack
151–160 of 194 posts
Re: Basecamp was under network attack
#152Earlier quoted context omitted.
Rhetoric? You've got people who just attempted to blackmail you and then take your service offline when you refuse. The descriptive term "criminal", i.e. one who breaks laws, is perfectly valid IMO.
While I agree, the term blackmailer or extortionist would had been better.
I blackmail my kids all the time... ("Wash your hands after using the bathroom or you will put 25 cents in this jar")
Re: Basecamp was under network attack
#153Colabtive: http://collabtive.o-dyn.de/
Re: Basecamp was under network attack
#154Earlier quoted context omitted.
http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb... > As I noted in a talk I gave last summer with Lance James at the Black Hat security conference in Las Vegas, a funny thing happens when you decide to operate a DDoS-for-hire Web service: Your service becomes the target of attacks from competing DDoS-for-hire services. Hence, a majority of these services have chosen to avail themselves of Cloudflare’s fr…
CloudFlare's CEO, Matthew Prince, has made his stance on this matter very clear: CloudFlare is firm in our belief that our role is not that of Internet censor. There are tens of thousands of websites currently using CloudFlare's network. Some of them contain information I find troubling. Such is the nature of a free and open network and, as an organization that aims to make the whole Internet faster and safer, such i…
Information isn't really the question here. These aren't sites telling people how to conduct DDOS attacks, these are sites where you pay them, and they run a DDOS for you. This effectively silences someone until they either give up on their message, or sign up for expensive DDOS mitigation packages (or Cloudflare).
You may consider that to be free speech. I don't.
Re: Basecamp was under network attack
#155We got hit by a DDoS about a year ago. Rackspace (who normally has amazing support) quietly null routed us and went about their day. No heads-up, trouble ticket, or any other form of notification. They didn't even put a note in our account so when we contacted their support to figure out why our servers were unresponsive outside their network the poor guy who answered the phone was just as confused as I was. We've ta…
I'm sure a few of you out there are readying this thinking "too bad for Basecamp, but this will never happen to us because we aren't an interesting target." That's what we thought too...
Re: Basecamp was under network attack
#156I've had really negative experience with these type of criminals. I was hired as a CEO at an company ($200m+ revenue) and we were hit by this type of attack. Every second of being down cost us literally $10k, so we quickly negotiated with criminals for $5k one time payment and they stopped the attack. Unfortunataly a few weeks later we were hit by 3 new attacks. Apparently the word had spread and these new attackers…
Re: Basecamp was under network attack
#157Earlier quoted context omitted.
CloudFlare does more than just caching. Even on non-cached pages it can filter and otherwise mitigate traffic that it has identified as malicious.
Correct, many times I've had to fill out a captcha to load a CloudFlare-protected page.
Re: Basecamp was under network attack
#158Earlier quoted context omitted.
I personally wouldn't do any business with cloudflare, while they're still hosting the various booter sites where you can pay to run these attacks.
CloudFlare is hosting booter sites?
Re: Basecamp was under network attack
#159Earlier quoted context omitted.
http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb... > As I noted in a talk I gave last summer with Lance James at the Black Hat security conference in Las Vegas, a funny thing happens when you decide to operate a DDoS-for-hire Web service: Your service becomes the target of attacks from competing DDoS-for-hire services. Hence, a majority of these services have chosen to avail themselves of Cloudflare’s fr…
I could post more, but why bother? The krebs story was interesting thanks, the forum posts less so. I understand why cloudflare are reluctant to start rejecting customers based on content, but surely it's illegal to sell DDOS services? Perhaps they should change their TOS to exclude any sites which sell attack tools/services, because it looks really bad for them to be protecting sites that promote DDOS, which then pr…
Selling attack tools, however, is explicitly legal in most places, it's just software just as a port-scanning tool, DeCSS or zero-day vulnerability data.
"Promoting this sort of activity" again is free speech issue, no matter what "that sort" is. For example, there are posts right here in HN that "promote this sort of activity", and it would be ridiculous if having such content is even close to allowing someone to take down a server.
In short, unless the actual site is performing illegal activities (implementing the DDoS or uploading childporn&stuff), I'd say that they're correct in explicitly ignoring whatever else the site is doing.
Re: Basecamp was under network attack
#160Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.
> This is like a bunch of people blocking the front door and not letting you into your house. The contents of your house are safe -- you just can’t get in until they get out of the way.