Showing posts with label ddos. Show all posts
Showing posts with label ddos. Show all posts

Sunday, July 1, 2012

Reality Bytes: CyberBusted 12/21/2010 Posted on Firetown.com

CyberBusted 12/21/2010 Posted on Firetown.com

FIRETOWN-- THIS IS YOU! I HOPE YOU ALL APPRECIATE THAT I WENT OUT ON A FUCKING LIMB TO PROTECT THE INTEGRITY OF THIS FORUM, BUT I WOULD LIKE AN APOLOGY FROM THE ADMINISTRATOR(S) OF THIS "CLOSED GROUP" AS TO WHY NOBODY RESPONDED [EXCEPT FROMMES- AND HE CAUSED EVEN MORE OF A MESS BY SUPPORTING YOU!]

@firetown URGENT log out of all accounts and change your pass... on Twitpic

MIKE-- I'M CALLING IT AS I SEE IT. IF YOU RUN THIS FORUM THAN YOU HAVE AN OBLIGATION TO PROTECT IT AND EACH OF US FOR SUPPORTING YOU BY GIVING US A SAFE PLACE TO SHARE IDEAS.


NOTICE THIS IS YOUR ACCOUNT THAT WAS HACKED ALONG WITH MINE.
ARE YOU A BLACK SHEEP OR A ASLEEP AT THE WHEEL? YOU HAD THE ABILITY TO CLEAR MY NAME AND PUT AN END TO THIS SITUATION BEFORE IT ESCALATED TO THIS POINT.SO, WHEN I AM BEING ACCUSED OF SOMETHING UNETHICAL AND ILLEGAL AND YOU HAVE THE ABILITY NOT ONLY CLEAR MY NAME BUT TO CONFIRM THAT YOU ALSO HAVE EVIDENCE TO PUT AN END TO DISINFO AGENTS AND PROVOCATEURS THEN YOU OWE IT TO EACH AND EVERY ONE OF US TO COME FORWARD.

I EXPECT YOU TO DO SOMETHING AND DO IT QUICKLY. REMOVE ANYONE WHO THREATENS THE SAFETY AND INTEGRITY OF THIS FORUM.

WHO IS GUARDING YOUR HOUSE TONIGHT? I HAVE BEEN ON WATCH NOW FOR WAY TOO FUCKING LONG WITH NO END IN SIGHT.

"FIRST THEY CAME FOR THE JEWS?"

WRONG!

FIRST THEY CAME FOR THE COMMUNISTS! [REF: NIEMOLLER]

WAKE THE FUCK UP.
HOW WOULD YOU FEEL IF YOU WERE ACCUSED OF NOT ONLY A CRIME, BUT BEING UNETHICAL AND DISLOYAL TO YOUR FOLLOWERS - WHICH BTW, YOU WERE!

WELL GUESS WHAT? I STEPPED UP FOR YOU AND YOU BETTER STEP UP TO THE FUCKING PLATE FOR THE REST OF US. WHEN DID YOU TURN INTO A GREY SHEEP? WAKE THE FUCK UP AND GET YOUR SHIT TOGETHER.

GET YOUR SHIT AND MY SHIT OUT OF THIS MESS BEFORE WE ALL GO DOWN WITH THIS SINKING SHIP.

I HAVE PAID DEARLY FOR BEING SO OUTSPOKEN AND DEDICATED IN MY SEARCH TO FIND A PLACE WHERE WE CAN CELEBRATE INDIVIDUAL FREEDOMS FREE FROM REPRESSIVE GOVERNMENT AND TOXIC PEOPLE.

I WOULD REALLY APPRECIATE A FUCKING ANSWER AS TO WHY WE ALLOW THIS KIND OF BULLSHIT TO CONTINUE? DON'T YOU GET IT... DIVIDE AND CONQUER.  [REF: COINTELPRO]

DIVIDED WE FAIL. 

FACE IT WE ARE NOT ON ANIMAL FARM-- WE ARE ON PLANET FUCKING PLUTO WHERE WE ARE TOO BUSY WATCHING THE MICKEY MOUSE CLUB INSTEAD OF OUR CHILDREN. [REF: THE CORPORATION]

WE ARE NOT ALL CREATED EQUAL. SOME ARE MORE EQUAL THAN OTHERS.  [REF: ORWELL, ANIMAL FARM]

SO WHEN I AM SENDING AN SOS FROM WHATEVER PLATFORM... THAN I DESERVE THE COURTESY OF SOMEONE TRYING TO DELIVER THE MESSAGE IN A LANGUAGE OR FORMAT THEY CAN UNDERSTAND. AND, TRYING TO SHOW SOME SUPPORT IN A LANGUAGE OR FORMAT THAT I CAN UNDERSTAND. [REF: #ONE]

#911 IS THE SAME IN EVERY LANGUAGE. #thatisall

NOTICE THIS IS YOUR ACCOUNT THAT WAS HACKED ALONG WITH MINE. SO, WHEN I AM BEING ACCUSED OF SOMETHING UNETHICAL AND ILLEGAL AND YOU HAVE THE ABILITY TO BOTH CLEAR MY NAME AND PUT AN END TO THE SITUATION I EXPECT YOU DO IT AND QUICKLY REMOVE ANYONE WHO THE MEMBERS OF THIS FORUM.

WHO IS GUARDING YOUR HOUSE TONIGHT? PUT AN END TO DISINFO AGENTS AND PROVOCATEURS.

IF YOU WON'T DO IT FOR ME, DO IT FOR YOURSELF. IF NOT FOR YOURSELF THEN DO IT FOR THE WORLD. [REF: STEVIE NICKS TIMESPACE]

#911 IS THE SAME IN EVERY LANGUAGE. #thatisall

see for yourself!

no response. none.

Posted from DailyDDoSe

Wednesday, June 22, 2011

LulzSec vs. CIA "Tango down- cia.gov - for the lulz || DDoS 33137 /b/tards

Internet LulzSec Downs CIA's Public Site, Appears to be Subject of Framing Attempt

Jason Mick (Blog) - June 15, 2011 7:20 P

Late this afternoon the CIA homepage was DDoSed.

The hacker group LulzSec claimed responsibility. They also did a phone attack on the FBI today. It's clear they think they're untraceable. (Source: LulzSec)

Aaron Barr, disgraced former CEO of HBGary appears to be involved in an attempt to implicate LulzSec in Bitcoin theft. It does not appear LulzSec did anything of the sort. It is unclear whether a series of posting are designed to discredit/attack LulzSec, Bitcoin, or both. (Source: Nerd Merit Badges)
Group's attack continue to grow more flagrant, as do its detractors

At around 6 p.m. Wednesday night after a busy day of distributed denial of service (DDoS) attacks some "31337" 2005-era "/b/tards" posted a microblog to Twitter. But these weren't just any "/b/tards"; these were the most infamous hackers of the year -- LulzSec.

And they didn't just post any old message. They typed:

Tango down - cia.gov - for the lulz.

Indeed the U.S. Central Intelligence Agency's homepage was unreachable.

I. Brazen Hacks, Phone DOS

The apparent takedown of the CIA homepage is merely the latest in the griefers' audacious run of high profile system intrusions and DDOS attacks on gaming services, government entities, and more.

The hack outraged th3j35t3r ("The Jester" in leetspeak), a pro-American "hacktivist". He swore to LulzSec:

@lulzsec - re: your last hit. Gloves off. Expect me. My silence is not an indication of weakness, as your mouth is an indication of yours.

But if The Jester or anyone else can stop the group, they haven't yet. LulzSec appears to think itself untraceable, given its flagrant hacks -- infiltrating the U.S. Senate servers, hacking an U.S. Federal Bureau of Investigations affiliate, and now hacking the public presence of the world's "most powerful" intelligence agency.

And it's using new tactics. LulzSec has set up two phone lines -- 614-LULZSEC or 732-993-7703 -- and is taking thousands of calls a day. Some it actually answers, asking guests questions for prizes or regaling them in a faux French accents. But it's also redirect the calls to phone denial of service (DOS) attacks -- something rarely seen today.

Today it direct this phone wrath at the online MMORPG World of Warcraft's customer support, the FBI's Detroit headquarters, and "a certain hosting company" (many suspect it was GoDaddy). Last, but not least it direct attacks at disgraced security firm HBGary who was the subject of much lashing at the hands of Anonymous earlier this year.

II. Framing Attempt?

LulzSec has been the subject of what appears to be wildly bizarre framing attempt involved the increasingly popular peer-to-peer digital currency Bitcoins. Former HBGary CEO, Aaron Barr, posted to Twitter:

Lulzsec manages to pilfer nearly a half million dollars in bitcoins while running their tele-DDOS-athon today. tinyurl.com/3mfngql

Only the link in question didn't receive the funds today -- it received them on Monday (6/13). And while it did send a donation to LulzSec's public donations account:
176LRX4WRWD5LWDMbhr94ptb2MW9varCZP

It only sent the typical token gesture: 0.31337 ("elite" in leetspeak) -- worth about $7 USD.

So where did this bizarre rumor begin? It appears to trace back to a Pastebin:
http://pastebin.com/88nGp508" rel="nofollow

Which was a repost of the Bethesda press release, with one important alteration -- the account was altered to make it look like:
1KPTdMb6p7H3YCwsyFqrEmKGmsHqe1Q3jg

...was a LulzSec donations account.

Clearly that account appears to be involved with some mass fraud or is a clever social engineering project to offer the appearance of a mass fraud. Either way, the attempt to tie LulzSec to it seems clearly flawed and like a clear framing. No official LulzSec press release has ever carried that number.

It's unclear whether Mr. Barr is merely a uninformed observer, or is more deeply involved with this possible framing attempt. But it's clear that his wild claims appear unfounded.

It's also possible that the postings are some sort of attempt to discredit Bitcoin itself. In recent weeks several news agencies have been spreading posts with dubious claims, attempting to discredit the digital crypto-currency.

For example The Guardian's Ruth Whippman writes:

An odd alliance of libertarians, geeks, businesspeople and drug kingpins hail Bitcoin as the future of the internet – global, private and immune from national economic crises and the whims of reckless bankers. Its critics in the political sphere fear that it could give rise to an online Wild West of gambling, prostitution and global bazaars for contraband.

Previously dismissed as a nerdy curiosity, the untaxable Bitcoin may soon be due for a crackdown.

And Gawker adds:

Not all Bitcoin enthusiasts embrace Silk Road. Some think the association with drugs will tarnish the young technology, or might draw the attention of federal authorities. "The real story with Silk Road is the quantity of people anxious to escape a centralized currency and trade," a longtime bitcoin user named Maiya told us in a chat. "Some of us view Bitcoin as a real currency, not drug barter tokens."

Silk Road and Bitcoins could herald a black market eCommerce revolution. But anonymity cuts both ways. How long until a DEA agent sets up a fake Silk Road account and starts sending SWAT teams instead of LSD to the addresses she gets? As Silk Road inevitably spills out of the bitcoin bubble, its drug-swapping utopians will meet a harsh reality no anonymizing network can blur.

Seemingly, some people are suggesting that Bitcoin is more villainous than the far more anonymous form of currency -- cash. The source of this misinformation/smear campaign is unknown, though, news agencies seem happy to spread it gleefully.

III. Insecure World

Much has been made to explain how LulzSec is doing what it does. But the fact of the matter is that the group isn't using new tactics, new tools, or new exploits. It's just getting more attention because it's good at advertising what it does and its affecting lots of people.

But the fact of the matter is that many corporate and government systems today are incredibly insecure and the vast majority of users are utterly incompetent when it comes to security [1][2][3] -- even some system administrators [1].

Combine these factors and you get an infinitely abusable system.

The abuses have occurred in years past. They may be happening at a faster rate this year. But the system has been insecure for years. And it will likely still be insecure next year, as well.

http://www.dailytech.com/LulzSec+Downs+CIAs+Public+Site+Appears+to+be+Subject...

Posted via email from Whistleblower

Saturday, April 23, 2011

Denial of Service Attacks: A Hall of Shame

Denial of Service Attacks: A Hall of Shame

Distributed denial of service (DDoS) attacks like the ones that nailed WordPress blogs in early March have been around for decades, but it's only in the last dozen years that they've had enough impact to grab public attention.

With the rise and commercial availability of botnets that provide a distributed platform from which to launch these attacks the means to carry them out are accessible.

BEYOND DDOS: PayPal CISO says DDoS attacks just one of many threats

Due to the cost, though, they have to be carried out by a motivated adversary bent on harm since there is little way to reap monetary profit from them aside from blackmailing potential victims with threats of crippling their servers.

Here are some of the notable DDoS attacks of the past few years:

Windows PCs become tools for denial-of-service attacks

In 2000, DDoS attacks on Yahoo!, eBay, eTrade, Amazon.com and CNN were launched from commandeered Unix machines in businesses and universities, but a few weeks later the malware directing the attacks called Trinoo shifted to Windows PCs.

DDoS attack highlights 'Net problems

Internet root servers were attacked in 2002, but the attacks were blunted enough for the servers to recover without a major take-down of the Internet itself. After the attack, limits on the Internet Control Message Protocol (ICMP) messages these servers will accept were set to ensure that type of attack in the future wouldn't succeed. The 13 root servers targeted run as the master directory for lookups that match domain names with their corresponding IP addresses

Estonia suffers massive denial-of-service attack

A spree of DDoS attacks against Web sites in Estonia in May of 2007 crippled Web sites for the prime minister, banks, and less-trafficked sites run by small schools. But most of the affected Web sites were restored quickly, and the government called for greater response mechanisms to cyber attacks within the European Union. Russia was accused of the attacks, but they could not be traced back to a single source there.

Storm worm strikes back at security pros

During the height of the Storm worm attacks in 2007, a security researcher revealed that the people behind it or the worm itself was launching DD0S attacks against researchers trying to figure out a way to defeat it. The worm was able to figure out which users were trying to probe its command-and-control servers, and it retaliated by launching DDoS attacks that shut down their Internet access for days, said Josh Corman, now an analyst with the 451 Group.

Georgia cyberattacks linked to Russian organized crime

DDoS attacks aganst the country of Georgia were seen as a way to soften up the country in preparation for a five-day military invasion by Russia in 2007. About a year later the U.S. Cyber Consequences Unit, an independent research institute concluded the attacks were launched by Russian criminal gangs in sympathy with the Russian government.

Twitter DDoS attack politically motivated

DDoS attacks in August of 2009 that affected Twitter, Facebook, LiveJournal and several Google sites may have been an attempt to silence a blogger named Cyxymu from the Eastern European country of Georgia who was an outspoken supporter of his country. Facebook CSO Max Kelly has said the attack was coordinated to keep the blogger's voice from being heard.

Mikko Hypponen, the Chief Research Officer of Internet security firm F-Secure, said of the attacks, "Launching DDoS attacks against services like Facebook is the equivalent of bombing a TV station because you don't like one of the newscasters."

DDoS attack on DNS hits Amazon and others just before Christmas

Amazon.com and Amazon Web Services servers were hit by a DDoS attack Dec. 23, 2009 , as North American consumers rushed to finish online shopping ahead of the end-of-year holiday season.

Anonymous takes down Visa.com in WikiLeaks protest

A loosely organized group of Internet hacktivists called Anonymous took down Visa's website Dec. 7, 2010 after organizing similar attacks on Mastercard and PayPal. Anonymous, had been encouraging volunteers to download software called LOIC (Low Orbit Ion Cannon), which let them centrally control these systems and direct them into a DDoS. The point of the attacks was to put pressure on financial companies that recently cut ties with the WikiLeaks website over its publication of more than a quarter million U.S. Department of State classified cables.

Read more about wide area network in Network World's Wide Area Network section.

Posted via email from Whistleblower

What It's Like to Get Hit With a DDoS Attack

What It's Like to Get Hit With a DDoS Attack

Google. Twitter. Government websites. Fortune 500 companies. All have been victims of crippling distributed denial-of-service (DDoS) attacks. The attacks have grown in reach and intensity thanks to botnets and a bounty of application flaws. And Akamai Technologies has a seen it all firsthand.

Many people use Akamai services without even realizing it. The company runs a global platform with thousands of servers that customers rely on to do business online. The company currently handles tens of billions of daily Web interactions for such companies as Audi, Fujitsu and NBC, and organizations like the Department of Defense and Nasdaq. There's rarely a moment--if there are any--when an Akamai customer is not under the DDoS gun.

Also read How a bookmaker and a whiz kid took on a DDoS extortion attack

What it's like to...

* ...get hit with a DDoS attack

* ...steal someone's identity

* ...dodge IED bombs

* ...see all our "What it's like" stories

So what's it like to be in charge of this much computing power when the attacker decides to strike? Akamai Security Evangelist Michael Smith recently took an audience at the SecTor security conference through a blow-by-blow account of some recent high-profile cases.

Taking center stage is the massive cyberattack on government websites and others around the world during the Fourth of July long weekend in 2009. In that onslaught, a botnet of some 180,000 hijacked computers hammered U.S. government websites and caused headaches for businesses here and in South Korea.

The attack started that Saturday, knocking out websites for the Federal Trade Commission and the Department of Transportation. US Bancorp, the nation's sixth-largest commercial bank, also took a direct hit. Attackers have also targeted the likes of Amazon, Google and Yahoo. Attacks against Google didn't last long, but when one considers that Google content accounts for about 5 percent of all Internet traffic, the prospect of better-sustained attacks against it is sobering.

When a DDoS is underway, Smith said, customers panic some, but it's not the freak-out you might expect.

"There is a bit of panic if the traffic starts hitting your infrastructure because things start failing over. So you're doing the usual 'restore service' drill, but it's going in multiple directions, and then it seems like all of your infrastructure is in a cascade failure," he said. "Maybe a better way to describe it is that you're scrambling to fix stuff and you don't really have time to panic."

Even in an Akamai environment, if the attackers target dynamic content--which is set to not cache--that goes through Akamai back to your origin, you'll see a traffic spike with your servers, Smith said. "Obviously we have ways to respond after that by caching the dynamic traffic for a small amount of seconds--most dynamic content is actually cacheable for a small period of time because the browser isn't loading it every 3 milliseconds like you might think," he says.

And some people don't panic because they may have been warned of the attack. If you're the target of an activist or protester attack, you might hear about it beforehand as they make plans via online forums.

"There has to be some panic, but then you calm down and realize it's manageable because you have time to react," Smith says. "But during the first 30 minutes of the attack, you're still sitting with your fingers crossed watching to see if anything gets through your defenses."

Posted via email from Whistleblower

Wednesday, April 20, 2011

PYTHONCLUB.ORG back in the dog house!

Posted
Spies Among Us
about 5 hours ago
Failed
@vaxen_var I read the etymology. I don't ...
Reason: request error 400: Blog has exceeded rate limit or otherwise requires word verification for new post
Next attempt in about 16 hours
about 16 hours ago
Failed
http://en.m.wikipedia.org/wiki/Hacker_Ma ...
Reason: request error 400: Blog has exceeded rate limit or otherwise requires word verification for new post
Next attempt in about 16 hours
about 16 hours ago
Failed
www.Pythonclub.org
Reason: request error 400: Blog has exceeded rate limit or otherwise requires word verification for new post
Next attempt in about 16 hours
about 16 hours ago
Posted
Spies Among Us
about 5 hours ago
Failed
@vaxen_var I read the etymology. I don't ...
Reason: request error 400: Blog has exceeded rate limit or otherwise requires word verification for new post
Next attempt in about 16 hours
about 16 hours ago
Failed
http://en.m.wikipedia.org/wiki/Hacker_Ma ...
Reason: request error 400: Blog has exceeded rate limit or otherwise requires word verification for new post
Next attempt in about 16 hours
about 16 hours ago
Posted
www.Pythonclub.org
about 16 hours ago

Pythoncode

Posted via email from Whistleblower