Author

Topic: MTGOX ordering DDOS ATTACKS!?!?!?!!? (Read 5325 times)

member
Activity: 88
Merit: 10
November 04, 2012, 09:44:05 AM
#45

heh - thanks for this nice story from Gibson.. I love that guy scince 1999 Smiley   This link was such a pleasure to read.. Thanks You MPOE-PR !
+1
hero member
Activity: 756
Merit: 501
There is more to Bitcoin than bitcoins.
November 01, 2012, 02:59:07 PM
#44

I don't think Russian courts care about slandering Japanese or American businesses doubt this lawsuit would go anywhere. I also doubt Gox would denial of service their competitors when they don't really have any on their level.

More likely some guy had his money seized by BTC-E for shady trading and reacted by slamming their servers and 'support' is just joking with the idiots in chat

Yeah that, it was very tongue in cheek from a non native English speaker. If you've been around and seen the user "support" 's mishandling of dialogue and sense of humor, you know it wasn't a real accusation, just a quip to say they're number two and getting more serious everyday.

Support had no idea who was DDOSing them when asked and assumed it was a random idiot like we all do.
Great, what a culture shock for some!
full member
Activity: 238
Merit: 100
November 01, 2012, 11:55:32 AM
#43

I don't think Russian courts care about slandering Japanese or American businesses doubt this lawsuit would go anywhere. I also doubt Gox would denial of service their competitors when they don't really have any on their level.

More likely some guy had his money seized by BTC-E for shady trading and reacted by slamming their servers and 'support' is just joking with the idiots in chat

Yeah that, it was very tongue in cheek from a non native English speaker. If you've been around and seen the user "support" 's mishandling of dialogue and sense of humor, you know it wasn't a real accusation, just a quip to say they're number two and getting more serious everyday.

Support had no idea who was DDOSing them when asked and assumed it was a random idiot like we all do.
hero member
Activity: 899
Merit: 1002
October 28, 2012, 09:48:39 PM
#42
That's one hell of an accusation to make without evidence, and making it without proving it can only damage BTC-e's reputation.

Explain yourself BTC-e support.
Seriously, that could be grounds for a lawsuit under slander/libel.

I don't think Russian courts care about slandering Japanese or American businesses doubt this lawsuit would go anywhere. I also doubt Gox would denial of service their competitors when they don't really have any on their level.

More likely some guy had his money seized by BTC-E for shady trading and reacted by slamming their servers and 'support' is just joking with the idiots in chat
legendary
Activity: 1176
Merit: 1001
October 27, 2012, 12:36:44 PM
#41
It's trivial to generate packets with the wrong source ip, it's not trivial to have some ISP not dropping these packets.

Nobody said it's trivial. Mere possible.
That many DDOS attacks succeed because of poor routing and firewall practices is nothing new.
Usually your upstream providers disconnects your link (no matter how much you pay them) if their routers detects packets coming from your link and from a range that wasn't assigned to you.

However i have to say that i really lack knowledge on how hard is it to do such an attack.
legendary
Activity: 1666
Merit: 1057
Marketing manager - GO MP
October 27, 2012, 12:34:20 PM
#40
It's trivial to generate packets with the wrong source ip, it's not trivial to have some ISP not dropping these packets.

Nobody said it's trivial. Mere possible.
That many DDOS attacks succeed because of poor routing and firewall practices is nothing new.
hero member
Activity: 756
Merit: 522
legendary
Activity: 1554
Merit: 1021
October 27, 2012, 08:40:04 AM
#38
Proof?

Sounds like BTC-e is trying to get some Mt.Gox customers Tongue

Well played BTC-e.
full member
Activity: 126
Merit: 100
October 27, 2012, 07:26:13 AM
#37
Quote from: Nolo
Yes it could.  That is an extremely serious allegation.  

Edit:  But we don't have the entire conversation.  Support could have said:  "All these rumors about the DDOS need to stop."  And the question could have been asked:  "What is the rumor that is going around?"  And support could have replied: "mtgox ordered it."

One screenshot can be taken completely out of context. 

+1 this exactly

Is there anything more to this than the one post? If not, it certainly isn't clear what the support person was saying.

They should clear it up, though.
legendary
Activity: 1176
Merit: 1001
October 27, 2012, 07:21:42 AM
#36
It's trivial to generate packets with the wrong source ip, it's not trivial to have some ISP not dropping these packets.
full member
Activity: 238
Merit: 100
October 27, 2012, 05:55:46 AM
#35
Why has BTC-e not posted a response on this yet?
vip
Activity: 756
Merit: 503
October 27, 2012, 05:23:01 AM
#34
Your ISP should lock ips coming from outside their allocated network, same should a server provider.
Quite curious on how easy/hard it's to fake an ip source anyway.

With nmap that's just a switch so must be trivial with DDOS tools.

Quote
-S (Spoof source address)
In some circumstances, Nmap may not be able to determine your source address (Nmap will tell you if this is the case). In this situation, use -S with the IP address of the interface you wish to send packets through.

Another possible use of this flag is to spoof the scan to make the targets think that someone else is scanning them. Imagine a company being repeatedly port scanned by a competitor! The -e option and -Pn are generally required for this sort of usage. Note that you usually won't receive reply packets back (they will be addressed to the IP you are spoofing), so Nmap won't produce useful reports.
http://nmap.org/book/man-bypass-firewalls-ids.html
legendary
Activity: 1176
Merit: 1001
October 27, 2012, 05:18:52 AM
#33
Your ISP should lock ips coming from outside their allocated network, same should a server provider.
Quite curious on how easy/hard it's to fake an ip source anyway.
vip
Activity: 756
Merit: 503
October 27, 2012, 04:49:40 AM
#32
Routers are designed to reject these packets.
It's a security flaw if that wouldn't happend.
Routers drop spoofed internal network address but I don't think they can filter spoofed WAN address.

Some more interesting reading"
Quote
Impersonation. In the DNS attacks, each attacking host uses the targeted name server's IP address as its source IP address rather than its own. The effect of spoofing IP addresses in this manner is that responses to DNS requests will be returned to the target rather than the spoofing hosts.

http://www.watchguard.com/infocenter/editorial/41649.asp


full member
Activity: 187
Merit: 100
October 27, 2012, 03:57:55 AM
#31
Wow talk about taking out your competition...
legendary
Activity: 1176
Merit: 1001
October 27, 2012, 03:53:46 AM
#30
Routers are designed to reject these packets.
It's a security flaw if that wouldn't happend.
vip
Activity: 756
Merit: 503
October 27, 2012, 03:10:17 AM
#29
Folks, a semi-competent script kiddie can drop a billion IP packets on the internet directed to btc-e (for example) with any "from" address you want (like mt-gox).  All the responses will go to the "from" address... so its pretty useless for everything except DDOS attacks.  Smart routers might drop the packets, but I guess not in this case.

This is the most likely explanation...


Absolutely not.

There is not such a thing as the "from" addresses, these are not mails.

The attack you are taking about requires exploit (serious ones) on the edge routers among the attacker and the attacked.

No, that's not going to happen nor has happend.

It's simply them being unable to put in place a minimal dos (I think) or ddos (unlikely) protection in place and blaming their ignorance on their competitor to gain some fan.

Stupid move, dear.
Wait wut?

http://en.wikipedia.org/wiki/IP_address_spoofing
legendary
Activity: 1666
Merit: 1057
Marketing manager - GO MP
October 27, 2012, 03:07:53 AM
#28
There is not such a thing as the "from" addresses, these are not mails.

Dude, every TCP/IP package includes a source address, how do you think communication is facilitated?
And under normal circumstances one can "spoof" this source address.
full member
Activity: 238
Merit: 100
October 27, 2012, 03:03:14 AM
#27
That's one hell of an accusation to make without evidence, and making it without proving it can only damage BTC-e's reputation.

Explain yourself BTC-e support.
Seriously, that could be grounds for a lawsuit under slander/libel.

Yes it could.  That is an extremely serious allegation.  

Edit:  But we don't have the entire conversation.  Support could have said:  "All these rumors about the DDOS need to stop."  And the question could have been asked:  "What is the rumor that is going around?"  And support could have replied: "mtgox ordered it."

One screenshot can be taken completely out of context. 

I witnessed it. It's not out of context at all, in fact that is the only thing support said.
legendary
Activity: 1176
Merit: 1001
October 27, 2012, 02:06:07 AM
#26
Folks, a semi-competent script kiddie can drop a billion IP packets on the internet directed to btc-e (for example) with any "from" address you want (like mt-gox).  All the responses will go to the "from" address... so its pretty useless for everything except DDOS attacks.  Smart routers might drop the packets, but I guess not in this case.

This is the most likely explanation...


Absolutely not.

There is not such a thing as the "from" addresses, these are not mails.

The attack you are taking about requires exploit (serious ones) on the edge routers among the attacker and the attacked.

No, that's not going to happen nor has happend.

It's simply them being unable to put in place a minimal dos (I think) or ddos (unlikely) protection in place and blaming their ignorance on their competitor to gain some fan.

Stupid move, dear.
hero member
Activity: 756
Merit: 501
There is more to Bitcoin than bitcoins.
October 27, 2012, 01:32:39 AM
#25
Just now on BTC-E support has come back online and said they were told MTGOX is behind the DDOS attacks on BTC-E right now.

COMMENTS?!

What? Pictures?

Ah, lol, found it myself:
https://i.imgur.com/0LXum.jpg
I've been avoiding this thread based on its title, and finally decided to peek in before going to bed. I am happy I did, and can go to sleep laughing. This is priceless.
hero member
Activity: 686
Merit: 500
Whoa, there are a lot of cats in this wall.
October 27, 2012, 01:12:58 AM
#24
That's one hell of an accusation to make without evidence, and making it without proving it can only damage BTC-e's reputation.

Explain yourself BTC-e support.
Seriously, that could be grounds for a lawsuit under slander/libel.

Yes it could.  That is an extremely serious allegation.  

Edit:  But we don't have the entire conversation.  Support could have said:  "All these rumors about the DDOS need to stop."  And the question could have been asked:  "What is the rumor that is going around?"  And support could have replied: "mtgox ordered it."

One screenshot can be taken completely out of context. 
legendary
Activity: 1002
Merit: 1000
Bitcoin
October 27, 2012, 01:09:00 AM
#23

heh - thanks for this nice story from Gibson.. I love that guy scince 1999 Smiley   This link was such a pleasure to read.. Thanks You MPOE-PR !
hero member
Activity: 868
Merit: 1000
October 26, 2012, 08:34:03 PM
#22
Folks, a semi-competent script kiddie can drop a billion IP packets on the internet directed to btc-e (for example) with any "from" address you want (like mt-gox).  All the responses will go to the "from" address... so its pretty useless for everything except DDOS attacks.  Smart routers might drop the packets, but I guess not in this case.

This is the most likely explanation...


The thing is that anyone competent would know that.  The fact that BTC-e support is accusing MtGox of organising a DDOS against them rather than assuming that it's just a script kiddie using the MtGox address for shit and giggles makes me question the technical knowledge and competence of BTC-e staff.
sr. member
Activity: 406
Merit: 250
LTC
October 26, 2012, 08:23:21 PM
#21
Folks, a semi-competent script kiddie can drop a billion IP packets on the internet directed to btc-e (for example) with any "from" address you want (like mt-gox).  All the responses will go to the "from" address... so its pretty useless for everything except DDOS attacks.  Smart routers might drop the packets, but I guess not in this case.

This is the most likely explanation...

Yeah, ofc, still, I guess btc-e wouldn't launch such a rumor without some solid intel.
legendary
Activity: 1246
Merit: 1010
October 26, 2012, 08:09:13 PM
#20
Folks, a semi-competent script kiddie can drop a billion IP packets on the internet directed to btc-e (for example) with any "from" address you want (like mt-gox).  All the responses will go to the "from" address... so its pretty useless for everything except DDOS attacks.  Smart routers might drop the packets, but I guess not in this case.

This is the most likely explanation...
full member
Activity: 238
Merit: 100
October 26, 2012, 06:37:02 PM
#17
Down again?

Edit: NVM
full member
Activity: 126
Merit: 100
Web Programmer, Gamer
October 26, 2012, 06:36:59 PM
#16
MtGox have like the biggest customer base and I see no reason for them to do that.
Wouldn't btc-e have to prove it with images showing ip address of an attacker?

Hard to believe that industry leader will order ddos attack agains competitor with turnouts 20 time smaller. BTC-e has reason to order ddos-atack against MtGox, hoping that some customers will use then as alternative, but not vice versa. So I suppose support was really on drugs) or mistyped somehow))
it would be funny if someone actually got drunk "sorry for the false accusation, one of the employees had a little bit to much".
hero member
Activity: 870
Merit: 500
Trading will make me rich)
October 26, 2012, 06:27:35 PM
#15
Hard to believe that industry leader will order ddos attack agains competitor with turnouts 20 time smaller. BTC-e has reason to order ddos-atack against MtGox, hoping that some customers will use then as alternative, but not vice versa. So I suppose support was really on drugs) or mistyped somehow))
legendary
Activity: 1176
Merit: 1001
October 26, 2012, 05:25:27 PM
#14
Tell them that you can configure the max connections per ip variable on nginx and its one line of config.
legendary
Activity: 916
Merit: 1003
October 26, 2012, 05:09:08 PM
#13
God I love this place.
legendary
Activity: 1400
Merit: 1005
October 26, 2012, 05:07:19 PM
#12
That's one hell of an accusation to make without evidence, and making it without proving it can only damage BTC-e's reputation.

Explain yourself BTC-e support.
Seriously, that could be grounds for a lawsuit under slander/libel.
hero member
Activity: 868
Merit: 1000
October 26, 2012, 04:49:50 PM
#11
That's one hell of an accusation to make without evidence, and making it without proving it can only damage BTC-e's reputation.

Explain yourself BTC-e support.
hero member
Activity: 784
Merit: 1000
Annuit cœptis humanae libertas
October 26, 2012, 04:30:41 PM
#10
"Oh, those Russians!" Smiley
legendary
Activity: 1666
Merit: 1057
Marketing manager - GO MP
October 26, 2012, 04:29:49 PM
#9
Tinfoilhat area imo.

But either way, it's disappointing that this community still hasn't outgrown these kind of things, if it is an actual attack or a false accusation either way.
sr. member
Activity: 406
Merit: 250
LTC
October 26, 2012, 04:28:37 PM
#8
Thanks for posting the pics. It's their support saying it, so.....

YW, luckily I had one tab open on BTC-e.
full member
Activity: 238
Merit: 100
October 26, 2012, 04:27:44 PM
#7
BTC-e support has to be joking right? Would Mtgox really order a ddos against them?

Unless someone has control over the BTC-e server...
legendary
Activity: 1204
Merit: 1002
RUM AND CARROTS: A PIRATE LIFE FOR ME
October 26, 2012, 04:26:13 PM
#6
Just now on BTC-E support has come back online and said they were told MTGOX is behind the DDOS attacks on BTC-E right now.

COMMENTS?!

What? Pictures?

Ah, lol, found it myself:
http://i.imgur.com/0LXum.jpg

Thanks for posting the pics. It's their support saying it, so.....
legendary
Activity: 1458
Merit: 1006
October 26, 2012, 04:26:07 PM
#5
Just now on BTC-E support has come back online and said they were told MTGOX is behind the DDOS attacks on BTC-E right now.

COMMENTS?!

Yeah...
legendary
Activity: 1022
Merit: 1000
October 26, 2012, 04:25:40 PM
#4
Can they back that up?
Otherwise its just a bold claim.
sr. member
Activity: 406
Merit: 250
LTC
October 26, 2012, 04:15:24 PM
#3
Just now on BTC-E support has come back online and said they were told MTGOX is behind the DDOS attacks on BTC-E right now.

COMMENTS?!

What? Pictures?

Ah, lol, found it myself:
http://i.imgur.com/0LXum.jpg
hero member
Activity: 868
Merit: 1002
October 26, 2012, 04:15:20 PM
#2
Told by someone in their web-chat room?  Roll Eyes
This is patently absurd.
legendary
Activity: 1204
Merit: 1002
RUM AND CARROTS: A PIRATE LIFE FOR ME
October 26, 2012, 04:14:02 PM
#1
Just now on BTC-E support has come back online and said they were told MTGOX is behind the DDOS attacks on BTC-E right now.

COMMENTS?!
Jump to: