Pages:
Author

Topic: [Spy Nodes && S2X] Attack on the Network in Progress - page 2. (Read 7571 times)

legendary
Activity: 1512
Merit: 1012
From 2017-03-31 to 2017-04-04

Code:
47.90.4.203 Hits = 9260
59.110.63.71 Hits = 5184
129.13.252.36 Hits = 4806
129.13.252.47 Hits = 3907
136.243.139.96 Hits = 1399
46.101.246.115 Hits = 1348
139.162.96.165 Hits = 987
[2a03:b0c0:3:d0::5c9:4001] Hits = 931
[2a00:1398:4:2a00::a1] Hits = 889
120.55.171.74 Hits = 845
[2a00:1398:4:2a00::a5] Hits = 666
188.65.213.21 Hits = 379
52.76.95.246 Hits = 248
52.8.99.184 Hits = 247
54.94.211.146 Hits = 247
45.32.130.19 Hits = 204
104.196.107.156 Hits = 199
52.210.89.26 Hits = 160
52.192.180.114 Hits = 129
54.223.77.14 Hits = 125
52.18.56.236 Hits = 119

Same list, IP range ordered.

Code:
[2a00:1398:4:2a00::a1] Hits = 889
[2a00:1398:4:2a00::a5] Hits = 666
[2a03:b0c0:3:d0::5c9:4001] Hits = 931
104.196.107.156 Hits = 199
120.55.171.74 Hits = 845
129.13.252.36 Hits = 4806
129.13.252.47 Hits = 3907
136.243.139.96 Hits = 1399
139.162.96.165 Hits = 987
188.65.213.21 Hits = 379
45.32.130.19 Hits = 204
46.101.246.115 Hits = 1348
47.90.4.203 Hits = 9260
52.18.56.236 Hits = 119
52.192.180.114 Hits = 129
52.210.89.26 Hits = 160
52.76.95.246 Hits = 248
52.8.99.184 Hits = 247
54.223.77.14 Hits = 125
54.94.211.146 Hits = 247
59.110.63.71 Hits = 5184
legendary
Activity: 1512
Merit: 1012
Samples in situation.


+++

+++

+++


The bitcoin developers have taken this thread into account because multi-client bitcoinj attacks of the same IP are now filtered.

That is why I continue to report, here, a follow-up.

+++

On early stage of somes P2P network, this "busing" job have been eradicate by apply a notation on IP (like if you try 3 times per minute = ban for 15min + if you re-try this after 2 minutes = ban for 1h, max ban time = 24h).

very usefull for filtering no-ordinary client that push all ports every 5 seconds ...
Original clients try 2 times (with 2 random port no followed) and search an other node (good boy !).
sr. member
Activity: 434
Merit: 250
Re-reading this thread as it is very interesting. 
Wondering what the motivation for this person is.
Is this someone who thinks they are causing damage? Prepping/ testing for a larger attack? An accident? 
legendary
Activity: 1512
Merit: 1012
From 2017-03-20 to 2017-03-24

Code:
129.13.252.36 Hits = 10917
129.13.252.47 Hits = 5399
46.101.246.115 Hits = 1585
136.243.139.96 Hits = 1578
[2a00:1398:4:2a00::a1] Hits = 1138
[2a00:1398:4:2a00::a5] Hits = 1040
139.162.96.165 Hits = 1026
37.34.48.17 Hits = 347
52.18.56.236 Hits = 335
54.94.211.146 Hits = 248
52.74.14.245 Hits = 247
52.70.130.28 Hits = 246
52.8.99.184 Hits = 246
104.196.107.156 Hits = 244
54.223.77.14 Hits = 231
52.192.180.114 Hits = 229
104.236.95.174 Hits = 193
52.76.95.246 Hits = 153
52.210.89.26 Hits = 123
[2a02:348:86:3011::1] Hits = 100
52.32.80.148 Hits = 78
72.36.89.11 Hits = 69
94.21.45.130 Hits = 69
46.63.26.63 Hits = 59
72.2.237.42 Hits = 29
52.29.215.16 Hits = 26
5.189.177.237 Hits = 19
[2001:0:9d38:90d7:3c5f:18c1:2a45:5592] Hits = 18

Same list, IP Range ordered.

Code:
[2001:0:9d38:90d7:3c5f:18c1:2a45:5592] Hits = 18
[2a00:1398:4:2a00::a1] Hits = 1138
[2a00:1398:4:2a00::a5] Hits = 1040
[2a02:348:86:3011::1] Hits = 100
104.196.107.156 Hits = 244
104.236.95.174 Hits = 193
129.13.252.36 Hits = 10917
129.13.252.47 Hits = 5399
136.243.139.96 Hits = 1578
139.162.96.165 Hits = 1026
37.34.48.17 Hits = 347
46.101.246.115 Hits = 1585
46.63.26.63 Hits = 59
5.189.177.237 Hits = 19
52.18.56.236 Hits = 335
52.192.180.114 Hits = 229
52.210.89.26 Hits = 123
52.29.215.16 Hits = 26
52.32.80.148 Hits = 78
52.70.130.28 Hits = 246
52.74.14.245 Hits = 247
52.76.95.246 Hits = 153
52.8.99.184 Hits = 246
54.223.77.14 Hits = 231
54.94.211.146 Hits = 248
72.2.237.42 Hits = 29
72.36.89.11 Hits = 69
94.21.45.130 Hits = 69
legendary
Activity: 1512
Merit: 1012
From 2017-03-10 to 2017-03-14 (yes, it's small ... but probes are busy after the 0.14.0)

Code:
129.13.252.47 Hits = 11809
129.13.252.36 Hits = 6677
[2a00:1398:4:2a00::a5] Hits = 2653
[2a00:1398:4:2a00::a1] Hits = 2315
46.101.246.115 Hits = 1165
136.243.139.96 Hits = 971
139.162.96.165 Hits = 717
37.34.48.17 Hits = 244
104.196.107.156 Hits = 233
54.94.211.146 Hits = 211
52.210.89.26 Hits = 197
52.76.95.246 Hits = 196
52.18.56.236 Hits = 194
54.223.77.14 Hits = 179
52.29.215.16 Hits = 129
52.70.130.28 Hits = 128
104.236.95.174 Hits = 94
52.192.180.114 Hits = 94
52.74.14.245 Hits = 61
88.147.58.140 Hits = 44
[2001:0:5ef5:79fd:304e:1543:fab0:b4fa] Hits = 43
46.63.26.63 Hits = 43
79.6.216.122 Hits = 40
72.36.89.11 Hits = 39
119.164.15.239 Hits = 23

Same list, IP Range ordered.

Code:
[2001:0:5ef5:79fd:304e:1543:fab0:b4fa] Hits = 43
[2a00:1398:4:2a00::a1] Hits = 2315
[2a00:1398:4:2a00::a5] Hits = 2653
104.196.107.156 Hits = 233
104.236.95.174 Hits = 94
119.164.15.239 Hits = 23
129.13.252.36 Hits = 6677
129.13.252.47 Hits = 11809
136.243.139.96 Hits = 971
139.162.96.165 Hits = 717
37.34.48.17 Hits = 244
46.101.246.115 Hits = 1165
46.63.26.63 Hits = 43
52.18.56.236 Hits = 194
52.192.180.114 Hits = 94
52.210.89.26 Hits = 197
52.29.215.16 Hits = 129
52.70.130.28 Hits = 128
52.74.14.245 Hits = 61
52.76.95.246 Hits = 196
54.223.77.14 Hits = 179
54.94.211.146 Hits = 211
72.36.89.11 Hits = 39
79.6.216.122 Hits = 40
88.147.58.140 Hits = 44
copper member
Activity: 2856
Merit: 3071
https://bit.ly/387FXHi lightning theory
I'm not entirely sure what the benefit of doing this is, pprobably to try to slow down the network (although it'd take a lot to do that).

I thought one of BTC network's benefits was being "resistant" to DDoS and similar kind of attacks. As you pointed out, it should take ALOT to slow it down even a bit. I do not think that is a realistic purpose at all. It is strange.

It isn't a useful attack. It's practically impossible to DoS the Bitcoin network. There will probably be quite a few people that run nodes on VPS services meaning that their IP can easily be chaned and IPs can te changed anyway (new nodes are also fairly simple to boot).
I'd think, a successful DoS of the bitcoin network would be several thousand GB/s of data transfer at least. This is practically impossible to equalise the network speed of all bitcoin nodes and be about 2x that to stop traffic which would still be unsuccessful as other traffic would still fit through or the network would go down shortly (but not the entire network).

Is the attack still running at full power?
hero member
Activity: 1204
Merit: 531
Metaverse 👾 Cyberweapons
I'm not entirely sure what the benefit of doing this is, pprobably to try to slow down the network (although it'd take a lot to do that).

I thought one of BTC network's benefits was being "resistant" to DDoS and similar kind of attacks. As you pointed out, it should take ALOT to slow it down even a bit. I do not think that is a realistic purpose at all. It is strange.
copper member
Activity: 2856
Merit: 3071
https://bit.ly/387FXHi lightning theory
I was looking at information here.
Could this be leading to some of the problems here as this thread was started on May 2016 which would be about the time that that warning is relevant to.

(Also, it's good that we havne't seen too many nodes sutdown as a result of this and that there are just the IPs that are being blocked which is a fairly simple solution - although there's still no information as to who is preforming this attack and no information as to the purpose why)?

I find it interesting. I am interested in offensive security, but I have never met with such an attack before.

So, I wonder what uses does such an attack have?

What can the hacker achieve with this (technically, since we do not know his/her true motives anyway)?
I'm not entirely sure what the benefit of doing this is, pprobably to try to slow down the network (although it'd take a lot to do that).
hero member
Activity: 1204
Merit: 531
Metaverse 👾 Cyberweapons
I find it interesting. I am interested in offensive security, but I have never met with such an attack before.

So, I wonder what uses does such an attack have?

What can the hacker achieve with this (technically, since we do not know his/her true motives anyway)?
legendary
Activity: 1120
Merit: 1012
I've been banning 12 or so of these connections every couple hours for the past several days. More pop up every time so far.
legendary
Activity: 1512
Merit: 1012
From 2017-01-14 to 2017-01-23 :

Code:
129.13.252.36 HITS = 3158
129.13.252.47 HITS = 2173
136.243.139.96 HITS = 778
148.251.151.71 HITS = 649
139.162.96.165 HITS = 568
52.8.99.184 HITS = 537
46.101.246.115 HITS = 486
50.7.71.172 HITS = 453
72.36.89.11 HITS = 266
54.223.77.14 HITS = 242
52.70.130.28 HITS = 183
52.18.56.236 HITS = 182
52.62.33.159 HITS = 181
52.210.89.26 HITS = 180
52.29.215.16 HITS = 179
178.62.20.190 HITS = 178
37.34.48.17 HITS = 175
52.74.14.245 HITS = 149
104.196.107.156 HITS = 141
46.63.26.63 HITS = 91

Same list, IP Range ordered :

Code:
104.196.107.156 HITS = 141
129.13.252.36 HITS = 3158
129.13.252.47 HITS = 2173
136.243.139.96 HITS = 778
139.162.96.165 HITS = 568
148.251.151.71 HITS = 649
178.62.20.190 HITS = 178
37.34.48.17 HITS = 175
46.101.246.115 HITS = 486
46.63.26.63 HITS = 91
50.7.71.172 HITS = 453
52.18.56.236 HITS = 182
52.210.89.26 HITS = 180
52.29.215.16 HITS = 179
52.62.33.159 HITS = 181
52.70.130.28 HITS = 183
52.74.14.245 HITS = 149
52.8.99.184 HITS = 537
54.223.77.14 HITS = 242
72.36.89.11 HITS = 266
legendary
Activity: 1512
Merit: 1012
From 2017-01-03 to 2017-01-08 :

Code:
129.13.252.36 HITS = 2808
129.13.252.47 HITS = 1130
136.243.139.96 HITS = 697
139.162.96.165 HITS = 580
148.251.151.71 HITS = 377
50.7.71.172 HITS = 333
45.33.65.130 HITS = 302
52.18.56.236 HITS = 249
54.94.211.146 HITS = 248
52.76.95.246 HITS = 247
52.29.215.16 HITS = 245
52.192.180.114 HITS = 226
52.62.33.159 HITS = 207
178.62.20.190 HITS = 161
52.205.213.45 HITS = 144
72.36.89.11 HITS = 46

IP range ordered, same list :

Code:
129.13.252.36 HITS = 2808
129.13.252.47 HITS = 1130
136.243.139.96 HITS = 697
139.162.96.165 HITS = 580
148.251.151.71 HITS = 377
178.62.20.190 HITS = 161
45.33.65.130 HITS = 302
50.7.71.172 HITS = 333
52.18.56.236 HITS = 249
52.192.180.114 HITS = 226
52.205.213.45 HITS = 144
52.29.215.16 HITS = 245
52.62.33.159 HITS = 207
52.76.95.246 HITS = 247
54.94.211.146 HITS = 248
72.36.89.11 HITS = 46
legendary
Activity: 2674
Merit: 2965
Terminated.
-snip-
I have recently wiped my node clean (thus also the banlist), and those connections appeared within seconds of me booting up the node. They seem very persistent. The majority seems to have moved away from 52.x range into 100+.x something (my banlist is empty once again, thus I don't see the exact IPs right now) for me. They are fairly easy to spot for those using a GUI (e.g. 3-4 nodes per IP).
legendary
Activity: 1512
Merit: 1012
Winners of this week (5 days) :

Code:
59.110.63.71 Hits = 2774
129.13.252.36 Hits = 1898
129.13.252.47 Hits = 1876
52.205.213.45 Hits = 822
136.243.139.96 Hits = 353
178.62.20.190 Hits = 265
50.7.71.172 Hits = 260
52.62.33.159 Hits = 246
54.94.211.146 Hits = 246
52.76.95.246 Hits = 245
139.162.96.165 Hits = 238
52.18.56.236 Hits = 237
45.33.65.130 Hits = 220
52.74.14.245 Hits = 218
148.251.151.71 Hits = 206
52.29.215.16 Hits = 198
52.70.130.28 Hits = 187
52.210.89.26 Hits = 179
52.32.80.148 Hits = 178
54.223.77.14 Hits = 159

Same list, Ordered by IP range :

Code:
129.13.252.36 Hits = 1898
129.13.252.47 Hits = 1876
136.243.139.96 Hits = 353
139.162.96.165 Hits = 238
148.251.151.71 Hits = 206
178.62.20.190 Hits = 265
45.33.65.130 Hits = 220
50.7.71.172 Hits = 260
52.18.56.236 Hits = 237
52.205.213.45 Hits = 822
52.210.89.26 Hits = 179
52.29.215.16 Hits = 198
52.32.80.148 Hits = 178
52.62.33.159 Hits = 246
52.70.130.28 Hits = 187
52.74.14.245 Hits = 218
52.76.95.246 Hits = 245
54.223.77.14 Hits = 159
54.94.211.146 Hits = 246
59.110.63.71 Hits = 2774
legendary
Activity: 1512
Merit: 1012
From 2016-12-09 to 2016-12-14.

Code:
129.13.252.36	HITS = 	4442
129.13.252.47 HITS = 4432
52.205.213.45 HITS = 1378
59.110.63.71 HITS = 965
136.243.139.96 HITS = 647
45.33.65.130 HITS = 326
148.251.151.71 HITS = 277
52.76.95.246 HITS = 249
52.192.180.114 HITS = 248
52.62.33.159 HITS = 247
197.231.221.211 HITS = 214
54.223.77.14 HITS = 198
50.7.71.172 HITS = 180
52.32.80.148 HITS = 175
52.70.130.28 HITS = 158
54.94.211.146 HITS = 135
37.34.48.17 HITS = 104
52.29.215.16 HITS = 84
106.187.49.47 HITS = 62
72.36.89.11 HITS = 56
46.63.26.63 HITS = 55

Same list, ordered by IP range :

Code:
106.187.49.47	HITS = 	62
129.13.252.36 HITS = 4442
129.13.252.47 HITS = 4432
136.243.139.96 HITS = 647
148.251.151.71 HITS = 277
197.231.221.211 HITS = 214
213.165.242.245 HITS = 49
37.34.48.17 HITS = 104
45.33.65.130 HITS = 326
45.55.45.119 HITS = 37
46.63.26.63 HITS = 55
47.222.206.109 HITS = 20
50.7.71.172 HITS = 180
52.192.180.114 HITS = 248
52.205.213.45 HITS = 1378
52.29.215.16 HITS = 84
52.32.80.148 HITS = 175
52.62.33.159 HITS = 247
52.70.130.28 HITS = 158
52.76.95.246 HITS = 249
54.186.75.87 HITS = 51
54.223.77.14 HITS = 198
54.94.211.146 HITS = 135
59.110.63.71 HITS = 965
72.36.89.11 HITS = 56


If you don't follow the rules of :

- client version
- disconnexion/connexion/reconnexion per day
- or use a port circular scanner (after a ban)
- or don't contribute at the Bitcoin network (blocks job)

You are in this lists.
copper member
Activity: 1498
Merit: 1528
No I dont escrow anymore.
ban counter.

You banned 129.13.252.47 ~39 times per hour over 11 days? For what?

normal client don't hit so more ... after a ban.
less than 100 is normal over 11 days (~10 connexions every 24h).

legendary
Activity: 1512
Merit: 1012
ban counter.
normal client don't hit so more ... after a ban.
less than 100 is normal over 11 days (~10 connexions every 24h).
copper member
Activity: 1498
Merit: 1528
No I dont escrow anymore.
Update (11 days monitoring, port doesn't matter)
Less than 100 connexions is a false flag for me (liberate after 7 days in my Bitcoin Core BAN strategy).
-snip-

Whats a "hit" here?
legendary
Activity: 1512
Merit: 1012
Update (11 days monitoring, port doesn't matter)
Less than 100 connexions is a false flag for me (liberate after 7 days in my Bitcoin Core BAN strategy).

Code:

129.13.252.47:60997 Hits = 10438
129.13.252.36:61000 Hits = 9594
52.205.213.45:60964 Hits = 2267
136.243.139.96:9996 Hits = 2078
45.33.65.130:60986 Hits = 890
37.34.48.17:60931 Hits = 558
52.210.89.26:60788 Hits = 498
52.32.80.148:60972 Hits = 497
52.76.95.246:60938 Hits = 495
104.236.95.174:60972 Hits = 493
52.18.56.236:60949 Hits = 493
52.62.33.159:60964 Hits = 492
148.251.151.71:60984 Hits = 476
178.62.20.190:60901 Hits = 418
52.70.130.28:60930 Hits = 375
50.7.71.172:60965 Hits = 257
52.192.180.114:60968 Hits = 249
54.94.211.146:60910 Hits = 247
50.7.47.93:60995 Hits = 246
52.29.215.16:61000 Hits = 245
52.74.14.245:60878 Hits = 245
54.186.75.87:60907 Hits = 169
131.114.88.218:60724 Hits = 168
52.39.120.87:9227 Hits = 129
106.187.49.47:60860 Hits = 127
146.57.248.225:60316 Hits = 105
197.231.221.211:9818 Hits = 67


Same list, ordered by IP range :

Code:

104.236.95.174:60972 Hits = 493
106.187.49.47:60860 Hits = 127
129.13.252.36:61000 Hits = 9594
129.13.252.47:60997 Hits = 10438
131.114.88.218:60724 Hits = 168
136.243.139.96:9996 Hits = 2078
146.57.248.225:60316 Hits = 105
148.251.151.71:60984 Hits = 476
178.62.20.190:60901 Hits = 418
197.231.221.211:9818 Hits = 67
37.34.48.17:60931 Hits = 558
45.33.65.130:60986 Hits = 890
50.7.47.93:60995 Hits = 246
50.7.71.172:60965 Hits = 257
52.18.56.236:60949 Hits = 493
52.192.180.114:60968 Hits = 249
52.205.213.45:60964 Hits = 2267
52.210.89.26:60788 Hits = 498
52.29.215.16:61000 Hits = 245
52.32.80.148:60972 Hits = 497
52.39.120.87:9227 Hits = 129
52.62.33.159:60964 Hits = 492
52.70.130.28:60930 Hits = 375
52.74.14.245:60878 Hits = 245
52.76.95.246:60938 Hits = 495
54.186.75.87:60907 Hits = 169
54.94.211.146:60910 Hits = 247

legendary
Activity: 3430
Merit: 1142
Ιntergalactic Conciliator
i have create this for everyone that want to ban them from nodes

http://pastebin.com/1DP1Kdik
Pages:
Jump to: