Author

Topic: We are under attack (Read 1431 times)

legendary
Activity: 1148
Merit: 1014
In Satoshi I Trust
December 22, 2014, 08:02:21 AM
#16
did you release the movie  "The Interview"   Wink ?
hero member
Activity: 826
Merit: 1000
Founder & CEO of Coinut.com, Litecoin Core Dev
December 22, 2014, 06:05:13 AM
#15
Asking for a measly 1btc? I think that shows that these guys are amateurs. Also, if you pay it it will likely lead to more attacks from them or others thinking they can easily get money out of you.
This. After you get the 'info' and 'fix' your defenses, they would probably strike down again with a different (possibly) name and ask for more.

When you can afford it use Cloudfare, good luck.

Yes, they are amateurs. Their technical skills are quite limited. Their requests pattern is quite obvious and can be filtered easily.

So Glad that your title computer science PhD student doesn't useless instead very usefull.

Singapore graduate is the best




Haha, I don't know if we are the best, but definitely we are not wasting our time here.  Grin
legendary
Activity: 1218
Merit: 1001
December 22, 2014, 05:26:51 AM
#14
Asking for a measly 1btc? I think that shows that these guys are amateurs. Also, if you pay it it will likely lead to more attacks from them or others thinking they can easily get money out of you.
This. After you get the 'info' and 'fix' your defenses, they would probably strike down again with a different (possibly) name and ask for more.

When you can afford it use Cloudfare, good luck.

Yes, they are amateurs. Their technical skills are quite limited. Their requests pattern is quite obvious and can be filtered easily.

So Glad that your title computer science PhD student doesn't useless instead very usefull.

Singapore graduate is the best

hero member
Activity: 826
Merit: 1000
Founder & CEO of Coinut.com, Litecoin Core Dev
December 22, 2014, 05:04:04 AM
#13
Asking for a measly 1btc? I think that shows that these guys are amateurs. Also, if you pay it it will likely lead to more attacks from them or others thinking they can easily get money out of you.
This. After you get the 'info' and 'fix' your defenses, they would probably strike down again with a different (possibly) name and ask for more.

When you can afford it use Cloudfare, good luck.

Yes, they are amateurs. Their technical skills are quite limited. Their requests pattern is quite obvious and can be filtered easily.
legendary
Activity: 2674
Merit: 2965
Terminated.
December 22, 2014, 04:59:40 AM
#12
Asking for a measly 1btc? I think that shows that these guys are amateurs. Also, if you pay it it will likely lead to more attacks from them or others thinking they can easily get money out of you.
This. After you get the 'info' and 'fix' your defenses, they would probably strike down again with a different (possibly) name and ask for more.

When you can afford it use Cloudfare, good luck.
global moderator
Activity: 3934
Merit: 2676
Join the world-leading crypto sportsbook NOW!
December 22, 2014, 04:48:11 AM
#11
Asking for a measly 1btc? I think that shows that these guys are amateurs. Also, if you pay it it will likely lead to more attacks from them or others thinking they can easily get money out of you.
hero member
Activity: 868
Merit: 1001
https://keybase.io/masterp FREE Escrow Service
December 22, 2014, 03:16:47 AM
#10
Cloudflare is pretty good and should be able to fend off this attacker just fine. Used it a lot when I worked in the hosting industry and large businesses/forums needed good DDOS protection, always recommended Cloudflare's.
legendary
Activity: 2058
Merit: 1431
December 21, 2014, 10:57:28 PM
#9
you can try this talk from defcon22: https://media.defcon.org/DEF%20CON%2022/DEF%20CON%2022%20video%20and%20slides/DEF%20CON%2022%20Hacking%20Conference%20Presentation%20By%20Blake%20Self%20&%20Shawn%20(cisc0ninja)%20Burrell%20-%20Don%27t%20DDoS%20Me%20Bro%20-%20Practical%20DDoS%20Defense%20-%20Video%20and%20Slides.m4v

my advice would be to use a ddos protection service like cloudflare. make sure to restart your aws instance after you make the switch so the attackers don't have your old IP.
hero member
Activity: 826
Merit: 1000
Founder & CEO of Coinut.com, Litecoin Core Dev
December 21, 2014, 10:17:21 PM
#8
one question regarding coinut, are you able to deposit btc into international debit cards?

edit: the site is pretty slow at the moment. Why dont people host with amazon aws to avoid ddos attacks?

We do not deposit BTC into debit cards at this moment. I don't know any other sites can do that.
The attack has stopped. The site is in AWS, but the bandwidth and CPU are limited so it can still be attacked.
legendary
Activity: 1143
Merit: 1000
December 21, 2014, 03:17:34 PM
#7
one question regarding coinut, are you able to deposit btc into international debit cards?

edit: the site is pretty slow at the moment. Why dont people host with amazon aws to avoid ddos attacks?
hero member
Activity: 826
Merit: 1000
Founder & CEO of Coinut.com, Litecoin Core Dev
December 21, 2014, 12:33:56 PM
#6
eligius pool also run into these ppl once, i dont know how they managed to resolve the issue btw


https://bitcointalk.org/index.php?topic=441465.3560

Finally they went away without any satoshi.
legendary
Activity: 1456
Merit: 1000
December 21, 2014, 12:11:07 PM
#5
eligius pool also run into these ppl once, i dont know how they managed to resolve the issue btw


https://bitcointalk.org/index.php?topic=441465.3560
hero member
Activity: 826
Merit: 1000
Founder & CEO of Coinut.com, Litecoin Core Dev
December 21, 2014, 11:23:31 AM
#4
Someone is spending money to make the attack. It can't last forever.

I also guess so. But it's a lot of fun to chat with this guy.  Grin
legendary
Activity: 3066
Merit: 1147
The revolution will be monetized!
December 21, 2014, 11:22:02 AM
#3
I seem to recall that a few weeks ago a bunch of these threats were sent out. The attackers were not able to follow through with their threats in those cases either.
donator
Activity: 1736
Merit: 1010
Let's talk governance, lipstick, and pigs.
December 21, 2014, 11:20:53 AM
#2
Someone is spending money to make the attack. It can't last forever.
hero member
Activity: 826
Merit: 1000
Founder & CEO of Coinut.com, Litecoin Core Dev
December 21, 2014, 11:12:28 AM
#1
We (https://coinut.com) were just attacked by a team called DD4BC using DDoS.

DD4BC Team <[email protected]>:
Hello,

Your site is extremely vulnerable to DDoS attacks.

I want to offer you info how to properly setup your protection, so that you can't be ddosed.

If you want info on fixing it, pay me 1 BTC to 13adm65yzzre7fLKSFZayQ8dYyxgXaVyMU


Xinxi Wang:
Thanks. Yes, I know this. It's currently a little vulnerable to DDoS attacks. But we just cannot afford the money to fix it at this moment. I will definitely contact you when we are ready.

Then they just sent millions of requests. And it's difficult for me to open the site.


Xinxi Wang:
Man, you just selected the wrong target. Maybe you should try this after a few months.

DD4BC Team:
OK, contact me within a few months and I will stop the attack. Smiley

CloudFlare will not help.

And one more thing: Price is 1 BTC today. Tomorrow it will increase to 2 BTC and will keep increasing for every day of delay.


Xinxi Wang:
Man, I am a computer science PhD student, and I don't have so much money.


DD4BC Team:
Good for you. I'm not sure how is your formal education going to help in this situation, but...good luck.


Xinxi Wang:
I also think so.


Xinxi Wang:
I am wondering how much it costs for you to send so much traffic?

DD4BC Team:
I'm using botnet which I paid 0 USD, so my cost is 0 USD. Smiley

Xinxi Wang:
Pretty cool.


BTW, I simply blacklisted their IP addresses. The site is now working although they are still attacking. It's a bit slower though. Anyone has good methods for this kind of attacks?
Jump to: