Showing posts with label DDOS. Show all posts
Showing posts with label DDOS. Show all posts

Saturday, August 6, 2011

PayPal Gave FBI Details Of 1,000 Hackers

After the FBI raids against Anonymous members that were carried out a few weeks ago, some might wonder where exactly the police was getting the names and addresses of the hackers the FBI claimed to arrest. Now the answer seems to be close to us: it turned out that such information was included into the shopping list details provided to the FBI by PayPal.

According to the media reports, PayPal, the online financial entity, is no longer a friend of Anonymous, and is known for collecting a thousand of IP addresses of people noticed to carry out Anonymous' denial-of-service attacks against PayPal late last year.

Meanwhile, everyone who understands that a hacker must know at least some ways to mask their address before doing things like this will realize that the names on the provided list most likely appear the bottom feeding script kiddies. Considering that the FBI is trying to catch the high-profiles Anonymous leaders rather than average members, there are some doubts that the clever hackers won’t think about hiding their IP addresses first. Still, an FBI affidavit suggests that the authorities may have many more people to arrest.

According to one of the FBI agents, PayPal security department has been cooperating with the bureau since the beginning of December, a couple days after the online payment system froze WikiLeaks’ donation account, because it soon found out that the company website started receiving serious DDoS traffic.

The FBI agents started monitoring Anonymous press releases, and at the same time PayPal started collecting traffic logs on its intrusion prevention system that had been installed on its network. The online payment company provided the FBI a USB thumb drive with the traffic logs in question, which contained about one thousand of IP addresses sending malicious network packets to the service within the DDoS attacks. The FBI receives the IP addresses engaged in sending the largest number of packets coming from hackers. Those packets contained such strings as “Wikileaks” and “Goodnight”.

According to the media reports, the affidavit was offered in support of a search warrant for the house of a Texas couple and their son. Although the family hasn’t been charged yet, the house became the source of over 3,500 packets in about 2.5 hours.

Tuesday, January 4, 2011

BitTorrent Can Be Used for DDoS Attacks

A talk at the CCC (Chaos Communications Congress) made it clear that BitTorrent swarms can be easily exploited to take down large sites. In short words, vulnerability in the technology of “trackerless” torrents indeed makes it possible to trick downloaders of popular torrents into send a great number of requests to a chosen server, finally taking it down. Virtually, this makes BitTorrent quite an effective DDoS instrument.

Everyone knows that BitTorrent is in the list of the most effective tools for transferring huge digital files to many people simultaneously. As distinct from a central server, BitTorrent transfers tend to increase speed as more people share the same file. That is the reason why BitTorrent has evolved into the most popular file-sharing platform.

Imagine that millions of people are downloading files through BitTorrent daily. Meanwhile, in some instances over 100 thousand people are sharing the same file at the given moment. While such large swarms of peers are good for sharing, they can also be used for DDoS attacks, as the Chaos Communications Congress recently revealed.

CCC talk was titled “Lying To Neighbors”, and revealed that the DHT technology powering “trackerless torrents” can easily be abused, as BitTorrent downloaders are able to effectively DDoS a certain server. In fact, DHT’s function is to find peers with the same files without communicating with a central tracker, which ensures that your downloads will continue even when the central BitTorrent tracker goes offline. However, DHT can also be exploited to carry out a DDoS attack. In case there’re enough peers downloading the same file, this can effortlessly take down large sites. The sad side of all this is that the downloaders involved in the DDoS attack may be unaware of that.

Such DHT vulnerabilities aren’t new concepts for the developers. In fact, they have been discussed earlier, but still no agreement has yet been reached on them. Meanwhile, over the last months DDoS attacks became a common event, major part carried out under the flag of Operation Payback. However, those attacks required hundreds of users to actively participate simultaneously, while the BitTorrent DDoS is able to take down a server from a single computer.

It unclear whether BitTorrent developers are planning to act upon that DHT vulnerability to prevent that kind of abuse after it became known to everyone, or not.

Monday, October 18, 2010

Major BitTorrent Trackers Have Been Offline

It has been almost 2 weeks since two of the most popular online BitTorrent trackers, PublicBitTorrent and OpenBitTorrent, started going down. Considering the recent news of DDoS attacks at many BitTorrent tracker websites, the public feared that both this trackers became victims of such an assault. However, the cause is friendly fire now, though the largest trackers are really overloaded.

Both PublicBitTorrent and OpenBitTorrent are BitTorrent tracker sites of a non-commercial origin using Opentracker software. None of this services hosts or links to the .torrent files. Besides, the trackers are free to use by any BitTorrent user. The services are actually listed on the top of the most popular services, coordinating in common the downloads of twenty million users at any given time.

One of the services, OpenBitTorrent, though had a seemingly neutral setup, managed to get lots of legal troubles last year. The tracker faces legal issues from both movie and music industry that were fighting against what they understand an illicit service. Hollywood was the first to win the court case against the Internet service provider of the tracker. Then, after the tracker found a new one, IFPI traced it in Spain, thus forcing the service to move again.

With all this intensive history in mind, it wasn’t a surprise that many file-sharers were afraid of the worst when the tracker appeared to become unresponsive a few days ago. Nevertheless, this time the outages were not caused by legal issues. It turned out that the downtime is actually caused by a constantly increasing number of file-sharers. OpenBitTorrent’s servers are just overloaded and aren’t able to process all the requests. However, the operators ensured the users that the troubles will be dealt with in a few days.

At the same time when OpenBitTorrent faced the issue, another major BitTorrent tracker, PublicBitTorrent, also had to solve the problem of too many users in the network, with similar results. Over the last few days PublicBitTorrent has also been unresponsive for 50% of the time, because its servers were also overloaded. This proves only how vulnerable the BitTorrent tracker ecosystem can be. The tracker also ensured the users it’ll be all right in a few days.

Still, the good news is that most users can continue downloading, because torrents work fine relying on DHT and PEX.