Bitcoin Forum

Bitcoin => Pools => Topic started by: FairUser on June 29, 2011, 11:56:51 PM



Title: ** BitcoinPool.com back online after DDoS attack **
Post by: FairUser on June 29, 2011, 11:56:51 PM
As many of our user's have noticed service has been less than good the last few days.  This was caused by a DDoS attack.  We have managed to get control of the situation by notifying hosting providers and blocked several thousand IP addresses in several dozen class C networks.

The main Russian ISP that the attacks were coming from is Yandex LLC.  When we blocked the attackers IP address or an entire class C network, within minutes the attacker would be using a different address in a completely different class C network.  After doing this song and dance for several hours, we realized that it was mostly coming from Yandex and sent off an e-mail to their abuse address.  We haven't received a response from them, so we took drastic action and blocked every IP address owned by Yandex.  After blocking Yandex, everything seems to have returned to normal.  If you are a user in our pool coming from this network, please PM me your IP address and I will white-list it.

We'd like to apologize to our users for the inconvenience of this attack.  We're keeping a close eye on logs and traffic analyzers to monitor for any new attacks so we can block them before they disrupt the pool any further. 

Thank you for your understanding and tolerance for the situation, we appreciate it.

Best Regards :)



Title: Re: ** BitcoinPool.com back online after DDoS attack **
Post by: samr7 on June 30, 2011, 02:11:18 AM
It sure wasn't down for long, I saw less than an hour of downtime.  Kudos on the quick response, Fairuser.


Title: Re: ** BitcoinPool.com back online after DDoS attack **
Post by: hollajandro on June 30, 2011, 10:02:42 PM
Glad you guys have this under control and glad you keep your users informed. Your transparency is appreciated. :)


Title: Re: ** BitcoinPool.com back online after DDoS attack **
Post by: Jack of Diamonds on July 01, 2011, 01:18:02 AM
Yandex abuse team doesn't give a shit about western companies or people emailing them.

They even have $USD rates on blackhat IRC for which they will let you use
domain ranges and bandwidth for spam, fraud, denial of service or other illegal activity without alerting the authorities or pulling the plug on you

These aren't just individual PC's or infections, they are renting their content crawlers in Ukraine and Russia for high bidders.

http://webhosting.bigresource.com/Should-I-block-Yandex-IMB0TFDV.html