Bitcoin Forum
April 19, 2024, 11:47:15 AM *
News: Latest Bitcoin Core release: 26.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: DDoS extortion  (Read 1357 times)
theymos (OP)
Administrator
Legendary
*
Offline Offline

Activity: 5166
Merit: 12865


View Profile
April 24, 2016, 12:52:23 AM
 #1

Someone threatened to DDoS the forum if I didn't pay 10 BTC, and then shortly afterward there was a DDoS attack which took down the forum for a while. Needless to say, I will never pay this demand. For now, the attack has either stopped or been significantly reduced, but it might happen again in the near future. If there is another attack, I will try my best to mitigate it.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
1713527235
Hero Member
*
Offline Offline

Posts: 1713527235

View Profile Personal Message (Offline)

Ignore
1713527235
Reply with quote  #2

1713527235
Report to moderator
1713527235
Hero Member
*
Offline Offline

Posts: 1713527235

View Profile Personal Message (Offline)

Ignore
1713527235
Reply with quote  #2

1713527235
Report to moderator
"Bitcoin: mining our own business since 2009" -- Pieter Wuille
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713527235
Hero Member
*
Offline Offline

Posts: 1713527235

View Profile Personal Message (Offline)

Ignore
1713527235
Reply with quote  #2

1713527235
Report to moderator
1713527235
Hero Member
*
Offline Offline

Posts: 1713527235

View Profile Personal Message (Offline)

Ignore
1713527235
Reply with quote  #2

1713527235
Report to moderator
1713527235
Hero Member
*
Offline Offline

Posts: 1713527235

View Profile Personal Message (Offline)

Ignore
1713527235
Reply with quote  #2

1713527235
Report to moderator
vodaljepa
Hero Member
*****
Offline Offline

Activity: 658
Merit: 500


View Profile
April 24, 2016, 12:53:48 AM
 #2

Thanks for letting us know, I was wondering what was going on

Hottest Girls On Webcam Naked - Naughty Cams
otrkid70
Hero Member
*****
Offline Offline

Activity: 920
Merit: 1014


View Profile
April 24, 2016, 01:11:49 AM
 #3

Don't pay those assholes anything......If the site goes down for a bit i'm sure we will all survive. Don't give into the demand.
--Encrypted--
Copper Member
Legendary
*
Offline Offline

Activity: 924
Merit: 1007

hee-ho.


View Profile
April 24, 2016, 01:18:11 AM
 #4

10BTC for some DDoS on a forum? that's just ridiculous.
Xexen4
Sr. Member
****
Offline Offline

Activity: 756
Merit: 290


View Profile
April 24, 2016, 01:19:08 AM
 #5

hey theymos ignore this threads but i can protect you with praying for 5btc Smiley security is most important ^^
gentlemand
Legendary
*
Offline Offline

Activity: 2590
Merit: 3008


Welt Am Draht


View Profile
April 24, 2016, 01:43:59 AM
 #6

I assumed this forum was threatened with that about a thousand times a second. Then the wee creeps come on here and eulogise what they're screwing with.
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2298


View Profile
April 24, 2016, 02:13:00 AM
 #7

Didn't we subscribe to some kind of DDoS mitigation service several months ago?

I have to agree that in the vast majority of the time it is not a good idea to pay this kind of extortion.
theymos (OP)
Administrator
Legendary
*
Offline Offline

Activity: 5166
Merit: 12865


View Profile
April 24, 2016, 02:19:11 AM
 #8

Didn't we subscribe to some kind of DDoS mitigation service several months ago?

Quite some time ago the forum was behind a DDoS protection service, but this service had many failures, and the alternatives were either unbelievably expensive or too intrusive (ie. they'd break HTTPS's security, make things difficult for Tor users, etc.), so I decided to roll my own DDoS protection. This has gone fairly well so far, though my DDoS mitigation techniques haven't been tested by any particularly large attacks until now. (Small-scale DoS attacks are very common, and my mitigations handle them easily.)

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
jacktheking
Legendary
*
Offline Offline

Activity: 1484
Merit: 1001


Personal Text Space Not For Sale


View Profile
April 24, 2016, 02:24:04 AM
 #9

Yes, you should never pay someone that threaten DDOS Bitcointalk. We, Bitcointalker here, will donate if there is a need to upgrade the server to a better standard.  Wink.

I guess that the attacker is out of resource now. Happy defending! Smiley.

So sad! This profile does not appear as the #1 result (on anonymous) Google searches anymore.

Time to be active on the crypto forums again? Proud to be one of the few Legendary members of the Sparkie Red Dot!

Gonna put this on my resume if I ever join a cryptocurrency/blockchain industry!
Alaki_away
Newbie
*
Offline Offline

Activity: 28
Merit: 0


View Profile
April 24, 2016, 02:30:32 AM
 #10

I'd guess that DDoS attacker hacked mah account as well or the beta is leaking passwords. I'm not getting the reason how am I hacked? However, I've sent you a pm(theymos) for mah account recovery. How about checking 'em(mah pm)?
KenR
Hero Member
*****
Offline Offline

Activity: 910
Merit: 1000


「きみはこれ&#


View Profile
April 24, 2016, 02:37:56 AM
 #11

Why not use cloudflaire servers? They proved to be resistant against all ddos attacks. Just my two cents.
Thanks for sharing the info.

  ████
█ ████
█ ████
█ ████
█ ████ █
█ ████ █
█ ████ █
█ ████ █
█ ████ █
  ████ █
  ████ █
  ████ █
  ████
  ████
█ ████
█ ████
█ ████
█ ████ █
█ ████ █
█ ████ █
█ ████ █
█ ████ █
  ████ █
  ████ █
  ████ █
  ████
  .WEBSITE.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
  .ANN THREAD.
.
▄▄▄▄▄▄▄▄
  ████
█ ████
█ ████
█ ████
█ ████ █
█ ████ █
█ ████ █
█ ████ █
█ ████ █
  ████ █
  ████ █
  ████ █
  ████
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2298


View Profile
April 24, 2016, 02:41:26 AM
 #12

Why not use cloudflaire servers? They proved to be resistant against all ddos attacks. Just my two cents.
Thanks for sharing the info.
This has been discussed a number of times. I believe that you need to give up your HTTPS keys to google in order to use CloudFlaire which is not something that theymos wants to do just yet. If you give your HTTPS keys to a third party then that party can potentially impersonate you without detection.
AgentofCoin
Legendary
*
Offline Offline

Activity: 1092
Merit: 1001



View Profile
April 24, 2016, 02:44:34 AM
 #13

I'd guess that DDoS attacker hacked mah account as well or the beta is leaking passwords. I'm not getting the reason how am I hacked? However, I've sent you a pm(theymos) for mah account recovery. How about checking 'em(mah pm)?
My guess is both of your above guesses are full of crap since your saying he also "hacked" your btc wallet.
So, you likely have malicious software on your computer and I'm guessing is still there now.

Also, this thread is to notify users of this DDoS extortion attempt and/or possible future downtime.
You posting in this thread to ask Theymos to check his PMs about your account reset is offtopic.

I support a decentralized & unregulatable ledger first, with safe scaling over time.
Request a signed message if you are associating with anyone claiming to be me.
notlist3d
Legendary
*
Offline Offline

Activity: 1456
Merit: 1000



View Profile
April 24, 2016, 04:25:10 AM
 #14

10BTC for some DDoS on a forum? that's just ridiculous.

Extortion is ridiculous to begin with.  I'm glad theymos shared so we know whats going on if site slows down, or worst stops.  But if you pay them once... they will come back again wanting more chances are.  So who ever doing it is a idiot to think they will get payment.

Heck on the big hack on DB a while back theymos offered reward for tips/telling who did attack.  I like this side much better find a way to legally get the person trying to do this in court.
Yazuki
Newbie
*
Offline Offline

Activity: 21
Merit: 0


View Profile
April 30, 2016, 09:44:18 PM
 #15

you go theymos! screw those lamers trying to extort you Smiley
Slark
Legendary
*
Offline Offline

Activity: 1862
Merit: 1004


View Profile
May 01, 2016, 02:25:21 PM
 #16

10BTC for some DDoS on a forum? that's just ridiculous.
Not really. This is the biggest cryptocurrency forum in the world. Everyone knows it. Hackers assume that Theymos has a small fortune in BTC from donations and ads published on bitcointalk.
So it will be easy for him to pay 'small fee' of 10 BTC to prevent DDOS. But paying anything is not the answer and solution but instead dead end and invitation to another DDOS.
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 01, 2016, 03:03:48 PM
 #17

Not really. This is the biggest cryptocurrency forum in the world. Everyone knows it. Hackers assume that Theymos has a small fortune in BTC from donations and ads published on bitcointalk.
So it will be easy for him to pay 'small fee' of 10 BTC to prevent DDOS. But paying anything is not the answer and solution but instead dead end and invitation to another DDOS.
I doubt that this is the case. The sender could probably be part of some larger group that is sending out these emails everywhere. Just recently, it has been discovered that a group has been doing this and due to receiving coins on a single address (some 'people' pay and some don't) they have not launched a single attack (free Bitcoins?). Anyhow, the forum should be fine for now. DDoS is just a temporary issue.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
Amph
Legendary
*
Offline Offline

Activity: 3206
Merit: 1069



View Profile
May 01, 2016, 06:32:21 PM
 #18

is this the same guy(i'm assuming) that back then caused that huge ddos of the forum and we remained two days without the forum? it may be the same person, but i don't remember an extorsion at that time...
Spoetnik
Legendary
*
Offline Offline

Activity: 1540
Merit: 1011


FUD Philanthropist™


View Profile
May 02, 2016, 08:22:16 AM
 #19

This was a common occurrence last year.
Cryptsy got hit as well as RarBG and many others.
I also seen stories about other P2P sites and rumors all over about Extortion demands for BTC.
Pretty sure a couple stories mentioned this last couple months at Torentfreak.

And ya screw 'em i would not give in to them.
Pay them once & they would be back later for more money anyway.

FUD first & ask questions later™
Your Point Is Invalid
Hero Member
*****
Offline Offline

Activity: 756
Merit: 510


Dear me, I think I'm becoming a god


View Profile WWW
May 02, 2016, 01:14:21 PM
 #20

How did you get the message @theymos? Maybe we can track them down

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!