Bitcoin Forum
May 03, 2024, 03:11:21 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 4 5 6 »  All
  Print  
Author Topic: [Spy Nodes && S2X] Attack on the Network in Progress  (Read 7504 times)
This is a self-moderated topic. If you do not want to be moderated by the person who started this topic, create a new topic.
Lauda (OP)
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 19, 2016, 09:12:59 PM
Last edit: November 07, 2017, 10:18:11 AM by Lauda
Merited by ABCbits (3)
 #1

After picking up some strange behavior on my node in the past 3 days (connections per 15 minutes):


After doing some research and queries, it seems like I'm not the only one affected, i.e. there is an attack in progress:


There's not much to worry about at the moment (we are gathering more information). However, it would be best to stop it sooner rather than later. In order to do that a person can either block the IP range via IPtables temporarily until either the attacker runs out of funds or gets removed, and/or report the abuse to Amazon.
Here are the lists that I was able to compile from my own node:

Update 10/01/2016:
There seems to be a second wave of this attack (see last post). It may not be an DOS attack, and thus I've labeled it as [Unknown]. I've also updated the thread (but it requires a complete revamp).

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
1714705881
Hero Member
*
Offline Offline

Posts: 1714705881

View Profile Personal Message (Offline)

Ignore
1714705881
Reply with quote  #2

1714705881
Report to moderator
1714705881
Hero Member
*
Offline Offline

Posts: 1714705881

View Profile Personal Message (Offline)

Ignore
1714705881
Reply with quote  #2

1714705881
Report to moderator
sho_road_warrior
Member
**
Offline Offline

Activity: 114
Merit: 10

PMs blocked, send answers to main.


View Profile
May 20, 2016, 05:16:15 AM
 #2

I just banned them via core. After some time another batch connected, banned them as well. Seems to shut it down. I wonder how many other nodes are affected by this.

┏(-_-)┛┗(-_- )┓┗(-_-)┛┏(-_-)┓
Lauda (OP)
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 20, 2016, 06:17:58 AM
Last edit: May 20, 2016, 07:01:24 AM by Lauda
 #3

I just banned them via core. After some time another batch connected, banned them as well. Seems to shut it down. I wonder how many other nodes are affected by this.
I haven't done that just yet. I'm trying to gather more information, but their constant disconnects are not helpful. If you take a closer look you will see that the amount of bandwidth that they spend is similar for all nodes and <1 MB. Additionally, the disconnect-reconnect interval seems to be 4559 minutes exact (although I'll have to verify this).

Update: They disconnect every after some of them reach ~59 minutes connection time and they all disconnect at the same time (number of connections dropped from 86 to 45 in 1 second) after which they imminently start reconnecting.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
Holliday
Legendary
*
Offline Offline

Activity: 1120
Merit: 1009



View Profile
May 20, 2016, 06:35:24 AM
 #4

I just banned them via core.

I did the same. Banned about 40 of them. Haven't seen any more pop up yet.

If you aren't the sole controller of your private keys, you don't have any bitcoins.
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1499


No I dont escrow anymore.


View Profile WWW
May 20, 2016, 12:24:06 PM
Merited by ABCbits (1)
 #5

I just banned them via core.

I did the same. Banned about 40 of them. Haven't seen any more pop up yet.

Wait 24 hours they will be back (unless you set a higher ban time for core). Todays list of IPs below. They seemed to have kept the connection established longer[1]. I am considering just banning all amazon IPs (already banning /16 subnets anyway) for a longer time. Mainly because I cant take care of this every day or think about a more smooth solution. Might not be needed if Lauda (or someone else) finds a good enough pattern for a fail2ban script.

Code:
52.51.204.60
52.51.204.57
52.51.136.220
52.51.204.88
52.51.170.201
52.51.170.223
52.51.32.197
52.51.186.21
52.17.174.61
52.51.32.197
52.51.204.55
52.51.170.201
52.51.170.223
52.51.204.57
52.51.180.197
52.51.186.21
52.51.204.55
52.51.186.21
52.51.204.60
52.51.136.220
52.51.204.93
52.51.32.197
52.51.204.57
52.51.204.55
52.51.170.223
52.51.204.88
52.51.204.93
52.51.170.201
52.17.174.61
52.51.136.220
52.17.174.61
52.51.204.60
52.51.180.197
52.51.180.197
52.51.204.88
52.51.204.93

[1] https://i.imgur.com/a2xwmwR.png

Im not really here, its just your imagination.
Lauda (OP)
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 20, 2016, 02:12:07 PM
Last edit: May 20, 2016, 05:40:16 PM by Lauda
 #6

I've still received no response from Amazon. I haven't had the time to block them just yet on my own node. I will do so later, check whether more will come up.

Mainly because I cant take care of this every day or think about a more smooth solution.
-snip-
Is the list that you've provided from your own node?

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
Holliday
Legendary
*
Offline Offline

Activity: 1120
Merit: 1009



View Profile
May 20, 2016, 04:16:31 PM
 #7

Wait 24 hours they will be back (unless you set a higher ban time for core).

I banned them for a year.

If you aren't the sole controller of your private keys, you don't have any bitcoins.
Lauda (OP)
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 20, 2016, 07:44:36 PM
Last edit: May 21, 2016, 09:06:11 AM by Lauda
 #8

Due to certain reasons, I had to ban them within the software. In order to ban them for 1 month, the following commands are needed:
Code:
setban 51.17.174.61 add 2592000
setban 52.30.29.120 add 2592000
setban 52.30.204.116 add 2592000
setban 52.51.32.197 add 2592000
setban 52.51.136.220 add 2592000
setban 52.51.170.201 add 2592000
setban 52.51.170.223 add 2592000
setban 52.51.180.197 add 2592000
setban 52.51.186.21 add 2592000
setban 52.51.204.39 add 2592000
setban 52.51.204.55 add 2592000
setban 52.51.204.57 add 2592000
setban 52.51.204.60 add 2592000
setban 52.51.204.88 add 2592000
setban 52.51.204.93 add 2592000


Another one appeared after:
setban 52.17.174.61 add 2592000


If you guys see more, please let me know. This is how it looks like after the ban (updated):


"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
unamis76
Legendary
*
Offline Offline

Activity: 1512
Merit: 1005


View Profile
May 20, 2016, 08:45:10 PM
 #9

So I guess this is why my node has been crashing... I haven't been monitoring it, so I haven't bothered to check what's happening, but I assume it was this since it was working flawlessly for quite some time. I'm rebuilding the blockchain now, crashes made it go corrupt. I'll be banning these IP's and I'll see if things get better.
Lauda (OP)
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 20, 2016, 11:55:44 PM
 #10

So I guess this is why my node has been crashing... I haven't been monitoring it, so I haven't bothered to check what's happening, but I assume it was this since it was working flawlessly for quite some time. I'm rebuilding the blockchain now, crashes made it go corrupt.
You shouldn't really 'not-monitor' your node completely. You should at least check it occasionally, or add e-mail notifications for downtime (in case that you haven't). As far as your node crashes are concerned, the 'attack' doesn't necessarily have to be be the cause of that. It comes down to the hardware and OS that you're running in addition to the configuration and internet speed. My node was 'fine' while only being 'sluggish' sometimes and failing to authenticate via the software that I use.

Quote
I'll be banning these IP's and I'll see if things get better.
The list that I've made with the 'setban' seems to be efficient. I've updated the picture a few minutes ago.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
glendall
Legendary
*
Offline Offline

Activity: 2100
Merit: 1018


Sugars.zone | DatingFi - Earn for Posting


View Profile
May 21, 2016, 12:13:35 AM
 #11

Any ideas on why anyone would do this? What could possibly be gained for these asshats? I don't get it.

.SUGAR.
██   ██

██   ██

██   ██

██   ██

██   ██

██   ██
▄▄████████████████████▄▄
▄████████████████████████▄
███████▀▀▀██████▀▀▀███████
█████▀██████▀▀██████▀█████
██████████████████████████
██████████████████████████
█████████████████████▄████
██████████████████████████
████████▄████████▄████████
██████████████████████████
▀████████████████████████▀
▀▀████████████████████▀▀

██   ██

██   ██

██   ██

██   ██

██   ██

██   ██
███████████████████████████
███████████████████████████
██████               ██████
██████   ▄████▀      ██████
██████▄▄▄███▀   ▄█   ██████
██████████▀   ▄███   ██████
████████▀   ▄█████▄▄▄██████
██████▀   ▄███████▀▀▀██████
██████   ▀▀▀▀▀▀▀▀▀   ██████
██████               ██████
███████████████████████████
███████████████████████████
.
Backed By
ZetaChain

██   ██

██   ██

██   ██

██   ██

██   ██

██   ██

██   ██

██   ██

██   ██

██   ██

██   ██

██   ██
▄▄████████████████████▄▄
██████████████████████████
████████████████████████████
█████████████████▀▀  ███████
█████████████▀▀      ███████
█████████▀▀   ▄▄     ███████
█████▀▀    ▄█▀▀     ████████
█████████ █▀        ████████
█████████ █ ▄███▄   ████████
██████████████████▄▄████████
██████████████████████████
▀▀████████████████████▀▀
▄▄████████████████████▄▄
██████████████████████████
██████ ▄▀██████████  ███████
███████▄▀▄▀██████  █████████
█████████▄▀▄▀██  ███████████
███████████▄▀▄ █████████████
███████████  ▄▀▄▀███████████
█████████  ████▄▀▄▀█████████
███████  ████████▄▀ ████████
████████████████████████████
██████████████████████████
▀▀████████████████████▀▀
Lauda (OP)
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 21, 2016, 12:19:10 AM
 #12

Any ideas on why anyone would do this? What could possibly be gained for these asshats? I don't get it.
It comes down to what they're trying to do with these nodes. They could be possibly testing some exploit or something (e.g. Bloom filter as listed in OP). I'm not really sure at the moment, and there isn't much information about it either. However, they don't seem to be causing much damage (besides crashing a few nodes) so there's nothing to worry about. I'm still waiting for Amazon to contact me back.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
chek2fire
Legendary
*
Offline Offline

Activity: 3416
Merit: 1142


Intergalactic Conciliator


View Profile
May 21, 2016, 12:30:55 AM
 #13

I have in my nodes the same problem. Is about 30 connections that begin from 52. How can i ban their ip from command line?

http://www.bitcoin-gr.org
4411 804B 0181 F444 ADBD 01D4 0664 00E4 37E7 228E
jacobmayes94
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250



View Profile
May 21, 2016, 01:15:23 AM
 #14

I blocked the range in the firewall. Wonder what they are doing...
chek2fire
Legendary
*
Offline Offline

Activity: 3416
Merit: 1142


Intergalactic Conciliator


View Profile
May 21, 2016, 01:34:12 AM
 #15

can i ban a range of ip with setban or i have to manual ban one by one?

http://www.bitcoin-gr.org
4411 804B 0181 F444 ADBD 01D4 0664 00E4 37E7 228E
chek2fire
Legendary
*
Offline Offline

Activity: 3416
Merit: 1142


Intergalactic Conciliator


View Profile
May 21, 2016, 01:53:40 AM
 #16

this is the ip range and the command lines to ban them for a month

http://pastebin.com/puNC4uET

http://www.bitcoin-gr.org
4411 804B 0181 F444 ADBD 01D4 0664 00E4 37E7 228E
franky1
Legendary
*
Offline Offline

Activity: 4214
Merit: 4458



View Profile
May 21, 2016, 03:37:17 AM
 #17

Any ideas on why anyone would do this? What could possibly be gained for these asshats? I don't get it.

seems like someone is trying to provoke people into banning amazon/cloud hosting services.
in all honesty. i see it as a good thing. no one should be running a full node on amazon/cloud hosting anyways, so if it has taken a crap DDoS attempt to prompt people to block these, then ultimately its a good thing

I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
Lauda (OP)
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 21, 2016, 08:34:04 AM
Merited by ABCbits (1)
 #18

can i ban a range of ip with setban or i have to manual ban one by one?
Yes, you can ban a whole range. For example (provided by Shorena):
Code:
bitcoin-cli setban 51.xx.0.0/16 add
I specifically chose single bans and a 1 month time period in order to see whether more will show up from AWS IPs and whether they would be taken down by then.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1499


No I dont escrow anymore.


View Profile WWW
May 21, 2016, 08:52:02 AM
 #19

-snip-
Is the list that you've provided from your own node?

Yes, the IPs came from my new node. The old one does not seem to have this problem. I think its because its at its limit of connections anyway.

Any ideas on why anyone would do this? What could possibly be gained for these asshats? I don't get it.

seems like someone is trying to provoke people into banning amazon/cloud hosting services.
in all honesty. i see it as a good thing. no one should be running a full node on amazon/cloud hosting anyways, so if it has taken a crap DDoS attempt to prompt people to block these, then ultimately its a good thing

Maybe. I usually dont like to outright ban an entire ISP (or hoster) just because someone is misbehaving. Their stupid report form does not even have a section "(D)DoS" though and they specificially asked for reports on this on twitter, yet the attacks continue. It boils down to my priorities and dealing with a low impact attack is very low on a long list. If there are new connections tomorrow, I will increase the ban time, probably to a month and just ban the entire amazon IP range. I know there are legit full nodes running via amazon, but as you said maybe they shouldnt in the first place.

Im not really here, its just your imagination.
jacobmayes94
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250



View Profile
May 21, 2016, 08:53:49 AM
 #20

Why would running a full node on amazons service be any problem if its legit? Unless I am missing something?

Pages: [1] 2 3 4 5 6 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!