Bitcoin Forum
May 25, 2024, 03:37:01 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: We are under attack  (Read 1425 times)
wangxinxi (OP)
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1000


Founder & CEO of Coinut.com, Litecoin Core Dev


View Profile WWW
December 21, 2014, 03:12:28 PM
Last edit: December 22, 2014, 09:06:26 AM by wangxinxi
 #1

We (https://coinut.com) were just attacked by a team called DD4BC using DDoS.

DD4BC Team <dd4bc@safe-mail.net>:
Hello,

Your site is extremely vulnerable to DDoS attacks.

I want to offer you info how to properly setup your protection, so that you can't be ddosed.

If you want info on fixing it, pay me 1 BTC to 13adm65yzzre7fLKSFZayQ8dYyxgXaVyMU


Xinxi Wang:
Thanks. Yes, I know this. It's currently a little vulnerable to DDoS attacks. But we just cannot afford the money to fix it at this moment. I will definitely contact you when we are ready.

Then they just sent millions of requests. And it's difficult for me to open the site.


Xinxi Wang:
Man, you just selected the wrong target. Maybe you should try this after a few months.

DD4BC Team:
OK, contact me within a few months and I will stop the attack. Smiley

CloudFlare will not help.

And one more thing: Price is 1 BTC today. Tomorrow it will increase to 2 BTC and will keep increasing for every day of delay.


Xinxi Wang:
Man, I am a computer science PhD student, and I don't have so much money.


DD4BC Team:
Good for you. I'm not sure how is your formal education going to help in this situation, but...good luck.


Xinxi Wang:
I also think so.


Xinxi Wang:
I am wondering how much it costs for you to send so much traffic?

DD4BC Team:
I'm using botnet which I paid 0 USD, so my cost is 0 USD. Smiley

Xinxi Wang:
Pretty cool.


BTW, I simply blacklisted their IP addresses. The site is now working although they are still attacking. It's a bit slower though. Anyone has good methods for this kind of attacks?
cbeast
Donator
Legendary
*
Offline Offline

Activity: 1736
Merit: 1006

Let's talk governance, lipstick, and pigs.


View Profile
December 21, 2014, 03:20:53 PM
 #2

Someone is spending money to make the attack. It can't last forever.

Any significantly advanced cryptocurrency is indistinguishable from Ponzi Tulips.
RodeoX
Legendary
*
Offline Offline

Activity: 3066
Merit: 1147


The revolution will be monetized!


View Profile
December 21, 2014, 03:22:02 PM
 #3

I seem to recall that a few weeks ago a bunch of these threats were sent out. The attackers were not able to follow through with their threats in those cases either.

The gospel according to Satoshi - https://bitcoin.org/bitcoin.pdf
Free bitcoin in ? - Stay tuned for this years Bitcoin hunt!
wangxinxi (OP)
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1000


Founder & CEO of Coinut.com, Litecoin Core Dev


View Profile WWW
December 21, 2014, 03:23:31 PM
 #4

Someone is spending money to make the attack. It can't last forever.

I also guess so. But it's a lot of fun to chat with this guy.  Grin
noobtrader
Legendary
*
Offline Offline

Activity: 1456
Merit: 1000



View Profile
December 21, 2014, 04:11:07 PM
 #5

eligius pool also run into these ppl once, i dont know how they managed to resolve the issue btw


https://bitcointalk.org/index.php?topic=441465.3560

"...I suspect we need a better incentive for users to run nodes instead of relying solely on altruism...",  satoshi@vistomail.com
wangxinxi (OP)
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1000


Founder & CEO of Coinut.com, Litecoin Core Dev


View Profile WWW
December 21, 2014, 04:33:56 PM
 #6

eligius pool also run into these ppl once, i dont know how they managed to resolve the issue btw


https://bitcointalk.org/index.php?topic=441465.3560

Finally they went away without any satoshi.
Reynaldo
Legendary
*
Offline Offline

Activity: 1143
Merit: 1000


View Profile
December 21, 2014, 07:17:34 PM
 #7

one question regarding coinut, are you able to deposit btc into international debit cards?

edit: the site is pretty slow at the moment. Why dont people host with amazon aws to avoid ddos attacks?
wangxinxi (OP)
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1000


Founder & CEO of Coinut.com, Litecoin Core Dev


View Profile WWW
December 22, 2014, 02:17:21 AM
 #8

one question regarding coinut, are you able to deposit btc into international debit cards?

edit: the site is pretty slow at the moment. Why dont people host with amazon aws to avoid ddos attacks?

We do not deposit BTC into debit cards at this moment. I don't know any other sites can do that.
The attack has stopped. The site is in AWS, but the bandwidth and CPU are limited so it can still be attacked.
grue
Legendary
*
Offline Offline

Activity: 2058
Merit: 1431



View Profile
December 22, 2014, 02:57:28 AM
 #9

you can try this talk from defcon22: https://media.defcon.org/DEF%20CON%2022/DEF%20CON%2022%20video%20and%20slides/DEF%20CON%2022%20Hacking%20Conference%20Presentation%20By%20Blake%20Self%20&%20Shawn%20(cisc0ninja)%20Burrell%20-%20Don%27t%20DDoS%20Me%20Bro%20-%20Practical%20DDoS%20Defense%20-%20Video%20and%20Slides.m4v

my advice would be to use a ddos protection service like cloudflare. make sure to restart your aws instance after you make the switch so the attackers don't have your old IP.

It is pitch black. You are likely to be eaten by a grue.

Adblock for annoying signature ads | Enhanced Merit UI
master-P
Hero Member
*****
Offline Offline

Activity: 868
Merit: 1001


https://keybase.io/masterp FREE Escrow Service


View Profile WWW
December 22, 2014, 07:16:47 AM
 #10

Cloudflare is pretty good and should be able to fend off this attacker just fine. Used it a lot when I worked in the hosting industry and large businesses/forums needed good DDOS protection, always recommended Cloudflare's.

Master-P's Free Escrow Service | 1% Fee for Multi-Party/Sig Campaigns | I Sign ALL of my addresses using PGP Key: https://keybase.io/masterp Verify
Tipping Address: 14PUWBwK854GLenxSa7MAuxXQUXK4DKKi5 | E-mail: masterp.bitcointalk {at} gmail {dot} com (for when/if the forum's offline)
Guide on How to Sign a Message
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3822
Merit: 2633


Join the world-leading crypto sportsbook NOW!


View Profile
December 22, 2014, 08:48:11 AM
 #11

Asking for a measly 1btc? I think that shows that these guys are amateurs. Also, if you pay it it will likely lead to more attacks from them or others thinking they can easily get money out of you.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
December 22, 2014, 08:59:40 AM
 #12

Asking for a measly 1btc? I think that shows that these guys are amateurs. Also, if you pay it it will likely lead to more attacks from them or others thinking they can easily get money out of you.
This. After you get the 'info' and 'fix' your defenses, they would probably strike down again with a different (possibly) name and ask for more.

When you can afford it use Cloudfare, good luck.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
wangxinxi (OP)
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1000


Founder & CEO of Coinut.com, Litecoin Core Dev


View Profile WWW
December 22, 2014, 09:04:04 AM
 #13

Asking for a measly 1btc? I think that shows that these guys are amateurs. Also, if you pay it it will likely lead to more attacks from them or others thinking they can easily get money out of you.
This. After you get the 'info' and 'fix' your defenses, they would probably strike down again with a different (possibly) name and ask for more.

When you can afford it use Cloudfare, good luck.

Yes, they are amateurs. Their technical skills are quite limited. Their requests pattern is quite obvious and can be filtered easily.
s1ng
Legendary
*
Offline Offline

Activity: 1218
Merit: 1001


View Profile
December 22, 2014, 09:26:51 AM
 #14

Asking for a measly 1btc? I think that shows that these guys are amateurs. Also, if you pay it it will likely lead to more attacks from them or others thinking they can easily get money out of you.
This. After you get the 'info' and 'fix' your defenses, they would probably strike down again with a different (possibly) name and ask for more.

When you can afford it use Cloudfare, good luck.

Yes, they are amateurs. Their technical skills are quite limited. Their requests pattern is quite obvious and can be filtered easily.

So Glad that your title computer science PhD student doesn't useless instead very usefull.

Singapore graduate is the best

wangxinxi (OP)
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1000


Founder & CEO of Coinut.com, Litecoin Core Dev


View Profile WWW
December 22, 2014, 10:05:13 AM
 #15

Asking for a measly 1btc? I think that shows that these guys are amateurs. Also, if you pay it it will likely lead to more attacks from them or others thinking they can easily get money out of you.
This. After you get the 'info' and 'fix' your defenses, they would probably strike down again with a different (possibly) name and ask for more.

When you can afford it use Cloudfare, good luck.

Yes, they are amateurs. Their technical skills are quite limited. Their requests pattern is quite obvious and can be filtered easily.

So Glad that your title computer science PhD student doesn't useless instead very usefull.

Singapore graduate is the best




Haha, I don't know if we are the best, but definitely we are not wasting our time here.  Grin
LiteCoinGuy
Legendary
*
Offline Offline

Activity: 1148
Merit: 1010


In Satoshi I Trust


View Profile WWW
December 22, 2014, 12:02:21 PM
 #16

did you release the movie  "The Interview"   Wink ?

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!