Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 02-18-2009, 12:30 PM   #1
AliGbone
Confirmed User
 
AliGbone's Avatar
 
Join Date: Sep 2004
Location: alabama
Posts: 547
Porn Site Feud Spawns New DNS Attack

http://www.pcworld.com/businesscente...ns_attack.html

Porn Site Feud Spawns New DNS Attack


A scrap between two pornographic Web sites turned nasty when one figured out how to take down the other by exploiting a previously unknown quirk in the Internet's Domain Name System (DNS).

The attack is known as DNS Amplification. It has been used sporadically since December, but it started getting talked about last month when ISPrime, a small New York Internet service provider, started getting hit hard with what's known as a distributed denial of service (DDOS) attack. The attack was launched by the operator of a pornographic Web site who was trying to shut down a competitor, hosted on ISPrime's network, according to Phil Rosenthal, the company's chief technology officer.

The attack on ISPrime started on the morning of Sunday, Jan. 18. It lasted about a day, but what was remarkable was that a relatively small number of PCs were able to generate a very large amount of traffic on the network.

One day later, a similar attack followed, lasting three days. Before ISPrime was able to filter the unwanted traffic, attackers were able to use up about 5GB/second of the company's bandwidth,

With a bit of work, Rosenthal's staff was able to filter out the hostile traffic, but in an e-mail interview he said that the attack "represents a disturbing trend in the sophistication of denial of service attacks."

According to Don Jackson, director of threat intelligence at security vendor SecureWorks, we may soon see a lot more of these DNS Amplification attacks. Late last week, the botnet operators, who rent out their networks of hacked computers to the highest bidder, started adding custom DNS Amplification tools to their networks.

"Everyone's picked it up now," he said. "The next big DDOS on some former Soviet republic, you'll see this mentioned, I'm sure."

One of the things that makes a DNS amplification attack particularly nasty is the fact that by sending a very small packet to a legitimate DNS server, say 17 bytes, the attacker can then trick the server into sending a much larger packet -- about 500 bytes --- to the victim of the attack. By spoofing the source of the packet, the attacker can direct it at specific parts of his victim's network.

Jackson estimates that the 5GB/second attack against ISPrime was achieved with just 2,000 computers, which sent out spoofed packets to thousands of legitimate nameservers, all of which started flooding the ISPrime network. ISPrime's Rosenthal says that about 750,000 legitimate DNS servers were used in the attack on his network.

Earlier this week, SecureWorks produced a technical analysis of the DNS Amplification attack.

The attack is generating a lot of discussion amongst DNS experts, according to Duane Wessels, program manager with DNS-OARC (Operations Analysis and Research Center), based in Redwood City, California.

"The worry is that this kind of attack could be used on more high-profile targets," he said.

One of the things that makes the attack particularly nasty is that it's very hard to protect against.

"As far as I know, the only real defense you have is to ask your upstream provider to filter [the malicious traffic]," he said. "It's not something the victim can do by themselves. They need cooperation from the provider."

The DNS system, a kind of directory assistance service for the Internet, has come under increased scrutiny over the past year, when hacker Dan Kaminsky discovered a serious flaw in the system. That flaw, which has now been patched by makers of DNS software, could be exploited to silently redirect Internet traffic to malicious computers without the victim's knowledge.

DNS-OARC has published some information on how to prevent BIND DNS servers from being used in one of these attacks. Microsoft was unable to immediately provide information on how to mitigate this particular attack on its own products, but its guidance on deploying secure DNS servers can be found here.


Interestin newz feed. Betterz make sure your host got the right protection! Times is getting tough!
__________________
I'm not Ali A, not Ali B, Ali C, Ali D, Ali E, Ali F... but... Ali G!

Booyakasha!!!!
Need Content? ADULTCENTRO ROCKS! ADULTCENTRO.COM

Last edited by AliGbone; 02-18-2009 at 12:32 PM..
AliGbone is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 12:40 PM   #2
AlienQ - BANNED FOR LIFE
best designer on GFY
 
AlienQ - BANNED FOR LIFE's Avatar
 
Join Date: Mar 2003
Location: IALIEN.COM - High Definition Video and Photographic Productions -ICQ 78943384
Posts: 30,307
So who is gonna target the thieving tubesites?
AlienQ - BANNED FOR LIFE is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 12:41 PM   #3
Fletch XXX
GFY HALL OF FAME DAMMIT!!!
 
Fletch XXX's Avatar
 
Join Date: Jan 2002
Location: that 504
Posts: 60,840
OMG someone DDosed someone else?

someone call Wired, have they heard of this tactic yet????
__________________

Want an Android App for your tube, membership, or free site?

Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - recent work - About me
Fletch XXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 12:46 PM   #4
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
I think this same thing happened to NatNet as well
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 12:50 PM   #5
undersoul
Confirmed User
 
undersoul's Avatar
 
Join Date: Sep 2006
Location: underground
Posts: 1,212
it was a pretty big attack , 5GB/sec. plus the fear of similar style attacks in the future. scary shit.
__________________
**RIP TD**
undersoul is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 12:51 PM   #6
WiredGuy
Pounding Googlebot
 
Industry Role:
Join Date: Aug 2002
Location: Canada
Posts: 34,456
So what was the porn sites involved?
WG
__________________
I play with Google.
WiredGuy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 12:53 PM   #7
Tom_PM
Porn Meister
 
Industry Role:
Join Date: Feb 2005
Posts: 16,443
Quote:
Originally Posted by WiredGuy View Post
So what was the porn sites involved?
WG
Yeah, and which one was the attacker?
__________________
43-922-863 Shut up and play your guitar.
Tom_PM is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 12:55 PM   #8
Fletch XXX
GFY HALL OF FAME DAMMIT!!!
 
Fletch XXX's Avatar
 
Join Date: Jan 2002
Location: that 504
Posts: 60,840
guys come on, its the same as the cyber security companies.

this is just put out there by the same people they quote in the article.... i doubt the attack occured. Really.

all you need to read is:
Quote:
According to Don Jackson, director of threat intelligence at security vendor SecureWorks, we may soon see a lot more of these DNS Amplification attacks.
to know its mostly horse shit.... like all the other press releases security related.

"Beware the new KillAss virus, buy our software to stop it."

over and over and over
__________________

Want an Android App for your tube, membership, or free site?

Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - recent work - About me
Fletch XXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 09:00 PM   #9
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
The same attacker has attacked:

PerfectLadyboys.com, LadyboyDolls.com, LadyboyPros.com, YoungAsianTrannies.com, IslandDollars.com and Grooby.com. And I believe at least one hosting company took a direct VERY HARD hit.

They have been targeting Asian Shemale sites. From what I have recently heard, both the FBI (they now have a cyber unit for such things) and INTERPOL are getting involved.

What's going on is, someone with a ladyboy site or two is attacking all NEW sites that are coming online in attempt to hold onto their share of the market. They are pretty big hits and have caused some damage. There are a few news stories about it and many DNS experts are looking into it as well because the strength of the attacks and the ease in which they are attacking.

It's all fun and games until INTERPOL is tracking you.

Last edited by DWB; 02-18-2009 at 09:01 PM..
DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 09:03 PM   #10
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
Quote:
Originally Posted by Fletch XXX View Post
guys come on, its the same as the cyber security companies.

this is just put out there by the same people they quote in the article.... i doubt the attack occured. Really.
Fletch, I already listed the sites. Two of them are mine. The attacks are real.

Here is another story with LadyboyDolls.com listed in it: http://www.theregister.co.uk/2009/02...ation_attacks/

Please remove your head out of your ass please.
DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 09:04 PM   #11
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
Quote:
Originally Posted by PR_Tom View Post
Yeah, and which one was the attacker?
hahahahahahahahahahahaha.com
DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 10:52 PM   #12
Iron Fist
Too lazy to set a custom title
 
Join Date: Dec 2006
Posts: 23,400
Quote:
Originally Posted by DirtyWhiteBoy View Post
hahahahahahahahahahahaha.com
Very funny.
__________________
i like waffles
Iron Fist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 11:23 PM   #13
AnniKN
Confirmed User
 
AnniKN's Avatar
 
Industry Role:
Join Date: Feb 2008
Location: South of the border
Posts: 1,682
Is the domain banned here already?
AnniKN is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 11:41 PM   #14
doridori
So Fucking Banned
 
Join Date: Jul 2008
Location: Canadia
Posts: 2,222
seems like a great way to go after competitors.
doridori is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-18-2009, 11:57 PM   #15
pornask
So Fucking Banned
 
Join Date: Aug 2006
Location: 253-233-241
Posts: 6,518
I host some of my sites with ISPrime. Damn. Did you guys find some form of solution so the sites don't go down for three days should such attack reoccur?
pornask is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-19-2009, 03:55 AM   #16
DWB
Registered User
 
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
Quote:
Originally Posted by pornask View Post
I host some of my sites with ISPrime. Damn. Did you guys find some form of solution so the sites don't go down for three days should such attack reoccur?
ISPrime seems to be able to hold their own against it now I think. They have some slick techs over there it seems.
DWB is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-19-2009, 06:29 AM   #17
bobby666
boots are my religion
 
bobby666's Avatar
 
Join Date: Nov 2005
Location: Heart of europe
Posts: 21,765
a thrilling story
__________________
bobby666 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-19-2009, 06:41 AM   #18
geedub
Confirmed User
 
Industry Role:
Join Date: Jun 2005
Location: concrete jungle
Posts: 3,488
lady boy mafia
__________________
Reliable web host that actually cares, tell em geedub sent ya. Vacares
geedub is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-19-2009, 07:05 AM   #19
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,316
if hosts would fix their dns servers
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-19-2009, 07:08 AM   #20
marketsmart
HOMICIDAL TROLL KILLER
 
Industry Role:
Join Date: Dec 2004
Location: Sunnybrook Institution for the Criminally Insane
Posts: 20,419
"Attack of the Ladyboy's".... i wonder who will direct it...
marketsmart is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-19-2009, 07:11 AM   #21
Dirty D
Confirmed User
 
Dirty D's Avatar
 
Join Date: May 2002
Location: Paying Webmasters Millions Since 1999
Posts: 4,044
Don't piss off the lady boys!
Dirty D is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.