Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM

[ARCHIVED THREAD] - DDOS, anyone? (Page 1 of 2)

Previous Page
/ 2
Next Page
1/2/2015 7:34:21 PM EDT
Looks like it's hitting St. Louis and Washington State. I haven't seen anything this big in a while.



1/2/2015 7:38:16 PM EDT
[#1]
Somebody from China sure has a hardon for St Louis right now.
1/2/2015 7:38:44 PM EDT
[#2]

Quote History
Quoted:


Somebody from China sure has a hardon for St Louis right now.
View Quote




 
Russia too
1/2/2015 7:39:39 PM EDT
[#3]
Quote History
Quoted:
Somebody from China sure has a hardon for St Louis right now.
View Quote


Someone going after Boeing maybe? Don't they also have a big presence in St.L?
1/2/2015 7:39:45 PM EDT
[#4]
Call of Duty is serious business.
1/2/2015 7:41:40 PM EDT
[#5]
Probably a drunk driver that hit a phone pole.

1/2/2015 7:43:48 PM EDT
[#6]
That would explain battlenet being down all day
1/2/2015 7:47:39 PM EDT
[#7]
I've seen it that bad quite frequently, generally from China.  And yes, St. Louis and Kirksville, MO, tend to get hit quite a bit.
1/2/2015 7:48:52 PM EDT
[#8]
What did we do?
1/2/2015 7:51:59 PM EDT
[#9]
Something is going on but it's not rare to see these types of attacks. The better story is that the recent Sony hack turns out to be a disgruntled former employee. Now, was this 'Lena' person working alone but I never bought the Nork angle, not without inside help.

And Obama announces new sanctions against NK because of the hack. Poor guy just catch a break.

Posted Via AR15.Com Mobile
1/2/2015 7:53:50 PM EDT
[#10]

Quote History
Quoted:


I've seen it that bad quite frequently, generally from China.  And yes, St. Louis and Kirksville, MO, tend to get hit quite a bit.
View Quote


I've been trying to figure out why Kirksville keeps getting hit.  The only thing I've been able to come up with is that there may be sort of co-location out there possibly belonging to Hurricane Electric(they do global networking and other shit) and it's taking the hit...but why?  



There is some university there but I doubt that's the target.  China wouldn't waste these resources for so long on a university in some no-name town in MO.



My dogs will probably get shot for even posting this.



 
1/2/2015 7:55:43 PM EDT
[#11]
Quote History
Quoted:
I've seen it that bad quite frequently, generally from China.  And yes, St. Louis and Kirksville, MO, tend to get hit quite a bit.
View Quote



what the hell is there that is so interesting?
1/2/2015 7:58:11 PM EDT
[#12]
... almost embarrassing to admit this, but I'm not sure how a DDOS attack works, why is it done, or what the endgame is for the offensive tactics. Would someone here post up a brief primer for dummies like me?
1/2/2015 8:00:58 PM EDT
[#13]

Quote History
Quoted:


... almost embarrassing to admit this, but I'm not sure how a DDOS attack works, why is it done, or what the endgame is for the offensive tactics. Would someone here post up a brief primer for dummies like me?
View Quote


Put simply...they pummel a network with so much data/requests for data that the network is overloaded.  This makes the network unresponsive for anyone trying to legitimately access the network.  The end game is to make it inaccessible for as long as the DDOS is taking place.  Once it's over everything goes back to normal.  They do this to bring down websites, services, etc.



 
1/2/2015 8:01:30 PM EDT
[#14]

Quote History
Quoted:


... almost embarrassing to admit this, but I'm not sure how a DDOS attack works, why is it done, or what the endgame is for the offensive tactics. Would someone here post up a brief primer for dummies like me?
View Quote
Just a ton of computers, or bot computers which are hijacked that hit a target over and over until it goes offline. It can't handle the traffic overload. Any good system can easily defeat it.

 
1/2/2015 8:01:59 PM EDT
[#15]
Isn't Ferguson near there?

Maybe they really Dindu Nuffin?
1/2/2015 8:03:46 PM EDT
[#16]

Quote History
Quoted:



Just a ton of computers, or bot computers which are hijacked that hit a target over and over until it goes offline. It can't handle the traffic overload. Any good system can easily defeat it.  
View Quote View All Quotes
View All Quotes
Quote History
Quoted:



Quoted:

... almost embarrassing to admit this, but I'm not sure how a DDOS attack works, why is it done, or what the endgame is for the offensive tactics. Would someone here post up a brief primer for dummies like me?
Just a ton of computers, or bot computers which are hijacked that hit a target over and over until it goes offline. It can't handle the traffic overload. Any good system can easily defeat it.  


Even a good system can be vulnerable to a big enough attack.  When it comes right down to it, that data has to be processed so traffic can be blocked or passed.



I'm sure what EA, Sony, and Microsoft run are far beyond what you or I would consider good.



 
1/2/2015 8:04:07 PM EDT
[#17]
Bastards had it where I couldn't get on here or surf porn.  I was about to psycho on someone or something.  
1/2/2015 8:04:26 PM EDT
[#18]
Quote History
Quoted:
... almost embarrassing to admit this, but I'm not sure how a DDOS attack works, why is it done, or what the endgame is for the offensive tactics. Would someone here post up a brief primer for dummies like me?
View Quote


1/2/2015 8:07:41 PM EDT
[#19]
that ipviking site is cray cray
1/2/2015 8:08:08 PM EDT
[#20]
Quote History
Quoted:



what the hell is there that is so interesting?
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
I've seen it that bad quite frequently, generally from China.  And yes, St. Louis and Kirksville, MO, tend to get hit quite a bit.



what the hell is there that is so interesting?

I don't know what's in Kirksville, and that has me stumped, too, but I used to do armed security with some interesting clients in the St. Louis area.  Sometimes Federal agencies have offices and other facilities in very nondescript buildings.

St. Louis is also home to the National Personnel Records Center, the US Army Personnel Command, and the National Archives and Records Administration.  I used to live about 300m from the front gate of their co-located facilities.
1/2/2015 8:10:25 PM EDT
[#21]

Quote History
Quoted:





I don't know what's in Kirksville, and that has me stumped, too, but I used to do armed security with some interesting clients in the St. Louis area.  Sometimes Federal agencies have offices and other facilities in very nondescript buildings.



St. Louis is also home to the National Personnel Records Center, the US Army Personnel Command, and the National Archives and Records Administration.  I used to live about 300m from the front gate of their co-located facilities.
View Quote View All Quotes
View All Quotes
Quote History
Quoted:



Quoted:


Quoted:

I've seen it that bad quite frequently, generally from China.  And yes, St. Louis and Kirksville, MO, tend to get hit quite a bit.






what the hell is there that is so interesting?


I don't know what's in Kirksville, and that has me stumped, too, but I used to do armed security with some interesting clients in the St. Louis area.  Sometimes Federal agencies have offices and other facilities in very nondescript buildings.



St. Louis is also home to the National Personnel Records Center, the US Army Personnel Command, and the National Archives and Records Administration.  I used to live about 300m from the front gate of their co-located facilities.


You guys don't know what honey pots are, huh?





 
1/2/2015 8:10:46 PM EDT
[#22]

Quote History
Quoted:





I don't know what's in Kirksville, and that has me stumped, too, but I used to do armed security with some interesting clients in the St. Louis area.  Sometimes Federal agencies have offices and other facilities in very nondescript buildings.



St. Louis is also home to the National Personnel Records Center, the US Army Personnel Command, and the National Archives and Records Administration.  I used to live about 300m from the front gate of their co-located facilities.
View Quote View All Quotes
View All Quotes
Quote History
Quoted:



Quoted:


Quoted:

I've seen it that bad quite frequently, generally from China.  And yes, St. Louis and Kirksville, MO, tend to get hit quite a bit.






what the hell is there that is so interesting?


I don't know what's in Kirksville, and that has me stumped, too, but I used to do armed security with some interesting clients in the St. Louis area.  Sometimes Federal agencies have offices and other facilities in very nondescript buildings.



St. Louis is also home to the National Personnel Records Center, the US Army Personnel Command, and the National Archives and Records Administration.  I used to live about 300m from the front gate of their co-located facilities.
Other than a university I'm not familiar with what might be in Kirksville.  

 



They moved the records center from its Page Ave location up to Dunn Rd in north county off of I-270.
1/2/2015 8:12:49 PM EDT
[#23]
Steam was down for a short while. Valve is located in Seattle WA, which was getting hammered earlier. No idea if there is any correlation.
1/2/2015 8:15:59 PM EDT
[#24]
Check it now. Shit's going crazy.
1/2/2015 8:16:10 PM EDT
[#25]
How come there are rarely any outgoing attacks?






Oh yea, they throw you in jail if you do it here.
1/2/2015 8:16:47 PM EDT
[#26]
1/2/2015 8:21:18 PM EDT
[#27]
Quote History
Quoted:

You guys don't know what honey pots are, huh?

 
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
Quoted:
Quoted:
I've seen it that bad quite frequently, generally from China.  And yes, St. Louis and Kirksville, MO, tend to get hit quite a bit.



what the hell is there that is so interesting?

I don't know what's in Kirksville, and that has me stumped, too, but I used to do armed security with some interesting clients in the St. Louis area.  Sometimes Federal agencies have offices and other facilities in very nondescript buildings.

St. Louis is also home to the National Personnel Records Center, the US Army Personnel Command, and the National Archives and Records Administration.  I used to live about 300m from the front gate of their co-located facilities.

You guys don't know what honey pots are, huh?

 

Yes, I do and what I'm guessing here. Could be .gov or some security company with enticing servers to lure the script kiddies in.

Posted Via AR15.Com Mobile
1/2/2015 8:23:20 PM EDT
[#28]
There was a thread about 2 weeks ago about the Chinese hitting Facebook.
Never did look to see if there was a connection.
1/2/2015 8:25:23 PM EDT
[#29]
holy hell this is cool
1/2/2015 8:27:43 PM EDT
[#30]
Will 'Ctrl Alt Dlt' fix this?

Posted Via AR15.Com Mobile
1/2/2015 8:28:30 PM EDT
[#31]
And what the hell is the Mil/Gov site south of Africa?
1/2/2015 8:30:15 PM EDT
[#32]
Quote History
Quoted:
Will 'Ctrl Alt Dlt' fix this?

Posted Via AR15.Com Mobile
View Quote


No, but 'Ctrl Alt Nuke' will.



1/2/2015 8:38:56 PM EDT
[#33]
Quote History
Quoted:
Just a ton of computers, or bot computers which are hijacked that hit a target over and over until it goes offline. It can't handle the traffic overload. Any good system can easily defeat it.  
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
... almost embarrassing to admit this, but I'm not sure how a DDOS attack works, why is it done, or what the endgame is for the offensive tactics. Would someone here post up a brief primer for dummies like me?
Just a ton of computers, or bot computers which are hijacked that hit a target over and over until it goes offline. It can't handle the traffic overload. Any good system can easily defeat it.  

Go on....
1/2/2015 8:39:37 PM EDT
[#34]
I noticed Steam fucking up with "no authorization" messages when I tried to join certain game servers (Rising Storm).

Those DDOS dutchbags can get fucked.
1/2/2015 8:49:48 PM EDT
[#35]
OST
1/2/2015 8:50:58 PM EDT
[#36]
Quote History
Quoted:
I noticed Steam fucking up with "no authorization" messages when I tried to join certain game servers (Rising Storm).

Those DDOS dutchbags can get fucked.
View Quote

havnt seen that yet
1/2/2015 8:52:21 PM EDT
[#37]
Quote History
Quoted:

Go on....
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
Quoted:
... almost embarrassing to admit this, but I'm not sure how a DDOS attack works, why is it done, or what the endgame is for the offensive tactics. Would someone here post up a brief primer for dummies like me?
Just a ton of computers, or bot computers which are hijacked that hit a target over and over until it goes offline. It can't handle the traffic overload. Any good system can easily defeat it.  

Go on....


Yes... do go on.

Anyway, there are certainly things a datacenter and it's firewalls/routers can do to defend against a DDOS attack, these days DDOS packets are quickly identified, and they're going to get ignored, and won't be allowed further into the system.

However, the various network devices still need to examine all packets at some level on the network to determine if they're the unwanted ones or not. And depending on the wider topology of the Internet leading in and out of the data center, there's going to be upstream and downstream routers and backbones which also could be affected negatively.

It's kind of like if you were getting DDOS'ed through snail-mail and physical letters. You know to shut your mail slot and not let any more letters in, but maybe your front yard is still full of unwanted junk mail, postal carriers, their trucks...
1/2/2015 8:54:05 PM EDT
[#38]
It's for the Dindus.
1/2/2015 8:57:13 PM EDT
[#39]
My server has been getting pounded with China IP's the past couple of weeks.

Here is an example from /var/log/messages

Jan  2 18:27:23 (none) auth.err sshd[15703]: error: Could not get shadow information for root
Jan  2 18:27:23 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15698]: Failed password for root from 122.225.97.74 port 55833 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:25 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:25 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:26 (none) auth.err sshd[15725]: error: Could not get shadow information for root
Jan  2 18:27:26 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:26 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:27 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:27 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:27 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:28 (none) auth.err sshd[15733]: error: Could not get shadow information for root

Whois of 122.225.97.74

General Information
IP Address: 122.225.97.74
Hostname:122.225.97.74
Country: CN
AS:4134
AS Name: CHINANET-BACKBONE No.31,Jin-rong Street,CN
Network: 122.224.0.0/12 (122.224.0.0-122.239.255.255) 122.240.0.0
Reports:79430
Targets:29027
First Reported:2014-10-12
Most Recent Report:2015-01-02

Fuckers
1/2/2015 9:00:27 PM EDT
[#40]
Checking in from Saint Louis ground zero.

I have been told by people that Google has servers in Kirksville... how accurate that is I don't know. Saint Louis is also the operations center for Mastercard, don't know if that has any bearing or not either.

Edit: And for those who don't know Kirksville MO is north central in the state... a good drive outside of Saint Louis. The two places are not really in the same area per se.

Also ARFCOM has been kludgy as fuck for me for a few weeks now. Slow to load, failures to load, you name it... but every other website I visit is perfectly fine. It started with my iPad not wanting to load ARFCOM and now my desktop is having problems with it as well... and no it isn't pornvirus.
1/2/2015 9:00:50 PM EDT
[#41]
And of course, it's not even necessarily "China" that's doing it. Could be that China just has the largest population of poorly secured PC's and servers that have been harvested as bots.
1/2/2015 9:02:06 PM EDT
[#42]
Quote History
Quoted:


Someone going after Boeing maybe? Don't they also have a big presence in St.L?
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
Somebody from China sure has a hardon for St Louis right now.


Someone going after Boeing maybe? Don't they also have a big presence in St.L?


That's what I'm thinking.
1/2/2015 9:10:16 PM EDT
[#43]

Quote History
Quoted:


Will 'Ctrl Alt Dlt' fix this?



Posted Via AR15.Com Mobile
View Quote


Nah you want to Alt F4.  
 
1/2/2015 9:13:30 PM EDT
[#44]
Quote History
Quoted:
My server has been getting pounded with China IP's the past couple of weeks.

Here is an example from /var/log/messages

Jan  2 18:27:23 (none) auth.err sshd[15703]: error: Could not get shadow information for root
Jan  2 18:27:23 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15698]: Failed password for root from 122.225.97.74 port 55833 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:25 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:25 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:26 (none) auth.err sshd[15725]: error: Could not get shadow information for root
Jan  2 18:27:26 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:26 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:27 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:27 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:27 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:28 (none) auth.err sshd[15733]: error: Could not get shadow information for root

Whois of 122.225.97.74

General Information
IP Address: 122.225.97.74
Hostname:122.225.97.74
Country: CN
AS:4134
AS Name: CHINANET-BACKBONE No.31,Jin-rong Street,CN
Network: 122.224.0.0/12 (122.224.0.0-122.239.255.255) 122.240.0.0
Reports:79430
Targets:29027
First Reported:2014-10-12
Most Recent Report:2015-01-02

Fuckers
View Quote



echo "block in quick from 122.224.0.0/12" >> /etc/ipf/ipf.conf && svcadm restart pfil ipf

Any time I see an attack in my logs, I whois, and if it's from APNIC...I block the whole network. I'm pretty much at the point where I'm just going to block China entirely, full stop.
1/2/2015 9:14:05 PM EDT
[#45]
Quote History
Quoted:
That would explain battlenet being down all day
View Quote


came to post.
1/2/2015 9:14:54 PM EDT
[#46]
I'm not sure what's happening now on that site, but it doesn't look good for Clifton, USA.    Geez.
1/2/2015 9:23:24 PM EDT
[#47]
Thats a pretty cool map.

I didn't realize switerzland hosted so many attacks.
1/2/2015 9:29:46 PM EDT
[#48]
Quote History
Quoted:



echo "block in quick from 122.224.0.0/12" >> /etc/ipf/ipf.conf && svcadm restart pfil ipf

Any time I see an attack in my logs, I whois, and if it's from APNIC...I block the whole network. I'm pretty much at the point where I'm just going to block China entirely, full stop.
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
My server has been getting pounded with China IP's the past couple of weeks.

Here is an example from /var/log/messages

[snip]

Fuckers



echo "block in quick from 122.224.0.0/12" >> /etc/ipf/ipf.conf && svcadm restart pfil ipf

Any time I see an attack in my logs, I whois, and if it's from APNIC...I block the whole network. I'm pretty much at the point where I'm just going to block China entirely, full stop.


This is pretty solid advice here, and my SOP for the past few years. China could drop off the internet completely and I wouldn't give a single fuck.
1/2/2015 9:30:55 PM EDT
[#49]
Boeing Defense, Space and Security is in St. Louis



tinfoil.jpeg
1/2/2015 9:31:09 PM EDT
[#50]
Quote History
Quoted:



echo "block in quick from 122.224.0.0/12" >> /etc/ipf/ipf.conf && svcadm restart pfil ipf

Any time I see an attack in my logs, I whois, and if it's from APNIC...I block the whole network. I'm pretty much at the point where I'm just going to block China entirely, full stop.
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
My server has been getting pounded with China IP's the past couple of weeks.

Here is an example from /var/log/messages

Jan  2 18:27:23 (none) auth.err sshd[15703]: error: Could not get shadow information for root
Jan  2 18:27:23 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15698]: Failed password for root from 122.225.97.74 port 55833 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:24 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:25 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:25 (none) auth.info sshd[15703]: Failed password for root from 122.225.97.74 port 56230 ssh2
Jan  2 18:27:26 (none) auth.err sshd[15725]: error: Could not get shadow information for root
Jan  2 18:27:26 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:26 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:27 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:27 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:27 (none) auth.info sshd[15725]: Failed password for root from 122.225.97.74 port 57401 ssh2
Jan  2 18:27:28 (none) auth.err sshd[15733]: error: Could not get shadow information for root

Whois of 122.225.97.74

General Information
IP Address: 122.225.97.74
Hostname:122.225.97.74
Country: CN
AS:4134
AS Name: CHINANET-BACKBONE No.31,Jin-rong Street,CN
Network: 122.224.0.0/12 (122.224.0.0-122.239.255.255) 122.240.0.0
Reports:79430
Targets:29027
First Reported:2014-10-12
Most Recent Report:2015-01-02

Fuckers



echo "block in quick from 122.224.0.0/12" >> /etc/ipf/ipf.conf && svcadm restart pfil ipf

Any time I see an attack in my logs, I whois, and if it's from APNIC...I block the whole network. I'm pretty much at the point where I'm just going to block China entirely, full stop.


I download this chinese-blocklist and add it to iptables daily.
I use this to parse the log files.
awk '($(NF-7) = /invalid user/){print $(NF-3)}' /var/log/messages.0 | sort | uniq -c | sort
Previous Page
/ 2
Next Page

[ARCHIVED THREAD] - DDOS, anyone? (Page 1 of 2)