CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image RoadRunner DDoS's CastleCops.com right now image
Email Hassles!
castlecops/roadrunner/pearl harbor fcu debacle

RoadRunner started attacking us with a DDoS targetting our MX. Unsure exactly when the DDoS against our MX started, but it began approximately 2-3 hours ago. A spammer targetted RR customers this evening with the Pearl Harbor FCU phish. Here is the email header:

Received: from smtp20.orange.fr (HELO smtp-msa-out20.orange.fr)
([80.12.242.27])
by clmboh-mx-05.mgw.rr.com with ESMTP; 24 Nov 2006 18:44:23 -0500
Received: from User (LNeuilly-152-21-126-197.w193-253.abo.wanadoo.fr
[193.253.213.197])
by mwinf2007.orange.fr (SMTP Server) with SMTP id 652621C000C8;
Sat, 25 Nov 2006 00:40:09 +0100 (CET)

The From: address is hservice@castlecops.com.


US-CERT does not have a contact at RR. One of our staff contacted RR customer service and made it known they are attacking our MX by issuing bounces:

The following message to <hixgzzl@hawaii.rr.com> was undeliverable.
The reason for the problem:
5.1.0 - Unknown address error 550-'5.1.1 unknown or illegal alias:
hixgzzl@hawaii.rr.com'

So far I've uncovered the following RR blocks sending these bounce backs:

24.28
65.24
66.75

RR said because we are not a customer, they are denying us service. The DDoS continues.

Contacted my ISP. He initially filtered those three blocks (moments ago). Then decided to filter on the hservice@castlecops.com To:. My ISP has bouncing back to RR saying they are spamming us, and to contact them immediately.

The same staffer above who called RR also was told we should email security@. It would hit the general queue and someone would eventually get to it.

So the firewall is blocking this RoadRunner DDoS, but it continues nonetheless.

FWIW, the phish link goes to http://cha.powweb.com/phfcu/login.htm.
Posted on Friday, 24 November 2006 @ 21:45:07 UTC by Paul (3840 reads)
[ Trackback ]
image

"RoadRunner DDoS's CastleCops.com right now" | Login/Create an Account | 2 comments | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: RoadRunner DDoS's CastleCops.com right now (Score: 1)
by Cudni  on Friday, 24 November 2006 @ 21:53:30 UTC
(User Info | Send a Message) http://www.dslreports.com/forum/security,1
just what you want to be doing on a weekend ...Not



 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· W3 Consortium
· Spam Cop
· More about Email Hassles!
· News by Paul


Most read story about Email Hassles!:
SORBS and bad Internet Providers out to destroy EMail.

block bottom
Article Rating
spacer
Average Score: 5
Votes: 2


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer