CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 927
Comments: 25
block bottom
spacer spacer

March 26: Genesis of an attack on CastleCops
Goto page Previous  1, 2
 
Post new topic   Reply to topic       All -> FavForums -> DDoS [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Coldmoon

Returnil
Premium Member

Joined: Sep 30, 2006
Posts: 148
Location: USA
Premium

PostPosted: Fri Mar 28, 2008 5:33 pm    Post subject:
Reply with quote

Paul wrote:
The attack continues... hopefully false positive blocks are kept to a minimum.


Thumbs Up

Have not noticed any issues except for a breif 20 minute period when the attack began. The site still loads faster than before the migration Wink

Well done and thanks for the great work

Mike

Back to top
View users profile Send private message Visit posters website
StopDDoS

Trooper
Trooper


Joined: Oct 02, 2007
Posts: 34
Location: USA

PostPosted: Fri Mar 28, 2008 5:54 pm    Post subject:
Reply with quote

seems fine to me, anymore IPs

Back to top
View users profile Send private message
spy1

Major
Major
Premium Member

Joined: Nov 20, 2002
Posts: 964

Premium

PostPosted: Fri Mar 28, 2008 6:06 pm    Post subject:
Reply with quote

Paul - There's nothing coming out of my immediate netrange ( NetRange: 68.208.0.0 - 68.223.255.255 ) that I can see from the list you posted, so I can't help you by reporting any of them this time.

If you have anything from there, let me know and I'll report them. Pete

Back to top
View users profile Send private message AIM Address Yahoo Messenger
Woody

Captain
Captain


Joined: Mar 09, 2002
Posts: 380


PostPosted: Fri Mar 28, 2008 8:50 pm    Post subject:
Reply with quote

Loads Ok once you are in the front door..nothing in my range to report.

Back to top
View users profile Send private message
Woody

Captain
Captain


Joined: Mar 09, 2002
Posts: 380


PostPosted: Fri Mar 28, 2008 8:50 pm    Post subject:
Reply with quote

Loads Ok once you are in the front door..nothing in my range to report.

Laughing but seems double postings has infected me with one click.

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27348

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri Mar 28, 2008 10:51 pm    Post subject:
Reply with quote

http://www.darkreading.com/document.asp?doc_id=149497

I'll try to post some IPs soon.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
newangels

Corporal
Corporal


Joined: Sep 06, 2007
Posts: 66


PostPosted: Fri Mar 28, 2008 11:40 pm    Post subject:
Reply with quote

The site is fast for me so they are not doing a good enough job, great work Paul

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2516

Premium

PostPosted: Sat Mar 29, 2008 12:24 am    Post subject:
Reply with quote

Their attack gives us encouragement to keep doing what we're doing, brings more publicity for the work we do, and barely slows the site down at all. As a DDoS, it's a failure all around.

Back to top
View users profile Send private message
newangels

Corporal
Corporal


Joined: Sep 06, 2007
Posts: 66


PostPosted: Sat Mar 29, 2008 11:11 am    Post subject:
Reply with quote

The stupidity of these people never ceases to amaze me.

They like all invaders forget, that there are always people that will one day Say ENOUGH, and then the fight begins, for us its digital, and a good fight it always worth the changes it will bring.

Back to top
View users profile Send private message
Tigger_bouncy_peep

Cadet
Cadet


Joined: Mar 29, 2008
Posts: 1
Location: UK

PostPosted: Sat Mar 29, 2008 12:14 pm    Post subject: Re: March 26: Genesis of an attack on CastleCops
Reply with quote

Paul wrote:
Looks like we're at the beginning of a new denial of service attack against www.castlecops.com. I'm currently investigating and mitigating. As this seems to be the start of an attack, there is the potential for it to increase.


Just joined after picking up on a new HSBC phishing site that is currently live and not flagged up by Site Advisor yet ( reported to them ).

The more of us that do this reporting the better - I always check these out as they come in and this one seems particularly bad !!

BTW - I agree with the other post in here .... you are rattling cages which shows what you are doing is working, keep it up Very Happy

Back to top
View users profile Send private message
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 83
Location: Uk

PostPosted: Sat Mar 29, 2008 9:57 pm    Post subject:
Reply with quote

DDoS? What DDoS? Smile A weedy one, went unnoticed here!

Oh dear, spammers, feel that jail-time a-comin...

Back to top
View users profile Send private message
seafsee

General
General
Premium Member

Joined: Apr 02, 2004
Posts: 4898

Premium

PostPosted: Sun Mar 30, 2008 1:26 pm    Post subject:
Reply with quote

I've noticed that the green banner across the top of the page is now gone. Does this indicate the attack is for now over?

I was also wondering if the attack had anything to do with recently banned members (of which I count a minimum of three)?

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 958
Location: USA

PostPosted: Mon Mar 31, 2008 5:55 pm    Post subject:
Reply with quote

I'm not sure what happened, but I think my IP address at home (i'm on campus right now, posting fine...) may have landed in a firewall or blocklist somewhere?

Any possibility of checking this? Smile It should be a HellSouth/ATT IP address. Check some of my past posts (from around March 26 and March 27) to grab the IP, it doesn't change too often.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27348

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Mon Mar 31, 2008 7:46 pm    Post subject:
Reply with quote

Yes it was blocked... now cleared.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 958
Location: USA

PostPosted: Mon Mar 31, 2008 8:55 pm    Post subject:
Reply with quote

That was quick, Thanks Paul Smile

Did you get the PM regarding the CastleCops Wiki? Smile

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> DDoS All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer