CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

CastleCops under DDoS and what we did
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8, 9  Next
 
Post new topic   Reply to topic       All -> FavForums -> General Site [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ShadowPuterDude

Trooper
Trooper
Premium Member

Joined: Oct 21, 2006
Posts: 27

MVP Premium

PostPosted: Tue Feb 20, 2007 3:24 am    Post subject:
Reply with quote

Good to have CC back. That was quite a DDoS.


_________________
Microsoft MVP Consumer Security 2007-2008
Member - Alliance of Security Analysis Professionals - Since 2006
Back to top
View users profile Send private message Visit posters website
LilBambi

Trooper
Trooper


Joined: Feb 23, 2005
Posts: 12
Location: USA

PostPosted: Tue Feb 20, 2007 2:27 pm    Post subject:
Reply with quote

So glad to have CC back! It had been intermittent even last night, so it was great to get in first time today.


_________________
"When the people find they can vote themselves money, that will herald the end of the republic." Benjamin Franklin
Back to top
View users profile Send private message Visit posters website
Bill_Bright

General
General
Premium Member

Joined: Jan 16, 2004
Posts: 8930
Location: Nebraska, USA
MVP Premium

PostPosted: Tue Feb 20, 2007 3:00 pm    Post subject:
Reply with quote

LilBambi wrote:
So glad to have CC back! It had been intermittent even last night
This morning too, but now I can consistently get on, but it is still a little sluggish.

Search is still a problem. The search window comes up in good time, but getting results (last 2 weeks of posts for user name) can take many minutes.

1. 145ppm Engine
ALL(207.249s) phpbb(206.318s) SQL(205.888s) FUNC(0.015s) MARKER(0.345s) GT(0.578s) PT(0s)

2. 101ppm Engine
ALL(95.969s) phpbb(92.567s) SQL(95.159s) FUNC(0.013s) MARKER(0.136s) GT(3.260s) PT(0s)

3. 39ppm Engine
ALL(88.550s) phpbb(86.414s) SQL(85.935s) FUNC(0.026s) MARKER(0.278s) GT(1.820s) PT(0s)

4. 160ppm Engine
ALL(148.100s) phpbb(147.234s) SQL(146.618s) FUNC(0.013s) MARKER(0.426s) GT(0.434s) PT(0s)

5. 51ppm Engine
ALL(346.714s) phpbb(345.721s) SQL(344.94s) FUNC(0.023s) MARKER(0.082s) GT(0.884s) PT(0s)


_________________
image Bill (AFE7Ret)
Freedom is NOT Free!

image
Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Tue Feb 20, 2007 3:19 pm    Post subject:
Reply with quote

We transitioned to a temp mysql server so we're fine tuning. This one is only for a day or so.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Bill_Bright

General
General
Premium Member

Joined: Jan 16, 2004
Posts: 8930
Location: Nebraska, USA
MVP Premium

PostPosted: Tue Feb 20, 2007 4:39 pm    Post subject:
Reply with quote

Sounds good. I seem to connect 3 out of 4 times - and I note that the flag in my sig appears correctly about half the time - seems to hang on "downloading picture".


_________________
image Bill (AFE7Ret)
Freedom is NOT Free!

image
Back to top
View users profile Send private message
PcPitWademan

Corporal
Corporal


Joined: Apr 30, 2006
Posts: 74
Location: USA

PostPosted: Tue Feb 20, 2007 4:40 pm    Post subject:
Reply with quote

Paul an Robin.. great job! great site.period! Wink

Back to top
View users profile Send private message
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4637
Location: USA

PostPosted: Tue Feb 20, 2007 5:39 pm    Post subject:
Reply with quote

In the news at The Register:

- http://www.theregister.com/2007/02/20/castlecops_ddos/
20 February 2007 ~ "...The motives of the attack are unclear, though it's reasonable to assume the phishing fraudsters or malware authors, who have most to gain from the inavailability of Castecop's website, are the likely perpetrators. Castlecops has become the latest target in a string of attacks targeting organisations looking to frustrate the efforts of phishing fraudsters, spammers, or other internet pond life. Veteran spam fighter Spamhaus suffered a denial of service attack last September, for example, while an attack by a rogue spammer brought down anti-spam firm Blue Security in April 2006. According to Blue Security, a renegade Russian language speaking spammer known as PharmaMaster succeeded in bribing a staff member at a top-tier ISP into black-holing Blue Security's former IP address at internet backbone routers."

Exclamation


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
Bill_Bright

General
General
Premium Member

Joined: Jan 16, 2004
Posts: 8930
Location: Nebraska, USA
MVP Premium

PostPosted: Tue Feb 20, 2007 5:49 pm    Post subject:
Reply with quote

Quote:
According to Blue Security, a renegade Russian language speaking spammer known as PharmaMaster succeeded in bribing a staff member at a top-tier ISP into black-holing Blue Security's former IP address at internet backbone routers.


Shocked Bribe?


_________________
image Bill (AFE7Ret)
Freedom is NOT Free!

image
Back to top
View users profile Send private message
hansBF

Blue Angel
Premium Member

Joined: May 03, 2006
Posts: 269
Location: USA
Blue Security Premium Team F@H

PostPosted: Tue Feb 20, 2007 6:06 pm    Post subject:
Reply with quote

Bill_Bright wrote:
Quote:
According to Blue Security, a renegade Russian language speaking spammer known as PharmaMaster succeeded in bribing a staff member at a top-tier ISP into black-holing Blue Security's former IP address at internet backbone routers.


Shocked Bribe?


Yes, that was the word from a reliable source.

Hans


_________________
Websplasher website design. Design with a splash.
Back to top
View users profile Send private message Visit posters website
nv1962

Sergeant
Sergeant
Premium Member

Joined: Jan 30, 2007
Posts: 120
Location: Reno, NV, USA
Premium

PostPosted: Tue Feb 20, 2007 6:15 pm    Post subject:
Reply with quote

What can I say other than I'm darn glad that CastleCops is approaching that bright spot at the end of the tunnel, that I'm impressed and appreciative of Prolexic's generosity in times of need, and that I hope you guys get into a near-Tempest class robust cage?

Keep it up Mr & Mrs CastleCops. As I said elsewhere, you're not alone in this. Frankly, I'm beginning to see the benefits of open distributed content server platforms at this point... Kinda like applying ju-jitsu on DDoS and reverting the gun as a defense.

But enough of that. How about a little bit of good news from the phishing front to add a bright spot?

PS: Technorati apparently shows some actual results for blog entries with a CastleCops tag. Twisted Evil

Back to top
View users profile Send private message Visit posters website
Bill_Bright

General
General
Premium Member

Joined: Jan 16, 2004
Posts: 8930
Location: Nebraska, USA
MVP Premium

PostPosted: Tue Feb 20, 2007 6:45 pm    Post subject:
Reply with quote

hansBF wrote:
Bill_Bright wrote:
Shocked Bribe?


Yes, that was the word from a reliable source.

Hans
Hmmm, thanks Hans, I had not heard that. I think that's funny actually - it demonstrates he is nothing more than lowly scumbag who had to digress to an ancient, wholly non-technical, unsophisticated tactic of bribing the poor gate-watcher. Figures. Laughing Rolling on the floor laughing...


_________________
image Bill (AFE7Ret)
Freedom is NOT Free!

image
Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Feb 20, 2007 8:49 pm    Post subject:
Reply with quote

Bill_Bright wrote:
Shocked Bribe?


AFAIK, that was alleged, but went no further in terms of any kind of demonstration or proof of it's veracity. I don't recall Blue Security ever publicly confirming the allegation either.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
hansBF

Blue Angel
Premium Member

Joined: May 03, 2006
Posts: 269
Location: USA
Blue Security Premium Team F@H

PostPosted: Tue Feb 20, 2007 10:18 pm    Post subject:
Reply with quote

There are times when we are confronted with information that challenges our notions of how the world should work. I don’t really want to encourage hijacking this thread which is supposed to be about Castlecops. Here is just one such report published on the web at the time: http://www.theregister.co.uk/2006/05/17/blue_security_folds/ . There were others, some more directly attributed. I can't prove the allegation. However, I do not believe that Blue Security was in the business of deliberately putting out false information. I don’t have the time to look for those and am not sure just how productive that would be. As one who was close to the action, I believe that it happened. Others are free to draw their own conclusions.

Hans


_________________
Websplasher website design. Design with a splash.
Back to top
View users profile Send private message Visit posters website
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Feb 20, 2007 10:34 pm    Post subject:
Reply with quote

I wasn't suggesting anything at all, just commenting that the allegation, true or not, laked anything substantive in the way of proof of veracity. I was a devoted BFer also, and appreciate greatly what they were trying to do, so don't misunderstand that. But it is dangerous to give credence to rumor and innuendo lacking anything more substantive than a couple of news articles with statements attributed but not verified.

When you fight a war, it is far better to deal from verifiable intelligence that you can rely upon, then subscribe to logical, but unproven, suspicions.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16509

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Tue Feb 20, 2007 10:40 pm    Post subject:
Reply with quote

.. for example in this case, enough verifiable intelligence in the form of forensic evidence to put the DDoS ingrate(s) in the slammer! Twisted Evil

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> General Site All times are GMT
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8, 9  Next
Page 4 of 9

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer