Six charged in mass takedown of DDoS-for-hire sites
krebsonsecurity.com
krebsonsecurity.com
But looking at the FBIs sophisticated analysis… it looks like the went to a clear web domain name, put in their credit card number, asked them to do an illegal thing, they did the illegal thing, and then they charged the owners of the domain. From my outside view, it looks like the FBI allowed DDoS as a Service providers to operate in public for at least a decade. Talking this up like it was hard work isn’t landing like they think it is.
To do that it sounds like they may advertise themselves on the dark web as an attack web site. They also don't bother to verify ownership of a target, like checking domain ownership for example is probably the most common use case here. They also use other people's mis-configured devices to amplify their attack. That last part is particularly salient I think.
It's very stupid to advertise yourself on the dark web for this if you host a site on the clear web. But you are probably right that LE lets this goes on for longer than it needs to. I don't know how long they have known about these sites or how they go about finding them. It sounds like it's just based on victim's sending in reports.
There's an incredibly limited amount of people working in cyber crime. Building a case, getting subpoenas takes a lot of effort. Even if something may be obvious to outsiders, building a case might still take a lot of effort. Those scarcely available people are usually put on the highest priority cases first. What they are, you might never know.
Then, if there's a network behind it you want to take down instead of only the fronts, you need to spend way more time on case building, writing, interacting with other agencies and I can go on.
Source: worked in the field.
The FBI has no problem spending tax payer money on criminal activities: drug buys, etc. They'll (hopefully) recover it from seized funds, otherwise its just part of their budget.
That being said, I wonder if these services are actually the limiting factor here. There is probably some zero-sum game here, with a fixed quantity of exploitable booter hosts available and all the providers vying for control of these. Shutting down a set of providers would then just make others more powerful.
Honestly, this part is pretty funny on its own. Approximately nobody actually uses these services to test their own networks, and I'm sure the site operators are perfectly aware of that.
I worked for the company, I was not the decision maker. Many of us have worked at companies where decisions are made that are questionable or unethical, sometimes even illegal (although I don't believe this would have been illegal in my country at the time).
That worked approximately as well as you would imagine.
25 years later some guy at a party was telling me this last month. It's amazing how this silly myth persisted.
What a bunch of super-geniuses.
Just look at the ADs to these sites that are super flashy and cool to cater to these teens
Edit: Example ADs: https://i.imgur.com/PjqG7dC.gif https://i.imgur.com/ebp4ERm.gif https://i.imgur.com/kTM3fAA.gif
Because of this, a lot of games companies will try to mask the actual IP of the other users now, and Steam has tooling for games they support for devs on their platform.
99% of ddos attacks aren't that serious
https://www.hackread.com/15-years-prison-for-man-who-hired-a...
Our small company's site got DDoSed a month ago and we just let it pass since we're not too convinced that the authorities will take us seriously. We don't even know where to start, just saved the logs with a few hundred random IPs from different countries hoping some day we can do something about it...
From my experience they will get back to you quickly (usually in <1-2 hour) and they can try helping out if you are still under attack / need some consultation.
Will we ever get compensated for the wasted engineering time to stop these attacks? probably not, but if the police ever finds them and they have extra logs of companies that reported issues, its likely an aggravation of the case.
Oh my, the attack caused so much wasted time and stress that it's still haunting me and the team, specially when thinking that it may not stop there and the attacker/s is just waiting for the next chance to hit us. The days after the attack the first thing I did after waking up was check the servers to see everything was safe. And our roadmap was severely affected too, prioritizing many security features we had in the backlog.
Thank you so much.
Regarding security features, if you are on a cloud such as GCP, AWS or Azure things are complicated since you can't easily route the traffic elsewhere(you can have BGP connections to DDoS mitigation inside GRE/L2TP tunnels only when attacks occur and it would be cheap to rent on a monthly/yearly basis). Voxility is an example that comes to mind and they are very affordable in general terms.
HTTP or HTTPs attacks are easier to handle with Cloudflare, however, there are other interesting solutions such as Stackpath.
I realize we were lucky that the attacker didn't find any of the soft spots (or at least none that hurt us). We do prioritize security though, always.
I hope all goes well for you and that in time this is just another learning experience. Maybe next time you'll smile when an attack is thwarted because of what you've all learned.
Both require tweaking and are far from being 1-click setup tools (despite some marketing attempts that try to make it seem that way), however, if you can manage them, they are very powerful and considerably cheaper than other alternatives.
It helps if you have a suspect, typically your local LE will have a cyber division that will know what the next steps are.
Thank you!
So perhaps the next wave of booter sites can avoid scrutiny by adding a dialog asking the customer if they own the target or are authorized to attack it (in addition to not publishing ads advertising targets like websites and game servers) ?
Also keep in mind that a DDoS affects infrastructure on the way whose operators have not consented.
I don't really think there's an ethical way to run a DDoS "stresser" service on the public Internet.
That should work.
The only way I can think around that would be to have a reverse proxy that forwards most traffic but not requests for that one file, but then your DDoS isn't actually distributed.
I create my own SharedPHPHosting site, host the file, and point the stress testing site at it. Both my site and my victim's site are down. Success.
I believe "neocities" uses the same IP and servers for all neocities websites, so there's another example where this would work.
2. Hurt your competition. In some online businesses DDoS attacks are used to compete with other businesses since if your competitor is offline more people will come to you.
3. Power. Some people want to flex the power they have over others.
4. Fame. You can get notoriety for taking something offline.
Dont like what a site is saying? DDOS so it cant load and people cant read it. For bonus points you are preventing site from getting clicks and thus ad revenue.
There are communities on discord that setup donation links to make sure sites they dont like keep getting hit by DDOS via crowdfunding.
Evil haxxxor: creates domain name pointed at target it doesn’t own
Innocent stress test site: prove you own this domain by adding cname in the DNS record
EH: sure, heh heh heh
ISTS: performs ddos against target
Requiring the owner to post a file at a specific URL would prove actual control of the server in a way that domain records don't. I can point a domain at whatever server I want, no need for it to be my own.
Typically a service using domain verification will ask you to create a specific, randomly generated TXT or similar record on your domain. After you’ve created the record you click a button or something and they do a query for it.
Only someone with access to DNS for the domain can create such a record.
Suppose:
EXAMPLE.VICTIM.XYZ -> A 1.2.3.4
EXAMPLE.ATTACKER.XYZ -> A 1.2.3.4
EXAMPLE.ATTACKER.XYZ -> TXT whatever verification is needed
DDoSes operate on IPs, not dns names. In the end, the target IP is getting DDoSed anyway.Yes, of course DDoS or any kind of traffic can be pointed at an IP or any arbitrarily created DNS record.
The only way for a “reputable” stress testing platform to validate IP space would be RIR validation via WHOIS or similar, PTR records, etc. Of course this isn’t practical because most people don’t control their IP space or even have the foggiest idea what any of that means (because why should they).
That's why OP specified their DNS record. You buy/use a random domain name you own, point the A record at the IP you wish to attach, and then simply complete the TXT record verification since you have full control over the domain, while the booter resolves the A record to the true target.
No, most (?) DDoS attacks aren’t botnets sending HTTP requests directly, those would have terrible throughput and be trivial to mitigate. Instead they use amplification from third party servers where you send a small packet to get a big packet in response, mistakenly routed to the victim. There’s usually no way to attach a Referer to those, most of which aren’t even HTTP-based.
How else do you imagine this working?
The company I work for actually contemplated creating such a service (strictly for testing purposes, which is our business), and one of the major problems was that we would actually need to have contracts with all ISPs and transit providers that the traffic would pass through, even if we could make sure that the destination was owned by whoever was paying for the test.
42. Finally, many of the booter services also use DDoSprotection services,3 such as those provided by the company Cloudflare (a company headquartered in the United States). While Cloudflare offers both paid and free services, the operator of one of the SUBJECT DOMAINS, bootyou.net paid Cloudflare for services relating to the operation of their website.I get that there are anti-piracy lobbies. I get that if you piss off enough companies they're going to put heat on you (see: this). But there are dozens of copycats of Ruben Rosales (https://www.justice.gov/usao-az/pr/mexican-national-sentence...) and they are truly awful people.
Honestly, one weird/humorous/sad thing I've noticed is that -- for purposes of "what is actually censored," messing around with celebrity images is often literally the worst thing you can do, ostensibly worse than violence, racism, etc.
Anyone know why so many cybercrime prosecutions happen out of Alaska? I know at least Mirai, Kelihos, and some Mirai clones were all charged in District of Alaska.
How many "stressers" do you think the feds don't have time or motivation to care about getting subpoenas for? Because I can guarantee you there are more than the "four dozen" taken down here, and the vast majority have their identities and infrastructure protected by Cloudflare -- who also profits from their existence.
Cloudflare gets the low-integrity prize.
(That type of bug bounty policy is how you get folks hording them for a cold winter rather than disclosing them to vendors.)
But man, the defendants, how can you be dumb enough to run something like this from US soil, like you're not going to end up in a cage?
Aus had a problem with the census site where everyone logged in at 5-6pm on the census date. So like millions at once.
Are there tools to stress test and build graphs about responsive times and such?
https://www.justice.gov/usao-cdca/pr/illinois-man-sentenced-...
Actually Krebs wrote about his sentence at the time: https://krebsonsecurity.com/2022/06/downthem-ddos-for-hire-b...
(I'm not a lawyer, I've just got the sentencing guidelines hotkeyed).
The scale for financial loss is really weird. $150k will get you 10 points. $1.5MM will get you 16 points. $550MM will get you 30 points. https://guidelines.ussc.gov/gl/%C2%A72B1.1
If you do the actual exercise of picking out a realistic loss number and doing the calculation, you'll find that the 2B1.1 loss table dominates the sentence.
I think SBF is in deep shit and I think the world is better for it. These guys? I don't know, probably not as deep as it looks; certainly not the 10 years that another poster was saying, though.
SBF will serve something close to life if convicted because the losses he incurred blow out the guidelines table.
The DDoS'ers will serve something scaled to the amount of losses they actually caused. I think $1MM is a reasonable ballpark, which gets you into the high single digit years.
That table looks like an attempt at a log scale, that's been distorted by wanting round numbers.
They're probably going to plea, and their plea will probably not be to wire fraud. They probably all have low criminal history scores.
Here's a similar situation where the guy lost at trial: https://krebsonsecurity.com/2022/06/downthem-ddos-for-hire-b...
If these kids plea — and they probably will — they'll probably get 1-2 years + 3 years probation if that. Their lawyer will bring up the comparable at sentencing and the judge will consider it.
This obviously did not help Ross Ulbricht.
Mirai authors - Home confinement
Peter Levashov - Time served (33 months)
Fabio Gasperini - 1 year
Maxim Senakh - 4 years
Marcus Hutchins - No prison
Sergey Vovnenko - 41 months
Aleksei Burkov - 9 years, released after 3.5 due to some sort of diplomatic intervention
Andrii Kolpakov - 7 years
Nikita Kuzmin - Time served
Karim Baratov - 5 years
Ruslan Bondars - 14 years but he went to trial, lost, and had a loss amount of $20 billion attributed to him
Shame it had to go this way