Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-21 Thread Luther Blissett
Hello once more! I was just one step away from seppuku when I remembered I've already asked sillier questions that went unpunished... :D Thank you for your time. It would have taken me some weeks at least to figure out that this hex was no mystery at all to the trained eye. I'm also a lot less wo

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-19 Thread Jordon Bedwell
On Sun, Aug 18, 2013 at 3:56 PM, wrote: > (a) Because 75% of the Internet doesn't allow spoofing of source addresses, > and (b) Although there's a chance that one machine throwing 3,000 SYN > packets a second will show up on somebody's network monitor, you're never > going to see 3,000 network mo

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-19 Thread Daniel Corbe
Not very subtle, but effective. Because you know the alternative would be to pick up the phone and call them. Stefan Jon Silverman writes: > Can I have my mid-90's ping-of-death back??? was incredibly useful for getting > people (on internal corporate networks) to call the helpdesk when their

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-19 Thread Alex
fragmented icmpv6 if they use windows Am 2013-08-19 06:35, schrieb Stefan Jon Silverman: > Can I have my mid-90's ping-of-death back??? was incredibly useful for > getting people (on internal corporate networks) to call the helpdesk when > their desktops were going DNS-crazy or otherwise sh

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-18 Thread Stefan Jon Silverman
Title: Message Can I have my mid-90's ping-of-death back??? was incredibly useful for getting people (on internal corporate networks) to call the helpdesk when their desktops were going DNS-crazy or otherwise showing up in other log-files after doing strange thing

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-18 Thread coderman
On Sun, Aug 18, 2013 at 1:56 PM, wrote: > ... > Near as I can tell, they've stopped teaching Evil 101 to the newbies. Doesn't > anybody spend any time anymore thinking about "Wow, if I'm going to attack > this site, what can I do to maximize the pain per packet?" Hi Valdis! We miss you too! Ca

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-18 Thread Valdis . Kletnieks
On Sun, 18 Aug 2013 10:04:58 +0200, Jann Horn said: > On Sat, Aug 17, 2013 at 07:50:34PM -0400, valdis.kletni...@vt.edu wrote: > > Not all DDoS are pure bandwidth based. Consider SYN flooding, where the > > packets sent are relatively small and often not even all that frequent, but > > can > > ti

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-18 Thread Jann Horn
On Sat, Aug 17, 2013 at 07:50:34PM -0400, valdis.kletni...@vt.edu wrote: > On Sat, 17 Aug 2013 13:39:16 +0200, Jann Horn said: > > > And yes, you're right, a DoS attack can be unsuccessful. My point was that > > this small amount of traffic shouldn't be called a DDoS because there's no > > way tha

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-17 Thread Valdis . Kletnieks
On Sat, 17 Aug 2013 13:39:16 +0200, Jann Horn said: > And yes, you're right, a DoS attack can be unsuccessful. My point was that > this small amount of traffic shouldn't be called a DDoS because there's no > way that the intention behind this amount of traffic was to take down that > service with

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-17 Thread Jann Horn
On Fri, Aug 16, 2013 at 02:58:41PM -0300, Luther Blissett wrote: > On Fri, 2013-08-16 at 19:31 +0200, Jann Horn wrote: > > > Let me google that for you. Hmm. Assigned to "Polipo Web proxy". So maybe > > someone tried to connect to them through your exit node and they do > > proxyscans > > on peop

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-17 Thread Luther Blissett
On Fri, 2013-08-16 at 19:31 +0200, Jann Horn wrote: > Let me google that for you. Hmm. Assigned to "Polipo Web proxy". So maybe > someone tried to connect to them through your exit node and they do proxyscans > on people who connect to them? > > Sorry but I did not understand this. I had alread

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-17 Thread Luther Blissett
On Fri, 2013-08-16 at 09:54 +, Bart van Tuil wrote: > Luther, > > Is it just me, or is this ddos of 19045 packets in three hours a really, > really sorry attempt at anything at all?? Even the peak of 30 pkts/sec > wouldn't really disrupt -any- service on a modern system, or disrupt any > sel

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-17 Thread peter_toyota
osure List Subject: Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123) On Fri, Aug 16, 2013 at 01:37:54PM -0400, Jeffrey Walton wrote: > On Fri, Aug 16, 2013 at 1:31 PM, Jann Horn wrote: > > On Thu, Aug 15, 2013 at 05:29:52PM -0300, Luther Blisset

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-17 Thread Jann Horn
On Fri, Aug 16, 2013 at 04:49:24PM -0500, adam wrote: > Jann, you know what's even worse than someone being a dick for no > reason? Someone being a _stupid_ dick for no reason. Maybe I'm being a dick, and maybe I'm being a dick for no reason, but I don't think I'm being a _stupid_ dick. > In cas

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-17 Thread Pascal Ernster
Binary? The only "binary" thing I see in that hexdump are a bunch of null bytes and the \n at the end. regards Pascal On Thu, 15 Aug 2013 17:29:52 -0300 Luther Blissett wrote: > Hello dear companions, > > Two days ago one of my tor exit nodes experienced something I'm now > calling "limestone

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Daniel Preussker
+1 Daniel Preussker [ Research and Engineering [ dan...@preussker.net [ http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x87E736968E490AA1 On 16.08.2013, at 23:49, adam wrote: > Jann, you know what's even worse than someone being a dick for no > reason? Someone being a _stupid_ dick for no r

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Stefan Jon Silverman
Title: Message +1     Regards, Stefan   On 8/16/2013 2:49 PM, adam wrote: Jann, you know wh

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread adam
Jann, you know what's even worse than someone being a dick for no reason? Someone being a _stupid_ dick for no reason. In case you're unaware, the word "massive" was completely absent from this thread until YOU attempted to put it in someone elses' mouth. Beyond that, since you want to rip apart an

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Jeffrey Walton
On Fri, Aug 16, 2013 at 4:30 PM, Jann Horn wrote: > On Fri, Aug 16, 2013 at 01:37:54PM -0400, Jeffrey Walton wrote: >> On Fri, Aug 16, 2013 at 1:31 PM, Jann Horn wrote: >> > On Thu, Aug 15, 2013 at 05:29:52PM -0300, Luther Blissett wrote: >> >> Hello dear companions, >> >> >> >> Two days ago one

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Jann Horn
On Fri, Aug 16, 2013 at 01:37:54PM -0400, Jeffrey Walton wrote: > On Fri, Aug 16, 2013 at 1:31 PM, Jann Horn wrote: > > On Thu, Aug 15, 2013 at 05:29:52PM -0300, Luther Blissett wrote: > >> Hello dear companions, > >> > >> Two days ago one of my tor exit nodes experienced something I'm now > >> ca

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Jeffrey Walton
On Fri, Aug 16, 2013 at 1:31 PM, Jann Horn wrote: > On Thu, Aug 15, 2013 at 05:29:52PM -0300, Luther Blissett wrote: >> Hello dear companions, >> >> Two days ago one of my tor exit nodes experienced something I'm now >> calling "limestonenetworks DDoS on polipo" ( $WAN_IP:8123 ), since all > > DDo

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Jann Horn
On Thu, Aug 15, 2013 at 05:29:52PM -0300, Luther Blissett wrote: > Hello dear companions, > > Two days ago one of my tor exit nodes experienced something I'm now > calling "limestonenetworks DDoS on polipo" ( $WAN_IP:8123 ), since all DDoS? So you mean your systems were impacted by that? > pack

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Bart van Tuil
e- > From: Full-Disclosure [mailto:full-disclosure-boun...@lists.grok.org.uk] > On Behalf Of Luther Blissett > Sent: donderdag 15 augustus 2013 22:30 > To: tor-relays > Cc: full-disclosure@lists.grok.org.uk; ad...@limestonenetworks.com; tor- > dev > Subject: [Full-disclosure]

[Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Luther Blissett
Hello dear companions, Two days ago one of my tor exit nodes experienced something I'm now calling "limestonenetworks DDoS on polipo" ( $WAN_IP:8123 ), since all packets in the storm were flowing from a range of 514 different IP addresses, all of them inside limestonenetworks IP range and targetin