This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Fraudsters Declare War on Anti-Scam Services

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://blog.washingtonpost.com/securityfix…_on_antisc.html
February 23, 2007 ~ "Spammers have been attacking and threatening several of the groups and individuals who have been performing some of the most important work in hobbling online scams, spam and computer viruses. The SANS Internet Storm Center on Thursday found a piece of malicious code (called "sans.exe") designed to update a group of several thousand infected computers that SANS has been monitoring. The code includes text strings that suggest an attack on the center if two of its crime fighters don't stop interfering with his money-making spam operations… The Web sites for CastleCops* - an all-volunteer, online scam fighting community - also have been under a consistent denial-of-service attack for the past couple of weeks…"
(Well, maybe not "weeks", but "days" for certain.)
* http://www.castlecops.com/article-topic-1.html

Backup/emergency URL for ISC
(per: http://isc.sans.org/diary.html?storyid=2292
Last Updated: 2007-02-23 04:53:15 UTC)
> http://iscems.dshield.org/index.txt

<_<
More on this…

Bots and DDoS attacks: a primer
> http://preview.tinyurl.com/3dmys5
February 23, 2007 ~ "My friends Paul and Robin Laudanski at CastleCops have been under a huge DDoS attack for over a week. The attack has initiated sustained malicious loads over 1GB/s. While that number is incredible in itself, it’s just on the high side of average. Some DDoS attacks come in at 10 GB/s and last for months. Many Web sites, including those dedicated to fighting spam, phishing, and malware in general, have been completely pushed off the Internet forever by DDoS attacks… A 30,000-bot network can easily generate 1GB/s of malicious traffic, as CastleCops unfortunately knows… It can be difficult to differentiate between legitimate and malicious traffic, and bots often used spoofed origination IP addresses to make it even more difficult. DDoS attacks using spoofed IP addresses can be stopped with ISP egress filtering as detailed in RFC 2827*, written in May 2000… The real weakness is our unauthenticated Internet. But as Paul and Robin of CastleCops said, "We're in this for the long haul. We aren't going to be intimidated. We aren't going to go away"

* http://www.faqs.org/ftp/bcp/bcp38.txt

:thumbup: