Made front page of the NT News! :)

46 public posts in this discussion.

Post 1

http://news.com.au/common/story_page/0,4057,10635088%255E421,00.html

(I run www.multibet.com )...

EDIT: An investigative reported from "The Australian" newspaper has picked it up and ran with this story - another to come tommorow about the telco's and their inability to handle the situation - Telstra are refusing to talk to her.

The head of the Australian High Tech Crimes Unit has told the NT commisionor of Police to investigate the story based upon the AHTCU being mentioned in what he sees as a derogatory light.

New article: http://www.theaustralian.news.com.au/common/story_page/0,5744,10654530%255E2702,00.html

Expect another tommorow.

Thank god I keep logs...

Post 2

Thought about you when I read this story, cos I remember a while back when you spoke to me about the Russian mafia hijacking the website - so Telstra obviously couldn't help out then?

Post 3

Then can but it takes a while, in some cases just easier to pay.

Post 4

We took out part of Telstras core network in Sydney - so NO, they couldn't do squat :)

Post 6

Their solution was laughed at by the company we finally went with. Sad thing is, its the same solution used by the Defence dept for their sites....

Post 7

LOL.

Good to see my Comrades hard at work :P

Post 8

Hmmmm.

This is where buying capacity from Akamai might come in handy.

Post 9

I take it was some form of DOS attack ?

Gee I am in the wrong business .... quite easy to do and prevent

Post 10

Quote from El Presidente:
Hmmmm.

This is where buying capacity from Akamai might come in handy.

They wont supply us bandwidth due to the nature of the business.

Post 11

Quote from TopGun:
I take it was some form of DOS attack ?

Gee I am in the wrong business .... quite easy to do and prevent

Easy to prevent?!? No offence, but if it melted the core routers in Sydney for Australias biggest ISP, I fail to see what you could've done...

Post 12

They'd have competitors - what did they say?

Post 13

Their policy is to not supply bandwidth to online gaming companies. Fullstop.

Post 14

Hehe, i read that last one Dan and i thought 'but multibet dont host any games servers' :P

Post 15

Quote from Milenko:
Hehe, i read that last one Dan and i thought 'but multibet dont host any games servers' :P

Multibet doesn't, BUT!......

http://www.gamers-underground.com/forum/showthread.php?t=15519

Post 16

Holy crap! How rich must you be to own that site and be profiting enough that you can actually pay up that much dosh..

wow, last time i was around here i didn't know overdrive was some form of BAZILLIONAIRE!!#@$

Post 17

Im just the head IT guy their mate - just another working stiff like the rest of you... I WISH I had that much cash...

Post 18

ooooooerr...I see..sif get pwned by russians..how come this doesn't happen to TAB?

Post 19

Because the TAB has an Australian rather than Worldwide clientele.

Post 20

A good bookie can rake it in, if they understand the maths and follow a system. It's a lot like insurance, gambling: a market in risk and probabilities.

A more interesting factoid is that for the last two elections, Centrebet's odds have been better predictors of election results than major opinion polls. Incidentally, the current odds show the Coalition well out in front. I'd have expected it to run closer. Go figure.

Post 21

Quote from OverDrive:
Easy to prevent?!? No offence, but if it melted the core routers in Sydney for Australias biggest ISP, I fail to see what you could've done...

So you are saying it took out the Australian leg of the Net ? or is that what the ISP told you ?

Ever hear of CERT or AUSCERT ?

If you have forensic evidence of the attack(s) then they can be prevented and if you really want to be nasty reply in kind ....

And yes I would be able to prevent it ....

Post 22

I'll bring the chairs and marshmallows....

(this should be good).

Post 23

CERT?!? Get real...

Mate, I've been dealing with http://www.ahtcc.gov.au/ and http://www.nhtcu.org/ .

It's not a matter of skill or great hardware in stopping this - its purely a question of pipe size, and based upon your location (Perth) you'd have sfa chance - there just isn't a pipe big enough going into the whole WA.

But please, by all means impart me with your wisdom...

Post 25

I've already got the chairs (see post above) - but beers would be good...

Post 26

Im quite happy to bring myself and drink spongys beers and sit in xaines chairs :)

Post 27

Ahhh check out the links into and out of perth ... bigger than you think ... and bigger than to the NT

http://www.telstra.com.au/internetdirect/aboutnet.htm

and

http://www.telstrawholesale.com/products/docs/appsandip_twi.pdf

hmmm not sure what you are on about ? what has wa got to do with anything to do with your site being shut down ?

Gladly impart any info and consulting at $250 per hour or part there of.

Post 28

We weren't sitting in the NT, we were sitting in Sydney, at the front door to the internet for Australia. I used WA as an example as you said you could've handled it, and I noticed your in Perth (as I said in my message "and based upon your location (Perth) you'd have sfa chance").

It was a multi-gig attack, and the head of Telstra Security told me they couldn't handle the capacity in Sydney without seriously degrading the performance of the network for the rest of the country and that we were to go offshore if we wanted protection that would actually WORK.

So, I restate my previous argument - "you would've done what exactly?" - and don't give me this $250/hr shit...

Post 29

hehe ... what sort of attack ? I am assuming ( maybe incorrectly ) it was a DOS or DDOS attack against your Sydney based site ?

And I further assume is was a web server(s) that was the target ?

Define multi-gig attack plz - was it a syn flood ? or just a whole pile of simultaneous connections ?

Provide more details and I can offer advice - it is not rocket surgery this type of attack and am suprised Telstra were unable to mitigate it .... but knowing Telstra I am not suprised ... all too hard for them ...

Post 30

DDOS, spoofed ips, syn flood USING multi gig, and if you know anything about synfloods you'd know that each packet is extraordinarily small, so picture how many packets it took per second (i'll leave you to do the math).

Post 31

Toppy these Russian Mafia have access to thousands if not 10 times that number of rooted boxes and ISP's.

They can throw more data at the general .au domain then our whole international pipe can handle. And when its all directed at a single domain/hosting service.....ouch.

So banning IP's is useless too many + they can spoof and change easily.
You can't block out the whole of Russia to au for any period of time.
When your talking this many packets its way too freaking hard for any software to keep up with bad/good for diversion purposes.
I don't believe Aus has any of these nifty Cisco gear that can try and sort it out on the hardware level.
At the same time your CPU is maxing trying to host all the connections or decide good/bad/oh dear wtf is that one.

An internal attack from the .au domain is much easier to deal with but yeah, these guys do this for a living. :)

Post 32

UPDATE: New info at hand - read top post.

Post 33

errrrgh...does anyone else feel as though they're out of their league? :?

Post 34

the only place you can really block this, is at the point where the good guys bandwidth exceeds the bad guys bandwidth :/

Post 35

Got it in one - but even then you still need to be capable of filtering the bad port 80 packets from the valid ones.

Post 36

i seem to remember a conversation along these lines when the whole thing was going down :).

Post 37

Any more info yet?

Post 38

UPDATE:

http://australianit.news.com.au/articles/0,7204,10687986%5E15306%5E%5Enbv%5E,00.html

http://forums.whirlpool.net.au/forum-replies.cfm?t=237347

Post 39

Have you tried zone alarm ?

Post 40

rofl

Post 41

what rec said, only i exploded.

Post 42

Quote from Stapla:
Have you tried zone alarm ?
omg

best. post. ever.

ima frame this whole thread.

Post 43

HAHAHAHAHAHAHAHAHA
zone alarm
yeah shit Overdrive why didnt you think of that you silly sausage.
:P

Post 44

LOL.. you guys crack me up! :)

Post 45

unplug teh cable next time :)

Post 46

We had them try take us on as well. We ended shutting down our international traffic whilst we couldnt withstand the barrage. Eventually Optus took some affirmative action and used Radware equipment to post a big F*ck 0ff sign on the door in Sydney. We already had two of these boxes on our site in Darwin but I figure that our pipe couldnt cope with it. Optus also ended up seconding our DNS and a few other tricks. We didnt pay a single cent to the extortionists (that I'm aware of) but we had the pull with Optus to ensure that they were looking after us. We havent had any trouble with them now for about 4 months that we've felt here in Darwin.