4 ms·
The typical botnet operator cycle: 1) Send email to <large_site_here>, asking for a large ransom, preferably in Bitcoins. 2) If <large_site_here> does not pay
by redegg 14y ago
The typical botnet operator cycle:
1) Send email to <large_site_here>, asking for a large ransom, preferably in Bitcoins.
2) If <large_site_here> does not pay, fire your packet cannons at them.
3) Rinse and repeat.
- Shenglong 14y agoDoes anyone actually pay?
- ihsw 14y agoIf nobody paid then the botnet operators wouldn't continue to try extorting.
- HCIdivision17 14y agoLike spam, botnet operating costs may be so low that hardly anyone at all may need to succumb to make the operation pay off. Someone's likely to cheat and pay to make the pain go away eventually.
- redegg 14y agoIt was actually on Freenode when a botnet operator sent a message to me to pay up or suffer the consequences. I can't remember, but he asked for an insane amount of Bitcoins (800 I think, ~$8400) which wasn't even remotely close to our operating costs. No way I would pay, our site was down 2 days but we moved to Heroku afterwards. No problems since, it probably scared him away. YMMV with bigger botnets.
- HCIdivision17 14y agoWould it be reasonable to think of these expletive redacted botnets as a force of nature? As something useful to harden resources against, or just disasters that you hope don't hit? (I'm thinking of this in terms of sour grapes, not poor planning.)
- redegg 14y agoMost hosts (Linode, SoftLayer) will null-route you in a heartbeat when you get a massive influx of traffic that affects their network. DDoS protection is expensive. Unless it is economically feasible for you to pay for the protection, most sites don't have it until they're a high target.
- ceslami 14y agoIsn't this the situation that Cloudflare was designed to protect against? Their service is free as well.
- redegg 14y agoCloudFlare will protect you from DDoS attacks to an extent. There are 2 kinds of DDoS attacks I know of (there are more but they're similar): bandwidth exhaustion and computer resource exhaustion. Bandwidth exhaustion DDoS mitigation is difficult, because it requires you to have a fat inbound pipe to let all the bogus traffic through. Fat pipes are _expensive_, there are few hosting providers that allow you to have a dedicated line more than 1 Gbps. Supposedly their Business plan ($200/month) protects against this, and their free plans protect much smaller amounts of traffic. You can prevent against some common resource exhaustion attacks (SYN floods) by having a proper firewall setup. CloudFlare has been known to let the attack traffic route to your server if it's big enough.
- leexgx 14y agowith CloudFlare spreads the load over loads of sites you need more then 1000GB/s to bring them down under an pure DDoS bandwidth exhaustion, they have loads of sites spread all over the world computer resource exhaustion is more likely to work then bandwidth exhaustion on CloudFlare
- zomgbbq 14y agoI believe that most people pay. It is perceived to be cheaper to pay off the extortionists than to mitigate the DoS attack.
- Shenglong 14y agoI've been put into a similar situation before, but I couldn't find any convincing evidence that I wouldn't be extorted in the future, even if I did pay. What's the logic behind this? After all, DDoSers probably aren't upstanding citizens.
- tisme 14y agoPaying an extortionist is the one way in which you guarantee that you'll be extorted in the future. Think of it as entering into a subscription arrangement.
- colinbartlett 14y agoWait, seriously? Is this a common thing? I've not heard a lot of noise about ransom demands.
- Kiro 14y agoI don't know if it's common but I can confirm it happened to us at least.
- xal 14y agoIt's very common to target ecommerce stores like this. Specifically jewellery stores for some reason. Probably because it's a luxury good and somehow botnet owners link that to wealth of the owners. We host tens of thousands ecommerce stores and sometimes get these forwarded. We estimate that our customers receive at least one a month. DDOS attacks are a weekly to bi-weekly occurance for us. The internet is a messy place.
- tptacek 14y agoIt is very common; these scams were the bane of online casinos a few years ago, and hit major financial services companies more recently. Sorry, did I say "scam"? I meant "digital equivalent of a sit-in".
- 14y ago