12 ms·
Hackers Who Shut Down PSN and Xbox Live Now Attacking Tor
- chatmasta 12y agohow many bottles of mountain dew?
- higherpurpose 12y agoKim Dotcom gave them 3000 Mega accounts yesterday, and now they seem to have created 3000 relays. Is the number just a coincidence, or are they doing it through those accounts somehow? http://torrentfreak.com/kim-dotcom-stops-xbox-and-playstation-attacks-141226/ http://torrentfreak.com/kim-dotcom-stops-xbox-and-playstatio...
- Shank 12y agoThey probably sold the vouchers and bought servers with them. Most of the relay IPs are coming from the Google cloud.
- timdorr 12y agoThose are simply file hosting accounts, so there's ability to run something like a Tor node from them. More likely is they're using the same botnet that was attacking PSN/XBL to run Tor relays.
- deleted 12y ago[deleted]
- AlyssaRowan 12y agoNo, they're all on Google Compute Engine. (Which means one person could very easily stop this cold…)
- michaelbuckbee 12y agoAs grateful as I was to be able to actually play the games I received on Christmas, it is hard to find anything positive longer term with respect to paying off DDOS attacks (though I'm assuming that this more or less happens constantly away from public view).
- tedivm 12y agoThere are currently 3346 relays, not 3000. The number is just a coincidence.
- alexivanovs 12y agoThis is fun to watch, even funnier when you realize that any talk around this is just that - talk. But, I'm intrigued for the future, this type of hacking is starting to make its comeback, and that's a cute thing.
- jamescun 12y agoFor Tor network status and node list: https://torstatus.blutmagie.de/ https://torstatus.blutmagie.de/ All names appear to begin with LizardNSA. It must be said, however, that all exit and non-exit nodes go through acceptance process over 88 days https://blog.torproject.org/blog/lifecycle-of-a-new-relay https://blog.torproject.org/blog/lifecycle-of-a-new-relay
- timdorr 12y agoThey claim a "0day", which may just be them coopting the term from real hackers, but may also be a legitimate attack that gets around the approval period. But it appears this is all running from Google's Compute Engine. They can easily shut it down, although they're probably using stolen credit cards, so there's no real traceability there.
- spacefight 12y agoSo the question is, why is Google not shutting them down now.
- Forbo 12y agoHave they taken any action that would be cause for a shutdown? Does Google not allow you to run Tor relays on their service? Genuine questions, I'm not familiar enough with the service.
- spacefight 12y agoI have no proof obviously, but I somehow think that those 3000 new GCE instances have not been registered according to the TOS of Google, most importantly in regard to real name and accountability policies.
- criley2 12y agoStolen credit cards is probably high on the list. You'd think Google wouldn't want to give away free computer resources to these 'hackers' since the banks will almost assuredly take back any mis-gotten money from stolen credit cards.
- comex 12y agoIt's unfortunate that they're attacking Tor, but at least this type of attacks is being demonstrated now by someone presumably only out for lulz, rather than potentially by more malicious entities in the future.
- r00fus 12y agoHow do you honestly know that? Everything can be pseudonymous or anonymous and behind several layers of indirections. Real names could be used so dox-ing can reveal "something" but in effect could simply be a steganographic ruse. Given the resources of large intelligence operations funded worldwide, would can you be sure one or more aren't really behind Lizard (or LulzSec or Anonymous even)?
- jayrox 12y agofirst off, quit calling them hackers. they aren't hackers. they are script kiddies.
- wyager 12y agoWhat makes you say this? Do we know exactly what they've done?
- onewaystreet 12y agoLizard Squad has access to a large botnet which they used to DDoS Sony and Microsoft and now to create a large number of TOR relays. It's not hacking. It's not even being a script kiddie.
- ck2 12y agoIt's organized crime.
- deleted 12y ago[deleted]
- tw04 12y agoI can tell you most of the TOR relays they've got aren't anything more than google cloud instances. So... not really hacking at all.
- jacquesm 12y agoCalling them script kiddies is not productive either. They're hackers by the now commonly accepted definition as used in the media. That ship sailed ages ago, but if you want to bicker about what to call them the correct term is probably something along the lines of cyber criminals.
- simias 12y agoI don't usually care for the meaning of "hacker" (tinkerer or pirate) but in this case calling them "hacker", even in the mainstream meaning of the word is giving them too much credit. They're not hacking anything any more that 4chan users "hack" websites by flooding them, there's no "hack" involved in any meaning of the word. I'm sure they love being called "hackers" by the media. So yeah, I'm definitely in favor of calling them script kiddies. It's much easier to understand, even for a mainstream audience. And I assume they'd find the attention they're getting less rewarding if they were called script kiddies everywhere...
- deleted 12y ago[deleted]
- sjreese 12y agoThat is the point .. the tor people said we are the USA and we will play the PIG movie World Police style. Just as with them working with the FBI, NSA and NRO.
- sjreese 12y agoSony - had this coming - fake security experts said the NK could do nothing - Now look - Ha! they stole the Admin password Ha! it was "lena" but we will kill their "NK" internet and stop them cold from further take-downs. Ha Ha he he ho ho ho..
- deanclatworthy 12y agoSo from what I've read so far they are trying to deanonymize TOR users by having a large number of relays in the network. This isn't an unknown attack vector. But surely the NSA could easily do the same. What's to say that half the relays aren't already NSA owned?
- jacquesm 12y agoYou make me wonder if there is yet another way of compromising TOR, to ask each intelligence service to contribute a small fraction of their capacity to TOR so that the vast majority of the nodes is owned by some agency, who then exchange data through some back channel. Harder to detect and with far more resources than any single agency could provide. Or is the NSA so large that it dwarfs the resources the rest of the world could contribute?
- deanclatworthy 12y agoI don't think its out the realms of possibility for any intelligence agency to set up a LOT of servers at different ISPs with different credit cards and account owners.
- belorn 12y agoThe problem with that approach is that it need to be done very quietly, slowly, and secretly, while being large scale. If a few hundred thousands nodes or a few massive large nodes suddenly popped up, then the admins of the tor directory servers (or some security research) would start asking question. It wasn't that long time ago that a rather large cluster came into discussion because it looked suspicious, and the situation got resolved a few days later. Then it need to say quiet since nodes require up-time in order to be weighted favorable compare to other nodes. During this time they will generate traffic, noise and like a few abuse letters. That mean the ISP will be in communication with the intelligence agency, which in turn either require lies which could fail or agreements which can leak. Simply put, it is likely easier, more cost effective and less fragile tap the back bone ISP network and sort out tor chains when needed.
- tw04 12y agoPLEASE stop calling them hackers. They're DDoS kiddies who have now switched to spinning up TOR on their botnet. THESE ARE NOT HACKERS.
- droopyEyelids 12y agoAt this point Hack is just a marketing/media term and Lisp nerds from MIT no longer have any say in the matter. Let it go.
- tw04 12y agoThat kind of attitude is why we have people denying global warming. Terms have meaning, allowing idiots to try to muddy the waters hurts all of mankind. It has nothing to do with "Lisp nerds from MIT".
- smtddr 12y agoThe whole argument of what "hacker" means in tech circles versus what it means to the mainstream is beyond a dead horse. That's like trying to make the word "gay" mean "happy" again.
- ddingus 12y agoIt still does mean happy! Nothing has changed there. We've just added homosexual to the list of things associated with the word "gay." When "gay" is used in the "happy" sense, context is what differentiates it from the more recent homosexual sense. "hacker" is no different. Really then, it's about more effective writing, insuring the context of "hacker" is clear from the surrounding context. What we lost in both instances was easy, utilitarian use of the word as more words are now required to convey information accurately.
- Aldo_MX 12y agoTo be honest, I never knew that "gay" meant "happy" until I watched The Three Caballeros in English
- a-ghost-fart 12y agoA bunch of children who don't know how to use Tor (take a look at the dox from TheFinest) decide to try and compromise Tor. Colour me surprised. Given that a bunch affiliated with the group's names, addresses, numbers and the like have been compromised, this doesn't seem like a very smart plan.
- ChristianBundy 12y agoLink to dox: http://thefinest.com/ http://thefinest.com/ Is it just me, or are there huge parallels between gang culture and hacker culture?
- yeukhon 12y agoThe thing I fear the most is cyber retaliation. So many of us have accounts on the Internet that matter to us day to day. If they are reading this (I am damn sure they are), and if they don't like you, they will try to take over your accounts and make fun of you. Fear is the most destructive and most effective weapon and such weapon is most terrible when targeting at individuals. But I still have to drop a line: please arrest these "hackers" / "crackers" / cyber criminals.
- pferde 12y agoOh no, someone might make fun of me. The horror!
- balls187 12y agoLuckily, you're not important enough for people to target. Luckily, neither am I.
- yeukhon 12y agoWell, you never know. They certainly can target you because you are working for X company and X company sounds awesome enough to exploit and place on the front page.
- abritishguy 12y agoThey appear to be using Google Compute instances (based upon the IP addresses) to create TOR relays but since they are not exit nodes I'm not really sure what they are hoping to achieve.
- abqio 12y agoThey're set up to be exit nodes, they just don't have the exit flag yet.
- mperret 12y agoQuite a few seem to have the exit flag now. Only glanced through the first 500 or so, but it looked to be about 50 which had the exit flag
- ChristianBundy 12y agoHow is that possible? I was under the impression that it took a long time to be a real exit node.
- deleted 12y ago[deleted]
- AlyssaRowan 12y agoNo stable flags. No guard flags, either. Google will probably shut them down quicker than the consensus gives them those. They are tiny; it's an attempted Sybil, but it's worse than GCHQ's one that used Amazon nodes. Edit: Down.
- abritishguy 12y agoAnd without that flag they might as well not be exit nodes - it takes 88 days to be approved.
- dirkk0 12y agoI don't get it. They attack the PSN and XBox networks. Kim Schmitz gives them 3000 vouchers for Mega to save christmas (what?) and/or the world. Then they claim, he's the reason they stopped the attacks. And then they target their next victim. My point is: one might not like Kim but he is way too smart to expect such a barter to be successful. So, given his own background, what makes him this? A stupid hero? Or is there a much smarter option?
- scrapcode 12y agoI honestly think he just wanted to play Destiny. That doesn't seems far-fetched to me at all.
- chc 12y agoIt was a chance to inject Mega's name into a big story. Before, the story was "Hackers steal Christmas." Now, the story is "Mega saves Christmas." Also, he probably wanted to play some video games and it's not like Mega vouchers cost him all that much, particularly considering this is basically an advertising expense.
- higherpurpose 12y agoNew headline: Mega Helps Destroy Tor Network Seriously, he just ended up passing the hot potato to someone else. That someone else is now Tor. I think I would've preferred to let Microsoft deal with the DDoS (they have the means). Giving in to criminals's demands really ends up making things worse in the long term, whether it's bank robbers, CryptoLocker creators or the owners of botnets that can DDOS sites.
- mattmanser 12y agoThat's not going to be the new headline as no-one knows what Tor is, but everyone knows when their kids can't play computer games.
- itsame 12y agoYou say that as if these guys wouldn't have touched Tor if Kim Dotcom didn't intervene. This is just what they do, whether or not they were given the vouchers. If not today, eventually they would probably have set their sights on Tor anyhow.
- rcamera 12y agoTor Devs haven't made any announcement yet, there is, however, a discussion about it on the mailing list: https://lists.torproject.org/pipermail/tor-talk/2014-December/036165.html https://lists.torproject.org/pipermail/tor-talk/2014-Decembe... If you use Tor, I would follow the suggestion by another member of the mailing list [1], simply add to your torrc file: ExcludeNodes US StrictNodes 1 That will disallow using any US nodes, which works since all of LizardNSA's nodes are currently in the US. [1] https://lists.torproject.org/pipermail/tor-talk/2014-December/036192.html https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...
- joliv 12y agoSupposed response from "lizards@riseup.net": > Why? I assure you, our exits are just fine. What's with people responding so negatively to us donating 360Gbit/s of exit BW? EDIT: From @lizardmafia: > To clarify, we are no longer attacking PSN or Xbox. We are testing our new Tor 0day. > Only hackers, miscreants and pedophiles use Tor.
- rcamera 12y agoThere is a clear explanation in the same thread as to why LizardNSA's actions of adding bandwidth to the network isn't good, and in fact, potentially dangerous (not very dangerous at this moment of writing): https://lists.torproject.org/pipermail/tor-talk/2014-December/036188.html https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...
- linuxydave 12y ago"Only hackers, miscreants and pedophiles use Tor." Oh please. They're trying to take the moral high ground to justify their behaviour.
- garrettgrimsley 12y agoWhat is trolling?
- 12y ago
- jwcrux 12y agoI'd be curious if this would be considered against the google compute engine ToS. If so, it'd be simple for Google to wipe them. Otherwise, I have no doubt the tor directory authorities will be keeping an eye on these for malicious activity and will mark them as Bad Relays if any is detected.
- yedpodtrzitko 12y agoThis isn't Fox News, can we call the things correctly, thus "crackers" in this case, pls?
- sanswork 12y agoThe crackers instead of hackers war was lost 15 years ago.
- mbel 12y agoI guess it can be won back if you convince people that calling programmers hackers and hackers crackers is hip now. Once we achieve that we can focus or more serious issues like naming Linux GNU/Linux :)
- cbd1984 12y agoYeah, like how 'gay' can mean 'stupid' in some contexts and moaning about it is pointless.
- scrollaway 12y agoYou mean the context of xbox online chatrooms? Why, yes, it is pointless.
- sanswork 12y agoYeah, like how 'gay' can mean 'homosexual' in some contexts instead of 'happy'.
- Karunamon 12y agoSo we just stop all use of correct language because of defeatism? Nonsense.
- sanswork 12y agoEnglish exists in its current state because it is constantly changing. Adding words, changing the pronunciation/spelling and even changing the definitions of them. You aren't concerned with correctness you're concerned with image and a pet word.
- s_q_b 12y agoThey're trying a correlation attack on the network. Create enough entries and exits, then matching traffic by time, size, and shape.
- gburt 12y agoDo you know this? It seems obvious to me, but calling it a "0day" suggests that maybe the attack is (at least marginally) more sophisticated than the obvious correlation attack. Not to mention, as far as I can see, we have no idea.
- s_q_b 12y agoTo date, no one to date has presented a reliable, scalable, consistent passive correlation algorithm.
- mattdeboard 12y agoThis group has been DDOSing game networks for quite awhile now, a year at least? Are they just super skilled at covering their tracks, are they not being investigated, is federal law enforcement not good at tracking this down yet, or what? I don't understand how a major crime spree is being conducted in public and gleefully boasted about for this long.
- AlyssaRowan 12y agoWould it be unreasonable to draw parallels to Lulzsec?
- mattdeboard 12y agoI forgot who these guys were, but yeah I reckon. IIRC LizardSquad did allegedly "disband" awhile back, I think when some heat got applied to them, but I don't know. They were repeatedly DDOSing the servers of a game I play so I started following their exploits. I do hope law enforcement catches up with these guys sooner rather than later.
- mschuster91 12y ago> I do hope law enforcement catches up with these guys sooner rather than later. Me not. Sony and MS need to be taught that online DRM is a massive customer experience clusterfuck, and they will only listen and learn one way: hit 'em in their pockets. Only when enough customers are angry and demand refunds that it hurts their bottom lines, then maybe online DRM measures will be finally allowed to rot in hell.
- biot 12y agoThe solution is to vote with your wallet and encourage others to do so as well, which will hit their bottom line. Attacking their network is basically acting like a petty thug, and thugs can rot in hell. Besides which, DRM-free solutions already exist for you: support developers who release their games without DRM such as via Humble Bundle, etc. Or just pirate whatever you want since you're apparently okay with illegal activity already.
- tanglesome 12y agoWhat a great bunch of guys! And, oh by the by, PSN is still down and Xbox Live is still having trouble.
- linksbro 12y agoSeems like it's coming to an end? https://twitter.com/CthulhuSec/status/548612570102640640 https://twitter.com/CthulhuSec/status/548612570102640640
- linksbro 12y agoTheir exits seem to be gone, too: https://globe.torproject.org/#/search/query=LizardNSA&filters%5Bflag%5D=Exit https://globe.torproject.org/#/search/query=LizardNSA&filter...
- alexggordon 12y agoI'm always a little bit fascinated by these sorts of attacks. On one hand, I guess I understand (yet don't condone) the motivation for the 'vigilante' justice they're trying to do. On the other, I really don't understand what benefit you can get from attacking Xbox, then Sony, and finally Tor. When I think of the people doing this, I tend to think of them as understanding the importance of Tor and the benefit of anonymity it brings. However, here are people doing a DDOS attack (obviously illegal) trying to bring down the biggest illegal goods marketplace on the internet. Maybe I'm alone in this, but outside of attention, I really don't understand any logical reason for this happening, and that really makes me dismiss any message they may have. I can comprehend being motivated by anger or some event, or just being a douchey company, but I just really don't understand what anyone besides the US Government would gain by attacking Tor.
- mrmondo 12y agoI personally think they're trying to get attention for themselves to build reputation and perhaps land some sort of job / payout.
- yeukhon 12y agoWell based on what they did, they obviously can't advertise their work. They also won't have any interest in working for SV companies. The only kind of job they are after is in the black market (organized crime and intelligence).
- alexggordon 12y agoThis. Another possibility I've considered is that they obviously wouldn't be able to get a job at any SV company, but perhaps when applying for the Chinese NSA, maybe hacking Sony is something you can put on your resume? I guess I'm not sure, but my guess is there could be a few entities outside the US that would appreciate that kind of skill.
- shitlord 12y agoYou can't even get into intelligence anymore after doing this, lol. They'd never pass the background checks.
- lizards 12y agoI like lizards in general, but I am not too pleased about lizards that are hacking. It is, quite frankly, a disgrace. Please be aware that the lizard community as a whole is appalled by these circumstances. I hope that this whole bag of shenanigans does not prejudice your fine selves against lizards - whether they be lizards of the past, present, or future. Thank you for your time.
- angersock 12y agoDo they run SUSE? This is important.
- ChristianBundy 12y agoUDPATE: Lizard Squad is currently being interviewed on BBC Live 5 right now: http://www.bbc.co.uk/radio/player/bbc_radio_five_live http://www.bbc.co.uk/radio/player/bbc_radio_five_live
- feld 12y agorequires flash :( darn, wanted to listen in but I'm sure it will be done before I can get flash installed
- lotsofmangos 12y agoThat was surreal. Felt like characters from Nathan Barley had walked into an early William Gibson novel.
- deanclatworthy 12y agoI didn't catch the interview, did they mask the voices? Presumably the filter they would use could be undone fairly easily, in the same way that the "swirl" filter paedophiles were using got them caught [1]. The way in which these people are acting right now is just asking for a mistake. I would guess they have made some huge opsec mistakes already. There's a supposed dox on them already (find it yourself on Twitter). [1] http://thelede.blogs.nytimes.com/2007/10/08/interpol-untwirls-a-suspected-pedophile/ http://thelede.blogs.nytimes.com/2007/10/08/interpol-untwirl...
- polack 12y agoFor those who missed it: https://www.youtube.com/watch?v=FNZg5NaPe0k https://www.youtube.com/watch?v=FNZg5NaPe0k
- bob917 12y agoDear PSN and Xbox hackers now attacking tor, I need tor to view pornography and hack Pakistani networks. I'll send you two coupons for $10 off your next meal at Red Lobster if you stop your attacks. Thank you.
- hwach 12y agoWold at arms
- hwach 12y agoWold at arms
- hwach 12y agoWold at arms
- LISPmasta 12y agoYeah I'm sure some rando bitch named Kate from gizmodo knows about DDoS. Any fucking moron can read twitter, thanks for "writing" an article about __nothing__. Seriously this site has zero standards compared to how it used to be.
- deleted 12y ago[deleted]