Monday, 30 October 2006
Update on Simpy DDoSing 
Earlier this month I wrote about Simpy getting DDoSed. I feel like I owe an update, so here it is.
Once the attachers were discovered, the "attackers" had no effect on Simpy. Got to love that secret defense sauce. All in all, at the last count earlier this month, there were several hundred distinct hosts involved. Some of the computers were clearly computers on residential networks, while others were infected business/hosted servers. Based on a few things I found about the attack, my guess is that a number of these hosts were infected without their owners even being aware of what their computers were doing while their owners were writing emails and surfing the web. In addition, based on the attack-related code I found, I am also pretty confident that these infected computers didn't target only Simpy, but also a number of other sites.
For the geeks among you, this DDoSs involved chunks of PHP, chunks of Perl, tcpflood, udpfood, httpflood, Google and AltaVista SERP parsing, an IRC bot, some HTTP GETs with a fake Firefox user-agent, some JavaScript and HTML forms, curl, wget, forking.... a whole soup of crackery.
Posted by at 4:54 PM in /
