Despite the evidence, 96.255.183.109 doesn't get it

2 replies [Last post]
RaT
RaT's picture
Offline
SX High Council
Joined: 2008/03/12

After our Defcon 22 talk, nobody has really been dumb enough to try DoS/DDoS attacks against the site. I figured even the dumbest of basement dwellers had figured out that not only do their attacks not work - but we have systems in place for reporting them to their ISPs (DoS is a quick way to lose your internet or VPN account).

Well, all of that changed today. While I was performing site maintenance, I got an alert that somebody was trying to DoS the site with a lame GET request DoS. It seems this guy was upset about the DDoSers manifesto.

Anyways, a snippet at the laughable logs are as follows:

96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"
96.255.183.109 - - [22/Mar/2015:18:08:54 -0400] "GET /misc/jquery.js?o HTTP/1.1" 408 502 "https://www.soldierx.com/bbs/201307/DoS-and-Dark-Day-SX" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-au) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27"

I guess I can give him credit for getting of 24 requests per second. I say laughable because it didn't even cause any site slowdown Tongue

What's also a little funny is that it's clear the guy doesn't know much about DoS. His initial attack against us looks like he was still struggling to configure his DoS attack tool from code.google.com/p/slowhttptest:

96.255.183.109 - - [22/Mar/2015:16:59:17 -0400] "GET /archives/labs/Kayin-SXOFace-0.4.zip HTTP/1.1" 200 57976 "http://code.google.com/p/slowhttptest/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30"
96.255.183.109 - - [22/Mar/2015:16:59:22 -0400] "GET /archives/labs/Kayin-SXOFace-0.4.zip HTTP/1.1" 200 56528 "http://code.google.com/p/slowhttptest/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30"
96.255.183.109 - - [22/Mar/2015:16:59:18 -0400] "GET /archives/labs/Kayin-SXOFace-0.4.zip HTTP/1.1" 200 21104 "http://code.google.com/p/slowhttptest/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30"
96.255.183.109 - - [22/Mar/2015:16:59:18 -0400] "GET /archives/labs/Kayin-SXOFace-0.4.zip HTTP/1.1" 200 21104 "http://code.google.com/p/slowhttptest/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30"
96.255.183.109 - - [22/Mar/2015:16:59:18 -0400] "GET /archives/labs/Kayin-SXOFace-0.4.zip HTTP/1.1" 200 21104 "http://code.google.com/p/slowhttptest/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30"
96.255.183.109 - - [22/Mar/2015:16:59:18 -0400] "GET /archives/labs/Kayin-SXOFace-0.4.zip HTTP/1.1" 200 21104 "http://code.google.com/p/slowhttptest/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30"
96.255.183.109 - - [22/Mar/2015:16:59:18 -0400] "GET /archives/labs/Kayin-SXOFace-0.4.zip HTTP/1.1" 200 21104 "http://code.google.com/p/slowhttptest/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30"