Slashdot Log In
SDF Punted, Due to DDOS
Posted by
Hemos
on Sat Feb 01, 2003 08:59 AM
from the kicking-them-offline dept.
from the kicking-them-offline dept.
bullshizzle writes "The longest running Public Access UNIX System (SDF, running BSD) est. 1989 had their services terminated abruptly by NWLink because of a DDoS attack. Termination was carried out immediately without prior notification, which violates their contract (page1, page2). Complaints can be filed to the Washington State Attorney General's Office by filling out this simple form conveniently located online. You can follow the story at lonestar.org." While still bad, I've been corrected - SDF was *not* the longest running public access Unix - ArborNet (Located right here in my town) has been around for at least a number more years.
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
public access (Score:1)
Easy to get rid of a company you don't like (Score:3, Interesting)
The problem I have with the stories is that they are very brief, only giving one side. One wonders if there was more history here.
Re:You're missing the point (Score:4, Informative)
hmmm (Score:1)
Seriously I never knew this existed
Now I want to check it out
Law suit? (Score:2)
I can't think of any reasonable circumstances prior to this that I've heard of a host cutting your connection just because of one incident without talking first...
Denial of Service Attack? (Score:3, Funny)
The Slashdot Effect
Who can blame them? (Score:1)
Their forum (Score:5, Informative)
Sorry Won't Fly. (Score:5, Interesting)
It doesn't say "prior written notice" but simply "written notice." That means that they can pull the plug on you at any time and tell you why afterwards.
It's interesting that the previous sentence says "either party" can terminate only for breaches of the contract that are not corrected within 15 days. In reality that only applies to Customer since the next sentence authorizes Northwest Link to do whatever it feels like doing.
Anyway, we only have half the story. It would be nice to see what Northwest Link has to say.
Tough luck.
Re:Sorry Won't Fly. (Score:5, Informative)
Posted to SDF message board by the owner of NWLink:
Dissapointing to see (Score:1)
A breach of contract, a new ISP, and couple the costs for a public service that has been running for fifteen years all because of a dumb DoS attack. As they say, many people have come to rely on SDF. This is one of the dumbest stunts that I have seen an ISP pull in a long time and I hope that NWLink [nwlink.com] have apropriate and successful legal action taken against them.
What a shame! And who's to blame? (Score:5, Interesting)
I have got my SDF public shell access at lonestar about two years ago, and I love it! It's (almost, because they required people to send in a buck to show they seriously want to use it and don't create lots of fake accounts) free, they have nice services, rely mostly on their users' affection and willingness to donate money or equipment to them, and you can upgrade for some money to use more features... I hope they will manage to migrate to their new hoster...
What puzzles me is that NWLink seemd to have disconnected SDF because they fell preyto some DDoS'ing, they were not actively involved in some (D)DoS towards other sites, at least that's how I read the announcement!
Consequently, this DDoS might have been one of the most successful one reported, since it not only hogged their connection and thus technically Dos'sed them for a while, but this led to some organizational DoS carried out by NWLink!
How can they dare blaming the victim? And how can they dare putting all the consequences (that is, disconnection) onto the victim as well? Is this legal? Is this good practice? And: Does it help stop the DDoS towards SDF? Okay, the target host(s) is/are down, but the packets might rush to the dangling patch cable end anyway, crossing NWLink's infrastructure...
All in all: Thanks to the DDoS people attacking a nice and free public service! :( (Not that I am some DDoS fan of any kind, but aren't there much more promising targets out there, both in terms of
popularity, evilness and challenging huge trunks? Or did some script kiddies just got their shell accounts revoked, and now they felt like stomping their virtual feet? I hope you have learnt to deal better with your frustration by the age of 12...)
And big thanks to NWLink for dealing with a customer's problem in a great and professional way by supporting a DDos through fully shutting down services!
--
"Where do you wanna go today / Somewhere you could never take me"
-- Chumbawamba
Why don't the police think of this? (Score:5, Interesting)
why oh why (Score:2, Interesting)
if my link was being used to host a ddos attack I would hope I could get notified of the problem and some assistance in fixing it.
to clean up the net we have to educate the users not move them somewhere else, though not for one second am I sugesting that these perticular admins needed educating but they did need notifying.
--required "I remember when"
years ago I was network admin in the UK for a company our exchange server was managed by the US office (the whole globes exchange services where US managed)
I realised that our server was an open relay and notified my director in the US and was told that it didnt matter because nobody would scan us why would anybody scan an advertising agency.
a quick install of snort on another box and a week later I had proof that we were being scaned.
still no action
a couple of weeks later our ISP sent us an official letter in telling us to fix the relay or be booted.
they could have booted us at any time but they did the right thing and warned us first.
the relay was fixed.
Thoughts from a member... (Score:2, Insightful)
Now, due to a couple of kiddies that wanted to prove their `skills', SDF has to go offline, leaving thousands of users unable to access their email and contact friends, and several more thousands unable to access Web and Gopher resources hosted on SDF... giving commercial providers like AOL just one more argument in their favour. They can afford lawyers to take care of shit like this... we can only depend on community leverage. I hope it will be plentyful. Damn. I wanna play netris on sdf....
You know my thoughts on this? (Score:1)
I woudn't be surprised if the DDOSers were in league with NWLink. Or maybe I'm just paranoid or something. Or maybe, as a member of SDF myself, I'm more than a little annoyed at this incidentr. It is SO WRONG.
M-Net? (Score:1)
SDF was moving (Score:4, Interesting)
Personally I find the timing suspicious - the move was originally scheduled for earlier in the week, then was delayed at NWLink's request, then when it actually happened "Oh, we're disconnecting you." Did they decide some time ago to get rid of those pesky SDF people and just try to make it look like an SDF problem instead of a NWLink disconnect?
How to complain? (Score:1)
Trying to link the WA consumer complaint form (Score:3, Informative)
Not Found
The requested object does not exist on this server. The link you followed is either outdated, inaccurate, or the server has been instructed not to let you have it. Please inform the site administrator of the referring page.
This kind of crap will continue (Score:3, Insightful)
And guess what, its EASY to stop! Simply require the netork borders to perform filtering on packets crossing the border. If your cable modem is spewing out packets addressed from China, and you're in Florida, SOMETHING IS WRONG. These packets should have never gotten into the internet in the first place.
Suddenly, when spoofing is no longer possible, DoS doesn't seem like such a great idea. Even with botnets and crap for DDoS usage, if you can be tracked back from a single trojaned box, you'd have to be stupid to try.
FUCKING A!! (Score:1)
FUCK FUCK FUCK FUCK SHIT FUCKING A!
Northwest Link (Score:4, Interesting)
I cancelled my account in mid 1999 because I got DSL. I received confirmation of this. Four months later I received a collection agency notice saying that I had not been paying my bill (on an account that I had cancelled). I responded with plenty of evidence that I had cancelled the account. The mailed response ignored any of my evidence and re-iterated the original claim. I finally called the NWLINK offices and talked to the NWLINK collections guy. I don't recall his name, but the collections guy sounded like the most crochety old man I had ever heard. I stated my case and his response was, "Pay your damn bill! We don't run a charity here!!!". It was as if he hadn't even heard a word I said, or as my father likes to say, "we were having two spearate conversations". I got the feeling that he thought I was some punk kid trying to scam NWLINK out of a few months of service.
I will never again do business with them. To those who have asked me about Internet Service Providers over the last 4 years, I have advised that they not do business with NWLINK either. I doubt I've made any impact on their bottom line, however I can assure you that the $75.00 they got out of me cost them at least ten customers. I mean really, all they had to do was treat me with a little respect regardless of who was right and who was wrong...
Complaint form link (Score:2, Informative)
PLEASE .. BE SENSIBLE! FOR THE SAKE OF SDF! (Score:1, Insightful)
Stephen Jones
Caretaker
SDF Public Access UNIX System
Is there a right way to deal with a DDoS ?? (Score:2)
There appears to be a pretty big need for a form of accountability.. right now, you can get almost any small site/organization off the net, simply by flooding them and getting them to run up their ISP bill. What would be the appropriate course of action for victims to such attacks?
what a bad day (Score:2)
The world loses another (virtual) PDP-10
twenex.org: No address associated with hostname
(That was part of SDF if you didn't already know)
8000 people die of AIDS as usual.
And the space shuttle doesn't make it back.
(I know I shouldn't begin sentances with and)
Can someone please explain... (Score:1)
A DDOS attack is an attack on bandwidth, not an attack on an operating system.
If I was more cynical...wait I am more cynical: I think its just because either Hemos doesn't understand the difference, or more likely, just wants to jump at a chance to badmouth that other operating system [freebsd.org] that he knows is so much of a threat to their treasured linux.
Personally I don't think this story comes under the heading of "News that matters", and even if it was worthy, it should have been put under the 'Security' heading, not "BSD".
Perhaps we can get a new section for Denial of Services, or perhaps, a wider umbrella would be a 'teenage HaX0r' section where we can put DDOSs, Web Defacements and Case Mods all together. (That way, people who have lives can choose the option not to display any of that shit on the front page)
Thanks, majestynine.
SDF withdrawal (Score:2)
I'm going through withdrawal pangs without my shell account. I've heard NWLINK's explanation but the timing and the anecdotes of former customers cast a pall over their credibility. My take on this is they were just covering their butts. As a result, thousands of us who rely on our accounts for email and more are high and dry. If what NWLINK said is true, the script kiddies won. That's the best that I can say for them.
Long live the Super Dimensional Fortress!
this will happen again.. (Score:1)
Ddos wont be stopped because in its current form, the net facilitates it....
"at least a number more years" is defined as: (Score:1)
Let's see, this one liner:
echo 'main(){printf("according to my calculations \"a number more years\" is: %d.\n",0xa);}'>./a.c;gcc ./a.c;./a.out
seems to produce the following output:
according to my calculations "a number more years" is: 10.
Shell provider + IRC = DDoS inevitability (Score:1)
One of the commercial providers that I use explicity disallows users from using IRC or running bots from their account, for the reason that IRC attracts DDoS. Some user gets into a disagreement with some little script kiddie fuckhead then Wham-O! The systems are knocked over or inaccessible and lots of users are inconvenienced. In this case, inconvenienced beyond the script kiddies wildest dreams. Right now the culprits will be laughing about it between frantic bouts of mutual masturbation.
Once Lonestar is moved to it's new provider or an amiable solution is found with it's current provider, I think it would be wise for to cease all IRC activity so that it can minimise the chances of this happening again.
Same with Dalnet (Score:1)
It's back ! (Score:1)
I can't resolve pop.freeshell.org from my machine, but I can resolve it from the shell on sdf.lonestar.org, so I presume that is a DNS propagation thing.
I took the IP address as found on sdf and put it in my
Woohoo !
I'll be checking the bboard later to see what this has cost SDF, and see if I should be sending them a little bit more money.
Re:I don't understand this. (Score:3, Informative)
(uugh, IHBT)
Re:slashdotted (Score:2)
Re:I don't understand this. (Score:2)
Next step is the switch in front again dependant on the type of switch it may have problems with a DOS attack as far as management goes.
The router above That may hav it's wan links flooded effectivly edging out valid traffic again and dependant on the router type taking up enormous ammounts of CPU time.
Then there are all the upstreams. When you buy bandwith from some local provider like they have they dont have the capacity to deal with the attack nessicarily and at minimum it may be degrading there network.
The only good solution to fix these things is source address verification from ALL ISP's (ok not happening any time soon) and oh that breaks mobil IP and some multi homes sites even the cheasy multiple DSL and cable modem setups for more bandwith and reliability configs.
Re:Link for the online form ? (Score:1)
Looks like the server has been told to block
Tom
Re:Link for the online form ? (Score:1)