<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by VPNprovider</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Sat, 25 Jul 2026 20:25:29 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>Screenshots under DDoS attacks</title>
            <link>http://forum.lowyat.net/topic/477292</link>
            <description>Screenshots under DDoS attacks&lt;br /&gt;&lt;br /&gt;INCIDENT 1: Screenshots became the target of Distributed Denial of Service (DDoS) attacks, making this blog in accessible from 19:30hr June 22 to 00:30hr June 23. The launchpads for the DDoS cyber attackers were traced to two zombies in Russia which were parked at IP addresses 89.169.181.137 (Yubileynyy, Moscow) and 89.163.36.11 (St Petersburg), respectively.&lt;br /&gt;&lt;br /&gt;INCIDENT 2: Earlier, Screenshots was also down from 10:00hr to 15:00hr June 22 as a result of a simpler DoS (Denial of Service) attempt via a zombie parked at IP address 202.186.86.222 (Kuala Lumpur), which hosted a cross-border gaming site.&lt;br /&gt;&lt;br /&gt;Both DoS and DDoS attackers smack of the modus operandi of SMS Scammers who fake Mobile Originated (MO) requests in the manner they used anonymous networks to create simultaneous, unwarranted traffic to Screenshots server in order to paralyse it, thus denying bona fide readers from reading this weblog.&lt;br /&gt;&lt;br /&gt;ACTIONS TAKEN. When Incident 1 happened, Screenshots&amp;#39; web-admin was alerted and immediately activated virtual surveillance of the server activities, and visual inspection of the hardware. The web admin laid out a bait -- by attributing it to a problematic network card as the red herring -- in anticipation of potential DoS and DDoS attacks.&lt;br /&gt;&lt;br /&gt;When Incident 2 happened, the zombies were identified and the web admin repelled the attacks systematically at the firewall level.&lt;br /&gt;&lt;br /&gt;There were no evidence of server intrusion, and all database of Screenshots remain intact.&lt;br /&gt;&lt;br /&gt;MOTIVE. In the event that the two rounds of cyber attacks were triggered by content and issues recently published in Screenshots, one of it stood up like a sore-thumb -- the detailed expose of SMS Scams and the ineffectiveness of MCMC in mitigating the scandal and kill the rogue players.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Digital trails of the DoS attacks via zombie parked at 202.186.86.222 (Kuala Lumpur, Malaysia):&lt;br /&gt;&lt;br /&gt;The following hops were tracerouted:&lt;br /&gt;&lt;br /&gt;    1 ) 62.216.144.5 (United Kingdom)&lt;br /&gt;    2 ) 62.216.128.49 (New York, NY, USA)&lt;br /&gt;    3 ) 62.216.128.134 (United Kingdom)&lt;br /&gt;    4 ) 62.216.128.165 (United Kingdom)&lt;br /&gt;    5 ) 62.216.128.33 (United Kingdom)&lt;br /&gt;    6 ) 62.216.137.25 (Hong Kong, Hong Kong SAR)&lt;br /&gt;    7 ) 62.216.128.182 (Hong Kong, Hong Kong SAR)&lt;br /&gt;    8 ) 62.216.128.6 (United Kingdom)&lt;br /&gt;    9 ) 62.216.145.66 (United Kingdom)&lt;br /&gt;    10 ) 61.6.13.157 (Kuala Lumpur, Malaysia)&lt;br /&gt;    11 ) 61.6.162.10 (Kuala Lumpur, Malaysia)&lt;br /&gt;    12 ) 161.142.25.85 (Malaysia - imported inetnum object for MIMOS)&lt;br /&gt;    13) 61.6.162.10 (Kuala Lumpur, Malaysia)&lt;br /&gt;    14 ) Hidden&lt;br /&gt;    15 ) 202.186.86.222 (Kuala Lumpur, Malaysia)&lt;br /&gt;&lt;br /&gt;Digital trails of the DoS attacks via zombie parked at 89.163.36.11(St Petersburg, Russia):&lt;br /&gt;&lt;br /&gt;The following hops were tracerouted:&lt;br /&gt;&lt;br /&gt;    1 ) 130.117.2.106 (London, UK)&lt;br /&gt;    2 ) 130.117.1.62 (London, UK)&lt;br /&gt;    3 ) 195.66.226.90 (London, UK)&lt;br /&gt;    4 ) 217.106.0.162 (Russia)&lt;br /&gt;    5 ) 195.161.4.246 (Russia)&lt;br /&gt;    6 ) 195.131.253.53 (Russia)&lt;br /&gt;    7 ) Hidden&lt;br /&gt;    8 ) 89.163.36.11 (Saint Petersburg, Russia&lt;br /&gt;&lt;br /&gt;Digital trails of the DoS attacks via zombie parked at 89.169.181.137 ((Yubileynyy, Moscow, Russia):&lt;br /&gt;&lt;br /&gt;The following hops were tracerouted:&lt;br /&gt;&lt;br /&gt;    1 ) 89.149.186.34 (Germany)&lt;br /&gt;    2 ) 213.200.72.38 (Germany)&lt;br /&gt;    3 ) 81.222.0.99 (Russia)&lt;br /&gt;    4 ) 81.222.0.113 (Russia)&lt;br /&gt;    5 ) 81.222.0.90 (Russia)&lt;br /&gt;    6 ) 83.217.192.135 (Russia)&lt;br /&gt;    7 ) 83.217.192.78 (Russia)&lt;br /&gt;    8 ) 89.169.181.137 (Yubileynyy, Moscow, Russia)&lt;br /&gt;&lt;br /&gt;</description>
            <author>VPNprovider</author>
            <category>Networks and Broadband</category>
            <pubDate>Sat, 23 Jun 2007 13:08:04 +0800</pubDate>
        </item>
    </channel>
</rss>
