PDA

View Full Version : Allakhazam DDOS Attack


Allakhazam
02-23-2008, 04:14 PM
<p>For those who are wondering, Allakhazam is currently under a ddos attack.  It's the third one we've had this week.  We're working hard to fight it off and get back on line.  Thank you for your patience.</p>

Vonotar
02-23-2008, 04:18 PM
*shakes head*Why on earth would anybody want to DDOS Allakhazam is beyond me.  I work for a large UK based gaming (a.k.a gambling) company who get regular DDOS attacks (a couple per year) from people who either want to blackmail for money (they can wish) or who just don't agree with gambling in general.  I can understand why they do that (don't agree with it, but I can understand their 'reasoning').  But what on earth did AK do?Good luck to you, I know it's unlikely the culprit will be found/brought to justice (they rarely are) but I hope they slip up and expose themselves.

SisterTheresa
02-23-2008, 07:18 PM
<p>All of this started happening when the lunar eclipse arrived ...</p><p>Coincidence?  *do do do doooo*</p>

Calthine
02-23-2008, 10:15 PM
<cite>Banedon@Antonia Bayle wrote:</cite><blockquote>*shakes head*Why on earth would anybody want to DDOS Allakhazam is beyond me.  I work for a large UK based gaming (a.k.a gambling) company who get regular DDOS attacks (a couple per year) from people who either want to blackmail for money (they can wish) or who just don't agree with gambling in general.  I can understand why they do that (don't agree with it, but I can understand their 'reasoning'<img src="/eq2/images/smilies/8a80c6485cd926be453217d59a84a888.gif" border="0" alt="SMILEY<img mce_tsrc=" />" />.  But what on earth did AK do?Good luck to you, I know it's unlikely the culprit will be found/brought to justice (they rarely are) but I hope they slip up and expose themselves.</blockquote>My vote is for some bright young hacker with nothing better to do, as I just can't imagine most people stooping that low.  It's a pita.  But the dev team at Allakhazam is simply awesome, I have great faith they'll persevere.  Meanwhile, if anyone has submissions they don't want to wait to submit, my Zam e-mail will get to me eventually ([email protected]) or PM me here for a non-zam addy.

Savanja
02-23-2008, 10:40 PM
I hope it gets under control quickly.  It's uncool when people behave like that.

Ama
02-24-2008, 12:40 AM
<cite>Allakhazam wrote:</cite><blockquote><p>For those who are wondering, Allakhazam is currently under a ddos attack.  It's the third one we've had this week.  We're working hard to fight it off and get back on line.  Thank you for your patience.</p></blockquote>I'm deffinately sorry to hear about that.  Wanted to go to allakhazam today to see about some information for a guildie and couldn't access the site.  Personally I find it quite pathetic people get so freakin bored they decided to attack others for the sheer pleasure of it.

SisterTheresa
02-24-2008, 07:56 PM
<cite>Amana wrote:</cite><blockquote><cite>Allakhazam wrote:</cite><blockquote><p>For those who are wondering, Allakhazam is currently under a ddos attack.  It's the third one we've had this week.  We're working hard to fight it off and get back on line.  Thank you for your patience.</p></blockquote>I'm deffinately sorry to hear about that.  Wanted to go to allakhazam today to see about some information for a guildie and couldn't access the site.  Personally I find it quite pathetic people get so freakin bored they decided to attack others for the sheer pleasure of it. </blockquote>And what's worse, those who do such things are either kids in college or young kids who taught themselves.  That's why I hope when I graduate from college, I'll be able to help more in stopping such things (taking Network security)

Ama
02-24-2008, 08:05 PM
<cite>SisterTheresa wrote:</cite><blockquote><cite>Amana wrote:</cite><blockquote><cite>Allakhazam wrote:</cite><blockquote><p>For those who are wondering, Allakhazam is currently under a ddos attack.  It's the third one we've had this week.  We're working hard to fight it off and get back on line.  Thank you for your patience.</p></blockquote>I'm deffinately sorry to hear about that.  Wanted to go to allakhazam today to see about some information for a guildie and couldn't access the site.  Personally I find it quite pathetic people get so freakin bored they decided to attack others for the sheer pleasure of it. </blockquote>And what's worse, those who do such things are either kids in college or young kids who taught themselves.  That's why I hope when I graduate from college, I'll be able to help more in stopping such things (taking Network security)</blockquote><p>More power to you if you are one of the few who can do this.  Problem is I know about this stuff IE what hackers do, how they do it, but I myself have little idea how to stop it from happening to me.  All I can do is follow simple protocols to help stop attacks on my personal computer.  My website is registered to a company and if my site were attacked/destroyed there's probably nothing that could be done.  </p><p>Biggest problem are these kids that log into several different computers getting passwords or using glitches/backdoors so they can hide their identities. </p>

Spyderbite
02-24-2008, 09:30 PM
Its a pity that a site like 'Zam gets hit. But, all the different reasons people pull such stunts have already been mentioned. I've always found it humorous that the punks usually rebut their actions by claiming they were just trying to how insecure various platforms are by exploiting them like this.Its modern vandalism.. plain and simple. And, its a shame that 20 years after spray painting public property was believed to be cool, that the attitude hasn't changed and its considered "a form of art" to destroy other people's property.

Calthine
02-25-2008, 01:17 AM
The site was much more stable today, although we're obviously still having issues.  I hope whomever is responsible gets bored soon.

MikesterBrau
02-25-2008, 11:33 AM
   Even though it sucks getting hit with a Denial of Service attack; I might say the one silver lining in it would be that it is a sign of your success and continuted high visibility.   Good luck resolving it quickly as I am sure you guys will overcome it quickly. <img src="/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif" border="0" alt="SMILEY" />

cooper9280
02-25-2008, 12:18 PM
<p>The part that really bothers me is the sheer waste of intelligence and effort that could be put to better use for good instead of vandalism !!!  Who knows what we are missing out on because they made the wrong choice ??</p><p>I hope that whoever is behind this gets bored quickly and moves on to another target.  'Zam is much too useful a site to have it down for long !!!!  All the best.</p>

FinalHolmes
02-26-2008, 02:24 PM
Is Allakhazam down again? I have tried several times to-day (26th February) but still no joy with the site loading<img src="http://forums.station.sony.com/eq2/images/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" border="0" alt="SMILEY" width="15" height="15" />I hope it will be up and running soon, it's a shame to see such a great site down.

Kiara-
02-26-2008, 02:25 PM
<p><span style="color: #cc99ff;">I'm having such a Sally Field at the oscars moment.</span></p><p><span style="color: #cc99ff;">You like us, you REALLY like us!</span></p><p><span style="color: #cc99ff;">* passes out hugs *</span></p>

Calthine
02-26-2008, 02:38 PM
<cite>FinalHolmes wrote:</cite><blockquote>Is Allakhazam down again? I have tried several times to-day (26th February) but still no joy with the site loading<img src="http://forums.station.sony.com/eq2/images/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" border="0" alt="SMILEY" width="15" height="15" />I hope it will be up and running soon, it's a shame to see such a great site down.</blockquote>Yeah, no joy this morning.  We went down around (/does time zone conversions in her head) um, shortly after 9pm PST last night, and no relief yet.I'm getting a lot of screenshots cropped and ready to upload, though!

Calthine
02-26-2008, 02:39 PM
<cite>Kiara wrote:</cite><blockquote><p><span style="color: #cc99ff;">I'm having such a Sally Field at the oscars moment.</span></p><p><span style="color: #cc99ff;">You like us, you REALLY like us!</span></p><p><span style="color: #cc99ff;">* passes out hugs *</span></p></blockquote>Hehe, yeah, me too.  And I'm miserably frustrated that there's nothing I can really do to help alleviate the situation.

Calthine
02-26-2008, 03:49 PM
As of right this minute, we're back <img src="/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif" border="0" alt="SMILEY" />

-Arctura-
02-26-2008, 04:04 PM
(( I once had a good friend who ran the FPS clan I was in, our site got HUGE hacker attacks.The unlucky hackers made their last mistake, our clan leader was ex military, some kind of telecommunications position or something, and the other members were all soldiers or ex law enforcement.I kid you not, the culprit and his buddy were apprehended by the FBI and it was televised a month later.Apparently they had been harassing many, many, many gaming websites to try to be l33t or something, well suffice it to say they went too far and got pwned by the long arm of the law.Big brother might not find you, but theres an awful lot of little brothers out there <img src="/eq2/images/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif" border="0" alt="SMILEY<img src="/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif" border="0" alt="SMILEY" />" /><img src="http://i53.photobucket.com/albums/g69/Arctura000/DarkShadow2ONEXX--------------.gif" alt="" border="0" />

Jehanne
02-26-2008, 04:07 PM
Maybe this is being done since Allakhazam is now owned by IGE?  Dunno, just a guess at a motive.

Kiara-
02-26-2008, 04:12 PM
<cite>Anasur@Antonia Bayle wrote:</cite><blockquote>Maybe this is being done since Allakhazam is now owned by IGE?  Dunno, just a guess at a motive.</blockquote><p><span style="color: #cc99ff;">Umm... Wow.  Zam is owned by IGE?  When did that happen?</span></p><p><span style="color: #cc99ff;">Cause last I checked that wasn't the case, and I'm pretty sure Cal and I would have known about this.</span></p>

Jehanne
02-26-2008, 04:23 PM
<a rel="nofollow" href="http://www.1up.com/do/newsStory?cId=3150282" target="_blank">It was announced in May 2006</a>.  And correction:  The parent company that owns IGE got Allakhazam.  So they're owned by the same corporation.

Kiara-
02-26-2008, 04:33 PM
<p><span style="color: #cc99ff;">So, no.  IGE doesn't own Zam.</span></p><p><span style="color: #cc99ff;">Good thing.  Cause that would mean that I was confused when they announced last year (that would be 2007, btw when I started working at Zam) that our parent company sold IGE off to someone else.  </span></p><p><span style="color: #cc99ff;">And I do so hate to be confused <img src="/eq2/images/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif" border="0" alt="SMILEY<img src=" width="15" height="15" /></span></p>

Calthine
02-26-2008, 04:52 PM
<cite>Anasur@Antonia Bayle wrote:</cite><blockquote><a rel="nofollow" href="http://www.1up.com/do/newsStory?cId=3150282" target="_blank">It was announced in May 2006</a>.  And correction:  The parent company that owns IGE got Allakhazam.  So they're owned by the same corporation.</blockquote>Your information is out of date, hon, Affinity Media sold IGE off in April 2007.  <a href="http://eq2.allakhazam.com/forum.html?forum=3;mid=117772225728544482;page=1" rel="nofollow" target="_blank">Linky</a>

Savanja
02-26-2008, 05:14 PM
lol.  That keeps getting dug up.  Knowing your infoz is good.

AllaK_Bludwyng
02-26-2008, 05:41 PM
Although we were still down this morning when Cal called me (about 4 hours ago?) we are back up now.

MikesterBrau
02-27-2008, 02:56 PM
<p>    When we find the folks responsible for the DDOS attack on your site I say we get them in a nice closet and all the other fan site staff can bring dirty socks and undies (yours, yours spouses, kids etc), some nice Taiwanese stinky tofu, and for the deal clincher some malaysina durian fruit that is over ripe then lock the door on the closet and get them in say 2 or 3 hours, yep that should fix em.  <img src="/eq2/images/smilies/69934afc394145350659cd7add244ca9.gif" border="0" alt="SMILEY<img src="/smilies/69934afc394145350659cd7add244ca9.gif" border="0" alt="SMILEY" />" width="15" height="15" />  Best wishes and swatting them down quickly.</p>

Kiara-
02-27-2008, 02:59 PM
<p><span style="color: #cc99ff;">right...  okay then.</span></p><p><span style="color: #cc99ff;">* makes a mental note NEVER to hang out with mikester *</span></p><p><span style="color: #cc99ff;">eww?</span></p>

Cyanbane
02-27-2008, 03:25 PM
Interesting reads on IGE and Affinity:<a href="http://www.mmo-gamer.com/?p=297" target="_blank" rel="nofollow">http://www.mmo-gamer.com/?p=297</a><a href="http://www.mmobux.com/articles/752/news-report-affinity-media-requests-to-put-ige-case-on-hold" target="_blank" rel="nofollow">http://www.mmobux.com/articles/752/...ge-case-on-hold</a><a href="http://www.wowinsider.com/2007/12/20/legal-files-reveal-ige-and-affinity-connection-once-and-for-all/" target="_blank" rel="nofollow">http://www.wowinsider.com/2007/12/2...ce-and-for-all/</a>Regardless of what the connection is between the two companies that those posts state, the DDOS is unnecessary in any event.

Calthine
03-03-2008, 01:24 PM
As Bludwyng mentioned elsewhere, we got hit again.  Our dev's are working on it.  Thanks very much for your patience. 

Vendolyn
03-03-2008, 01:29 PM
I was just going to PM  you about that.  Guess I'll have to wait to see what the IRC configs are (Trillian's being mean today, was going to give ChatZilla a stab, if I can figure it out).Good luck with the fighting attacks.

Calthine
03-03-2008, 01:37 PM
Unfortunately, our IRC server is also suffering <img src="/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" border="0" alt="SMILEY" />  Sorry.But it's irc.allakhazam.com, port 6667.  And we hang in #eq2, of course.

Ogrebe
03-03-2008, 02:19 PM
<cite>Katryina@Antonia Bayle wrote:</cite><blockquote><cite>Amana wrote:</cite><blockquote><cite>Allakhazam wrote:</cite><blockquote><p>For those who are wondering, Allakhazam is currently under a ddos attack.  It's the third one we've had this week.  We're working hard to fight it off and get back on line.  Thank you for your patience.</p></blockquote>I'm deffinately sorry to hear about that.  Wanted to go to allakhazam today to see about some information for a guildie and couldn't access the site.  Personally I find it quite pathetic people get so freakin bored they decided to attack others for the sheer pleasure of it. </blockquote>And what's worse, those who do such things are either kids in college or young kids who taught themselves.  That's why I hope when I graduate from college, I'll be able to help more in stopping such things (taking Network security)</blockquote>That not exactly easy though, A lot of people who use DDOS attacks use zombie computers. So the attack is normally not from 1 source only or it would be easily stop it. But it from thousands of different sources, which makes blocking people hard.

moeppel
03-03-2008, 02:23 PM
<a href="http://www.whois.sc/<attackers" target="_blank" rel="nofollow">www.whois.sc/<attackers</a> ip> to look up the ip pools he uses. Of course, this will most likely not get you any closer to the person doing it, but you got ip ranges you can ban manually, or ask  your provider to block em. It's likely he abuses company networks having nothing more than a pool of maximum 255 addresses, meaning that range bans won't block people you didn't want to ban in the beginning.

moeppel
03-03-2008, 02:32 PM
Sorry for posting twice. I either cannot find an edit / delete button, or there is none.Anyways, in addition to my former post, turn off all possible services on the server that are nukeable, which are not necessary. Such as FTP if it's hardly / never used.One of our servers was ddos'ed once too, we pretty much handled with cookie synchronization I think. Though we were still under ddos users wouldn't really notice it, but the apache sure had lotsa threads running.

Vendolyn
03-03-2008, 03:17 PM
<cite>Calthine wrote:</cite><blockquote>Unfortunately, our IRC server is also suffering <img src="/eq2/images/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" border="0" alt="SMILEY<img src="/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" border="0" alt="SMILEY" />" />  Sorry.But it's irc.allakhazam.com, port 6667.  And we hang in #eq2, of course.</blockquote>Thanks, Cal...now to figure out where in the world I plug that into ChatZilla*shakes angry fist at Trillian*

Calthine
03-03-2008, 03:24 PM
<cite>moeppel wrote:</cite><blockquote><a rel="nofollow" href="http://www.whois.sc/<attackers" target="_blank">www.whois.sc/<attackers</a> ip> to look up the ip pools he uses. Of course, this will most likely not get you any closer to the person doing it, but you got ip ranges you can ban manually, or ask  your provider to block em. It's likely he abuses company networks having nothing more than a pool of maximum 255 addresses, meaning that range bans won't block people you didn't want to ban in the beginning.</blockquote>I don't pretend to understand the tech end of it, but our developers and our ISP have been working together on it.  And yes, it's zombies.

Calthine
03-03-2008, 03:24 PM
<cite>Vendolyn@Unrest wrote:</cite><blockquote><cite>Calthine wrote:</cite><blockquote>Unfortunately, our IRC server is also suffering <img src="/eq2/images/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" border="0" alt="SMILEY<img mce_tsrc=" />" />  Sorry.But it's irc.allakhazam.com, port 6667.  And we hang in #eq2, of course.</blockquote>Thanks, Cal...now to figure out where in the world I plug that into ChatZilla*shakes angry fist at Trillian*</blockquote>Hm, I like Triliian, once I figured out how to add the IRC bit to it, which isn't very intuitive.

Vendolyn
03-03-2008, 03:39 PM
I *love* Trillian.  The issue I have, though, is sometimes it only partially connects, which means no IRC for me =/This usually means that I have a software update soon, but I've been checking over the past week or so, and Trillian just doesn't want to be nice to me!

Calthine
03-03-2008, 03:45 PM
<cite>Vendolyn@Unrest wrote:</cite><blockquote>I *love* Trillian.  The issue I have, though, is sometimes it only partially connects, which means no IRC for me =/This usually means that I have a software update soon, but I've been checking over the past week or so, and Trillian just doesn't want to be nice to me!</blockquote>Well, 'Zam is the only IRC server I use, and when IT'S down I get partial connects.  IMO a partial connect means something on the other end is kerflooey.

Vendolyn
03-03-2008, 05:53 PM
To entertain myself when I should be taking a lunch break, but just am not hungry, I wrote this: <p >Dear Allakhazam:</p> <p > </p> <p >When you are down</p> <p >I am so sad</p> <p >This is because</p> <p >My IRC can’t be had</p> <p > </p> <p >I must do work</p> <p >Instead of browsing</p> <p >I sit here filing</p> <p >Instead of dreaming about housing</p> <p > </p> <p >I miss the people who</p> <p >Talk to me throughout the day</p> <p >Fight those mean jerks</p> <p >So I can log in with a YAY!</p>

Stuge
03-03-2008, 06:23 PM
<span style="font-family: courier new,courier;">We need to get this resolved.  Vendolyn is losing it.</span>

Vendolyn
03-03-2008, 06:26 PM
<cite>Stugein@Antonia Bayle wrote:</cite><blockquote><span style="font-family: courier new,courier;">We need to get this resolved.  Vendolyn is losing it.</span></blockquote>*giggle*Anyway I can help ;pI seriously blame my lack of hunger, since I'm just sitting here staring at my monitor.  Everyone I normally chat with seems to be afk/non respondent.  So, I'll just sit here thinking about my newly made Test characters.

Calthine
03-03-2008, 06:44 PM
I am so posting that to our staff forums when we're back up <img src="/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif" border="0" alt="SMILEY" />  It's lovely to be missed! 

Ama
03-03-2008, 06:47 PM
Sorry to hear the attacks have started up again.  I really value Allakhazam as a source to check my notes/findings for putting up articles on my site.  Personally I would have thought it was anti-EQ2 people, but hearing WoW and FFXI sites got hit i'm rethinking that. 

einar4
03-03-2008, 06:54 PM
<p> Without going into too much detail, sites usually are picked not because of content but due to some known or newly discovered vulnerability of the host.  The "script-kiddies" run scripts they get from fairly common sources that scan for vulnerable sites and then use an attack on them.   These things aren't done to make a statement or protest or anything, they are just done to cause havoc. </p>

Calthine
03-03-2008, 07:54 PM
I'm told that if everything goes as planned, we should be back up tomorrow (Tuesday) morning, and past most of this mess.Thanks for your patience, everyone.

Spyderbite
03-03-2008, 07:56 PM
This bites. I know Stug misses me more than his rubber duckey. <img src="/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" border="0" alt="SMILEY" />

Ama
03-03-2008, 09:18 PM
<cite>Ikarri@Lucan DLere wrote:</cite><blockquote><p> Without going into too much detail, sites usually are picked not because of content but due to some known or newly discovered vulnerability of the host.  The "script-kiddies" run scripts they get from fairly common sources that scan for vulnerable sites and then use an attack on them.   These things aren't done to make a statement or protest or anything, they are just done to cause havoc. </p></blockquote>Ugg don't even talk to me about freakin script kiddies.  I ran a small server for Counter-Strike and had to deal with those punks.  Also hated it when they would come onto the Cybertron server screwing up the stats. 

Kaolian
03-03-2008, 10:23 PM
When we finally figure out who is behind this I've been told I get to feed them to the wombats!

Spyderbite
03-03-2008, 11:06 PM
<cite>Kaolian wrote:</cite><blockquote>When we finally figure out who is behind this I've been told I get to feed them to the wombats! </blockquote>Koalas.. they have blunt teeth, chew slower and usually fall asleep between meals. Much more painful. /nods

Stuge
03-04-2008, 03:35 PM
<span style="font-family: courier new,courier;">I wonder if it's the pipe or the equipment that can't stand up here.  Does Alla need to get tighter servers or does Alla need to find a better host?In any case, I blame the devs.  No reason.  That just seems the popular thing to do 'round these parts. <img src="/smilies/8a80c6485cd926be453217d59a84a888.gif" border="0" alt="SMILEY" />I kid.</span>

Spyderbite
03-04-2008, 07:57 PM
<cite>Stugein@Antonia Bayle wrote:</cite><blockquote><span style="font-family: courier new,courier;">In any case, I blame the devs.  No reason.  That just seems the popular thing to do 'round these parts.</span></blockquote>Yupper. You're spot on, Stug. Lazy, stupid, interns and don't care about any of the players. /nodsOk.. I couldn't say that with a straight face... sorry. XD

Calthine
03-04-2008, 10:25 PM
We're back, and we've every confidence that we won't poof any more.  Allakhazam posted a statement here:  <a rel="nofollow" href="http://eq2.allakhazam.com/sdetail.html?story=12500" target="_blank">http://eq2.allakhazam.com/sdetail.html?story=12500</a>

Ama
03-04-2008, 10:32 PM
<cite>Calthine wrote:</cite><blockquote>We're back, and we've every confidence that we won't poof any more.  Allakhazam posted a statement here:  <a rel="nofollow" href="http://eq2.allakhazam.com/sdetail.html?story=12500" target="_blank">http://eq2.allakhazam.com/sdetail.html?story=12500</a></blockquote>Well I'd becareful playing with the script kiddies cause they might get their friends involved that are real hackers.  It's kind of like the snob cheerleader queen who calls on her big boyfriend to shut someone up cause they talk about her.