LIZARD SQUAD is Back. Planning XBL Attack. "Biggest attack yet". [UP: XBL/PSN Down]

Anonymous posted a picture of one of the guys on Twitter along with his address:

If that's true or not I have no idea.

Saw where a bunch of people were supposedly driving to his address to beat the shit out of him.

Not good.

Oh man guess I gotta keep my eye cp24 in the morning.
 
This is what I never understood about hackers - or cheaters or a number of other people : What makes you think if you can't do something that someone else doesn't have the same abilities you do and also disagree with what you're doing? This thought is what keeps me from ever using my abilities for evil atleast.



"Prank videos", "reality" tv, news articles, Facebook contests.... it's 2014, nothing is real anymore, don't believe anything without proof.

I question your reasoning about not using your abilities for evil. You shouldn't use it for malicious purposes because it's wrong, not because you're afraid someone is going to make you look foolish.
 
smh...

The worst part is all you need is a basic understanding of the internet to understand why this isn't preventable. You don't need to be in "infosec"

This thread just people coming in without reading the rest of the thread or understanding how the internet works and complaining about companies being stupid and/or greedy over and over again while they try to defend themselves instead of learning why the problem exists.

That could be said for a lot of things here, where you wonder if people read the OP or why they asked a question answered two posts above them.

I question your reasoning about not using your abilities for evil. You shouldn't use it for malicious purposes because it's wrong, not because you're afraid someone is going to make you look foolish.

The latter is why I don't do most things such as lie, cheat and steal. Not everything - or everyone - is like that though; I believe there was a book made long ago under the idea a lot of people need a higher incentive for not acting like an asshole.

The thought is there, I can't control what I think but I can control how I act. Earlier today someone posted FedEx gifs of employees throwing packages, and I'm sure everyone has wanted to take shortcuts at work. Do they not think what if they ordered something how they'd want it treated? Empathetic reasoning like that influences some decisions I make.
 
Anonymous posted a picture of one of the guys on Twitter along with his address:


If that's true or not I have no idea.

Saw where a bunch of people were supposedly driving to his address to beat the shit out of him.

Not good.
Don't post private information on GAF man, might want to edit your post.
 
Forgive my ignorance, but you and others are making it sound as if there is no defense against this. Is that correct? If so, really sucks that some asshole can do this whenever the urge arrives.

There are defenses against DDoS attacks such as server load balancing, cloud mitigation and application-layer blocks. At a certain scale though, many of these defenses become unfeasible against large-scale attacks. Especially when methods of mitigating these attacks require tens of millions of dollars worth of hardware and external services that can't be acquired over a single weekend.

This also isn't carried out by a single asshole as you put it. DDoS attacks are carried out by infected machines via malware. When your grandmother installs a shitty toolbar on her computer, there's a good change she's installing malicious software that uses her computer to aid in these attacks against large organizations.

The complexity of these botnet networks grow exponentially every year.
 
Forgive my ignorance, but you and others are making it sound as if there is no defense against this. Is that correct? If so, really sucks that some asshole can do this whenever the urge arrives.

An extremely simplified version, is it is a numbers game. A server can handle an onslaught to so many zombie asshole computers trying to knock on a door. So lets say a server can handle 500 asshole computers banging on it at the same time before a second server needs to be added to help.... only the asshole computers cost pennies or less, and the servers cost thousands. When you get up to 10's of thousands of ass hole computers banging on the door, either you reach the end of servers available or the cost incurred is so great it is not longer feasible or practical to deal with.

Whats worse, the reactions. It is like being in a McDonalds that is getting robbed and bitching that our McNuggets are cold... or that McDonalds food is crap anyway so they deserved to be robbed.
 
So I turned off my ps4 hours ago and decided to watch some movies instead.

What's the word on the #VirginSquad ladies and gents? Did their Mom's make them go to bed yet? I don't feel like reading through the past several pages to get caught up on the saga.

Where's Lionel?
^^^
Got stuck at the bottom of the damn page.
 
Anonymous posted a picture of one of the guys on Twitter along with his address:

If that's true or not I have no idea.

Saw where a bunch of people were supposedly driving to his address to beat the shit out of him.

Not good.

Onatario, never heard of the place :P

He's from Toronto. What a jerk.

Can't say I have any respect for anyone that'd be dumb enough to do anything to this person whether he has anything to do with it or not.
 
So I turned off my ps4 hours ago and decided to watch some movies instead.

What's the word on the #VirginSquad ladies and gents? Did their Mom's make them go to bed yet? I don't feel like reading through the past several pages to get caught up on the saga.

They are oddly consistent on when they call a stop for the day (usually around 1-2am EST). That's what they claim on Twitter anyway.

jwD6V8w.png


Boom.

The attack maps are still showing quite a bit of action still, but it does appear to be winding down. It will take several hours for things to start feeling right again, I think. However, there's a good chance the attackers will fire up the botnet again tomorrow.
 
Anonymous posted a picture of one of the guys on Twitter along with his address:

<I'm not quoting that link>

If that's true or not I have no idea.

Saw where a bunch of people were supposedly driving to his address to beat the shit out of him.

Not good.

Is this like the last time when Finest supposedly released all of that info about Lizard? Or the time a few months back when some other group did the same thing and released some info about Lizard?

Come on...
 
Forgive my ignorance, but you and others are making it sound as if there is no defense against this. Is that correct? If so, really sucks that some asshole can do this whenever the urge arrives.

As I posted in the DDOS thread:
"It's like a prankster has 100 friends he calls up and says, "Everyone go park your car at this McDonalds and block all legitimate customers from going there.

...and then everyone blames McDonalds for not having enough parking spaces."
 
Why people on GAF continue to post information from Anonymous Twitter accounts is beyond me. As the recent Antonio Martin shooting thread proved, they often create misinformation to stir their political pot in the name of social justice.

Stop posting this shit.
 
You know why they attack psn and xbl and not google or amazon or something?

Cause they wanna piss off teenagers and see their reactions like 'fuck off lizard' etc.

If they hacked google or amazon, no teenager would give a shit. I think we should just ignore it and maybe they'll shift their attention to something else. Insult them, tweet them etc... Is just feeding them
 
But you don't seem to have a grasp on how this works do the analogy is lost on you. So go ahead and be mad at Sony for not having magic dust in their days centers.

I honestly laughed at how someone with "engineer" in his name can't grasp the analogy.

PSN Japan seems ok.
 
As I posted in the DDOS thread:
"It's like a prankster has 100 friends he calls up and says, "Everyone go park your car at this McDonalds and block all legitimate customers from going there.

...and then everyone blames McDonalds for not having enough parking spaces."

This is a crappy metaphor because McDonalds can just call the cops and have them towed.
 
Thanks for the info, guys. I had an idea what ddos was, but it sounds like it takes some time to pull this type of thing off.
 
Has anyone moved from being angry at Lizard Squad, disappointed with Finest Squad, and annoyed with Sony?

I mean, how can they not withstand some botnet that a bunch of chavs spin up on your authentication servers? It's far on Sony's shoulders now and they SHOULD be embarrassed.

Guys ignore this clown. ^^^^ It's super obvious he is just trying to stir the pot. Nobody reply to him and he will go away.
 
You know why they attack psn and xbl and not google or amazon or something?

Cause they wanna piss off teenagers and see their reactions like 'fuck off lizard' etc.

If they hacked google or amazon, no teenager would give a shit. I think we should just ignore it and maybe they'll shift their attention to something else. Insult them, tweet them etc... Is just feeding them

They're attacking Sony and Microsoft's video game services because those respective audiences are vocal on the internet and basically provide free advertising for the effectiveness of their botnet networks. Also, attacking Google or Amazon would require FAR more resources.
 
It's a symbol of a movement, among other things :)

Be careful of symbols, especially ones attached to movements. The movement can change, and people might think that just because the symbol is still the same, the movement is.

I think we should just ignore it and maybe they'll shift their attention to something else. Insult them, tweet them etc... Is just feeding them

Ignoring a sociopath or bully has very little evidence proving that it makes them give up. If anything, it usually results in an escalation from them, raising the stakes higher and higher to see how far they have to go before they get a reaction. I'm not saying we *should* give them a reaction, but avoiding it entirely just leaves a them-shaped hole being talked around, and can cause more problems. I'm more for education over ignorance.

This is a crappy metaphor because McDonalds can just call the cops and have them towed.

Not to strain a metaphor, because that's kinda against the point, but before the cops arrive the 100 people blocking the McDs just go to another McDs. Cops are called, cycle repeats. In a way, this is a bit like current DDoS mitigation - most mitigation is based on responding to an existing threat, analyzing it, then deploying a countermeasure of sorts. So, after a while the cops might wise up and send a cop to every single McDs in the city, waiting, with tow trucks et all - and the reign of terror of the parkinglot blockers ends. But not before massive costly police action that resulted in nobody being arrested.

So, the next day, should the cops wait at every McDs in the city again, just in case? Who foots the bill? How long do they need to keep doing it, just in case? - This is the problem with costly DDoS mitigation. It costs money to set up, it costs money to maintain.
 
Can they require some kind of encrypted connection from consoles? Reject all inbound attempts that don't have the right keys.
The sheer amount of connections probably fry any prevention though. :(
 
Why people on GAF continue to post information from Anonymous Twitter accounts is beyond me. As the recent Antonio Martin shooting thread proved, they often create misinformation to stir their political pot in the name of social justice.

Stop posting this shit.
So much this. Hell all the shit they did during Ferguson should've been proof enough.
 
I can't understand how Live and PSN crumble in the face of a DDOS. Microsoft has been doing this kind of service for over a decade, does Azure shit the bed when this happens? And Google's services never seem to go down.

That's because they've learned. An acquaintance works at Google and he mentioned that Google has shared their knowledge with Facebook, Twitter etc. So it's hard to take down those companies with this type of DDOS attacks (same with Amazon). As mentioned here, it takes a lot of resources to implerment. I wish these awful kids will get caught soon.
 
Not sure if anyone has posted this. I thought it was interesting.
Infamous self-proclaimed cyber-terrorist group, Lizard Squad, chose December 25, 2014 to take down both Microsoft’s Xbox Live and Sony’s PlayStation Network. The group has been responsible for several past incidents, but today marks the organization’s largest attack. We virtually sat down and spoke to the group about their actions, motives, and the future to come.
WinBeta verified via multiple methods, that we were in fact speaking to the core members of the Lizard Squad. A verification file can still be found on their official website by clicking here.

The conversation took place through an encrypted connection, and as their Twitter account proudly proclaims, there would not have been a chance to track them down. Instead, we took the time to ask about the group’s methodology and ideology behind the series of attacks.
Lizard Squad explains that the task simply began for the laughs, but evolved into what they say is a real cause. Taking down Microsoft and Sony networks shows the companies’ inability to protect their consumers and instead shows their true vulnerability. Lizard Squad claims that their actions are simple, take down gaming networks for a short while, and forcing companies to upgrade their security as a result.

When asked why Microsoft and Sony where both targeted on Christmas day, the group explained they felt it would anger and reach the largest amount of people – more people angry calls for a greater response from the companies; others were considered, including Nintendo, but no action was taken. The group is attempting to stress the point of computer security, while also getting a few “laughs”.

Lizard Squad noted that they could take down NASDAQ if they wanted to damage the economy, but stated that it was not their goal; they jokingly refer to themselves as terrorists, but do not feel they are on that level of notorious mischief.
When asked which company was easier to bring down, Microsoft was the immediate response. They commented that Sony had recently upgraded their security, via a new system we will not mention here, which took a bit of time to work around, but that Microsoft simply had the poorest security – “almost nothing”. When asked how each company was fighting back – the group alluded to the idea that they were easily keeping the networks down.

When asked how long they would continue their series of intermittent attacks, the Lizard Squad stated that they would continue to do it until companies learned from their security issues – they were unwilling to comment on any timeframe.
http://www.winbeta.org/news/exclusi...squad-why-they-brought-down-xbox-live-and-psn
 
This is a crappy metaphor because McDonalds can just call the cops and have them towed.
Not exactly. With a DDoS you're essentially dealing with illegitimate legitimate traffic, which is what makes them so difficult to mitigate. I think a better metaphor would be hundreds or thousands of friends creating a traffic jam out front of McDonalds to prevent them from providing services to customers, which would be illegitimate legitimate traffic.

How do you discern between the real and fake traffic within the jam?
 
Metaphors help give a better understanding, they're not meant to be analyzed and critiqued in a literal sense.

Better metaphors give better understanding.

Not exactly. With a DDoS you're essentially dealing with illegitimate legitimate traffic, which is what makes them so difficult to mitigate. I think a better metaphor would be hundreds or thousands of friends creating a traffic jam out front of McDonalds to prevent them from providing services to customers, which would be illegitimate legitimate traffic.

How do you discern between the real and fake traffic within the jam?

Like this, this is much better.
 
Can they require some kind of encrypted connection from consoles? Reject all inbound attempts that don't have the right keys.
The sheer amount of connections probably fry any prevention though. :(

HaRyu said it best earlier in the thread:

Imagine you live in a house and you only let in people whom you designate as friends. Unfortunately, the only way to tell if someone is your friend is they have to ring a doorbell, and you have to go up to the door, open it and physically check if they are your friend or not before you let them in.

Now, if it was normal internet traffic, you can handle this simple task fairly well.

Now if a DDOS was going on, imagine millions of people (who have no business being there) rushing to your door, and each one constantly ringing the doorbell, and you having to keep getting back up, open the damn door, and check each one.

I mean, by your example, a system is already in place like that: authetication/security certificates. But like I said, you still have to actually check each connection to even verify. A DDOS is just the massive traffic spike while the server is going crazy trying to figure out who the hell is trying to come in.

why not just have your friends do a special door bell ring sequence? that way you know when its a friend or some random asshole.

Aha, you forget the part about the million assholes at your front door all trying to ring the doorbell.

Your legitimate friends might actually be in that million, and they're trying to get to the door... but they can't, because there's a million assholes trying to ring the damn doorbell.

By some miracle, one of your friends actually makes it to the doorbell, THEN you let them in. This is why during a DDOS attack, you might get amazingly lucky and actually be able to log in. By pure dumb luck, you managed to initiate a handshake and the server went "oh thank fucking god, someone who isnt an asshole" and lets you in.

But then you do the stupid thing, and realize that you forgot something in your car, so you have to go back outside. And goddamit, the only way back in is through those million assholes. This is also why if you're already logged in, you're could be perfectly fine, but as soon as you do the stupid thing and log out, you're screwed.

Hope that explains it a bit better.

Better metaphors give better understanding.

Dude, that's just splitting hairs. C'mon.
 
Not sure if anyone has posted this. I thought it was interesting.


[p]
Let us never stop giving them attention - Maybe Rolling a Stone can give them a cover too?
Okay where to start... started for laughs and became a real cause? Okay then.
How is doing something that makes them spend more money - something usually passed on to consumers - on something that only you've been doing a noble cause? Do they steal watches so walmart get more cameras too? Thanks I feel better now.
 
Top Bottom