Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Website that we were running was under DDOS couple of years ago, what we did is we took ips of servers that made ddos. Then we scanned the ports, found vulnerability in the application that was running on it then get into the server using this vulnerability. We checked open connections and found one used for command and control server (irc server) then we listened to irc channel. DDOSers were talking private things on that channel... Then we entered their channel and disabled all their bots using their own software that we got source from link pasted on their channel. Then we confronted them, period of silence after they have read what we wrote was priceless. They never ddosed us again.


These days I'd be worried about CFAA or otherwise getting V& for this. In the "good old days", it was possible to get away with and laugh about this type of vigilante justice. These days though, you're more likely to wind up in prison. No longer worth it for lulz. Sad times now, but good memories.


Honestly, my bigger concern would be motivating a retaliatory attack. A lot of the people who run botnets have big egos and respond poorly to this kind of challenge, especially when it can mean serious lost money for them. I've caused a retaliatory attack against a system I was responsible for once (thankfully not an important one) and I know at least one other security professional with a similar story - and in his case it was an important network and it stayed down due to retaliatory DDoS for long enough to generate a lot of upset people.

Any kind of active and specific pushback to malicious actors is poking a hornet's nest, and if done on the behalf of an employer, there should be serious discussion and acceptance of the risk of retaliation. Particularly with people running DDoS operations who, in my experience, tend to be a little immature.


I have had the opposite experience. What the author did here is something I've been doing for years (I've got quite a collection of crapware and have published a couple of articles about operating honeypots and honeynets). I occasionally drop in on the people running botnets and surprise them in their C&C channels. More often than not, the person is surprised and quiet and suspicious, and then curious. I get the sense there is some respect coming back the other way for whatever reason. I do spend time cataloging the botnet and its inventory and features, though I don't always present that information to the person running it. The worst reaction I've ever had was just having people hang up on me immediately after I reveal myself to them. They must think I'm law enforcement. Perhaps it's because I don't confront these guys in public, or that I don't antagonize them. I'm not sure. But I have never had anyone retaliate against me, and I have done this quite a lot over the years.


What they did at the time would still have definitely been illegal. Probably not any more illegal than it is now. I doubt they'd be prosecuted, but breaking into any system is illegal.


I'd just be afraid I'd have rotten luck and wind up on the wrong person's computer (government, big business, etc) because they happened to be part of a bot net. (I'm not ready to move to Moscow quite yet)


> I'm not ready to move to Moscow quite yet

Me neither, it's damn expensive


Well I'm sure they'll let you vacation for free... In the Siberian Gulags :)


Watch out. You laugh at this as if it's some Marvel Universe pop culture thing. In fact, some of the readers here have families that were sent to Siberia during or shortly after WW2. You wouldn't joke about concentration camps. I hope.


Technically, my grandmother went to a camp that was west of proper Siberia. (Something about being family of a war hero in what they called the Polish-Bolshevik war.)


Yes, this needs to be said. I've read stories about Siberian Gulags and they are really not something to joke about.


My grandfather. 1936.


Uggg sorry if I offended anyone.


People are being overly sensitive. Don't worry about it.


I don't think he was offended, just pointed out that it happened.

That said I found the original joke quite un-amusing and I think it didn't add much


Hitting people in the face is illegal; hitting people in the face in self-defense is legal. So... It would be interesting court case :)


Following them back to their house, picking the lock on their door, walking into their bedroom and hitting them in their face is not legal.


Nicely done! This would make a great scene in Mr. Robot :)


> found vulnerability in the application that was running on it

Could you give more a more detailed explanation on how you did that?


Go to http://sectools.org and look under "vuln scanners" on the left side menu.


I’ve had a very similar experience – I’m surprised I’m not the only one who did that.

I’d have expected the DDoSers to have better security


Botnets have notoriously bad security. Many of the people running them have no technical knowledge and/or are using "cracked" versions of paid botnet software that are backdoored or intentionally left unsecured. A lot of the software is heavily modified or even left incomplete by the person that leaked it, leading to vulnerabilities open to anybody with some technical competence and the time to poke around a little.


Unrelated to this discussion, I must compliment you on your chosen handle. I used a variation of that back in the day during Half-Life and early Counter-Strike. Zero and everything hehe. Cheers.


Why? DDOSers are mostly dumb skids who rent botnets.


Pretty much everyone is very bad at security


Serial DDoSers tend to have about the same level of computer knowledge as your parents. They just buy/rent botnets or pre-made software and templates to spread botnets.

And that's for the people actually hosting the botnet or "booter" (which seems to be what the parent poster found). Most of the time, it's one more layer down: just some kids paying for the right to enter an IP to DDoS temporarily.


This is brilliant. Hack the hackers! Heheh.


I wish HN had a `save` feature so I don't lose gems like these.


Just up-vote the stories and comments you want to save. When you view your profile on HN, you can see a list of your up-votes.


Most modern browsers still have bookmarking ability.


Use bookmarks feature. At least Chrome and FF allows you to sync it between different instances.

(Personally I use pinboard.in and would happily recommend it but I don't think everyone need it.)


There's no need. If you upvote the story you can find it again under 'upvoted stories' in your HN profile.

That said, pinboard.in is a decent service, and it's useful to have all your bookmarks in a central location.


When I use a desktop browser, I just right-click on the post age data and select "Save link as..." or "Bookmark This Link" or whatever.


are you Steve? I read a similar story a while back!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: