I was right after all - LizardSquad attacks explained

  • 52 results
  • 1
  • 2

This topic is locked from further discussion.

Avatar image for Shewgenja
Shewgenja

21456

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#1 Shewgenja
Member since 2009 • 21456 Posts

Long story short of it? LizardSquad has created a botnet (Kind of like Internet Zombies infected with their software and spewing the DDoS packets) out of people's routers that haven't configured the default administrative account credentials.

So for all this talk about Sony and MS needing better security that some of you have been complaining about, the real problem is Johnny and Susie Glue-eater that plugs in their Netgear router, configures their wifi network and continues to let the internet be their septic tank.

I hope some of you feel awfully silly right now but even moreso, I hope some of you reading this log into your routers and set proper credentials.

You'd be completely nuts to think LizardSquad is the only hacker group who uses this type of infection to slave your systems, FYI.

Avatar image for SolidTy
SolidTy

49991

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#2  Edited By SolidTy
Member since 2005 • 49991 Posts

This is why my router password is admin because I believe in security.

I'm also thinking about upgrading to WEP level security as right now I'm free as the wind.

Avatar image for R3FURBISHED
R3FURBISHED

12408

Forum Posts

0

Wiki Points

0

Followers

Reviews: 7

User Lists: 0

#3 R3FURBISHED
Member since 2008 • 12408 Posts

So they're creating a library of peoples usernames and passwords? Yeah they're great people.

At least Anonymous is attacking jihadist websites, lizardsquad are just assholes

Avatar image for wolverine4262
wolverine4262

20832

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#4  Edited By wolverine4262
Member since 2004 • 20832 Posts

Shewgenja was right?!

Avatar image for mikhail
mikhail

2697

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#5 mikhail
Member since 2003 • 2697 Posts

Console gamers can thank the uneducated masses for their beloved online services being down so often...so I guess they can thank themselves.

Avatar image for mr_huggles_dog
Mr_Huggles_dog

7805

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

#6 Mr_Huggles_dog
Member since 2014 • 7805 Posts

Cool, looks like I'm part of the solution and not the problem.

Avatar image for RoboCopISJesus
RoboCopISJesus

2225

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#7 RoboCopISJesus
Member since 2004 • 2225 Posts

@Shewgenja said:

the real problem is Johnny and Susie Glue-eater

So consolites screwed themselves over?

Avatar image for CrownKingArthur
CrownKingArthur

5262

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#8  Edited By CrownKingArthur
Member since 2013 • 5262 Posts
@SolidTy said:

This is why my router password is admin because I believe in security.

I'm also thinking about upgrading to WEP level security as right now I'm free as the wind.

mate 'admin' is just not long enough (that's what she said).

that's why i go with 'password'.

Avatar image for lostrib
lostrib

49999

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#9 lostrib
Member since 2009 • 49999 Posts

yeah...that's how a DDoS works. It's not new

Avatar image for foxhound_fox
foxhound_fox

98532

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

#10 foxhound_fox
Member since 2005 • 98532 Posts

Wasn't it known that this was a DDoS attack from the start?

Avatar image for bldgirsh
BldgIrsh

3044

Forum Posts

0

Wiki Points

0

Followers

Reviews: 6

User Lists: 5

#11  Edited By BldgIrsh
Member since 2014 • 3044 Posts

@foxhound_fox said:

Wasn't it known that this was a DDoS attack from the start?

Hacker Group ‘Lizard Squad’ Hits Xbox Live and PlayStation Network with DDoS Attacks

Yep... dunno who stated otherwise.

Avatar image for foxhound_fox
foxhound_fox

98532

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

#12 foxhound_fox
Member since 2005 • 98532 Posts

@bldgirsh said:

@foxhound_fox said:

Wasn't it known that this was a DDoS attack from the start?

Hacker Group ‘Lizard Squad’ Hits Xbox Live and PlayStation Network with DDoS Attacks

Yep... dunno who stated otherwise.

Yeah, a hacker group using a DDoS attack... what's your point?

Avatar image for jhcho2
jhcho2

5103

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 2

#13  Edited By jhcho2
Member since 2004 • 5103 Posts

@bldgirsh said:

@foxhound_fox said:

Wasn't it known that this was a DDoS attack from the start?

Hacker Group ‘Lizard Squad’ Hits Xbox Live and PlayStation Network with DDoS Attacks

Yep... dunno who stated otherwise.

The problem is that an average system warrior doesn't know the distinction between a hack and a DDoS attack. All they know or care about is that the incident is an opportunity to potentially down-play their rival console's online network, and perhaps up-play their own online network on the basis of 'security', without any understanding of it. But that's System Wars 101 right?

Avatar image for bldgirsh
BldgIrsh

3044

Forum Posts

0

Wiki Points

0

Followers

Reviews: 6

User Lists: 5

#14 BldgIrsh
Member since 2014 • 3044 Posts

@foxhound_fox said:

@bldgirsh said:

@foxhound_fox said:

Wasn't it known that this was a DDoS attack from the start?

Hacker Group ‘Lizard Squad’ Hits Xbox Live and PlayStation Network with DDoS Attacks

Yep... dunno who stated otherwise.

Yeah, a hacker group using a DDoS attack... what's your point?

Trying to say that its been known as a DDoS for quite a while. Agreeing with your comment.

Avatar image for tymeservesfate
tymeservesfate

2230

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#15 tymeservesfate
Member since 2003 • 2230 Posts

ur never right.

Avatar image for SolidTy
SolidTy

49991

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#16  Edited By SolidTy
Member since 2005 • 49991 Posts

@CrownKingArthur said:
@SolidTy said:

This is why my router password is admin because I believe in security.

I'm also thinking about upgrading to WEP level security as right now I'm free as the wind.

mate 'admin' is just not long enough (that's what she said).

that's why i go with 'password'.

Nice. I'll be updating soon! :)

Avatar image for GreySeal9
GreySeal9

28247

Forum Posts

0

Wiki Points

0

Followers

Reviews: 41

User Lists: 0

#17 GreySeal9
Member since 2010 • 28247 Posts

I heard that tooting your own horn can turn you into B4X, which is a most undesirable outcome.

Avatar image for Shewgenja
Shewgenja

21456

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#18 Shewgenja
Member since 2009 • 21456 Posts

@foxhound_fox said:

Wasn't it known that this was a DDoS attack from the start?

That's not what was being debated and you know it. The point is this:

In the first few days of 2015, KrebsOnSecurity was taken offline by a series of large and sustained denial-of-service attacks apparently orchestrated by the Lizard Squad.

So, even a website fucking dedicated to cyber security was taken offline due to the DDoS. In other words, while System Wars factions were trying to One-Up each other over shit they don't know about and crying like a bunch of infants that had their little bottle taken away from them for a day or two whilst making threads DEMANDING more unecessary infrastructure, the truth of the matter is that untold numbers of networks were taking part of the attack and many more could be lying in wait to carry out something else.

If it connects to the internet, it can be taken down. Crying about a botnet taking down your consoles online is like bitching about it raining outside. Welcome to the year 2015, people.

Avatar image for Gue1
Gue1

12171

Forum Posts

0

Wiki Points

0

Followers

Reviews: 7

User Lists: 0

#19  Edited By Gue1
Member since 2004 • 12171 Posts

my router is wpa2 but is using the default pass. Not the "admin" one though, it actually has letters and numbers. I might change it now then.

People always explain what a DDOS attack is but not how it is done. I always though hackers had severs in place or something but this is actually very clever. Taking advantage of people's lack of knowledge about technology. There must be millions of people out there using not only WEP but the default pass too.

Avatar image for Phazevariance
Phazevariance

12356

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#21  Edited By Phazevariance
Member since 2003 • 12356 Posts

@CrownKingArthur said:
@SolidTy said:

This is why my router password is admin because I believe in security.

I'm also thinking about upgrading to WEP level security as right now I'm free as the wind.

mate 'admin' is just not long enough (that's what she said).

that's why i go with 'password'.

Password? Man, mine's still blank. works like a charm.

Avatar image for lostrib
lostrib

49999

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#22 lostrib
Member since 2009 • 49999 Posts

I guess I shouldn't use password as a password

Avatar image for ten_pints
Ten_Pints

4072

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

#23  Edited By Ten_Pints
Member since 2014 • 4072 Posts

I always roll with "password123" and I've only been hacked 14 times. Only n00bs use "password" or "admin".

Avatar image for bldgirsh
BldgIrsh

3044

Forum Posts

0

Wiki Points

0

Followers

Reviews: 6

User Lists: 5

#24 BldgIrsh
Member since 2014 • 3044 Posts

@lostrib said:

I guess I shouldn't use password as a password

Replace all the letters S with dollar signs. You can thank me later when that hacker 4chan can't access your accounts.

Avatar image for CrownKingArthur
CrownKingArthur

5262

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#25 CrownKingArthur
Member since 2013 • 5262 Posts

@getyeryayasout: nice

very nice

Avatar image for GreySeal9
GreySeal9

28247

Forum Posts

0

Wiki Points

0

Followers

Reviews: 41

User Lists: 0

#26 GreySeal9
Member since 2010 • 28247 Posts

@ten_pints said:

I always roll with "password123" and I've only been hacked 14 times. Only n00bs use "password" or "admin".

lol

Avatar image for Litchie
Litchie

34605

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

#28 Litchie
Member since 2003 • 34605 Posts

This is news?

Avatar image for jun_aka_pekto
jun_aka_pekto

25255

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#29 jun_aka_pekto
Member since 2010 • 25255 Posts

Gee. I can't even remember my router username and password because they're so convoluted. But, I have them in a text file stored somewhere.

Avatar image for SapSacPrime
SapSacPrime

8925

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#30 SapSacPrime
Member since 2004 • 8925 Posts

But the point is with all the money they take from you they could defend against DoS attacks, Lizard Squad are idiots and their timing was outright disgusting but they did prove a point.

Avatar image for FoxbatAlpha
FoxbatAlpha

10669

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#31 FoxbatAlpha
Member since 2009 • 10669 Posts

I know set my router on "septic spew" and locked in Sonys coordinates.

Avatar image for Shewgenja
Shewgenja

21456

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#32 Shewgenja
Member since 2009 • 21456 Posts

@GreySeal9 said:

I heard that tooting your own horn can turn you into B4X, which is a most undesirable outcome.

I can understand that sentiment but, as you can also see, people are actually learning from this. The thread is less about me being right and more about what can be done to solve the issue.

Avatar image for GrenadeLauncher
GrenadeLauncher

6843

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#33 GrenadeLauncher
Member since 2004 • 6843 Posts

My wifi password is 654321 for added security.

Avatar image for misterpmedia
misterpmedia

6209

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

#34 misterpmedia
Member since 2013 • 6209 Posts

lol @ people not knowing how to sign into their own router and change the deats so the password isn't 'password'. Top kek.

Avatar image for LegatoSkyheart
LegatoSkyheart

29733

Forum Posts

0

Wiki Points

0

Followers

Reviews: 16

User Lists: 1

#36  Edited By LegatoSkyheart
Member since 2009 • 29733 Posts

They are still jerks*.

Avatar image for Shewgenja
Shewgenja

21456

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#37 Shewgenja
Member since 2009 • 21456 Posts

@farrell2k said:

@Shewgenja said:

Long story short of it? LizardSquad has created a botnet (Kind of like Internet Zombies infected with their software and spewing the DDoS packets) out of people's routers that haven't configured the default administrative account credentials.

So for all this talk about Sony and MS needing better security that some of you have been complaining about, the real problem is Johnny and Susie Glue-eater that plugs in their Netgear router, configures their wifi network and continues to let the internet be their septic tank.

I hope some of you feel awfully silly right now but even moreso, I hope some of you reading this log into your routers and set proper credentials.

You'd be completely nuts to think LizardSquad is the only hacker group who uses this type of infection to slave your systems, FYI.

So you blame the non-technically-minded people who respond to advertising and buy a product that is promised to be safe and secure, instead of the billion dollar corporations who ship routers without default passwords? Right...

Well, from a support perspective, there has to be a default password. Just like every car has a key. It's just that most people don't have their keys hanging out in their front lawn quite the same way they have the default password still active on their routers.

These are just realities when it comes to anything IT related. People don't see the importance of information security so they are happy to have Password123 as their login for anything from their routerto even their credit card online statements. Typically, it's baby boomers.

Avatar image for StormyJoe
StormyJoe

7806

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#39  Edited By StormyJoe
Member since 2011 • 7806 Posts

@Shewgenja said:

Long story short of it? LizardSquad has created a botnet (Kind of like Internet Zombies infected with their software and spewing the DDoS packets) out of people's routers that haven't configured the default administrative account credentials.

So for all this talk about Sony and MS needing better security that some of you have been complaining about, the real problem is Johnny and Susie Glue-eater that plugs in their Netgear router, configures their wifi network and continues to let the internet be their septic tank.

I hope some of you feel awfully silly right now but even moreso, I hope some of you reading this log into your routers and set proper credentials.

You'd be completely nuts to think LizardSquad is the only hacker group who uses this type of infection to slave your systems, FYI.

They're a bunch of pimpled faced virgins who cannot walk up a single flight of stairs without wheezing.

Avatar image for freedomfreak
freedomfreak

52426

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#40  Edited By freedomfreak  Online
Member since 2004 • 52426 Posts

My router password was ridiculously long, so I just changed it to 'password'. Much easier that way.

Avatar image for Shewgenja
Shewgenja

21456

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#41 Shewgenja
Member since 2009 • 21456 Posts

@SapSacPrime said:

But the point is with all the money they take from you they could defend against DoS attacks, Lizard Squad are idiots and their timing was outright disgusting but they did prove a point.

Well, that's just the thing. They really didn't. For a carefully orchestrated DDoS with a large botnet, there isn't really a way of "securing" your network. You HAVE to understand what a DDoS is to get it. I was hoping this thread would get through to the naysayers such as yourself but it's becoming a dead horse.

A DDoS will, in effect, require you to have some things in place which are a ludicrous expense.

You can have a redundant datacenter with a fallback collocation (doubling your hardware and maintenance expenses).

You can pay for up to 8 times your normal bandwidth (Some DDoS can get even bigger than that, though, so you might still have that dastardly day or two of downtime that seems to be a mortal sin to the ignorant).

You can offer to pay some sort of ransom fee to the people negating access to your network (but more often than not, you become a target for multiple groups that way.)

And if you thought that past suggestion was bad there's an even worse one if you are a serious company such as Sony or MS.. Find a webhosting provider with an impossibly large network you can put your infrastructure on in the hopes that they have enough astronomical bandwidth at their disposal to see and thwart a packet flood at their gateway (Which, as it turns out, is something I used to do for a living). This service comes at a premium, of course. Said network may also retain the right to refuse service to you if you are deemed a nuisance to their operations.

Those are your options and I guaran-fucking-damn-tee you that neither XBox Live or PSN's server farms are on the same Time Warner Cable box or DSL modem you are connected to. We're not talking about changing your service fee from teh $60 plan to teh Ultra Deluximafied $120 a month one. We are talking about connectivity that is costing thousands and thousands ... tens or hundreds of thousands of dollars a month to maintain as it is. To the point where you have to decide whether you want software engineers and network engineers working on super cool Skype features/ Vue/whatever in your firmware updates or if you want to sacrifice all that cool shit because a day or two of DDoS is a mortal sin.

I won't try to explain this any more. It's just getting redundant. I hope one day you have a child as terrified of an invisible monster as you are. Then you will understand the hopelessness of arguing against ignorance.

Avatar image for SapSacPrime
SapSacPrime

8925

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#42 SapSacPrime
Member since 2004 • 8925 Posts

@Shewgenja:

MS managed to get XBL up and running -- intermittently at first granted -- a lot faster than Sony fixed PSN, I suppose this has nothing to do with a superior infrastructure and better response plan no?

Avatar image for dalger21
dalger21

2231

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#43 dalger21
Member since 2002 • 2231 Posts

I find it hilarious that people didn't know the difference between hacking and DDoS. Hilarious.

Avatar image for speedfog
speedfog

4966

Forum Posts

0

Wiki Points

0

Followers

Reviews: 18

User Lists: 0

#44 speedfog
Member since 2009 • 4966 Posts

@Shewgenja said:

@foxhound_fox said:

Wasn't it known that this was a DDoS attack from the start?

That's not what was being debated and you know it. The point is this:

In the first few days of 2015, KrebsOnSecurity was taken offline by a series of large and sustained denial-of-service attacks apparently orchestrated by the Lizard Squad.

So, even a website fucking dedicated to cyber security was taken offline due to the DDoS. In other words, while System Wars factions were trying to One-Up each other over shit they don't know about and crying like a bunch of infants that had their little bottle taken away from them for a day or two whilst making threads DEMANDING more unecessary infrastructure, the truth of the matter is that untold numbers of networks were taking part of the attack and many more could be lying in wait to carry out something else.

If it connects to the internet, it can be taken down. Crying about a botnet taking down your consoles online is like bitching about it raining outside. Welcome to the year 2015, people.

You sound mad.

Avatar image for Shewgenja
Shewgenja

21456

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#45 Shewgenja
Member since 2009 • 21456 Posts

@SapSacPrime said:

@Shewgenja:

MS managed to get XBL up and running -- intermittently at first granted -- a lot faster than Sony fixed PSN, I suppose this has nothing to do with a superior infrastructure and better response plan no?

Much larger network. Live is behind all of MSes infrastructure which is very robust. Sony hasn't had the same footprint in that sense (MSN, Bing, Azure, etc).

Avatar image for Snugenz
Snugenz

13388

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#46  Edited By Snugenz
Member since 2006 • 13388 Posts

@speedfog said:

@Shewgenja said:

@foxhound_fox said:

Wasn't it known that this was a DDoS attack from the start?

That's not what was being debated and you know it. The point is this:

In the first few days of 2015, KrebsOnSecurity was taken offline by a series of large and sustained denial-of-service attacks apparently orchestrated by the Lizard Squad.

So, even a website fucking dedicated to cyber security was taken offline due to the DDoS. In other words, while System Wars factions were trying to One-Up each other over shit they don't know about and crying like a bunch of infants that had their little bottle taken away from them for a day or two whilst making threads DEMANDING more unecessary infrastructure, the truth of the matter is that untold numbers of networks were taking part of the attack and many more could be lying in wait to carry out something else.

If it connects to the internet, it can be taken down. Crying about a botnet taking down your consoles online is like bitching about it raining outside. Welcome to the year 2015, people.

You sound mad.

He's offended on the company he worships behalf for some bizarre reason.

Moogenja gonna moo.

Avatar image for Shewgenja
Shewgenja

21456

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#47 Shewgenja
Member since 2009 • 21456 Posts

@Snugenz said:

He's offended on the company he worships behalf for some bizarre reason.

Moogenja gonna moo.

It must really make you cross to know you posted this right after I praised MS for having a more robust infrastructure than Sony literally in the post directly above. Good work!

Avatar image for Snugenz
Snugenz

13388

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#48 Snugenz
Member since 2006 • 13388 Posts

@Shewgenja said:

@Snugenz said:

He's offended on the company he worships behalf for some bizarre reason.

Moogenja gonna moo.

It must really make you cross to know you posted this right after I praised MS for having a more robust infrastructure than Sony literally in the post directly above. Good work!

Not at all actually. toodles.

Avatar image for ej902
EJ902

14338

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#49 EJ902
Member since 2005 • 14338 Posts

Sounds about right, DDOS is difficult to protect against. It's important that people practice better networking security, I'd first advise them to throw away their botnet routers and burn them to kill the bots inside, then buy a new router that doesn't use a password so hackers can't guess what the password is.

Avatar image for ButDuuude
ButDuuude

1907

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#50  Edited By ButDuuude
Member since 2013 • 1907 Posts

I thought we already knew this here.

I spray bug spray on my computer once a week, so I should be fine.