Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Anonymous is planning to bring down the internet. March 31.
#1
Anymous Wrote:"The greatest enemy of freedom is a happy slave."

To protest SOPA, Wallstreet, our irresponsible leaders and the beloved
bankers who are starving the world for their own selfish needs out of
sheer sadistic fun, On March 31, anonymous will shut the Internet down.

In order to shut the Internet down, one thing is to be done. Down the
13 root DNS servers of the Internet. Those servers are as follow:

A 198.41.0.4
B 192.228.79.201
C 192.33.4.12
D 128.8.10.90
E 192.203.230.10
F 192.5.5.241
G 192.112.36.4
H 128.63.2.53
I 192.36.148.17
J 192.58.128.30
K 193.0.14.129
L 199.7.83.42
M 202.12.27.33

By cutting these off the Internet, nobody will be able to perform a
domain name look-up, thus, disabling the HTTP Internet, which is,
after all, the most widely used function of the Web. Anybody entering
"http://www.google.com" or ANY other url, will get an error page,
thus, they will think the Internet is down, which is, close enough.
Remember, this is a protest, we are not trying to 'kill' the Internet,
we are only temporarily shutting it down where it hurts the most.

While some ISPs uses DNS caching, most are configured to use a low
expire time for the cache, thus not being a valid failover solution
in the case the root servers are down. It is mostly used for speed,
not redundancy.

We have compiled a Reflective DNS Amplification DDoS tool to be used for
this attack. It is based on AntiSec's DHN, contains a few bugfix, a
different dns list/target support and is a bit stripped down for speed.

The principle is simple; a flaw that uses forged UDP packets is to be
used to trigger a rush of DNS queries all redirected and reflected to
those 13 IPs. The flaw is as follow; since the UDP protocol allows it,
we can change the source IP of the sender to our target, thus spoofing
the source of the DNS query.

The DNS server will then respond to that query by sending the answer to
the spoofed IP. Since the answer is always bigger than the query, the
DNS answers will then flood the target ip. It is called an amplified
because we can use small packets to generate large traffic. It is called
reflective because we will not send the queries to the root name servers,
instead, we will use a list of known vulnerable DNS servers which will
attack the root servers for us.

DDoS request ---> [Vulnerable DNS Server ] <---> Normal client requests
\
| ( Spoofed UDP requests
| will redirect the answers
| to the root name server )
|
[ 13 root servers ] * BAM

Since the attack will be using static IP addresses, it will not rely
on name server resolution, thus enabling us to keep the attack up even
while the Internet is down. The very fact that nobody will be able to
make new requests to use the Internet will slow down those who will try
to stop the attack. It may only lasts one hour, maybe more, maybe even
a few days. No matter what, it will be global. It will be known.

-----------------------------------------------------------------------

download link in #opGlobalBlackout
The tool is named "ramp" and stands for Reflective Amplification. It is
located in the \ramp\ folder.

----------> Windows users

In order to run "ramp", you will need to download and install these two
applications;

WINPCAP DRIVER - http://www.winpcap.org/install/default.htm
TOR - http://www.torproject.org/dist/vidalia-bundles/

The Winpcap driver is a standard library and the TOR client is used as
a proxy client for using the TOR network.

It is also recommended to use a VPN, feel free to choose your own flavor of this.

To launch the tool, just execute "\ramp\launch.bat" and wait. The attack
will start by itself.

----------> Linux users

The "ramp" linux client is located under the \ramp\linux\ folder and
needs a working installation of python and scapy.

Read more: http://www.disclose.tv/forum/on-march-31...z1modrC1Jn

"He who sacrifices freedom for security deserves neither."
Benjamin Franklin

We know you won't listen. We know you won't change. We know it's because
you don't want to. We know it's because you like it how it is. You bullied
us into your delusion. We have seen you brutalize harmless old womans who were
protesting for peace. We do not forget because we know you will only use that
to start again. We know your true face. We know you will never stop. Neither
are we. We know.

We are Anonymous.
We are Legion.
We do not Forgive.
We do not Forget.
You know who you are, Expect us.

Does anyone think this will really happen or is even real?
Discuss.

EDIT: Source: http://pastebin.com/GFkQnf6e
Reply
#2
Jesus christ. So it's only knocking down browsers?
Reply
#3
"Allow me to recite my diabolical scheme in detail before I kill you."
Reply
#4
Onion Knight Wrote:"Allow me to recite my diabolical scheme in detail before I kill you."

You cant totally totally compare a Evil villain talk with the hero of the story with a message thrown by anonymous not only to make the attack known to the general public, but also recluiting henchmen to carry the attack. But ok.

Also Black march absolute failure then? I think this is the 3 Op of the month.
Reply
#5
Onion Knight Wrote:"Allow me to recite my diabolical scheme in detail before I kill you."

I think it's more of a flex of power because they are confident nothing can stop it at this point, just by sheer number.
Reply
#6
I made that quip on the blind assumption that these supposed "roots" where every single piece of data sent over HTTP passes through at least once are not completely unguarded or surceptible to DDoSes and are being protected by some of the best network security teams and software out there. Posting up something like this in such detail as an activist is just kind of silly if the aforementioned assumption is true, like basically asking for your diabolical scheme to be foiled.

Huge assumption I know.
Reply
#7
Onion Knight Wrote:I made that quip on the blind assumption that these supposed "roots" where every single piece of data sent over HTTP passes through at least once are not completely unguarded or surceptible to DDoSes and are being protected by some of the best network security teams and software out there. Posting up something like this in such detail as an activist is just kind of silly if the aforementioned assumption is true, like basically asking for your diabolical scheme to be foiled.

Huge assumption I know.

Just because something has tight security doesn't mean it can't be broken.

Stuxnet, for one thing.

Anon has the capacity to do this. The fact they announced it as early as a month ago proves it'll most likely happen.
Reply
#8
Takebacker Wrote:Just because something has tight security doesn't mean it can't be broken.

Stuxnet, for one thing.

Anon has the capacity to do this. The fact they announced it as early as a month ago proves it'll most likely happen.

Like my dad use to say, "If it was made by a human, a human can easily unmade it too"
Reply
#9
Takebacker Wrote:Just because something has tight security doesn't mean it can't be broken.

Stuxnet, for one thing.

Anon has the capacity to do this. The fact they announced it as early as a month ago proves it'll most likely happen.

This. There is always a way to crack a security no matter how great it is. It's just a matter of time before
someone finds out how to crack it. And in my personal oppinion, though it sounds really unlikely to shut
down the entire internet for everyone in the world. I do think that it's possible so i'm not going to mark this
as something impossible.
Reply
#10
I see it more as a nuisance if anything. This doesn't do anything for me, I'll be at a wedding.
Reply
#11
Remember that internet worm that was supposedly going to be released a few years ago? It never happened. I don't expect this to happen either.
Reply
#12
Killing the internet itself its a pretty big task, even for anonymous.

Shutting down the translators of the internet (The ones that takes an IP address and make it a word and viceversa) its something much more feasible., They themselves have said so, if you try to enter the "WWW.Southperry.com" address it should not work (If they suceed), but if you enter the IP of the southperry website instead it should pass.
Reply
#13
Won't believe it til I see it.
Reply
#14
You'd think somebody would've done it already.
Reply
#15
well at least I'lll have a reason to study >.O
Reply
#16
Corn Wrote:You'd think somebody would've done it already.

Few people have a grudge against Corporate bastards, and Even Few people only use the internet as their Weapon of choice.
Reply
#17
They are doing it the wrong way. The load bearing of even one of those root servers could handle all of anon combined; spreading their resources across all 13 is flat retarded. I couldn't say what a good way to do this for real would be, but then, that's not something I'm interested in doing in the first place.

edit: actually, I'm not sure how their "reflective DDoSing" would even work, or if they are just making pomegranate up to sound like a threat. Either way, I still don't think it would be enough to work, UNLESS they targeted much fewer (more like, one) of the servers.
Reply
#18
Let's just wait for @Eos to essentially make us all look like idiots about this.
Reply
#19
FenixR Wrote:Few people have a grudge against Corporate bastards, and Even Few people only use the internet as their Weapon of choice.

You underestimate the evil of the world, my friend.
Reply
#20
I'm more shocked that the internet has 13 root servers.
Seriously. that's just asking for bad luck.
Reply


Forum Jump:


Users browsing this thread: 2 Guest(s)