BearShare Forums  

Go Back   Gnutella Forums > Current Gnutella Client Forums > BearShare (Windows) > BearShare Open Discussion
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

BearShare Open Discussion Open topic discussion for BearShare users

Preview this popular software (BearShare Beta v5 "Download")


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old September 14th, 2007
Share Junkie
 
Join Date: July 18th, 2007
Location: AZ
Posts: 41
Nick Storm is flying high
Default Denial of Service Attack?

I was watching my BS server run a few days ago, and noticed that uploads had dropped to zero, when there are normally 10 or 12 going on. I switched over to the Upload page, and saw huge lists of files (20 or more at a time) pop up in red, with the status of "authorizing". All of the "requests" appear to be from the same user (someone using Limewire, if it matters), and all vanish after a moment, then reappear a few seconds later. It kept on doing this until I rebooted BS.

It occurred to me that BS probably has a finite ceiling for the number of simultaneous inquiries it can handle, and if someone slammed it all at once (as in a classic DOS attack), they could clog up the works and prevent legitimate users from being able to get in. I've since noticed this happen several times now, and when it does, UL's drop to nothing. It will keep it up for an hour or so, then stop.

Granted, this might also just be some idiot batching files via Limewire, but the end result is not very pretty. And this is on a fast machine (2.8ghz dual cpu unit w/2 gig of ram). On systems with either a slower machine or a slower connection, it would clog things up quite nicely.

I may have to play with Limewire some to see if I can make it hit a specific address in such a manner.

Cheers

Nick
Reply With Quote
  #2 (permalink)  
Old September 15th, 2007
Peerless's Avatar
Riding a Pale Horse and Wielding THE Sword of the Forum
 
Join Date: June 19th, 2002
Location: Your Worst Nightmare
Posts: 2,993
Peerless is a jewel in the rough
Default

this is most likely macrovision doing this...there are a few others that do this, but not nearly to the intensity of macrovision...

what I want to know is how is this legally allowed?

just how do they know that any user is illegally using the network?...I know for a fact that none of my downloads or uploads carry any sort of copyright so its obvious they are blindly hammering every user they can on the network...aren't DDOS attacks illegal?

download and install PeerGuardian2 to in some way mitigate the effects of this, but trust me they can still knock you off of the network with the concentrated attacks you get from their IP range...
__________________


So Long and Thanks for All the Files
_____________________________________________

Beware of the big 3 insurance companies in Texas! Read your policies carefully (maybe you'll need a lawyer) Allstate, Farmers & State Farm are overextended and their 'coverage' is worthless...a true waste of your money Read This
Reply With Quote
  #3 (permalink)  
Old September 15th, 2007
Share Junkie
 
Join Date: July 18th, 2007
Location: AZ
Posts: 41
Nick Storm is flying high
Default DOS Attacks

I tried to discern the originating IP addresses, but didn't find a way to see them. If I could find out where they're coming from, I think I could convince them to leave me alone. I have no problem shutting down their email server if they persist in doing this. Of course, I need to know WHO it is, before I can respond in kind.

Cheers

Nick
Reply With Quote
  #4 (permalink)  
Old September 15th, 2007
Peerless's Avatar
Riding a Pale Horse and Wielding THE Sword of the Forum
 
Join Date: June 19th, 2002
Location: Your Worst Nightmare
Posts: 2,993
Peerless is a jewel in the rough
Default

if you install PG2 it will display all the attempts at connections by blocked IPs....as noted, I've found macrovision to be the worst offender...
__________________


So Long and Thanks for All the Files
_____________________________________________

Beware of the big 3 insurance companies in Texas! Read your policies carefully (maybe you'll need a lawyer) Allstate, Farmers & State Farm are overextended and their 'coverage' is worthless...a true waste of your money Read This
Reply With Quote
  #5 (permalink)  
Old September 15th, 2007
Share Junkie
 
Join Date: July 18th, 2007
Location: AZ
Posts: 41
Nick Storm is flying high
Default DOS Attacks

Thanks... I'll have to check that out. I've never blocked an IP address using BS. Isn't that done via the Hostiles list?

Nick
Reply With Quote
  #6 (permalink)  
Old September 15th, 2007
Share Junkie
 
Join Date: July 18th, 2007
Location: AZ
Posts: 41
Nick Storm is flying high
Default DOS Legality

BTW, Denial of Service attacks are illegal, but if someone is hassling a P2P file-sharing network, they have to figure they can get away with it, as most law enforcement consider us "criminals".
Reply With Quote
  #7 (permalink)  
Old September 15th, 2007
AaronWalkhouse's Avatar
***ּLegendary Axeman***ּ
 
Join Date: January 17th, 2005
Location: My igloos melt in June.
Posts: 1,974
AaronWalkhouse is a great assister to others; your light through the dark tunnel
Default

It looks like you have not enabled the IP address column in the uploads view. Right-click any
column header in any view to see a list of available columns. By default less than a third of them
are enabled.
Reply With Quote
  #8 (permalink)  
Old September 15th, 2007
Share Junkie
 
Join Date: July 18th, 2007
Location: AZ
Posts: 41
Nick Storm is flying high
Default UL display

Ahh... (thumping head on desk). Gracias. I should have looked for that. Suffering from CRS (Can't Remember Sh*t).

Nick
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 10:34 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.