SlideShare a Scribd company logo
Booters
Things that you already know
and beyond
Jair Santanna
jairsantanna.com
11/10/2016
José Jair Cardoso de Santanna
Belém, Pará, Brazil
Hieperdepiep Hoera!!
Distributed Denial of
Service attack
a.k.a.
DDoS attack
DDoS attackHow many calls can you handle?
DDoS attack
Inter-actief presentation
Operation
Payback
Amazon, PayPal, MasterCard, Visa and the Swiss bank PostFinance
LOIC
Who can preform a DDoS attack?
12
Anyone!
Booter"DDoS as a $ervice"
"DDoS for Hire"
Stresser
15
Inter-actief presentation
No more opponents!!
No more ONLINE exams!!
Economic Impact!!
Booter"DDoS as a $ervice"
"DDoS for Hire"
Stresser ?????
Inter-actief presentation
It is not my fault!
Inter-actief presentation
Clear?!
2013
Inter-actief presentation
Database "Leakage"
Inter-actief presentation
2013
Inter-actief presentation
Booter Environment
Booter Environment
Direct
Indirect
Reflected
Booter Environment
Direct
Indirect
Reflected
Booter Environment
Direct
Indirect
Reflected
Booter Environment
Direct
Indirect
Reflected
Definition and Goals
Attacks
# Booter URL
Offer
[Gbps]
1 http://booter.tw ?
2 http://restricted-stresser.info 5
3 http://anonymous-stresser.net 5
4 http://destressbooter.com 25
5 http://flashstresser.net ?
6 http://dejabooter.com 10
7 http://rebel-security.com Up to 3
8 http://grimboot.com 6
9 http://quantumbooter.net 1,5
10 http://olympusstresser.org Up to 3
11 http://ebooter.5gbfree.com ?
12 http://vdoss.net ?
13 http://respawn.ca 8
14 http://onionstresser.com ?
Price [€]
10,90
1,95
3,12
3,89
3,89
3,89
3,00
3,90
8,00
4,90
free
3,11
3,90
3,90
€58,35
Unique IPs
8281
7369
6075
4486
3779
2970
281
78
54
Protocol
*DNS
*DNS
*DNS
*DNS
*Chargen
*DNS
*Chargen
*DNS
*DNS
Attacks
It is not my fault!
Reflection Attack
&
How the Internet works?
Reflected!
Client
Jair Server
(UDP)
Request
Response
"Amplified"
How attackers control the distributed source of attacks?
Reflected
Server
(UDP)
Client
Jair
Attacker
“Jair”
"Spoofed"
Request
Response
"Amplified" &
"Reflect"
Reflection Attack
0
1.5
3
4.5
6
7.5
0 20 40 60 80 100
Trafficrate[Gbps]
Time [s]
CharGen-based attacks DNS-based attacks
0
0.4
0.8
1.2
1.6
2
0 20 40 60 80 100
Trafficrate[Gbps]
Time [s]
NTP
CharGen
SSDP
Quake P.
Steam P.
QOTD
BitTorrent
Kad
NetBIOS
SNMP
DNS
556.9x
358.8x
108x
29x
Unique IPs
8281
7369
6075
4486
3779
2970
281
78
54
Protocol
*DNS
*DNS
*DNS
*DNS
*Chargen
*DNS
*Chargen
*DNS
*DNS
9427x
Unique IPs
8281
7369
6075
4486
3779
2970
281
78
54
Protocol
*DNS
*DNS
*DNS
*DNS
*Chargen
*DNS
*Chargen
*DNS
*DNS
Inter-actief presentation
CN
US
KR
RU
IN
TR
UA
FR
TH
DE
Top 10
1755
630
275
192
105
81
76
56
55
530 1755
US
JP
DE
RU
CN
NL
GB
CA
FR
TW
5822
1986
1909
1871
825
731
716
603
561
459
Top 10
0 5822
CharGen-based attacks DNS-based attacks
Inter-actief presentation
Clients
http://pastebin.com/
Timeline
Domain Registration
First attack
Passive DNS
15 Databases
Clients
Booters [market]
[under-revision]
Booters [market]
0
50
100
150
200
250
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
#Booters
Time
Registration Date
Expiration Date
Registration Interval
First Passive DNS
10
50
100
200
300
wif...com
exr....nl
ips...com
ano...comano...netone...netres...nfo
boo....in
rou...comsta...com
pow...comboo...orgboo....mlboo...xyzexp...orgnet....ec
qua...netspb...netstr...com
smo...comuns...comnet...com
dat...com
cst...net
str...net
evi...net
str....in
ddo...ity
abs...netpar...comdow...orgexi....to
vdo...cominb....me
the...com
boo...xyzyou...net
Gbits/sec
Max. Advertised Attack Rate
30k
100k
1M
3M
10M
0 10 20 30 40 50
AlexaRank(logscale)
Top 50 Booter
Booter Rank
exr..b.nl
boo...xyz
ips...comnet...com
exo..s.inorc...com
vbo...org
ddo..cityboo...com
cst...netaur...com
inb..t.me
vdo...com
str..e.ioque...com
pow...com
you...net
exi..s.tostr..clubstr..r.instr...netweb..r.co
boo...org
k-s..s.pwpar...com
qua...net
rag...net
spb...net
syn...net
tit...netalp...comhor..s.me
raw...com
ano...net
rek...com
vbo...com
rou...com
dar..r.fridd...net
ave...com
fra..g.nlddo...com
con...com
ddo...com
ips...comust..s.coxpl..r.pwjit...comnet..k.ec
rag...com
There are 300M registered domain names in the Internet
Booters [market]
Payment Systems
23 Booters
Payment Systems
Very good?
Payment Systems
0
10
20
30
40
50
60
70
80
90
#Booters
Payment Systems
June 2015
PayPal
Bitcoin
Paysafecard
CoinPayments
Starpass
Skrill
Litecoin
Youpass
Creditcard
OKPay
Payza
LibertyReserve
RSGP
PerfectMoney
TrueMoney
Amazon
Minecraftmarket
Moneylib
Starpass
Bitpay
GoCoin
December 2015
Payment Systems
“it is really tricky when private
organisations act as law
enforcement“
https://www.youtube.com/watch?v=wW5vJyI_HcU
DDoS Protection Companies
Ethical implications
[under-revision]
& civil disobedience
Mitigation?
Mitigation?
Payment Systems?!
Fail!
Mitigation?
at the Target ?!
http://ddosdb.org Big + Open
[under-revision]
Mitigation?at the access level ?!
http://booterblacklist.com
at the access level ?!
TOR node
What I’m working now?
Inter-actief presentation
On What I have assignment?
Inter-actief presentation
Booters
Things that you already know
and beyond
Jair Santanna
jairsantanna.com
11/10/2016
https://www.youtube.com/watch?v=VUSoC5BVZCU
jairsantanna.com
http://bit.ly/judge_jairs_presentation

More Related Content

PDF
Booter Blacklist: Unveiling DDoS-for-hire Websites
PDF
20160816 amlight popbahia_rnp_ansp
PDF
Civil Disobedience, DDoS attacks, Booters, and Beyond!
PDF
DDoS attacks and Booters -- *my thesis summary
PDF
20160613 TNC TERENA
PDF
20170926 Inter-Actief Lunchtalk Jair Santanna
PDF
20140313_tu_delft
PDF
DDoS attacks, Booters, and DDoSDB
Booter Blacklist: Unveiling DDoS-for-hire Websites
20160816 amlight popbahia_rnp_ansp
Civil Disobedience, DDoS attacks, Booters, and Beyond!
DDoS attacks and Booters -- *my thesis summary
20160613 TNC TERENA
20170926 Inter-Actief Lunchtalk Jair Santanna
20140313_tu_delft
DDoS attacks, Booters, and DDoSDB

More from University of Twente (8)

PDF
20170406 delft
PDF
Meeting Towards Collaboration for DDoS Attack Mitigation
PDF
20160416_de-cix
PDF
20160416_flamingo
PDF
20150909_network_security_lecture
PDF
20150311 bit module7_tbk_bit_lecture
PDF
20150909_cybercrime_cybersecurity_minor
PDF
20160316_tbk_bit_module7
20170406 delft
Meeting Towards Collaboration for DDoS Attack Mitigation
20160416_de-cix
20160416_flamingo
20150909_network_security_lecture
20150311 bit module7_tbk_bit_lecture
20150909_cybercrime_cybersecurity_minor
20160316_tbk_bit_module7
Ad

Recently uploaded (20)

PPTX
Lesson notes of climatology university.
PPTX
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
PDF
Classroom Observation Tools for Teachers
PPTX
GDM (1) (1).pptx small presentation for students
PDF
Module 4: Burden of Disease Tutorial Slides S2 2025
PPTX
Final Presentation General Medicine 03-08-2024.pptx
PDF
Chinmaya Tiranga quiz Grand Finale.pdf
PDF
STATICS OF THE RIGID BODIES Hibbelers.pdf
PDF
OBE - B.A.(HON'S) IN INTERIOR ARCHITECTURE -Ar.MOHIUDDIN.pdf
PDF
Trump Administration's workforce development strategy
PPTX
human mycosis Human fungal infections are called human mycosis..pptx
PDF
Computing-Curriculum for Schools in Ghana
PPTX
Cell Structure & Organelles in detailed.
PDF
GENETICS IN BIOLOGY IN SECONDARY LEVEL FORM 3
PPTX
PPT- ENG7_QUARTER1_LESSON1_WEEK1. IMAGERY -DESCRIPTIONS pptx.pptx
PPTX
Microbial diseases, their pathogenesis and prophylaxis
PPTX
Pharma ospi slides which help in ospi learning
PDF
VCE English Exam - Section C Student Revision Booklet
PDF
Yogi Goddess Pres Conference Studio Updates
PDF
A systematic review of self-coping strategies used by university students to ...
Lesson notes of climatology university.
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
Classroom Observation Tools for Teachers
GDM (1) (1).pptx small presentation for students
Module 4: Burden of Disease Tutorial Slides S2 2025
Final Presentation General Medicine 03-08-2024.pptx
Chinmaya Tiranga quiz Grand Finale.pdf
STATICS OF THE RIGID BODIES Hibbelers.pdf
OBE - B.A.(HON'S) IN INTERIOR ARCHITECTURE -Ar.MOHIUDDIN.pdf
Trump Administration's workforce development strategy
human mycosis Human fungal infections are called human mycosis..pptx
Computing-Curriculum for Schools in Ghana
Cell Structure & Organelles in detailed.
GENETICS IN BIOLOGY IN SECONDARY LEVEL FORM 3
PPT- ENG7_QUARTER1_LESSON1_WEEK1. IMAGERY -DESCRIPTIONS pptx.pptx
Microbial diseases, their pathogenesis and prophylaxis
Pharma ospi slides which help in ospi learning
VCE English Exam - Section C Student Revision Booklet
Yogi Goddess Pres Conference Studio Updates
A systematic review of self-coping strategies used by university students to ...
Ad

Inter-actief presentation