Author Topic: AvailsMew/AnimalSwivel - DoS attacker  (Read 2741 times)

[ Any logs I post in this topic can be verified by 5 forumers. ]
Everything started here: http://forum.blockland.us/index.php?topic=253559.msg7353581#msg7353581
I added this individual into a Skype group chat I had going on quite a while ago, in preparation for a fun tabletop RP experience. One thing led to another, and I ended up not actually doing it until today.
Today I got everyone in the group together, scheduled a time, and made a Skype call to everyone in the group. An individual called "Che Ven" was a part of this Skype group.
I made the call, and Che Ven joined in. He also added about 10 different alts into the chat.

Here's some logs:
Quote
> [Saturday, March 29, 2014 12:49:31 PM Che Ven] Add my new account please
> [Saturday, March 29, 2014 12:49:34 PM Che Ven] It is xepherr
> [Saturday, March 29, 2014 12:49:40 PM Che Ven] [12:49:40 PM] * Che Ven invited xepherr
> [Saturday, March 29, 2014 12:49:49 PM Lugnut] just call in or something
> [Saturday, March 29, 2014 12:49:50 PM lordfeline] Its 'Zephyr' but with more edge
> [Saturday, March 29, 2014 12:50:03 PM xepherr] [12:50:03 PM] * xepherr invited hf.xepherr
> [Saturday, March 29, 2014 12:50:04 PM xepherr] [12:50:04 PM] * xepherr invited xepherr2
> [Saturday, March 29, 2014 12:50:04 PM xepherr] [12:50:04 PM] * xepherr invited xepherr3
> [Saturday, March 29, 2014 12:50:05 PM xepherr] [12:50:05 PM] * xepherr invited xepherr8
> [Saturday, March 29, 2014 12:50:06 PM xepherr] [12:50:06 PM] * xepherr invited xepherr4
> [Saturday, March 29, 2014 12:50:07 PM xepherr] [12:50:07 PM] * xepherr invited xepherr5
> [Saturday, March 29, 2014 12:50:07 PM xepherr] [12:50:07 PM] * xepherr invited xepherr6
> [Saturday, March 29, 2014 12:50:08 PM xepherr] [12:50:08 PM] * xepherr invited xepherr7
> [Saturday, March 29, 2014 12:50:09 PM xepherr] [12:50:09 PM] * xepherr invited xepherr9
> [Saturday, March 29, 2014 12:50:10 PM xepherr] [12:50:10 PM] * xepherr invited xepherr10
> [Saturday, March 29, 2014 12:50:28 PM lordfeline] there goes the neighborhood
> [Saturday, March 29, 2014 12:50:42 PM Lugnut] [12:50:42 PM] * Lugnut kicked hf.xepherr from the chat.
> [Saturday, March 29, 2014 12:51:09 PM xepherr] MY CHE VENS ARE BEAUTIFUL
> [Saturday, March 29, 2014 12:51:15 PM lordfeline] Highly debatable
I kicked hf.xepherr as a test to check my kicking ability. Right around this time, over voice, Che Ven asked "how to run a perl script on CentOS?" (CentOS is a version of linux designed for use on server computers)  Apparently, Che Ven didn't care for me kicking people:
Quote
> [Saturday, March 29, 2014 1:00:22 PM xepherr7] IF YOU KICK ME
> [Saturday, March 29, 2014 1:00:26 PM xepherr7] I SWEAR TO loving GOD
> [Saturday, March 29, 2014 1:00:32 PM xepherr7] I WILL BUY A VPS AND HIT YOU WITH CHARGEN FOR WEEKS AT A TIME
> [Saturday, March 29, 2014 1:01:09 PM lordfeline] motherforgeter ill beat you with the ac adapter from an intellivision
> [Saturday, March 29, 2014 1:01:25 PM xepherr] SEE
> [Saturday, March 29, 2014 1:01:28 PM xepherr] NOW I HAVE TO LEARN CENTOS
> [Saturday, March 29, 2014 1:01:37 PM xepherr] MY 5 USD VPS IS ON CENTOS
> [Saturday, March 29, 2014 1:01:38 PM xepherr] mondayrichardL
(I missed the bit about "Chargen" at the time, as I was trying to get 5 uncooperative individuals into one Skype call.) Anyway, I got tired of the BS with the dozen alts, so I kicked them all (manually, because you can't mass kick in skype?)
Quote
> [Saturday, March 29, 2014 1:02:34 PM Lugnut] [1:02:34 PM] * Lugnut kicked xepherr from the chat.
> [Saturday, March 29, 2014 1:02:42 PM Lugnut] [1:02:42 PM] * Lugnut kicked xepherr3 from the chat.
> [Saturday, March 29, 2014 1:02:43 PM Lugnut] [1:02:43 PM] * Lugnut kicked xepherr4 from the chat.
> [Saturday, March 29, 2014 1:02:45 PM Lugnut] [1:02:45 PM] * Lugnut kicked xepherr5 from the chat.
> [Saturday, March 29, 2014 1:02:49 PM Lugnut] [1:02:49 PM] * Lugnut kicked xepherr6 from the chat.
> [Saturday, March 29, 2014 1:02:51 PM Lugnut] [1:02:51 PM] * Lugnut kicked xepherr7 from the chat.
> [Saturday, March 29, 2014 1:02:52 PM Lugnut] [1:02:52 PM] * Lugnut kicked xepherr8 from the chat.
> [Saturday, March 29, 2014 1:02:54 PM Lugnut] [1:02:54 PM] * Lugnut kicked xepherr9 from the chat.
> [Saturday, March 29, 2014 1:02:56 PM Lugnut] [1:02:56 PM] * Lugnut kicked xepherr10 from the chat.
> [Saturday, March 29, 2014 1:03:00 PM Lugnut] [1:03:00 PM] * Lugnut kicked xepherr2 from the chat.
Fast forward a bit, the Skype call dies. I end up offline, and Skype is trying to reconnect. I don't know why, I'm checking some websites and they aren't opening up. I presume it's a DNS error, which I've been having quite a bit of trouble with my DNS recently - no, that's not it, Google Chrome reports the connection failed, not the DNS lookup... right as I'm about to use my alternate internet connection to check in on Skype and apologize for being unable to run the game, everything starts working again and I receive these messages:
Quote
> [Saturday, March 29, 2014 1:05:01 PM lordfeline] [1:05:01 PM] Conference call, duration 05:25.
> [Saturday, March 29, 2014 1:05:07 PM lordfeline] Oh well it died
> [Saturday, March 29, 2014 1:05:09 PM Che Ven] There
> [Saturday, March 29, 2014 1:05:17 PM Che Ven] I can hold down Lugnut for days
> [Saturday, March 29, 2014 1:05:35 PM lordfeline] i can hold down ur mom 4 days
> [Saturday, March 29, 2014 1:05:36 PM Lugnut] what
> [Saturday, March 29, 2014 1:05:40 PM Lugnut] are you loving kidding me
> [Saturday, March 29, 2014 1:05:44 PM Lugnut] now you're going to loving ddos me?
> [Saturday, March 29, 2014 1:05:55 PM Lugnut] [1:05:55 PM] * Lugnut kicked animalswivel from the chat.
> [Saturday, March 29, 2014 1:06:03 PM Lugnut] forget that guy
> [Saturday, March 29, 2014 1:06:14 PM Lugnut] gotta swap my ip around if he takes me down again
> [Saturday, March 29, 2014 1:06:52 PM Che Ven] I GOT DOS FOR DAYS brother
> [Saturday, March 29, 2014 1:07:15 PM Lugnut] what a richard
As my internet connection fails for the second time, I log into my router and change my IP address so I can't be targeted anymore. My internet comes back, I resume the call, and forget about the problem for the next 7 hours having a great time.
I then remember the starfish, and decide to make a drama:
Quote
> [Saturday, March 29, 2014 7:51:07 PM Lugnut] does anyone know who Che Ven actually was?
> [Saturday, March 29, 2014 7:51:19 PM Cassord] yeah, who the forget is che ven?
> [Saturday, March 29, 2014 7:51:29 PM Lugnut] i'm gonna drama him if I can figure it out
> [Saturday, March 29, 2014 7:51:55 PM Cassord] why?
> [Saturday, March 29, 2014 7:51:57 PM Cassord] what did he do
> [Saturday, March 29, 2014 7:52:08 PM Lugnut] DoS'd me
> [Saturday, March 29, 2014 7:52:39 PM Lugnut] AvailsMew
> [Saturday, March 29, 2014 7:53:00 PM Lugnut] Ugh, I wish I had logs.
> [Saturday, March 29, 2014 7:53:03 PM Cassord] oh lord
> [Saturday, March 29, 2014 7:53:05 PM Masterockets] yes
> [Saturday, March 29, 2014 7:53:05 PM Lugnut] I should
> [Saturday, March 29, 2014 7:53:06 PM Cassord] ddos?
> [Saturday, March 29, 2014 7:53:08 PM Lugnut] DoS
> [Saturday, March 29, 2014 7:53:10 PM Masterockets] he was talking about being a wizard
> [Saturday, March 29, 2014 7:53:32 PM Lugnut] http://forum.blockland.us/index.php?topic=253559.msg7353581#msg7353581
> [Saturday, March 29, 2014 7:53:37 PM Lugnut] Can I join? Eladrin Wizard here.
> [Saturday, March 29, 2014 7:53:51 PM Masterockets] [3/26/2014 3:58:38 PM] Che Ven: Eladrin Wizard
> [Saturday, March 29, 2014 7:55:09 PM Lugnut] actually, if he targeted a specific service on my computer I might be able to get a bunch of connection attempts..
> [Saturday, March 29, 2014 7:56:27 PM Lugnut] nope, he didn't
> [Saturday, March 29, 2014 7:56:47 PM Masterockets] he added all those alts into the call
> [Saturday, March 29, 2014 7:56:57 PM Lugnut] which i booted in seconds...
> [Saturday, March 29, 2014 7:57:18 PM Lugnut] definitely not the brightest bulb in the bin
> [Saturday, March 29, 2014 7:57:43 PM Lugnut] you do recall me going offline, then him sending "okay, i can hold lugnut down for days" right?
> [Saturday, March 29, 2014 7:57:51 PM Masterockets] yes

> [Saturday, March 29, 2014 7:58:02 PM Lugnut] .
[1:00:22 PM] xepherr7: IF YOU KICK ME
[1:00:26 PM] xepherr7: I SWEAR TO loving GOD
[1:00:32 PM] xepherr7: I WILL BUY A VPS AND HIT YOU WITH CHARGEN FOR WEEKS AT A TIME
> [Saturday, March 29, 2014 7:58:15 PM Lugnut] > [Saturday, March 29, 2014 1:05:09 PM Che Ven] There
> [Saturday, March 29, 2014 1:05:17 PM Che Ven] I can hold down Lugnut for days
> [Saturday, March 29, 2014 7:58:33 PM Lugnut] forget that starfish
> [Saturday, March 29, 2014 7:58:36 PM Masterockets] [1:11:58 PM] Che Ven: I can hold down Lugnut for days
> [Saturday, March 29, 2014 7:58:45 PM Lugnut] he might have even been the richardface who took down my service for all i loving know
> [Saturday, March 29, 2014 8:04:11 PM Cassord] who added him in the first place
> [Saturday, March 29, 2014 8:04:16 PM Lugnut] I did
> [Saturday, March 29, 2014 8:04:21 PM Cassord] ok
> [Saturday, March 29, 2014 8:04:27 PM Cassord] hmm
> [Saturday, March 29, 2014 8:10:32 PM Cassord] look through his posts?
> [Saturday, March 29, 2014 8:10:36 PM Cassord] he is certainly an alt

[0]It was clearly a DoS. Not only did he flat out claim it to be one, he actually described the nature of it - additionally, since he claimed to be able to take me down for weeks at a time, he presumably was not concerned about the cost
  • I do not think he was related to the DDoS on my hosting service.
  • [0]I do not have logs of the attack, nor his IP address. However, I do have both Masterockets and Cassord who were there at the time and witnessed me going offline in correspondence with Che Ven's gloating.

    Here is Cassord's verification that the logs I've posted here are accurate (he's banned or something, idk):
http://forum.blockland.us/index.php?action=profile;u=92286 (he put it at the bottom - "Lugnut's logs are accurate")
I'll try to convince Masterockets to post.

Wow, good investigation.
I'm planning to do a drama topic on Okiver tomorrow.

After a bit of research, it appears CHARGEN corresponds to a well documented DoS attack that fires data at UDP port 19 on a target device. This is the same vulnerability that took down HamHost (remember the "omg virus!" post from Hammereditor?) a number of months ago.

http://www.iss.net/security_center/reference/vuln/Chargen_Denial_of_Service.htm
https://isc.sans.edu/diary/A+Chargen-based+DDoS%3F+Chargen+is+still+a+thing%3F/15647

I do not have the Chargen service enabled on any of my devices, but due to the nature of UDP data packets, he presumably just fired a bunch of data at me that my low bandwidth connection couldn't handle.

Wow, good investigation.
I'm planning to do a drama topic on Okiver tomorrow.
what that forgetwit still hanging around
geeeeeez

anyway full support. revoke this starfish's key.

Wow, good investigation.
I'm planning to do a drama topic on Okiver tomorrow.
Hardly. I just posted logs, which could be easily doctored. I'm trying to get Masterockets to verify them as accurate so I'll have at least two people who say they're true.
If they're true (they are, but no one can prove that without witnesses) then it's pretty clear where he FLAT OUT SAYS HE'S DOSING ME.
also,
Quote
> [Saturday, March 29, 2014 8:35:44 PM Masterockets] http://forum.blockland.us/index.php?topic=219630.msg6406046#msg6406046
> [Saturday, March 29, 2014 8:36:10 PM Lugnut] fantastic
> [Saturday, March 29, 2014 8:36:15 PM Cassord] nice
> [Saturday, March 29, 2014 8:36:20 PM Masterockets] Wertel goes to the account freedomfrie
> [Saturday, March 29, 2014 8:36:38 PM Lugnut] oh it's that guy? I don't remember him hating me for anything.
> [Saturday, March 29, 2014 8:36:44 PM Masterockets] and frenchfrie
> [Saturday, March 29, 2014 8:37:10 PM Masterockets] http://forum.blockland.us/index.php?topic=205015.msg5671774#msg5671774
> [Saturday, March 29, 2014 8:37:36 PM Masterockets] http://forum.blockland.us/index.php?topic=155973.msg3753199#msg3753199
> [Saturday, March 29, 2014 8:39:36 PM Masterockets] http://forum.blockland.us/index.php?topic=242546.msg6941765#msg6941765
what that forgetwit still hanging around
geeeeeez

anyway full support. revoke this starfish's key.
presumably so, although... Hammereditor is the only one on the entire forums who is supposedly still in contact with him. Either Hammereditor is proving to be excellent troll bait, or he's making it up.
Sorry Hammereditor, that's just how it looks from our end!

Let me dedicate a post to pointing out that this individual is likely not the person who took out my hosting service.

That might prove confusing due to recent events.

It's really sad to see this stuff happen.

Yes, I've started e-mailing Okiver ever since the first DoS attack on my hosting service 2 days ago. Okiver admitted to the two attacks on Thursday, and then I asked if he was also responsible for the Lug-host DDoS. Okiver said, "Do you want more DoS?", and I've faced a 1-hour packet flood attack today, with an average of 75 Mbps, and bursting to 1 Gbps for 10 minutes. I'm already tired of this.

Anyway, I'm not going to talk more about it; this is for a separate drama topic. This Okiver would probably go to jail for at least 5 years if all his crimes were revealed, and it's high time he does.

Yes, I've started e-mailing Okiver ever since the first DoS attack on my hosting service 2 days ago. Okiver admitted to the two attacks on Thursday, and then I asked if he was also responsible for the Lug-host DDoS. Okiver said, "Do you want more DoS?", and I've faced a 1-hour packet flood attack today, with an average of 75 Mbps, and bursting to 1 Gbps for 10 minutes. I'm already tired of this.

Anyway, I'm not going to talk more about it; this is for a separate drama topic. This Okiver would probably go to jail for at least 5 years if all his crimes were revealed, and it's high time he does.
I would highly recommend you contact your local law enforcement about that so that hopefully Okiver can get punished.

I would highly recommend you contact your local law enforcement about that so that hopefully Okiver can get punished.
Noedit:Forgot Agency after enforcement

Noedit:Forgot Agency after enforcement
the guy is danish
we can't touch him so easily without a real lawyer, and no one on this forum who gives a damn has enough money to do that

Is there anyone else danish here?



Port isn't, iirc he's American.
definitely not american
Sweden? Danish?