Jump to content

Popular web browser extension Hola turns you into a botnet

GoodBytes

The popular Hola web browser extension for Chrome and Firefox is used to by-pass region lock content, and access Netflix and other services from the U.S. It is praised for its easy-to-use and free service.

hola_splash.0.0.jpg

It has been recently found that when used and your bandwidth it idle, it uses you as a botnet through another service from the company: Luminati VPN, which is a service, where you buy traffic in bulk, and has been found to be used for DDOS attack by attackers to hide themselves.

 

The issue came to light after the moderator of the controversial 8chan forum — an off-shoot of 4chan that has been criticized for acting as an "active pedophile network" — reported that the site had been the target of multiple DoS attacks from Hola's network. "[Hola] recently ... realized that they basically have a 9 million IP strong botnet on their hands, and they began selling access to this botnet," says a note on the site. "An attacker used the Luminati network to send thousands of legitimate-looking [requests to 8chan] in 30 seconds, representing a 100x spike over peak traffic."

The real reason for this, is that Hola doesn't provide its own bandwidth or servers, but simply redirects that of its users'. That is how it is able to provide fast, quality service to all, all the time. The big problem with this, is those with bandwidth qupta from their ISP, and being part for potential online attacks without knowing.

Hola says that if you don't want to contribute your bandwidth, you need to pay 5$ per month (45$ per year) for Hola Premium.

The company claim that this was made clear to it's users that they do this, however, it doesn't seam to be case for most.

Source: http://www.theverge.com/2015/5/29/8685251/hola-vpn-botnet-selling-users-bandwidth

Do you use, or used Hola extension? Did you know about this before your got it?

Link to comment
Share on other sites

Link to post
Share on other sites

Funnily I uninstalled Hola yesterday since I currently do not have a premium Netflix subscription (I used it to watch the US netflix content) and don't really have a use for it. Oh well, glad I found primewire.ag a couple of months ago, so there's no real need for me anymore to use it. Glad I uninstalled it!

phanteks enthoo pro | intel i5 4690k | noctua nh-d14 | msi z97 gaming 5 | 16gb crucial ballistix tactical | msi gtx970 4G OC  | adata sp900

Link to comment
Share on other sites

Link to post
Share on other sites

lol'd. Just buy a VPS in the US and host your own OpenVPN or Shadowsocks proxy. Even cheaper than a VPN and you can do other stuff with it.

Link to comment
Share on other sites

Link to post
Share on other sites

My dad uses it.... Better tell him.

LTT's unofficial Windows activation expert.
 

Link to comment
Share on other sites

Link to post
Share on other sites

I already knew this and have a few months of premium. You can use a referall to sign up for hola with a dispostable email and get a month of hola for free each time you do this

Case: NZXT Phantom PSU: EVGA G2 650w Motherboard: Asus Z97-Pro (Wifi-AC) CPU: 4690K @4.2ghz/1.2V Cooler: Noctua NH-D15 Ram: Kingston HyperX FURY 16GB 1866mhz GPU: Gigabyte G1 GTX970 Storage: (2x) WD Caviar Blue 1TB, Crucial MX100 256GB SSD, Samsung 840 SSD Wifi: TP Link WDN4800

 

Donkeys are love, Donkeys are life.                    "No answer means no problem!" - Luke 2015

 

Link to comment
Share on other sites

Link to post
Share on other sites

Unless someone has a smoother replacement it can stay for the time being. still worth noting.

Everything you need to know about AMD cpus in one simple post.  Christian Member 

Wii u, ps3(2 usb fat),ps4

Iphone 6 64gb and surface RT

Hp DL380 G5 with one E5345 and bunch of hot swappable hdds in raid 5 from when i got it. intend to run xen server on it

Apple Power Macintosh G5 2.0 DP (PCI-X) with notebook hdd i had lying around 4GB of ram

TOSHIBA Satellite P850 with Core i7-3610QM,8gb of ram,default 750hdd has dual screens via a external display as main and laptop display as second running windows 10

MacBookPro11,3:I7-4870HQ, 512gb ssd,16gb of memory

Link to comment
Share on other sites

Link to post
Share on other sites

I don't know what is funnier, the fact that Hola was hacked for abusive use this easily or the fact that people think 8chan is a bad website.

hola wasn't hacked

"they began selling access to this botnet"

If your grave doesn't say "rest in peace" on it You are automatically drafted into the skeleton war.

Link to comment
Share on other sites

Link to post
Share on other sites

I use this to watch Community on Yahoo!

Good to know, thanks.

Why is SpongeBob the main character when Patrick is the star?

Link to comment
Share on other sites

Link to post
Share on other sites

I use Hola all the time to watch American netflix, obviously I could just use streaming websites for free without it being locked by region, but using netflix and hola is just so much more convenient and enjoyable, so I don't really plan on stopping, but this is good to know. 

i5 4690k | GTX 980Ti G1 Gaming | 16GB RAM | MSI Z97 Gaming 7 | NZXT Kraken X61 | 850 EVO 250GB x2  | 1TB 850 Evo NZXT Noctis 450 | EVGA 750W 80+ Gold

 

 Ducky Shine 3 TKL (Browns) | LG 34UC87C | Logitech MX Master ATH-M50x's + DT990 Pro's 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Got myself an unlimited, lifetime vpn subscription for 40$ so I unistalled Hola a while back. Always wondered how they could manage the bandwith without charging. Like it was too easy... 

 

If you want the deal for the VPN, it comes back really often. Check for VPN Unlimited. The only drawback is that it works with apps so you can't set it at the router level. But's it no big deal and it's easier to turn on and off. 

Link to comment
Share on other sites

Link to post
Share on other sites

Popular web browser extension Hola turns you into a botnet

 

Umm, it turns your computer into a bot.

This bot collaborates with other bots controlled by the same entity forming a network of bots - a botnet.

Link to comment
Share on other sites

Link to post
Share on other sites

I had never heard of this extension.

I just use a VPN and am very happy with what I have.

“Advertising has us chasing cars and clothes. working jobs we hate, so we can buy shit we dont need.”- Chuck Palahniuk, Fight Club

"Oh, beauty is a beguiling call to death and I'm addicted to the sweet pitch of its siren."- Johnny Quid

"Without our imaginations, we'd be like all those other poor... dullards."- Dr. Hannibal Lecter

Link to comment
Share on other sites

Link to post
Share on other sites

The plug in can be turned on and off (and not just by deactivating the plug in extension settings) so I'd say its still a small price to pay since it's free and pretty hard to defeat by being p2p other vpns can be routinely blocked by sites.

-------

Current Rig

-------

Link to comment
Share on other sites

Link to post
Share on other sites

lol'd. Just buy a VPS in the US and host your own OpenVPN or Shadowsocks proxy. Even cheaper than a VPN and you can do other stuff with it.

ZenMate is nice. It's free. And snappy. And doesn't your computer into a bot.
Link to comment
Share on other sites

Link to post
Share on other sites

ZenMate is nice. It's free. And snappy. And doesn't your computer into a bot.

Or so you think.

Link to comment
Share on other sites

Link to post
Share on other sites

Or so you think.

or so I know. I've checked everything about it. It's code. And even if it does, I still have given my computer into another PAID VPN, as well as I fold...
Link to comment
Share on other sites

Link to post
Share on other sites

or so I know. I've checked everything about it. It's code. And even if it does, I still have given my computer into another PAID VPN, as well as I fold...

Release build doesn't have to exactly mirror what's in the repositories.

Link to comment
Share on other sites

Link to post
Share on other sites

Guess i'll be removing that when I get home tonight.

System Specs:

CPU: Ryzen 7 5800X

GPU: Radeon RX 7900 XT 

RAM: 32GB 3600MHz

HDD: 1TB Sabrent NVMe -  WD 1TB Black - WD 2TB Green -  WD 4TB Blue

MB: Gigabyte  B550 Gaming X- RGB Disabled

PSU: Corsair RM850x 80 Plus Gold

Case: BeQuiet! Silent Base 801 Black

Cooler: Noctua NH-DH15

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Release build doesn't have to exactly mirror what's in the repositories.

No no no... Grease Monkey, or the GOOGLE Plugins Tool allows you to view source code.

And, either way, even if it does turn my computer in a bot. I don't really care. I'll just switch to my paid VPN for primary use.

Link to comment
Share on other sites

Link to post
Share on other sites

I thought this was common knowledge, that it used other people with the extension like a p2p service.  That is how it was always described to me, though my own knowledge may bias my understanding of such things.  When you already understand how things like p2p, torrent, vpn, the internet, and computers all work, its easy to understand new things that are similar without realizing the person talking to you about it doesn't understand how it actually works.  Though the people that have told me and others about this at work and such always made sure to warn others that it is basically just sharing your connection with other people who use it.

Link to comment
Share on other sites

Link to post
Share on other sites

As a canadian wouldn't this not affect me, since no one is using Hola to view candian websites?

 

It seems Hola should be using data in the region the users are trying to get to

 

EDIT: i uninstalled the extention some time ago though, so i am not worried

Intel i5-3570K/ Gigabyte GTX 1080/ Asus PA248Q/ Sony MDR-7506/MSI Z77A-G45/ NHD-14/Samsung 840 EVO 256GB+ Seagate Barracuda 3TB/ 16GB HyperX Blue 1600MHZ/  750w PSU/ Corsiar Carbide 500R

 

Link to comment
Share on other sites

Link to post
Share on other sites

As a canadian wouldn't this not affect me, since no one is using Hola to view candian websites?

 

It seems Hola should be using data in the region the users are trying to get to

It does affect you, as the service that is being used is VP purposes. So if a person uses VPN to torrent, and the service uses your connect... well.. you are tormenting without knowing.
Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×