Jump to content

Did I get DDoS'd? Thinking about reporting to authorities but not sure if it was.

lucagrabacr

Hey guys, so earlier someone on Steam basically said to me via chat "would you like 100% packet loss?" (because my display name on Steam has "40% packet loss" in it since I'm laggy from time to time).Which I jokingly replied "No :P" then he said, "It can be arranged"

 

Seconds later, I got disconnected from Steam and was unable to connect to most websites. Domestic websites and Google still worked, however, and I was still able to connect to Steam through my mobile Steam app (which is connected to the same router my PC is connected to), even though I can't connect to the internet in general on my phone.

 

I talked again with the person on Steam through my mobile Steam app which somehow still worked, and he implied that he was the one who did it (said he got 650gbps or even 1tbps connection if he enables his other server). He also said, "It has been arranged" which I read on my mobile steam app.

 

Also, that person asked me if I was from Asia a few days ago, and I told him that I am.

 

Based on those information, was it a DDoS attack? Or was it just a mere coincidence that my internet connection got messed up seconds after he said that? Is there a way to monitor this kind of thing to see if it was? Don't really want to file a report to the authorities without being 100% sure that it was an attack. Thanks in advance guys.

Link to comment
Share on other sites

Link to post
Share on other sites

DoS

A DoS Attack is a Denial of Service attack.

This means that one computer and one internet connection is used to flood a server with packets (TCP / UDP). The point of such a denial of service attack is to overload the targeted server’s bandwidth and other resources. This will make the server inaccessible to others, thereby blocking the website or whatever else is hosted there.

DDoS

A DDoS Attack is a Distributed Denial of Service Attack.

In most respects it is similar to a DoS attack but the results are much, much different. Instead of one computer and one internet connection the DDoS attack utilises many computers and many connections. The computers behind such an attack are often distributed around the whole world and will be part of what is known as a botnet. The main difference between a DDoS attack vs a DoS attack, therefore, is that the target server will be overload by hundreds or even thousands of requests in the case of the former as opposed to just one attacker in the case of the latter.

Therefore it is much, much harder for a server to withstand a DDoS attack as opposed to the simpler DoS incursion.

 

3 minutes ago, lucagrabacr said:

(said he got 650gbps or even 1tbps connection if he enables his other server).

http://thehackernews.com/2016/09/ddos-attack-iot.html

 

He is a bragger, and how the flying fuck did he get your ip then! Did you open any links he sent or a file?

Link to comment
Share on other sites

Link to post
Share on other sites

he's bullshitting. 1tbs to ddos random people on the internet and he owns it, and talks about it on an easily verifiable platform with chat logs? this screams script kiddie looking for attention. if you want to be sure call your ISP and ask if they see a lot of data going to your IP, that is a clear indication of DDOS.

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Bwithnewcast said:

He is a bragger, and how the flying fuck did he get your ip then! Did you open any links he sent or a file?

I'm not sure. I suspected he got it from my non-https forum and I asked him if it was, he said it was none of that and it was "black magic". It might have also been one of the game servers I played on.

 

1 minute ago, tlink said:

he's bullshitting. 1tbs to ddos random people on the internet and he owns it, and talks about it on an easily verifiable platform with chat logs? this screams script kiddie looking for attention. if you want to be sure call your ISP and ask if they see a lot of data going to your IP, that is a clear indication of DDOS.

Ah, alright :) I'll call my ISP asap and asked them about it. Thanks for the suggestion tlink, didn't think about that.

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, lucagrabacr said:

I'm not sure. I suspected he got it from my non-https forum and I asked him if it was, he said it was none of that and it was "black magic". It might have also been one of the game servers I played on.

if they owned / have access to a server you connected to and possibly identified yourself on (user account, name, email etc) then thats how he could've gotten your ip. this means any website link they might've send you, any server you have connected to that they suggested.

Link to comment
Share on other sites

Link to post
Share on other sites

47 minutes ago, Ethocreeper said:

also download glasswire and see incoming ips and block him

Downloading it now. Edit: Called my ISP about it and they said everything's normal, told them that it happened about two hours ago, they checked and they said everything's normal. Not sure if it really was just a coincidence or my ISP couldn't detect it. Anyway, I have glasswire running now :) so I guess I can see if something like that does happen in the future, thanks again for the help guys.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Ethocreeper said:

also download glasswire and see incoming ips and block him

Do you believe his PC is directly connected to the Internet?

The router won't forward a single connections to his PC. He would need to monitor his router's wan interface.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, .spider. said:

Do you believe his PC is directly connected to the Internet?

The router won't forward a single connections to his PC. He would need to monitor his router's wan interface.

he can see his ip from the chat or something and block it from the router

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, Ethocreeper said:

he can see his ip from the chat or something and block it from the router

No he can't do anything with a software firewall on a client behind a router.

Link to comment
Share on other sites

Link to post
Share on other sites

If it was a smurf attack (which is what hes bragging when he talks about how much bandwidth he has available which im guessing is a botnet for hire) - then your ISP will see a huge spike in data. Its probably just a troll . He would have needed to get your IP from connecting to you P2P in some way. If you had a voice chat with him over Steam then i believe that is P2P - but if it was just via text, thats all over Steam servers, so he cannot get it that way. Same with most game servers - keep voice off in game and you'll be fine. This is why we use discord for any team based games.

Spoiler

Desktop: Ryzen9 5950X | ASUS ROG Crosshair VIII Hero (Wifi) | EVGA RTX 3080Ti FTW3 | 32GB (2x16GB) Corsair Dominator Platinum RGB Pro 3600Mhz | EKWB EK-AIO 360D-RGB | EKWB EK-Vardar RGB Fans | 1TB Samsung 980 Pro, 4TB Samsung 980 Pro | Corsair 5000D Airflow | Corsair HX850 Platinum PSU | Asus ROG 42" OLED PG42UQ + LG 32" 32GK850G Monitor | Roccat Vulcan TKL Pro Keyboard | Logitech G Pro X Superlight  | MicroLab Solo 7C Speakers | Audio-Technica ATH-M50xBT2 LE Headphones | TC-Helicon GoXLR | Audio-Technica AT2035 | LTT Desk Mat | XBOX-X Controller | Windows 11 Pro

 

Spoiler

Server: Fractal Design Define R6 | Ryzen 3950x | ASRock X570 Taichi | EVGA GTX1070 FTW | 64GB (4x16GB) Corsair Vengeance LPX 3000Mhz | Corsair RM850v2 PSU | Fractal S36 Triple AIO | 12 x 8TB HGST Ultrastar He10 (WD Whitelabel) | 500GB Aorus Gen4 NVMe | 2 x 2TB Samsung 970 Evo Plus NVMe | LSI 9211-8i HBA

 

Link to comment
Share on other sites

Link to post
Share on other sites

If you used VOIP on the steam chat, he would of retrieved your IP.

Then you can utilise anything to perform a DoS or DDoS against a single IP.  Send enough traffic to the IP and it will make your connection useless.  As for the claims of massive GB/s of bandwidth I very much doubt it, just sounds like a kid using free tools to 'DDoS a skid'

Please quote or tag me if you need a reply

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, Falconevo said:

If you used VOIP on the steam chat, he would of retrieved your IP.

Then you can utilise anything to perform a DoS or DDoS against a single IP.  Send enough traffic to the IP and it will make your connection useless.  As for the claims of massive GB/s of bandwidth I very much doubt it, just sounds like a kid using free tools to 'DDoS a skid'

I think they they fixed that insecurity.

My native language is C++

Link to comment
Share on other sites

Link to post
Share on other sites

Don't listen to anyone else in this thread. He's using exploited iot devices to hit you offline, or DNS servers. Even if you did report him, the authorities wouldn't give a shit. Keep in mind most cops don't even know what twitter is; good luck explaining ddos to them.

 

Change your IP address through your provider. You will need to call them up and ask for a new ip (you probably will need a new modem to get a new ip.)

 

next, buy a privateinternetaccess subscription and use it 24/7 even when you're gaming.

 

how did he get your IP address in the first place? You either: clicked a link he sent you; joined his game server; accepted a voice call from him on steam; or he found a dump with your ip in it.

 

Can you block the attack on your end? Fuck no, that's not how the internet works. You'll still go offline regardless of how expensive your router or firewall is.

 

After you get a new ip and get on a vpn, go on steam and make fun of him for being powerless and a skid. Also make fun of the fact that he pays for a ragebooter subscription and can't hit over 200mbps. Then ask him for a dstat of his "power" with your name on the graph.

 

you're welcome.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×