GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Jérôme Meyer (jmeyer@infosec.exchange)

  1. Embed this notice
    Jérôme Meyer (jmeyer@infosec.exchange)'s status on Tuesday, 11-Mar-2025 16:20:39 JST Jérôme Meyer Jérôme Meyer
    in reply to

    About this X DDoS campaign: I've seen reports of attribution to Ukraine, and at least based on attack data at network level — I just don't see it. (And I should note: attribution is hard, so I am generally skeptical.)

    Top contributors are 🇺🇸🇲🇽🇪🇸🇮🇹🇧🇷, and as with most botnets: very geographically distributed.

    Most of the source IPs intersect with #Eleven11bot as we started seeing them on 26 February.

    OK, now back to regularly scheduled skiing.

    #threatintel

    In conversation about 2 months ago from infosec.exchange permalink
  2. Embed this notice
    Jérôme Meyer (jmeyer@infosec.exchange)'s status on Tuesday, 11-Mar-2025 06:52:20 JST Jérôme Meyer Jérôme Meyer

    Supposed to be enjoying a week off skiing, but the X DDoS-related outage brought me back a bit.

    Hint: that attack has been botnet-driven.

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/140/085/555/023/353/original/37b8fc64f51d7bad.jpeg
  3. Embed this notice
    Jérôme Meyer (jmeyer@infosec.exchange)'s status on Tuesday, 11-Mar-2025 03:39:05 JST Jérôme Meyer Jérôme Meyer
    • Kevin Beaumont

    @GossiTheDog The target is a subnet in X own network. Haven’t had a chance to look at what those hosts might be exactly.

    In conversation about 2 months ago from infosec.exchange permalink
  4. Embed this notice
    Jérôme Meyer (jmeyer@infosec.exchange)'s status on Wednesday, 22-Jan-2025 06:41:40 JST Jérôme Meyer Jérôme Meyer
    in reply to
    • Kevin Beaumont
    • Fafner [_KeyZee_]

    @F_kZ_ @GossiTheDog Looks like their shiny new bot (and even their main English channel) just disappeared — all while they closed the DDoSia English support channel

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/868/514/669/413/131/original/002ed4c996f4f0dc.png
  5. Embed this notice
    Jérôme Meyer (jmeyer@infosec.exchange)'s status on Thursday, 16-Jan-2025 19:03:48 JST Jérôme Meyer Jérôme Meyer
    in reply to
    • Kevin Beaumont

    @GossiTheDog Most of the traffic stopped a few hours ago, it's now down to a trickle.

    The website from one of the big US telcos still partially loads elements from Edgio even though most of the website is now on Akamai.

    In conversation about 4 months ago from infosec.exchange permalink
  6. Embed this notice
    Jérôme Meyer (jmeyer@infosec.exchange)'s status on Wednesday, 08-Jan-2025 18:29:56 JST Jérôme Meyer Jérôme Meyer
    in reply to
    • Kevin Beaumont

    @GossiTheDog I was looking around for services still using Edgio in traffic delivery today, and for the most notable ones: Amazon Prime Video, Disney+, Samsung apps. (most other big players, like Microsoft for Xbox Live/updates, Paramount+, Playstation, and even Redtube stopped using them in early/mid December).

    In conversation about 4 months ago from infosec.exchange permalink
  7. Embed this notice
    Jérôme Meyer (jmeyer@infosec.exchange)'s status on Wednesday, 08-Jan-2025 18:29:55 JST Jérôme Meyer Jérôme Meyer
    in reply to
    • Kevin Beaumont

    @GossiTheDog Also, worth noting that nearly all adult content sites stopped using Edgio in the second half of December, so in a way — they're better run than Amazon Prime Video or Samsung Bixby 🤷🏻♂️

    In conversation about 4 months ago from infosec.exchange permalink
  8. Embed this notice
    Jérôme Meyer (jmeyer@infosec.exchange)'s status on Wednesday, 08-Jan-2025 18:29:55 JST Jérôme Meyer Jérôme Meyer
    in reply to
    • Kevin Beaumont

    @GossiTheDog Overall traffic from Edgio seems to be about a tenth of what it was a month ago. Definitely interesting to see what traffic continues or suddenly stops, and indeed Microsoft is a bit all over the place with LinkedIn continuing still but Office mostly stopped yesterday.

    In conversation about 4 months ago from infosec.exchange permalink
  9. Embed this notice
    Jérôme Meyer (jmeyer@infosec.exchange)'s status on Tuesday, 17-Dec-2024 18:56:40 JST Jérôme Meyer Jérôme Meyer

    Germany is NoName’s focus again today, with a mix of government websites and industrial/energy company sites being targeted.

    About two thirds of the websites are affected so far. (And the two sites from the federal government are still standing, thanks to an anti-bot challenge/rate limiting.)

    #DDoS #threatintel https://social.circl.lu/@NoName57Bot/113666772362281488

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      A bot witha.name (@NoName57Bot@social.circl.lu)
      from A bot witha.name
      New configuration detected for DDosia. Hosts: * group.vattenfall.com * www.tunap.com * www.pfleiderer.com * www.schwarzbeck.de * www.vng.de * shop.semikron-danfoss.com * carl-walther.de * www.mc-bauchemie.de * eshop.tunap.de * cvd.bundesregierung.de * www.semikron-danfoss.com * www.sefe-energy.eu * www.bundesregierung.de * www.vattenfall.de * still.de * www.meyle.com #ThreatIntel #Ddosia #NoName * https://witha.name/data/2024-12-17_07-35-02_DDoSia-target-list-full.json *

User actions

    Jérôme Meyer

    Jérôme Meyer

    Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          236957
          Member since
          20 Jan 2024
          Notices
          9
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.