Welcome, Guest. Please login or register.

Login with username, password and session length

 
Advanced search

498 Posts in 114 Topics- by 711 Members - Latest Member: aColetteSnon




Links:
FurnitureDepots  -+-  -+-   Openports.info  -+-   .net chat
February 07, 2012, 12:32:45 pm
QSDCHublist ForumDev ZoneNMDC Hublist DiscussionsTopic: CTM Flooding hub on QSDCHublist front page.
Pages: [1]   Go Down
Print
Author Topic: CTM Flooding hub on QSDCHublist front page.  (Read 2233 times)
Znupi
Newbie
*

Reputation: +0/-0
Offline Offline

Posts: 2


View Profile
« on: March 09, 2009, 12:58:20 am »

You write everywhere about ways to detect CTM flooding and ban such hubs from hublists, but there's a hub that does CTM flooding right on the first page. Here's the hub: http://www.qsdchublist.com/?s=hubdetails&id=405

How do I know it's doing CTM flooding? Well, I'm writing my own hublist pinger and maybe I'll even make a hublist some day, so here's some of its output:
Code:
felix@the-machine:~/Work/py/pybot$ ./pybot.py -b "PyBot" dchub.hacker.lv -p4012
[8] Ping finished.
Lingering around for 20 seconds for CTM detect...
--------------------------------------------------------------------------------
Hub name     : dchub.hacker.lv:4012  www.tikli.lv ���� � ����� ������������ � �����
Hub topic    : VerliHub
Operators    : Torrent.Hacker.Lv, forester, Mavr, OpChat, Kruzo
Users        : 8823
Connect      : 18.947388 seconds
CTM Flood    : Detected (type 7)
CTM Requests :
 --* 91.121.84.128:411
 --* 194.9.94.86:80
 --* 91.121.82.24:411
 --* 194.9.94.86:411
Extra info   :
 --* dchub.hacker.lv:4012  www.tikli.lv ���� � ����� ������������ � �����
 --* dchub.hacker.lv:4012
 --* VerliHub
 --* 15000
 --* 0
 --* 0
 --* 100
 --* VerliHub
 --* hacker
My bot is not yet complete so it doesn't show the amount of CTM requests it got for each IP, but CTM Flood type 7 means that it was requested to connect to at least one IP:PORT combination more than once in 5 seconds. I would guess it was requested to connect to all IP:PORT combinations multiple times.
This is not the first time this happens on this hub. It happened a couple days ago, too. Even if I connect with a DC++ client I can see myself starting 5-6 "uploads".

EDIT: I made my bot count requests, too. Behold:
Code:
CTM Requests :
 --* 91.121.84.128:411 x 4
 --* 194.9.94.86:80 x 2
 --* 91.121.82.24:411 x 2
 --* 194.9.94.86:411 x 2
So it got a total of 10 requests in 20 seconds. They're not only flooding other hubs but they are even flooding a web server.
« Last Edit: March 09, 2009, 01:09:12 am by Znupi » Logged
Molotov
Administrator
Full Member
*****

Reputation: +11/-1
Offline Offline

Posts: 128


View Profile Email
« Reply #1 on: March 09, 2009, 04:15:42 am »

Like Lord_Zero answered you:

When the pinger is registered with class -1 it doesn´t not receive CTM's.

This is something we will have to work around later.
Logged
Znupi
Newbie
*

Reputation: +0/-0
Offline Offline

Posts: 2


View Profile
« Reply #2 on: March 09, 2009, 02:39:10 pm »

Well, you should make it log in as a regular user, too. But anyway, not my business. You should, at least, ban that hub. If you don't trust me that it's doing CTM flooding, test for yourself. Either with a bot or just log in using your client of choice and see the fake uploads starting (well, it doesn't happen EVERY time, but it happens once every 2-3 logins).
Logged
The Architect
God
Administrator
Full Member
*****

Reputation: +10/-0
Offline Offline

Gender: Male
Posts: 127


linuxphreakr@gmail.com messerschmitt123 mikhail_polenin
View Profile Email
« Reply #3 on: March 15, 2009, 01:44:44 am »

Thanks for the information. I will be developing the pinger more in the near future and might consider your suggestion of having another bot logging in as a user. Reports like these can help the hublist determine hubs that are trying to hide as CTM attack hubs.
Logged

Pinger Developer, Forum Administrator, Clumsy Coordinator, Coffee Machine Repairman, and Proud Supporter of Cheese Products
Pages: [1]   Go Up
Print
QSDCHublist ForumDev ZoneNMDC Hublist DiscussionsTopic: CTM Flooding hub on QSDCHublist front page.
Jump to: