As many of you know, Revision3′s servers were brought down over the Memorial Day weekend by a denial of service attack. It’s an all too common occurrence these days. But this one wasn’t your normal cybercrime – there’s a chilling twist at the end. Here’s what happened, and why we’re even more concerned today, after it’s over, than we were on Saturday when it started.
It all started with just a simple “hi”. Now “hi” can be the sweetest word in the world, breathlessly whispered into your ear by a long-lost lover, or squealed out by your bouncy toddler at the end of the day. But taken to excess – like by a cranky 3-year old–it gets downright annoying. Now imagine a room full of hyperactive toddlers, hot off of a three hour Juicy-Juice bender, incessantly shrieking “hi” over and over again, and you begin to understand what our poor servers went through this past weekend.
On the internet, computers say hi with a special type of packet, called “SYN”. A conversation between devices typically requires just one short SYN packet exchange, before moving on to larger messages containing real data. And most of the traffic cops on the internet – routers, firewalls and load balancers – are designed to mostly handle those larger messages. So a flood of SYN packets, just like a room full of hyperactive screaming toddlers, can cause all sorts of problems.
For adults, it’s typically an inability to cope, followed either by quickly fleeing the room, or orchestrating a massive Teletubbies intervention. Since they lack both legs and a ready supply of plushies, internet devices usually just shut down.

That’s what happened to us. Another device on the internet flooded one of our servers with an overdose of SYN packets, and it shut down – bringing the rest of Revision3 with it. In webspeak it’s called a Denial of Service attack – aka DoS – and it happens when one machine overwhelms another with too many packets, or messages, too quickly. The receiving machine attempts to deal with all that traffic, but in the end just gives up.
(Note the photo of our server equipment responding to the DoS Attack)
In its coverage Tuesday CNet asked the question, “Now who would want to attack Revision3?” Who indeed? So we set out to find out.
Internet attacks leave lots of evidence. In this case it was pretty easy to see exactly what our shadowy attacker was so upset about. It turns out that those zillions of SYN packets were addressed to one particular port, or doorway, on one of our web servers: 20000. Interestingly enough, that’s the port we use for our Bittorrent tracking server. It seems that someone was trying to destroy our bittorrent distribution network.
Let me take a step back and describe how Revision3 uses Bittorrent, aka BT. The BT protocol is a peer to peer scheme for sharing large files like music, programs and video. By harnessing the peer power of many computers, we can easily and cheaply distribute our huge HD-quality video shows for a lot less money. To get started, the person sharing that large file first creates a small file called a “torrent”, which contains metadata, along with which server will act as the conductor, coordinating the sharing. That server is called the tracking server, or “tracker”. You can read much more about Bittorrent at Wikipedia, if you really want to understand how it works.
Revision3 runs a tracker expressly designed to coordinate the sharing and downloading of our shows. It’s a completely legitimate business practice, similar to how ESPN puts out a guide that tells viewers how to tune into its network on DirecTV, Dish, Comcast and Time Warner, or a mall might publish a map of its stores.
But someone, or some company, apparently took offense to Revision3 using Bittorrent to distribute its own slate of shows. Who could that be?
Along with where it’s bound, every internet packet has a return address. Often, particularly in cases like this, it’s forged – or spoofed. But interestingly enough, whoever was sending these SYN packets wasn’t shy. Far from it: it’s as if they wanted us to know who they were.
A bit of address translation, and we’d discovered our nemesis. But instead of some shadowy underground criminal syndicate, the packets were coming from right in our home state of California. In fact, we traced the vast majority of those packets to a public company called Artistdirect (ARTD.OB). Once we were able to get their internet provider on the line, they verified that yes, indeed, that internet address belonged to a subsidiary of Artist Direct, called MediaDefender.
Now why would MediaDefender be trying to put Revision3 out of business? Heck, we’re one of the biggest defenders of media around. So I stopped by their website and found that MediaDefender provides “anti-piracy solutions in the emerging Internet-Piracy-Prevention industry.” The company aims to “stop the spread of illegally traded copyrighted material over the internet and peer-to-peer networks.” Hmm. We use the internet and peer-to-peer networks to accelerate the spread of legally traded materials that we own. That’s sort of directly opposite to what Media Defender is supposed to be doing.
Who pays MediaDefender to disrupt peer to peer networks? I don’t know who’s ponying up today, but in the past their clients have included Sony, Universal Music, and the central industry groups for both music and movies – the RIAA and MPAA. According to an article by Ars Technica, the company uses “its array of 2,000 servers and a 9GBps dedicated connection to propagate fake files and launch denial of service attacks against distributors.” Another Ars Technica story claims that MediaDefender used a similar denial of service attack to bring down a group critical of its actions.
Hmm. Now this could have been just a huge misunderstanding. Someone could have incorrectly configured a server on Friday, and left it to flood us mercilessly with SYN packets over the long Memorial Day weekend. If so, luckily it was pointed at us, and not, say, at the intensive care unit at Northwest Hospital and Medical Center But Occam’s razor leads to an entirely different conclusion.
So I picked up the phone and tried to get in touch with ArtistDirect interim CEO Dimitri Villard. I eventually had a fascinating phone call with both Dimitri Villard and Ben Grodsky, Vice President of Operations at Media Defender.
First, they willingly admitted to abusing Revision3′s network, over a period of months, by injecting a broad array of torrents into our tracking server. They were able to do this because we configured the server to track hashes only – to improve performance and stability. That, in turn, opened up a back door which allowed their networking experts to exploit its capabilities for their own personal profit.
Second, and here’s where the chain of events come into focus, although not the motive. We’d noticed some unauthorized use of our tracking server, and took steps to de-authorize torrents pointing to non-Revision3 files. That, as it turns out, was exactly the wrong thing to do. MediaDefender’s servers, at that point, initiated a flood of SYN packets attempting to reconnect to the files stored on our server. And that torrential cascade of “Hi”s brought down our network.
Grodsky admits that his computers sent those SYN packets to Revision3, but claims that their servers were each only trying to contact us every three hours. Our own logs show upwards of 8,000 packets a second.
“Media Defender did not do anything specific, targeted at Revision3″, claims Grodsky. “We didn’t do anything to increase the traffic” – beyond what they’d normally be sending us due to the fact that Revision3 was hosting thousands of MediaDefender torrents improperly injected into our corporate server. His claim: that once we turned off MediaDefender’s back-door access to the server, “traffic piled up (to Revision3 from MediaDefender servers because) it didn’t get any acknowledgment back.”
Putting aside the company’s outrageous use of our servers for their own profit, and the large difference between one connection every three hours and 8,000 packets a second, I’m still left to wonder why they didn’t just tell us our basement window was unlocked. A quick call or email and we’d have locked it up tighter than a drum.
It’s as if McGruff the Crime Dog snuck into our basement, enlisted an army of cellar rats to eat up all of our cheese, and then burned the house down when we finally locked him out – instead of just knocking on the front door to tell us the window was open.
In the end, here’s what I know:
- A torrential flood of SYN packets rained down on Revision3’s network over Memorial Day weekend.
- Those packets – up to 8,000 a second – came primarily from computers controlled by MediaDefender, who is in the business of shutting down illegal torrent sites.
- Revision3 suffered measurable harm to its business due to that flood of packets, as the attacks on our legitimate and legal Torrent Tracking server spilled over into our entire internet infrastructure. Thus we were unable to serve videos and advertising through much of the weekend, and into Tuesday – and even our internal email servers were brought down.
- Denial of service attacks are illegal in the US under 12 different statutes, including the Economic Espionage Act and the Computer Fraud and Abuse Act.
Although I can only guess, here’s what I think really happened. Media Defender was abusing one of Revision3′s servers for their own purposes – quite without our approval. When we closed off their backdoor access, MediaDefender’s servers freaked out, and went into attack mode – much like how a petulant toddler will throw an epic tantrum if you take away an ill-gotten Oreo.
That tantrum threw upwards of 8,000 SYN packets a second at our servers. And that was enough to bring down both our public facing site, our RSS server, and even our internal corporate email – basically the entire Revision3 business. Smashing the cookie jar, as it were, so that no one else could have any Oreos either.
Was it malicious? Intentional? Negligent? Spoofed? I can’t say. But what I do know is that the FBI is looking into the matter – and it’s far more serious than toddlers squabbling over broken toys and lost cookies.
MediaDefender claims that they have taken steps to ensure this won’t happen again. “We’ve added a policy that will investigate open public trackers to see if they are associated with other companies”, promised Grodsky, “and first will make a communication that says, hey are you aware of this.”
In the end, I don’t think Media Defender deliberately targeted Revision3 specifically. However, the company has a history of using their servers to, as Ars Technica said, “launch denial of service attacks against distributors.” They saw us as a “distributor” – even though we were using Bittorrent for legitimate reasons. Once we shut them out, their vast network of servers were automatically programmed to implement a scorched earth policy, and shut us down in turn. The long Memorial Day weekend holiday made it impossible for us to contact either Media Defender or their ISP, which only exacerbated the problem.
All I want, for Revision3, is to get our weekend back – both the countless hours spent by our heroic tech staff attempting to unravel the mess, and the revenue, traffic and entertainment that we didn’t deliver.
If it can happen to Revision3, it could happen to your business too. We’re simply in the business of delivering entertainment and information – that’s not life or death stuff. But what if MediaDefender discovers a tracker inside a hospital, fire department or 911 center? If it happened to us, it could happen to them too. In my opinion, Media Defender practices risky business, and needs to overhaul how it operates. Because in this country, as far as I know, we’re still innocent until proven guilty – not drawn, quartered and executed simply because someone thinks you’re an outlaw.
- Jim Louderback
CEO – Revision3
UPDATE
We’ve received several requests for some technical data to illustrate the specifics of the attack. So we’ve provided a text file with some more “under the hood” data.
This file represents every packet we identified as being part of the DoS for a period of time less than .02 *seconds* on Monday morning. If you count, there’s a total of 96 packets. (We removed 12 legitimate packets from the trace). We used a combination of tcpdump and wireshark to gather this information. (this particular trace is from tcpdump)
View the text file: rev3packettrace.txt
Tags: blog
This entry was posted on Thursday, May 29th, 2008 at 7:49 am and is filed under Polemics. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.
Pingback: A Cautionary Tale From Revision3 | Paul Colligan’s Profitable Podcasting
Pingback: Media Defender launches illegal DoS attack on Revision 3 | Technology Viewer
Pingback: CrunchGear » Archive » Revision 3 says RIAA/MPAA anti-piracy company responsible for recent outage
Pingback: Endnu et fejltrin fra pladeindustrien « Når nørder keder sig
Pingback: Anything + Everything » Revision3 Servers Brought Down By MediaDefender DoS Attack
Pingback: Nullset
Pingback: Brandon Paddock's Blog - Desktop Search and more » Blog Archive » Two wrongs make a… start-up?
Pingback: Inside the Attack that Crippled Revision3
Pingback: MediaDefender = Spawn of Satan | Way Too Much Information About Randy Peterman
Pingback: that canadian girl
Pingback: FVB > Revision3, MediaDefender and the Robot Wars
Pingback: Web 2.0 Announcer
Pingback: For my more nerdly readers . . . by JakeStapleton.com
Pingback: revision3 | Lasts information
Pingback: revision3 | Hottags
Pingback: O’DonnellWeb - This is not a homeschooling blog » Blog Archive » links for 2008-05-29
Pingback: init.sh » [HOWTO] Survive a DoS attack from MediaDefender
Pingback: revision3 | Information Blog
Pingback: FBI Investigating MediaDefender for DoS-ing Revision3 | JustinFlood.com
Pingback: The Lazy Canadian » Blog Archive » It was an accident, I swear.
Pingback: revision3 | hottrends
Pingback: Web 2.0 Announcer
Pingback: Web 2.0 Announcer
Pingback: MPAA Dogs Hack Diggnation
Pingback: Future of News - Tägliche Hard- und Softwarenews
Pingback: MPAA Dogs Hack Diggnation | gadgetsnews.info
Pingback: Revision3 hit with DoS attack. at Garrett Kelley
Pingback: Cell Phones Call Center Cellular Phones
Pingback: drivebychicken.com » Blog Archive » Ancient media must die…
Pingback: virtual risk
Pingback: Online Cash Advance
Pingback: Video Music Photos Mp3 Players
Pingback: Health Insurance Florida Individual Health Insurance Patient Safety
Pingback: Anti Virus Antivirus Filing Bankruptcy
Pingback: Future Shop Cars For Sale Small Dogs For Sale
Pingback: Kassy
Pingback: Totally Free Calling Cards
Pingback: Marketing Direct Mail Marketing Add Link
Pingback: George
Pingback: Boost Adsense Revenue
Pingback: Automated Advertising
Pingback: forexG
Pingback: private kontakte,kontaktanzeigen,private sexcams,private-sexcams.info,erotische kontakte,kontaktanzeigen,kontaktanzeige,er sucht sie, sie sucht ihn, sexkontakte,private sexcam,private livedates,abenteuer,affaire,affaere,amateursex,autosex,bekanntschaft,be
Pingback: Money Quick Cash Ways
Pingback: Web Hosting Free Forum Hosting Dedicated Server Web Hosting
Pingback: World Map Map Of Africa Australia
Pingback: free porn password forum
Pingback: Ass Round Ass Tight Ass
Pingback: Mary
Pingback: Pokemon Harry Potter Naked Pokemon Misty
Pingback: Naked Girls Beyonce Naked Naked Teen Girls
Pingback: Jack
Pingback: Health Insurance Aetna Health Insurance Universal Life Insurance
Pingback: Dogs Ugliest Dogs German Shepherd Puppies
Pingback: Download Games For Mobile Phones
Pingback: free money from the government
Pingback: common florida
Pingback: Online Dating First Date Can You Feel The Love Tonight
Pingback: Ecommerce Michigan Ecommerce Base Business Home Online Opportunity
Pingback: One Way Text Links
Pingback: front page web hosting
Pingback: corporate photography
Pingback: loprox +oily skin
Pingback: diflucan nizoral yeast infection male
Pingback: Business For Sale Mallorca
Pingback: » Revision3 Servers Brought Down By DoS Attack | Bainbridge Studios
Pingback: WP Spam Hitman - Revision3 | www.TheWordpressPlugin.com
Pingback: [gel]
Pingback: Arco Arena Events
Pingback: Barrys tickets
Pingback: Revision3 Servers Brought Down By MediaDefender DoS Attack | Anything + Everything
Pingback: hire australia
Pingback: Jessie
Pingback: different types of bankruptcy
Pingback: befriend
Pingback: Debt Management
Pingback: Bad Credit Debt Consolidation
Pingback: jackie O
Pingback: internet advertising jobs
Pingback: Debt Consolidation
Pingback: Debt Relief
Pingback: local used cars for sale
Pingback: internet advertising jobs
Pingback: can make money teen ways
Pingback: garbage trucks
Pingback: long-leg girls long-leg girls
Pingback: commercial trucks for sale
Pingback: China man
Pingback: liger
Pingback: sonson
Pingback: liger
Pingback: elchinas
Pingback: elchinas
Pingback: AlexanderGreat
Pingback: elchinas
Pingback: elchinas
Pingback: Jack
Pingback: Eric
Pingback: software for insurance agents
Pingback: getting multiple online insurance
Pingback: insurance flood
Pingback: jobs in internet security
Pingback: triumph insurance
Pingback: network insurance agents
Pingback: home loan california no doc
Pingback: adult gear
Pingback: Keith
Pingback: direct tv on computer
Pingback: turn your pc into big ben
Pingback: debt consolidation organizations
Pingback: Computer Rental
Pingback: phone numbers for free debt consolidation
Pingback: information on yeast infection
Pingback: Jessie
Pingback: august burns red mp3
Pingback: A. HALIM
Pingback: Miks
Pingback: Funny Videos
Pingback: Mary Whitten
Pingback: Change Me
Pingback: legitimate business
Pingback: business for sale northwest
Pingback: 150 best flash games
Pingback: HALIM
Pingback: im yours
Pingback: Sex Young Pussy
Pingback: Victoria Redd
Pingback: Stripping
Pingback: young teen fuck
Pingback: hot young teen porn videos
Pingback: hotyoungteen
Pingback: credit repair service
Pingback: credit repair company
Pingback: credit repair service
Pingback: credit repair service
Pingback: fix your credit
Pingback: Teen Couple Porn
Pingback: credit repair company
Pingback: New vs. Old Media :: in propria persona
Pingback: debt consolidation leads
Pingback: credit repair service
Pingback: holiday scout
Pingback: phone numbers for free debt consolidation
Pingback: turn your pc into big ben
Pingback: debt consolidation leads
Pingback: turn your pc into big ben
Pingback: debt consolidation organizations
Pingback: non for profit debt consolidation programs
Pingback: totally free debt consolidation
Pingback: how to watch direct tv on computer
Pingback: Dmitri Young
Pingback: turn your pc into big ben
Pingback: direct tv on computer
Pingback: Isp Deals
Pingback: free pussy movies
Pingback: turn your pc into big ben
Pingback: watch direct tv on computer
Pingback: Crippling
Pingback: Squabble
Pingback: Sara's Prints Kids - Long John Pj's (toddler/little Kids) (ball Game) - Apparel
Pingback: Xerox - Color Printer Supplies - 108r00661 Solid Ink Stick, 3 Ink Sticks, Magenta - Mfg Part: 108r00661
Pingback: Haiku Yakitori 8.25 Bread Knife
Pingback: Computer Printer Supply
Pingback: Verbatim Magenta Toner Cartridge - Magenta
Pingback: Copier Toner Cartridge
Pingback: Compatible Recycled Hp 74xl (cb336wn) High Capacity Black Ink Cartridge
Pingback: Dbl - Boss Audio Systems - Boss 725ca Car Audio Player - Cd-r, Cd-rw - Cd-da, Mp3 - 4 - 200w - Mfg Part: 725ca
Pingback: Director's Collection Brown Leather Home Theater Extension Sofa Seat
Pingback: Iqua Vizor Sun Bluetooth Car Kit
Pingback: Wright Brothers (hardback) - Michelle Prater Burke : Illustrated By Meredith Johnson - Special Order (non-refundable) 2-3 Weeks Despatch
Pingback: Mtd Genuine Part # 1767449 Scr-car 5 16-18x4.
Pingback: Bmw L7 Car Cover
Pingback: Brown Crawling Shoes Kidssize3
Pingback: Vinyl 24 Hour Black Computer Task Chair With High Back
Pingback: Oki Type 9 Black Toner Cartridge - Black
Pingback: Free Shipping. Computer Desk With 2 Corner Hutch
Pingback: Utg Accushot Shadow Ops Olive Drab Sniper Rifle 30 Rnd 460 Fps Bipod Airsoft Gun
Pingback: Brookwood Wall Clock
Pingback: Mini Nitro Gas Rc Car Measures About 10 Inches Long
Pingback: Honda Pilot Car Cover
Pingback: Eurostyle Z Deluxe Small Computer Desk With Shelf
Pingback: Legal Credit Repair For New York State
Pingback: Ibm Toner Cartridge For Ibm Network Printer 12 (4312)
Pingback: Cytosport Monster Milk, 2.2lb
Pingback: superdrupermegapuper54321
Pingback: Nail Head Style Genuine Brown Leather Sofa Couch Love Seat
Pingback: Bunn - Raccoon's Masked Ball 16.00 X 12.00
Pingback: pay day loan wisconsin
Pingback: advance cash fast get in loans online payday
Pingback: Tippmann 98 Custom Act Platinum Marker - Semiauto
Pingback: The Whole Grain Diet Miracle
Pingback: Papush Pink Flowers And Butterflies Shoes Size: 18-24mos
Pingback: online payday loans
Pingback: Valuesmile 3-pack For Compatible Recycled (2) Lexmark 32 And (1) Lexmark 33
Pingback: Cadillac Xlr Car Cover
Pingback: Premium Compatibles Black Toner Cartridge For Lanier Ld425c Printer
Pingback: Konica Minolta Magicolor 4650dn Color Laser Printer
Pingback: cash advance payday loans
Pingback: Pacific Coast Fishing Charts
Pingback: debt consolidation leads
Pingback: Jerry
Pingback: background check
Pingback: buy viagra
Pingback: MP3Monster’s Blog » Blog Archive » Antipiracy company uses denial of service attack on legitimate media company.
Pingback: Twitter Trackbacks for Revision3 > Blog > Inside the Attack that Crippled Revision3 [revision3.com] on Topsy.com
Pingback: TravisHarder.ca » Blog Archive » Old Media v. New Media