Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Thank Jebus Bhrist. - Page 2
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Thank Jebus Bhrist.

2

Comments

  • jbilohjbiloh Administrator, Veteran

    @thedp said:
    And all of this is supposedly because of a ban on Discord? :D

    No kidding, right?

  • yoursunnyyoursunny Member, IPv6 Advocate
    edited July 2021

    @stevewatson301 said:

    @yoursunny said: directly accessing the IP would leak the certificate of available virtual hosts.

    You could also use a webserver like caddy which only presents certificates if the ServerName in ClientHello matches one of the configured certificates, and sends a TLS alert otherwise.

    As I mentioned at the bottom, the MJJ's scanning method is ineffective: the attacker should always include the target domain instead of the IP in the ClientHello, so that the TLS server would return the certificate if it exists.
    Using a TLS server that validates SNI cannot protect against this improved attack.

    @yoursunny said: It is possible to configure firewall to only allow Cloudflare IP Ranges, but this would require periodical updates so that it's more complex than using a random IPv6 that nobody could guess.

    If the DDOS has already reached the origin, it's difficult to handle it using a firewall as it would now compete for CPU with the rest of the kernel and applications. You could consider filtering IPs in the PREROUTING tables though so that the packets get dropped without conntrack being invoked.

    The firewall is not a countermeasure for DDoS.
    It is to prevent finding the server by scanning global IP space, because anyone other than Cloudflare cannot reach the webserver.

    Thanked by 1dahartigan
  • DPDP Administrator, The Domain Guy

    @jbiloh said:

    @thedp said:
    And all of this is supposedly because of a ban on Discord? :D

    No kidding, right?

    But yeah, it's not that surprising, considering I have been on IRC since the 90s (until today) and have seen my fair share of attacks that has happened for no apparent reason even.

  • skorupionskorupion Member, Host Rep

    and once again ddos. FUCK YOU ATTACKERS

  • jbilohjbiloh Administrator, Veteran

    Yes the attacks are absolutely raging, constantly changing techniques and really causing some annoyances over here. Why attack our community?

  • LeeLee Veteran

    @jbiloh said: Why attack our community?

    lol.

    Thanked by 2BlaZe donko
  • Use proper ddos protection instead of colocrossing weaksauce protection & dont have to hide behind cloudflare.

    Thanked by 1redcat
  • defaultdefault Veteran

    @jbiloh said:
    [...] Why attack our community?

  • against american :D

  • right ????????

  • Time to have a little drinkiepoo..

  • HakimHakim Member

    What does "MJJ" stand for?

  • Having to solve all these captchas is getting annoying though. @yoursunny can you please implement a captcha where the user has to do pushups in front of the device?

  • yoursunnyyoursunny Member, IPv6 Advocate
    edited July 2021

    @Hakim said:

    What does "MJJ" stand for?

    LET celebrity @codydoby explains MJJ:
    https://www.lowendtalk.com/discussion/comment/3210266/#Comment_3210266

    Note: he is unlikely to be the attacker.


    @stevewatson301 said:
    Having to solve all these captchas is getting annoying though. @yoursunny can you please implement a captcha where the user has to do pushups in front of the device?

    squat captcha

    push-ups required for phpinfo()

    Thanked by 2Hakim dahartigan
  • LeviLevi Member

    It is pathetic how LET owners unable to cope with this MJJ DDoS. Monetized traffic to the max and still cluster can't hold a bit of traffic spike.

  • @Ahfaiahkid said:
    Use proper ddos protection instead of colocrossing weaksauce protection & dont have to hide behind cloudflare.

    Your statement isn't helpful at all. Cloudflare is required at the moment, as that attack is L7 (Application layer).

    Yes, there are better solutions than Cloudflare, but they're expensive ($$$).

  • LeviLevi Member

    @Gabitzuu said:

    @Ahfaiahkid said:
    Use proper ddos protection instead of colocrossing weaksauce protection & dont have to hide behind cloudflare.

    Your statement isn't helpful at all. Cloudflare is required at the moment, as that attack is L7 (Application layer).

    Yes, there are better solutions than Cloudflare, but they're expensive ($$$).

    LET has a ton of money to spare. From all that juicy traffic. At the moment it is golden age on this forum.

  • jbilohjbiloh Administrator, Veteran

    The battle continues guys. Sorry about the issues.

    We've doubled our hosting resources and are working diligently to block the evolving attacks.

    Thanked by 1Levi
  • jbilohjbiloh Administrator, Veteran

    Woohoo attacks continue. Doing our best everyone.

  • jbilohjbiloh Administrator, Veteran

    Test post

    Thanked by 1pedagang
  • skorupionskorupion Member, Host Rep

    @jbiloh said:
    Test post

    just buy a fcking better l7 protection from the ad money ffs

    Thanked by 2yoursunny dosai
  • jbilohjbiloh Administrator, Veteran

    @skorupion said:

    @jbiloh said:
    Test post

    just buy a fcking better l7 protection from the ad money ffs

    The effort continues.

    Thanked by 1CheepCluck
  • skorupionskorupion Member, Host Rep

    This website www.lowendtalk.com/ is currently offline. Cloudflare's Always Online™ shows a snapshot of this web page from the Internet Archive's Wayback Machine. To check for the live version, click Refresh

  • skorupionskorupion Member, Host Rep

    use Google cloud armor it won't cost you so much ffs @jbiloh

  • jbilohjbiloh Administrator, Veteran

    I will look into that, thanks for the suggestion.

  • @skorupion said: use Google cloud armor it won't cost you so much ffs @jbiloh

    Referring to this by any chance? https://cloud.google.com/armor
    If so, have you seen the price tag of $3000/mo with per request billing as well? A DDOS protected website, along with the tips mentioned above by yoursunny, will help you a long way.

    If you were referring to https://projectshield.withgoogle.com/landing, then it's only for political/news orgs/non-profits, so not an option.

  • skorupionskorupion Member, Host Rep

    @stevewatson301 said:

    @skorupion said: use Google cloud armor it won't cost you so much ffs @jbiloh

    Referring to this by any chance? https://cloud.google.com/armor
    If so, have you seen the price tag of $3000/mo with per request billing as well? A DDOS protected website, along with the tips mentioned above by yoursunny, will help you a long way.

    If you were referring to https://projectshield.withgoogle.com/landing, then it's only for political/news orgs/non-profits, so not an option.

    it's pay as you fucking go, and that ddos attack can't cost let much more than 20 bucks

  • skorupion losing billions while LET is taking hits

    Thanked by 2yoursunny neverain
  • skorupionskorupion Member, Host Rep

    @GOBBLES said:
    skorupion losing billions while LET is taking hits

    billions? I woudnt even budge WE ARE TALKING ABOUT TRILLIONS

  • PMS-ing over LET downtime, that's new. Touch grass.

    Thanked by 2yoursunny bulbasaur
Sign In or Register to comment.