Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


DDOS UK StormVZ - Page 3
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

DDOS UK StormVZ

1356

Comments

  • No...

  • Nick_ANick_A Member, Top Host, Host Rep

    @taronyu said: I/O and network. Your vps'es are awesome however in the US. StormVZ looks really nice (is ssd and on a gigabit port) and is in the UK. That would be awesome as my yearly box to put irc on it. While I keep 2 at Ramnode for testing and using.

    I don't think they still offer SSD, but I'll be happy to be corrected. That idea lasted a couple weeks IIRC.

  • This is it, im going to sleep.

    I'm sure I saw ssd on the site. Apperently not...

  • Nick_ANick_A Member, Top Host, Host Rep

    @taronyu said: I'm sure I saw ssd on the site. Apperently not...

    It was lingering on their ads and somewhere on their site, but I'm pretty Patrick dropped that a while back.

  • jarjar Patron Provider, Top Host, Veteran

    I think everyone in this thread overlooks the most likely possibility.

    The Chinese government secretly hates the UK.

  • @Neo Hardly matters how simple it is, I doubt they're even looking at tickets. Is your question more urgent than getting everyone else's servers back up? If not, I suspect you'll be waiting for a while.

  • PatrickPatrick Member
    edited February 2013

    image

    Have fun with that 5Gbps+ which was all towards us, it peaked at 19Gbps for a few minutes yesterday to later that day after that SS we got sent.

    We are not ignoring you, refunds/credits/tickets will be replied to by next week.

    We hope all VPSs are restored by the end of this weekend.

  • :O
    @Patrick

    Why is it outputting 13Gbps

  • @Patrick if you need any help with the load of tickets throw me a PM.

    Same offer here, if you need it. I have no problem with helping someone on need - especially when they provide such an amazing service.

    Otherwise, I look forward to finally seeing the end of these attacks, and for everything to settle down, because you really do provide a great service!

  • PatrickPatrick Member
    edited February 2013

    @Patrick

    Why is it outputting 13Gbps

    A mixture of SYN/UDP/Spoofing/DNS Amplification

    We were told:
    "The bandwidth graph on your account won't show as the switch is being hammered - the attack is over 6G"

    95th percentile is over 3G per second on one link currently. We have 2 main links serving traffic to you- that's approaching 7G on 95th percentile.

    Looking at a £10k bill if we let it continue.

  • @Patrick said: "The bandwidth graph on your account won't show as the switch is being hammered - the attack is over 6G"

    Someone must really hate you. sigh

  • PatrickPatrick Member
    edited February 2013

    @Jack said: Wait @Patrick is that your Switch or all RS's bandwidth?

    It's there switch, 6G+ was incoming towards us.

  • PatrickPatrick Member
    edited February 2013

    Some more network porn:

    Network Link one:
    image

    Network Link two:
    image

    We had got all our servers moved to one rack and the outcome above.

  • Happened to me once, and first thing I did was get my own ip's and network connections.

  • Why is it showing outgoing? If the graph reversed?

  • AlexBarakovAlexBarakov Patron Provider, Veteran

    @Patrick said: Looking at a £10k bill if we let it continue.

    Why are you tanking it, if it does take down your nodes? Just apply nullroutes and wait for it to pass. Not sure if I am not mistaken, however according to this thread - the VMs are down, so no reason to keep tanking the traffic?

  • PatrickPatrick Member
    edited February 2013

    @apollo15 said: Why is it showing outgoing? If the graph reversed?

    Outbound to server from switch I think it is

    @Alex_LiquidHost said: Why are you tanking it, if it does take down your nodes? Just apply nullroutes and wait for it to pass. Not sure if I am not mistaken, however according to this thread - the VMs are down, so no reason to keep tanking the traffic?

    They were targeting any IP, rotating every few minutes. They just null routed all the IP blocks, but it's still costing them money because it's null routed at router but they still have to pay bandwidth fees from there T1 peers as overages as it's incoming to the DC?

    As it appears they don't have BGP community to blackhole traffic

  • Nick_ANick_A Member, Top Host, Host Rep

    @Patrick said: As it appears they don't have BGP community to blackhole traffic

    D:

  • AlexBarakovAlexBarakov Patron Provider, Veteran

    @Patrick said: As it appears they don't have BGP community to blackhole traffic

    Which DC is this? I find it extremely weird they don't have a BGP in the DC.

  • PatrickPatrick Member
    edited February 2013

    @Alex_LiquidHost said: Which DC is this? I find it extremely weird they don't have a BGP in the DC.

    Blackhole Community, they do have BGP ofc

    RapidSwitch

    Though I could be talking crap, they weren't happy with even a 1Gbps attack few months back. There was also a ~500mb/s incoming attack just before that 1Gbps earlier that day and did nothing and waited for me to find the attacked ips to null route. Surely could have taken them few secs to check on there end/router?

  • @Jack said: Depends they have senior network engineers which are the only ones that can do netflow's ect therefore standard techs dont have that access.

    It was around 3-5PM when that happened anyways, whats done is done.

    RS overall provided good service when we didn't need support.

  • Sadly, ddos can really ruin the business, especially small ones. Hope you will recover somehow, wish you best of luck Patrick.

  • zserozsero Member

    This is proper shit, I really loved StormVZ in the UK. I only used them on a tiny node, but they were a much much better experience then I had with httpzoom before.

  • It was interesting how easy was to storm kick Patrick out of his own country :)

  • NekkiNekki Veteran

    @goexodus said: It was interesting how easy was to storm kick Patrick out of his own country :)

    Either you're an arsehole or that's a really inappropriate use of a smile.

  • @goexodus let me know a provider that lets you tank 15gbps without kicking you out or charging you thousands of whom doesn't target ddos protection services

  • fislefisle Member

    Wow insane amount of data. Hope you will defeat this, I'd want to see the look on their faces when they are unable to shut you down.
    It's sad that some people have to use these kind of tactics to attract more customers to their shitty services. :/ We really should dig deeper to find out what's going on in UK.

  • NekkiNekki Veteran

    @fisle said: Hope you will defeat this, I'd want to see the look on their faces when they are unable to shut you down.

    They're already moving to NL from the UK.

  • fislefisle Member

    @Nekki said: They're already moving to NL from the UK.

    Oh, too bad. But yeah reasonable since the costs become so high. Good luck with the move!

  • goexodusgoexodus Member
    edited March 2013

    @Patrick First you have to ask yourself who would spend money and time to attach three of your little servers in the UK with such ferocity.

    Then you should ask whether you had the proper emergency response planned and whether you had an SLA to mitigate risk away from your hands. Did you made the right choice in the first place about your DC in terms of being able to handle such threats with Auto DDoS detection, immediate response procedures, upstream router traffic shaping, whitelists etc. Even after the fact do they even have all the logs needed to prosecute and deliver the data to the authorities.

    Maybe in the end you should educate all of us about the lessons learned.

Sign In or Register to comment.