Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


DDoS attacks plaguing the internet - Page 3
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

DDoS attacks plaguing the internet

13567

Comments

  • @GCat said:
    A customer of ours got an attack early this morning, and DC decided to kick us off their network. They happily provided me with the dump of the attack log.

    So what happens next? Is that only temporary? That's basically what they mean by null routing right? Cut off customers to protect the rest of the network but only for the duration of the attack right?

    I ask in case it ever happens to me.

  • mavrickmavrick Member
    edited September 2016

    @GCat said:
    A customer of ours got an attack early this morning, and DC decided to kick us off their network. They happily provided me with the dump of the attack log.

    If you don't mind me asking, did you see any new patterns in the attack logs provided to you ?
    Something you haven't seen reported or happen to your networks before ?

  • @pbgben said:
    http://krebsonsecurity.com/ redirects to my localhost :P

    Seems hostsailor smashed him :)

  • NeoonNeoon Community Contributor, Veteran
    edited September 2016

    @dragon2611 said:

    @Neoon said:
    Well, OVH upgrading to 12 VAC's, usually they can tank 160Gbit each, so they could tank with ease 1.9Tbit

    I thought I read somewhere their new ones will be able to handle 500Gbit/s or so each.

    Well, VAC4 is already online, OVH can tank more as 480Gbit.

    http://travaux.ovh.net/?do=details&id=17994

    Thanked by 1GCat
  • tr1ckytr1cky Member
    edited September 2016

    Now is the time to get famous, LET providers. Go get Brian Krebs a new home and you can ocassionally brag about dealing with 700gbps ddos attacks.

    Tagging @matteob here cause he for sure is interested in the free marketing.

  • MaouniqueMaounique Host Rep, Veteran
    edited September 2016

    The attacks will stop when carriers start dropping ASs which launch the attacks, they will have incentives to disconnect the bots.
    The way it works now is this:
    1. Bot launches attacks.
    2. Infected machine owner notices slow connection and machine, goes buy bigger pipe and newer machine paying a lot of money.
    3. Provider upgrades capacity to face the new demands.
    4. Carriers get a large cut and upgrade capacity.
    5. DCs and other targets buy routers and other gear to scrub the attacks, and, you guessed it, more BW.
    6. Some victims pay up so the attackers are not only collecting from angry kids kicked for cheating, but also from major players, big ransoms.
    7. The bot operators operate mainly in impunity and make big money continuously investing into "R&D" to increase their capacity and sophistication.

    So, bot operators make money, practically a whole industry, carriers and ISPs as well as hardware manufacturers make good money, only people who pay to maintain this scheme are victims and infected people.

    Nope, I don't see anything being done to solve the problem until the internet will be shutdown by russia or china. By then, most people will be on p2p encypted layer 8 or 9.

  • ClouviderClouvider Member, Patron Provider

    @teamacc said:
    Would be nice if there was some technical possibility to tell the source router and all routers along the way to drop traffic from [source ip] to [your own ip]. I know this probably wont happen, just dreaming a bit.

    There is. It's called FlowSpecs. Allows for sending firewall like ACL request through BGP. Some tier 1s supported this, that's how some DDoS protection providers were working, they don't any more unfortunately.

  • FranciscoFrancisco Top Host, Host Rep, Veteran

    @Clouvider said:

    @teamacc said:
    Would be nice if there was some technical possibility to tell the source router and all routers along the way to drop traffic from [source ip] to [your own ip]. I know this probably wont happen, just dreaming a bit.

    There is. It's called FlowSpecs. Allows for sending firewall like ACL request through BGP. Some tier 1s supported this, that's how some DDoS protection providers were working, they don't any more unfortunately.

    Last I heard it was shittastic too, very problematic supposedly.

    Francisco

  • TamerciagaTamerciaga Member, Host Rep

    Providers should collaborate and use ingress filtering together, it will be a good move against huge attacks like this.

    https://en.wikipedia.org/wiki/Ingress_filtering

  • FranciscoFrancisco Top Host, Host Rep, Veteran

    @Qarizma said:
    Providers should collaborate and use ingress filtering together, it will be a good move against huge attacks like this.

    https://en.wikipedia.org/wiki/Ingress_filtering

    This isn't a spoofed flood. It's 100's of thousands of compromise DVR's, IP Cameras, and things like that.

    Francisco

    Thanked by 2GCat vimalware
  • ClouviderClouvider Member, Patron Provider

    Francisco said: Last I heard it was shittastic too, very problematic supposedly.

    I suppose not really designed to be used by external peers, but it works quite nice internally when you need to patch something small enough on all your routers at once.

  • HarambeHarambe Member, Host Rep

    @Francisco said:

    >

    This isn't a spoofed flood. It's 100's of thousands of compromise DVR's, IP Cameras, and things like that.

    Francisco

    Is there a published list of the compromised models somewhere?

  • FranciscoFrancisco Top Host, Host Rep, Veteran

    @Harambe said:

    @Francisco said:

    >

    This isn't a spoofed flood. It's 100's of thousands of compromise DVR's, IP Cameras, and things like that.

    Francisco

    Is there a published list of the compromised models somewhere?

    On hackforums I'm sure. The current exploits I've heard so far are:

    • Telnet open on the public interface with a hardcoded root login/password
    • Web interface that passes the login right to CLI for validating w/o any sort of sanitizing/etc (hello HyperVM!)

    Supposedly both are fixed in newer firmwares but short of a vigilanty going through and patching those exploits, it's a shit show.

    Francisco

    Thanked by 1netomx
  • jarjar Patron Provider, Top Host, Veteran
    edited September 2016

    Francisco said: It's 100's of thousands of compromise DVR's, IP Cameras, and things like that.

    Thanks, Amazon. I was thinking about putting my cheap camera from China outside because who cares if the whole world watches the wind blow grass, right? But now... I'm not firewalling it off again, it was too much trouble last time (when I used it indoors).

  • @AnthonySmith said:
    Just give DDOS attacks a severe terrorism charge with minimum life sentence without chance of parole or even the death sentence where allowed, they will reduce pretty quickly.

    That should curb some more of it.

    Pretty sure they call that totalitarianism

  • MaouniqueMaounique Host Rep, Veteran

    It is relatively easy IF ISPs cooperate and are ready to drop infected people.
    Say, one big attack happens, they can see where from the news or internal channels, then simply find out who sends those packets in their network and disconnect the sender. This way they will know they are infected, and, from the attack type, what is vulnerable or how the infection happened.
    It will obviously NOT stop the attacks, but 100 GB+ attacks will not be so accessible anymore, also, the average joe will know what NOT to buy and IoT device manufacturers will have a good incentive to increase security, or, at least, to build SOME damned security in the first place...

  • jarjar Patron Provider, Top Host, Veteran

    mycosys said: Pretty sure they call that totalitarianism

    Hey even communism has to work in one or two situations, right? :)

    Burn the wit...DDOS attackers!

    Thanked by 2mycosys k0nsl
  • MaouniqueMaounique Host Rep, Veteran
    edited September 2016

    jarland said: communism

    That is not the only totalitarianism, there is religious right wing nationalistic racist kind (not with all those characteristics necessarily present, but one usually suffices), the military dictatorship type, technocratic type, oligarchic type, like Mafia states, militaristico-industrialist type (which can mix with others to support them, usually, but has been seen "stand-alone" in the wild, a close example in south korea some decades ago) even corporatist stand-alone cases, there can be mixes of those, too, so, yeah, communism or "socialist" dictatorship is one form of totalitarianism, but very far from being the only one.

    Thanked by 1vimalware
  • dailydaily Member
    edited September 2016

    Why the fuck does everything have to become political? When someone makes a joke, roll with it. Nobody cares about your political opinions unless people look up to you. No offense, but nobody here strikes me as someone I care to know politically. I've shared opinions before, but not every single time someone wants to talk. People learn not to like you that way. Calling @Maounique out.

    Thanked by 1raidz
  • MaouniqueMaounique Host Rep, Veteran

    daily said: Calling @Maounique out.

    K, leaving.

  • @mycosys said:

    @AnthonySmith said:
    Just give DDOS attacks a severe terrorism charge with minimum life sentence without chance of parole or even the death sentence where allowed, they will reduce pretty quickly.

    That should curb some more of it.

    Pretty sure they call that totalitarianism

    That's not really an argument.

  • @Maounique said:

    daily said: Calling @Maounique out.

    K, leaving.

    Not my intention, but your decision.

  • MikeAMikeA Member, Patron Provider

    @daily said:
    Why the fuck does everything have to become political? When someone makes a joke, roll with it. Nobody cares about your political opinions unless people look up to you. No offense, but nobody here strikes me as someone I care to know politically. I've shared opinions before, but not every single time someone wants to talk. People learn not to like you that way. Calling @Maounique out.

    I'm vegan.

  • @daily said:

    @Maounique said:

    daily said: Calling @Maounique out.

    K, leaving.

    Not my intention, but your decision.

    WHAT DID YOU MAKE @MAO DO!!

  • @MikeA said:

    @daily said:
    Why the fuck does everything have to become political? When someone makes a joke, roll with it. Nobody cares about your political opinions unless people look up to you. No offense, but nobody here strikes me as someone I care to know politically. I've shared opinions before, but not every single time someone wants to talk. People learn not to like you that way. Calling @Maounique out.

    I'm vegan.

    Lmao

  • smansman Member
    edited September 2016

    @mycosys said:

    @AnthonySmith said:
    Just give DDOS attacks a severe terrorism charge with minimum life sentence without chance of parole or even the death sentence where allowed, they will reduce pretty quickly.

    That should curb some more of it.

    Pretty sure they call that totalitarianism

    The kid who hacked some company and gave the info to the Islamic State just got 20 years.
    http://abcnews.go.com/US/wireStory/foreign-hacker-aided-islamic-state-sentenced-us-42300022

    Thanked by 1default
  • pbgbenpbgben Member, Host Rep

    It also has to do with media coverage, many if the big players dont know about ddos or care to report about it.

    If the media post articles about the people that have been caught and what's happening to them then maybe there will be more public support.

    DOS attacks, put in layman's terms, are simple. Gain access to a internet connected device and send traffic to a target, in mass quantities this is effective.

    As people have mentioned above, if providers worked together then we could stop this at the device layer, and thus reduce the flow of malicious traffic.

    Like a spam filter or antivirus definition, an appliance can be used to identify malicious traffic and "share" that as a definition, other appliance's receive the definition and check if its coming out via its network and blocks the traffic.

    I know its not that simple, but 100% doable.

  • @sman said:

    @mycosys said:

    @AnthonySmith said:
    Just give DDOS attacks a severe terrorism charge with minimum life sentence without chance of parole or even the death sentence where allowed, they will reduce pretty quickly.

    That should curb some more of it.

    Pretty sure they call that totalitarianism

    The kid who hacked some company and gave the info to the Islamic State just got 20 years.
    http://abcnews.go.com/US/wireStory/foreign-hacker-aided-islamic-state-sentenced-us-42300022

    Deliberately providing intelligence to an enemy state is a VERY different thing to a DDoS.
    I would have thought that obvious to any idiot.

  • oh yea the vDos guys, let's see - they probably end up in jail again anyway, haaretz probably has all dem infoz then. Weird they got out again but the cybercrime laws are... not so clear, especially if you avoid anything local and have some money (being white/jewish also helps, obviously). I expect them to get issues for the owed tax (at 500k or so income noted in the DB at least 200k if paid out to individuals/no infra costs) more likely than the actual business also considering the age.

    Could be their friends at play now, just how it works - the retaliation as usual, might also be some more state like actor but the targets are rather weird then unless they are just side effects of another target that should not be detected.

  • @Maounique said:

    jarland said: communism

    That is not the only totalitarianism, there is religious right wing nationalistic racist kind (not with all those characteristics necessarily present, but one usually suffices), the military dictatorship type, technocratic type, oligarchic type, like Mafia states, militaristico-industrialist type (which can mix with others to support them, usually, but has been seen "stand-alone" in the wild, a close example in south korea some decades ago) even corporatist stand-alone cases, there can be mixes of those, too, so, yeah, communism or "socialist" dictatorship is one form of totalitarianism, but very far from being the only one.

    Honestly I thought much the same - would have much more resemblance to Franco's dictatorship, a Nationalist Corporatist state than any so-called 'socialist' regime (of which there werent actually any) - but it was a throwaway joke and honestly deeper analysis seemed redundant

Sign In or Register to comment.