Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

AVSISP - 3 Days Under DDoS - Update to Clients & Others

avsispavsisp Member, Patron Provider

We are currently dealing with a large DDoS attack against AVS ISP that has been ongoing for approximately 3 days now. We decided it is time to make a post here, as many have been reporting outages falsely due to ICMP filtering and ping limiting.

The main focus of the attack is ICMP (ping), and for that reason we have temporarily disabled ICMP to protect our network and customers.

All VMs remain online. Some customers may see “downtime” alerts from uptime monitoring services that rely only on ping checks. These alerts are false positives caused by ICMP being blocked. We recommend either testing your VM directly (logging in or using the services you run on it) or using monitoring tools that check actual services instead of just ping.

So far we have experienced very little real downtime. The majority of the disruption has been limited to ICMP (ping) filtering. If you do run into problems with your VM or services, please let us know. You can also try rebooting from the control panel if needed.

Because these types of attacks are sometimes used as cover for other malicious activity, we strongly advise customers to:

  • Use SSH keys instead of passwords.
  • Run SSH on a non-standard port or listening only on your VPN IP if using for Wireguard, etc.
  • Restrict access to admin panels or sensitive services with firewall rules (e.g. allowing only your own IP or VPN).

We do not know for certain which customer(s) or service(s) are the direct target of this attack, so it is best that everyone take extra precautions.

Though ICMP is the only service we are fully dropping (ping only, other ICMP being filtered, limited, validated, etc to allow services to function normally) this is indeed a multi-vector attack using such methods as NTP & DNS reflection, UDP AMP, Fragmentation, and many many 100s of vectors.

Thank you for your patience while we continue to mitigate this.

Comments

  • $7 DDOS deals?

    Thanked by 1384_cz
  • What are you doing about it?

    Thanked by 1borkedascii
  • avsispavsisp Member, Patron Provider

    @tsusu said:
    $7 DDOS deals?

    Right now we won't be doing any offers until we get things under control. Don't want new customers to come into a situation where they wonder why they can't ping their VM even though everything is working fine for ssh, http, etc etc.

    After this is over, we will definitely put out a lovely offer - and for those customers sticking with us through this - there will be credits and discounts applied to accounts ☺️

  • avsispavsisp Member, Patron Provider

    @DrNutella said:
    What are you doing about it?

    Filtering it. We are currently filtering between 10 and 50 GB/s of bad traffic. The ICMP pings that people think are down is actually a protection for them and their VM. The limits are per destination, not source. So if their IP isn't pinging, it means they were being attacked and so we are dropping ONLY pings to them to protect their VMs.

    We are working daily throughout this to advance our filtering and soon should have a solution that can validate the ICMP pings before they hit the destination IP filters - allowing more pings to start flowing normal again while still blocking out the bad one. We don't wanna give away details publicly on this as it may allow attackers to develop an evasion solutions to avoid it.

    We must remember LET is public. And as such, the attacker can read this just as much as all of us. Which means we cannot give out all details now. Apologies.

  • MikeAMikeA Member, Patron Provider

    Part of the biz. Happens to all of us. Even right now.

  • Thanks you @avsisp

    Thanked by 2oloke avsisp
  • Thanks, hope it will be gone soon. Not nice to have something destructive like this just because somebody does not like you or what you do.

    Thanked by 2oloke avsisp
  • Thanks <3

  • Heh, sketchy! Since the beginning of your appearance somebody is "attacking" you for unknown reason, first it was due to mitigation the ping was high to your fake locations, now blocking icmp ping requests completely with the pretex to "mitigate" the attack. I mean gona believe you :)

    Thanked by 1zed
  • avsispavsisp Member, Patron Provider

    @iceman said:
    Heh, sketchy! Since the beginning of your appearance somebody is "attacking" you for unknown reason, first it was due to mitigation the ping was high to your fake locations, now blocking icmp ping requests completely with the pretex to "mitigate" the attack. I mean gona believe you :)

    You are a troll who should be banned from the face of the planet for all your attacks on people. Nobody is here to play games with you. We are under a DDoS and we are mitigating it over London. ICMP is disabled due to the attack vectors being used. And we are entirely online otherwise.

    I'm not sure what your personal beef is with me or why you keep coming after me to talk crap - but it's extremely immature and I wouldn't even be surprised if it's you who launched the attack knowing that under DDoS we mitigate through London - so you can run around talking B.S about us not being in Albania which simply isn't true - many ISPs reroute during DDoS for mitigation - standard practice. There is literally a whole market around being the provider you reroute through remotely to filter.

    Do me a favor and leave me alone - go mind your own business - and stop attacking others just for your own personal satisfaction. Nobody has started anything with you until you started attacking me for no reason claiming we aren't in Albania besides the 100s of evidence we gave you otherwise.

    The only thing a DDoS on us is doing is causing us to have to mitigate over London and increase latency back to Albania a bit + drop ICMP echo and filter icmp echo reply to allow only those matching outbound requests. So yeah -- annoying at best.

    If the DDoS does continue much longer, law enforcement in the UK, Albania, and USA will have to be notified as this kind of thing is criminal in nature and this is becoming a Persistent threat instead of a simple "DDoS for fun" at this point.

  • avsispavsisp Member, Patron Provider

    @avsisp said:

    @iceman said:
    Heh, sketchy! Since the beginning of your appearance somebody is "attacking" you for unknown reason, first it was due to mitigation the ping was high to your fake locations, now blocking icmp ping requests completely with the pretex to "mitigate" the attack. I mean gona believe you :)

    You are a troll who should be banned from the face of the planet for all your attacks on people. Nobody is here to play games with you. We are under a DDoS and we are mitigating it over London. ICMP is disabled due to the attack vectors being used. And we are entirely online otherwise.

    I'm not sure what your personal beef is with me or why you keep coming after me to talk crap - but it's extremely immature and I wouldn't even be surprised if it's you who launched the attack knowing that under DDoS we mitigate through London - so you can run around talking B.S about us not being in Albania which simply isn't true - many ISPs reroute during DDoS for mitigation - standard practice. There is literally a whole market around being the provider you reroute through remotely to filter.

    Do me a favor and leave me alone - go mind your own business - and stop attacking others just for your own personal satisfaction. Nobody has started anything with you until you started attacking me for no reason claiming we aren't in Albania besides the 100s of evidence we gave you otherwise.

    The only thing a DDoS on us is doing is causing us to have to mitigate over London and increase latency back to Albania a bit + drop ICMP echo and filter icmp echo reply to allow only those matching outbound requests. So yeah -- annoying at best.

    If the DDoS does continue much longer, law enforcement in the UK, Albania, and USA will have to be notified as this kind of thing is criminal in nature and this is becoming a Persistent threat instead of a simple "DDoS for fun" at this point.

    And here is your lovely logs for proof of the DDoS so I don't have to hear you claiming it doesn't exist:

    Full output of stats:

    | SYN packets received:         1792054
    | SYN cookies sent:             1527612
    | SYN direct whitelisted:       264442
    | SYN Prod. activated:          1527612
    | SYN allowed:                  3658288
    | ACK packets received:         57196402
    | ACK packets validated:        402610
    | ACK packets dropped:          592904
    | Rate limited packets:         11166068168
    | Malformed packets:            1337804895
    | UDP blocked:                  361315045
    | UDP allowed:                  83160826
    | ICMP blocked:                 580751239
    | ICMP allowed:                 749236232
    | TCP invalid packets:          2985
    | SYN-ACK attacks blocked:      0
    | RST flood blocked:            1148950
    | RST allowed:                  223957
    | FIN flood blocked:            56650
    | FIN allowed:                  1697266
    | URG flood blocked:            0
    | PSH flood blocked:            540
    | Large payload blocked:        0
    | Retransmission blocked:       0
    | SRC-DST port invalid:         2267617465
    | Whitelist auto-renewed:       144803
    | Fragments blocked:            8892056009
    | Fragments allowed:            65542255
    | First fragments blocked:      3220444223
    | First fragments allowed:      23806959
    | Unsolicited SYN-ACK blocked:  0
    | Unsolicited SYN-ACK allowed:  11042
    | SYN rate limited whitelisted: 25802
    | AMP attacks blocked:          358919030
    | AMP packets allowed:          51511
    | DNS from trusted servers:     92142
    | AMP mitigation activated:     0
    

    Current size dropped (goes up and down):

    Type         PPS          Throughput (Mbit/s) Throughput (Gbit/s)
    ----------------------------------------------------------------------------
    Drops        2200840      5686 Mbit/s        5.69 Gbit/s       
    ----------------------------------------------------------------------------
    

    1-second dropped packets:

    Drops/s: 2124668   TX/s: 161
    

    1-second report:

    ===== 15:50:59 =====
    Large payload blocked:                     0
    SYN Prod. activated:                     146
    URG flood blocked:                         0
    PSH flood blocked:                         0
    Fragments allowed:                     4,863
    ACK packets received:                 10,148
    SYN cookies sent:                        146
    AMP packets allowed:                       2
    RST allowed:                              31
    UDP allowed:                          12,772
    Rate limited packets:              1,714,472
    FIN allowed:                             305
    Unsolicited SYN-ACK blocked:               0
    SYN-ACK attacks blocked:                   0
    First fragments blocked:             487,480
    ICMP allowed:                        291,825
    Retransmission blocked:                    0
    Unsolicited SYN-ACK allowed:               2
    DNS from trusted servers:                 11
    ACK packets validated:                    61
    SYN direct whitelisted:                   40
    RST flood blocked:                        99
    SYN allowed:                             531
    FIN flood blocked:                         7
    UDP blocked:                          50,121
    Whitelist auto-renewed:                   30
    Fragments blocked:                 1,340,032
    Malformed packets:                   216,475
    SYN rate limited whitelisted:               0
    AMP attacks blocked:                  49,780
    ACK packets dropped:                       3
    TCP invalid packets:                       0
    SRC-DST port invalid:                373,889
    AMP mitigation activated:                  0
    ICMP blocked:                            943
    First fragments allowed:               1,764
    SYN packets received:                    186
    

    There you go. Plenty of proof that a DDoS is indeed underway... Day 4 now.

    Thanked by 1oloke
  • zedzed Member

    subscribe

  • @zed said: subscribe

    Popcorn reserved.

    Thanked by 1oloke
  • VlPVlP Member

    Seems my Albania VPS is unreachable..And panel also inaccessible?

  • @VlP said: unreachable

    Yeah same...mine was jumping up and down and there was period where ssh did not work but everything else worked fine. Currently not working.

  • avsispavsisp Member, Patron Provider

    Yes. We are working on it all day. The attackers keep switching methods. We have to update filters to keep up.

    Thanked by 1oloke
  • avsispavsisp Member, Patron Provider

    Is anyone else still having any issues? This is a call for feedback.

    Other than PING, everything should be working perfectly.

    Apologies for the late replies here - have been working hard to try and keep everything online despite the attempts from them to try any method they can to keep us down.

    Anyone who wants to - we can move you to London for free. Just let us know.

    We promise - we are doing everything in our power to ensure everything stays online NO MATTER WHAT. The attacker(s) are/is stubborn. But so are we.

    We made a promise to this community that we would never deadpool and we meant it. Do not worry - all data is safe, everything will remain online. And we are working hard to ensure it stays that way.

  • My server works but cannot ssh into it, which is not a bit deal for the time being but annoying ofc.

  • avsispavsisp Member, Patron Provider

    @JohnFilch123 said:
    My server works but cannot ssh into it, which is not a bit deal for the time being but annoying ofc.

    Please try changing your SSH port, running after "systemctl restart ssh && systemctl restart ssh.socket && systemctl restart ssh" and then trying?

    It could be that your SSH port is a commonly used port for another service abused during a DDoS and is being blocked for that reason. It seems highly likely that this is the case here as I remember speaking earlier and you having the same issue and all.

  • @avsisp said: Please try changing your SSH port, running after "systemctl restart ssh && systemctl restart ssh.socket && systemctl restart ssh" and then trying?

    Tried it and it did not help. Getting timeout on all the ports I tried.

  • avsispavsisp Member, Patron Provider

    @JohnFilch123 said:

    @avsisp said: Please try changing your SSH port, running after "systemctl restart ssh && systemctl restart ssh.socket && systemctl restart ssh" and then trying?

    Tried it and it did not help. Getting timeout on all the ports I tried.

    First attempt will always fail due to SYN cookies. You have to retry attempt at least 2 times back to back. Then it should unlock and go.

  • @avsisp said: You have to retry attempt at least 2 times back to back

    Tried it like 10 times, does not work.

  • icemaniceman Member
    edited September 2025

    @avsisp said:

    @iceman said:
    Heh, sketchy! Since the beginning of your appearance somebody is "attacking" you for entirely online otherwise.

    I'm not sure what your personal beef is with me or why you keep coming after me to talk crap - but it's extremely immature and I wouldn't even be surprised if it's you who launched the attack knowing that under DDoS we mitigate through London - so you can

    Stop accusing me for your shitty services you dumbfc! Unlike you, i don't do illegal shit and you or your services are not worth a minute of my time! You had "ddos attack" (as per your words in another thread) before i even knew or heard about you and your crappy services! A Wyoming registered company, providing prices with albanian shitty currency, tunneling everything to hide your crap and its my fault and everyones for your shitty crap services that dont work!

  • allthemtingsallthemtings Member, Megathread Squad

    @iceman said:

    @avsisp said:

    @iceman said:
    Heh, sketchy! Since the beginning of your appearance somebody is "attacking" you for entirely online otherwise.

    I'm not sure what your personal beef is with me or why you keep coming after me to talk crap - but it's extremely immature and I wouldn't even be surprised if it's you who launched the attack knowing that under DDoS we mitigate through London - so you can

    Stop accusing me for your shitty services you dumbfc! Unlike you, i don't do illegal shit and you or your services are not worth a minute of my time! You had "ddos attack" (as per your words in another thread) before i even knew or heard about you and your crappy services! A Wyoming registered company, providing prices with albanian shitty currency, tunneling everything to hide your crap and its my fault and everyones for your shitty crap services that dont work!

Sign In or Register to comment.