Live data from Hacker News

Posterous is being DDoS'd

twitter.com

11–20 of 49 posts

Re: Posterous is being DDoS'd

#11
post #6

Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.

I severely doubt this line of thought.. but they didn't make any friends with their "switch from X to us" campaign, and it only takes one bruised ego with a lack of ethics to stir up trouble. That said, if it's like most other DDOS attacks I've seen reported, the target is probably a user of the service with Posterous merely being unlucky enough to host a particular site someone doesn't like. I vaguely recall another…

Must be something that they really dislike.

Re: Posterous is being DDoS'd

#13
post #6

Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.

someone probably has an issue w/ the blog/content of someone who is using posterous rather than posterous themselves.

[deleted]

Re: Posterous is being DDoS'd

#14
post #6

Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.

Maybe, and take it with a grain of salt, some people got infuriated by their recent switch to posterous campaign. I know this may be a very remote option, but in my opinion it's very possible.

"A grain of salt" is the expression.

Re: Posterous is being DDoS'd

#16
post #6

Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.

Never underestimate the power of lulz when trying to understand a DDoS.

Re: Posterous is being DDoS'd

#17
post #5

Our datacenter is experiencing heavy packet loss. We're on the line with Rackspace now. I don't see where they stated it was a DDOS attack. Packet loss can occur due to a large number of different issues. EDIT: They just clarified with the following: The DDoS attackers have returned and evolved their attack around our countermeasures. We expect to be back online ASAP w/ @gigenet antiddos

It's interesting that they're basically saying Rackspace's network couldn't hold up and doesn't have an effective solution for DDOS victims on their network.

Gige's DDOS protection is basically a hosted redirect and filtering system that "leverage[s] the cost of DDoS mitigation amongst a large group of businesses, giving you access to the infrastructure that would normally be out of reach financially." http://www.gigenet.com/ddos-protection.html

But if Posterous is hosted on the Rackspace cloud, why isn't there a mechanism to do this through their existing host? After all, Rackspace has an equivalent service (maybe rebranded?) that would seem to offer protection without needing to go to a 3rd party vendor. http://www.rackspace.com/managed_hosting/services/security/d...

So it's interesting that Posterous needed to go around Rackspace to get a solution.

Re: Posterous is being DDoS'd

#18
We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes.

TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be learning. But then again, so are we.

Gigenet's anti-DDoS service has helped us a ton here and is now serving as our front door IP to block the synflood. They've been really responsive.

Re: Posterous is being DDoS'd

#19
post #6

Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.

someone probably has an issue w/ the blog/content of someone who is using posterous rather than posterous themselves.

That's my guess as well.

Weebly said (I think in their YC Founders at Work interview) that they get multiple DDoSes a day, aimed not at them but at sites they host. Now they have good enough systems in place to deal with it that they said they often just don't notice.

I guess when you host enough people's content, it's only a matter of time before someone wants to DoS something you're hosting.

Re: Posterous is being DDoS'd

#20

We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…

Any suggestions for customers with DNS names pointing to posterous blogs? Are we going to need to follow you on each hop?
Post reply on HN