Live data from Hacker News

Posterous is being DDoS'd

twitter.com

31–40 of 49 posts

Re: Posterous is being DDoS'd

#31

Earlier quoted context omitted.

Maybe, and take it with a grain of salt, some people got infuriated by their recent switch to posterous campaign. I know this may be a very remote option, but in my opinion it's very possible.

"A grain of salt" is the expression.

Thank you

Re: Posterous is being DDoS'd

#32

So this is the 2nd DDOS attack. Can DDOS attack be fended off?

Usually it means using a hardware solution like Intruguard or going through a third party vendor that resells Intruguard and/or other proprietary anti-DDOS technology.

We've opted to use Gigenet, and they're holding the line right now quite well.

Re: Posterous is being DDoS'd

#33
post #6

Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.

The botnet controller could be extorting websites directly... wire $5000 to my paypal account or your website will go down. Anyone from Posterous care to confirm/deny in this case?

Re: Posterous is being DDoS'd

#34
post #6

Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.

The botnet controller could be extorting websites directly... wire $5000 to my paypal account or your website will go down. Anyone from Posterous care to confirm/deny in this case?

Do you have any evidence that this has ever been done in the past?

It's not inconceivable, but it seems like a huge leap.

Re: Posterous is being DDoS'd

#35

We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…

I really wish setting DNS TTL's to 5 minutes meant that browsers and everything else (OS caching) would respect that but sadly in my experience it doesn't.

Surprising that it works so well for you.

Re: Posterous is being DDoS'd

#36
post #6

Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.

Who knew what the attackers are thinking. Not too long ago DnsMadeEasy was DDoS from Korea.

Maybe there's financial incentives?

Re: Posterous is being DDoS'd

#37

We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…

Gigenet's service looks interesting. They don't provide pricing though. I'm guessing it's not cheap? Is it based on the bandwidth they'd have to use?

Re: Posterous is being DDoS'd

#38

We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…

Relying on a DNS TTL of 5 minutes doesn't work everywhere. Some ISPs will forcefully reset any TTL below 24 hours to 24h.

Re: Posterous is being DDoS'd

#39
post #34

Earlier quoted context omitted.

The botnet controller could be extorting websites directly... wire $5000 to my paypal account or your website will go down. Anyone from Posterous care to confirm/deny in this case?

Do you have any evidence that this has ever been done in the past? It's not inconceivable, but it seems like a huge leap.

Google seems to provide plenty of examples. Even if it didn't, I don't understand why you see this extortion as a stretch.

Re: Posterous is being DDoS'd

#40
post #38

We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…

Relying on a DNS TTL of 5 minutes doesn't work everywhere. Some ISPs will forcefully reset any TTL below 24 hours to 24h.

AT&T/sbcglobal being one.
Post reply on HN