Earlier quoted context omitted.
Maybe, and take it with a grain of salt, some people got infuriated by their recent switch to posterous campaign. I know this may be a very remote option, but in my opinion it's very possible.
"A grain of salt" is the expression.
Posterous is being DDoS'd
31–40 of 49 posts
Re: Posterous is being DDoS'd
#32So this is the 2nd DDOS attack. Can DDOS attack be fended off?
We've opted to use Gigenet, and they're holding the line right now quite well.
Re: Posterous is being DDoS'd
#33Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.
Re: Posterous is being DDoS'd
#34Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.
The botnet controller could be extorting websites directly... wire $5000 to my paypal account or your website will go down. Anyone from Posterous care to confirm/deny in this case?
It's not inconceivable, but it seems like a huge leap.
Re: Posterous is being DDoS'd
#35We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…
Surprising that it works so well for you.
Re: Posterous is being DDoS'd
#36Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.
Maybe there's financial incentives?
Re: Posterous is being DDoS'd
#37We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…
Re: Posterous is being DDoS'd
#38We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…
Re: Posterous is being DDoS'd
#39Earlier quoted context omitted.
The botnet controller could be extorting websites directly... wire $5000 to my paypal account or your website will go down. Anyone from Posterous care to confirm/deny in this case?
Do you have any evidence that this has ever been done in the past? It's not inconceivable, but it seems like a huge leap.
Re: Posterous is being DDoS'd
#40We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…
Relying on a DNS TTL of 5 minutes doesn't work everywhere. Some ISPs will forcefully reset any TTL below 24 hours to 24h.