Live data from Hacker News

Posterous is being DDoS'd

twitter.com

41–49 of 49 posts

Re: Posterous is being DDoS'd

#41
post #6

Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.

The botnet controller could be extorting websites directly... wire $5000 to my paypal account or your website will go down. Anyone from Posterous care to confirm/deny in this case?

This is very common with online gaming (== gambling) sites, and payment systems; anything where there is obviously money being processed.

Re: Posterous is being DDoS'd

#42
post #38

We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…

Relying on a DNS TTL of 5 minutes doesn't work everywhere. Some ISPs will forcefully reset any TTL below 24 hours to 24h.

Absolutely true, and completely ridiculous. What, DNS bandwidth is too high? Please.

Re: Posterous is being DDoS'd

#43
post #42
post #38

Earlier quoted context omitted.

Relying on a DNS TTL of 5 minutes doesn't work everywhere. Some ISPs will forcefully reset any TTL below 24 hours to 24h.

Absolutely true, and completely ridiculous. What, DNS bandwidth is too high? Please.

Well, not following the RFCs is bad, but I can see why they do it.

Most people using low TTLs probably don't know what they're doing, and if you're a big ISP having to constantly make recursive queries hurts page load times for your customers, who'll blame you.

Re: Posterous is being DDoS'd

#44
post #6

Why DDOS posterous? What's there to gain from it? This isn't like the ones who DDOS'ed MS out of their hatred for it or the ones who blackmailed & DDOS'ed a gambling website when they refused to pay up.

Could this have anything to do with Posterous' risqué post claiming superiority over Tumblr?

http://www.blogherald.com/2010/06/24/posterous-slanders-tumb...

Re: Posterous is being DDoS'd

#45

We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes. TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be l…

[deleted]

Re: Posterous is being DDoS'd

#46
I could claim with nearly all certainty that this is a result of their campaign. The attacked several communities. Not just startups, but communities with developers (wordpress, tumblr etc). Their marketing was bold; but looking back they might have been more subtle.

Re: Posterous is being DDoS'd

#49
post #34

Earlier quoted context omitted.

The botnet controller could be extorting websites directly... wire $5000 to my paypal account or your website will go down. Anyone from Posterous care to confirm/deny in this case?

Do you have any evidence that this has ever been done in the past? It's not inconceivable, but it seems like a huge leap.

It's not uncommon. There was an article a long time ago telling the story of a DDOS attack on a gambling website, and how a guy who was a philosophy major (iirc) figured out how to beat it, and then formed a company providing the same service. Forgot the url/title/etc, but it was good. Plenty more available with a search.
Post reply on HN