The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…
I would add Turkey to that list. Many many years ago I had a kind of popular podcast about computer graphics and all of my grief was coming from Turkey. After I banned all of Turkey‘s IPs my drama was over. Occasionally I would get an email from someone saying they couldn’t listen to the episodes and I would explain to them why their country is blocked and they would say it’s not fair, I couldn’t disagree, its not fa…
Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
31–40 of 151 posts
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#32The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…
Harm vs good assessment, anyone?
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#33Earlier quoted context omitted.
I'm curious what kind of grief a country caused you for a podcast. What were they doing?
Constantly trying to get to the backend of the site and occasional ddos. Once one of them managed to deface the front page I had enough and just banned all of Turkey.
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#34Earlier quoted context omitted.
I would add Turkey to that list. Many many years ago I had a kind of popular podcast about computer graphics and all of my grief was coming from Turkey. After I banned all of Turkey‘s IPs my drama was over. Occasionally I would get an email from someone saying they couldn’t listen to the episodes and I would explain to them why their country is blocked and they would say it’s not fair, I couldn’t disagree, its not fa…
I would remove Turkey from that list. Because, Turks are turks and they should have their own category. Also, Why would turks specifically target a computer graphics podcast ? I don't think it makes sense at all...
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#35Earlier quoted context omitted.
Constantly trying to get to the backend of the site and occasional ddos. Once one of them managed to deface the front page I had enough and just banned all of Turkey.
What were they upset about? "Computer graphics" doesn't sound like a controversial topic.
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#36This just feels like a typical sales team fluff piece. I worked in this space, and constantly read articles of different providers claiming to have blocked the biggest attack ever. Some go by total bandwidth, some by pps, some by number of actors, and apparently some by rps. Not that it isn't impressive, still, but hardly seems newsworthy.
Usually I wouldn't post a Cloudflare mitigates blah blah blah blog, but I thought this one was particularly interesting because of the range of addresses, an attack that large spawning from over 30,000 IPs is a pretty well orchestrated attack. The most I've read pervious was well under half that (granted I've been out of networking for a long time).
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#37The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…
I suppose that would put cloudflare and anyone else doing ddos mitigation out of business.
When I worked at a small ISP and we would get complaints, we would block the user until we could reach them. Then let them online long enough to update their antivirus. I can't imagine Comcast committing to that, but it would be nice.
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#38Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#39The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…
Just for a different perspective, here in the EU I get most of the attacks from US servers. Often times Google cloud or AWS. But we can't block the IP space of the US for obvious reasons
Yup.
The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's.
These days most attacks originate from US/Western cloud and other rent-a-box providers.
They are a gift to attackers because they can hop around at the click of the button and they know the victims can't block the IP ranges because they're managed by US/Western organisations.
DDOS attacks tend to happen on a Command and Control basis, and again, good luck blocking US/Western ISP IP ranges because their customers won't be able to visit your website.
I have long given up on reporting to Google, AWS and others because nothing gets done, most of the time you get an automated message saying they just forward your Abuse report to the customer ... gee, thanks guys.
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#40Earlier quoted context omitted.
Usually I wouldn't post a Cloudflare mitigates blah blah blah blog, but I thought this one was particularly interesting because of the range of addresses, an attack that large spawning from over 30,000 IPs is a pretty well orchestrated attack. The most I've read pervious was well under half that (granted I've been out of networking for a long time).
30k isn’t even noteworthy in size for botnets thanks to shitty iot stuff. Mirai attacked Dyn with 100k unique devices.