Sounds like an opportunity for the other managed Rails hosts.
>"Sounds like an opportunity for the other managed Rails hosts." They can play it up, but if you throw enough bandwidth at /any/ host, they'll null route you. Other hosts (at least, the not-stupid ones who have been in this position before) know this and (hopefully) wouldn't sling mud at them over this.
Pastie.org host pulls hosting after DDoS attack
71–80 of 90 posts
Re: Pastie.org host pulls hosting after DDoS attack
#72Re: Pastie.org host pulls hosting after DDoS attack
#73I'd like to apologize to those who have been negatively impacted by my decision to pull support for Pastie (especially Josh). To understand why I made the decision to pull our support after 9 hours of multiple DDOS attacks, I'd like to share some background and our ops philosophy. It is important to understand that I put our existing customers that pay us to manage and scale their high growth revenue-generating web a…
Keep on keeping on. You made the right choice and in the long run dealing with the take down notices and legal wrangling would have been a full time job.
What most people probably wont understand is that no sane business is going to go to bat for a non-customer who is costing them signifigant time and money as well as putting their whole business at risk.
Re: Pastie.org host pulls hosting after DDoS attack
#74Earlier quoted context omitted.
So if someone throws multiple tens of gigabits at your customer, and your upstream threatens to turn off your entire hosting company, you would respond "no way, we're going the extra mile for our customer"? Rails Machine was, in all likelihood, compelled to act to either (a) preserve its relationship with is upstream or (b) preserve its relationship with its other paying customers that do not attract DoS attacks. You…
Any given site might not experience a DDoS attack, but if you run a hosting company, it will happen. The frequency depends on how many customers you have, how popular they are, etc. If a DDoS attack catches you by surprise, then you are very ill-prepared. One possible strategy is to throw the targeted customer under the bus and call it a day. For hosts of a certain size, that may be reasonable, as long as you clearly…
https://www.gigenet.com/order/index.php?order=true&form=...
95% of dedicated hosts out there will immediately nullroute you if you get a DDoS attack like Softlayer, Ubiquity, etc... Unfortunate as it is, this is a common practice for hosting companies.
At the risk of getting downvoted again, I am going to re-paste a comment I made.
DDoS attacks are way too easy to do now, and something needs to be done about it.
Anyone can go to www.hackforums.net for a free UDP flooder (called shell booters there), or rent one capable of over 20 gb/s for $5.
Or if you want to do it yourself, pick a cheap throwaway vps from www.lowendbox.com, go to www.gametracker.com and grab IPs from COD4, Wolfeinstein ET, Medal of Honor, etc... and send UDP query packets with your IP spoofed as the victim. This will amplify the size of your attack 20x or more and hide your IP address. You can easily get 10-20 gb/sec attacks like this.
Re: Pastie.org host pulls hosting after DDoS attack
#75Earlier quoted context omitted.
> paying customers that do not attract DoS attacks A little off topic, but I've always felt a slightly uneasy about the concept of "attracting" DDoS attacks. Sure, if you knowingly piss off a bunch of script kiddies, you're attracting attacks. But it seems that nowadays, any site that hosts user-generated content is at risk of being attacked for any random reason. And yet, a lot of people talk about "customers who at…
> It almost sounds like blaming women who wear certain types of clothes for attracting sex crime. I completely stopped reading this comment here, when you wrote this, because that was a completely off-base comparison and has absolutely nothing to do with the topic at hand. Worse, you probably know it; I wouldn't assume you to be stupid. And that was a mountainously stupid comment. In hosting, there are customers that…
It is as ridiculous as banning airports because it attracts suicide bombers.
The longer hosting companies put off developing a real solution to this problem, the more DDoS attacks are going to happen because they are so effective at getting servers kicked.
Re: Pastie.org host pulls hosting after DDoS attack
#76This behavior of unplugging the destination of the DDoS is common with smaller hosts. They don't have the capital to spend on expensive mitigation devices. There are times when these attacks affect their entire network (bad design), so their quick and fast solution is to null route you at their cores.
Even expensive and large hosts like Softlayer will null route you.
They just don't want to pay bandwidth or go through the hassle of asking their upstream providers to filter the attack for them.
Re: Pastie.org host pulls hosting after DDoS attack
#77Earlier quoted context omitted.
That's what most providers (certainly the one I've worked at) do, in fact, do, is null route the entire machine. Rather than leave you nulled in the router for weeks waiting for the attack to subside, eventually, they'll just cut you loose. That's the typical form these things take. It would be tempting to blackhole UDP, but it's just as easy to flood a pipe with TCP. You don't need an established connection to get p…
"You mess with my customers"? So, pastie.org was asking for it by hosting a free-form data pasting site? Again, this is you acting like pastie.org is the one at fault and is responsible for a bunch of idiots deciding to saturate the line. It seems as though you're skewing the issue here. And I think the real issue has nothing to do with whether pastie.org was a paying customer. I'd be interested to know if RM would d…
Nine hours pass. You get frustrated. You take to Twitter. Anybody else on Amazon down? you ask. You get several people to confirm that they are. You tweet that it's an Amazon issue from your company Twitter. You start Googling alternatives. You write a blog post, months later, about how incompetent Amazon must be and you're so glad that you moved your million-dollar app to Rackspace Cloud. You make the front page of Hacker News. Hundreds follow you. Amazon gains a reputation for unreliability among those that read HN. Sales start decreasing.
Or, they null the customer and none of this happens.
Welcome to hosting.
Re: Pastie.org host pulls hosting after DDoS attack
#78Earlier quoted context omitted.
Dropping UDP is a start, because most of these attacks randomize the UDP source address. The real problem is AS operators who let forged UDP addresses escape their network. If your outgoing edge ACL is not dropping source addresses that do not belong to you, you are doing it wrong . Period. Full stop. If the packets are random UDP sources, then there's not really much you can do on the receiving end except strategies…
That's assuming the AS operator is not actually sponsoring the DDoS attack.
Re: Pastie.org host pulls hosting after DDoS attack
#79Earlier quoted context omitted.
"You mess with my customers"? So, pastie.org was asking for it by hosting a free-form data pasting site? Again, this is you acting like pastie.org is the one at fault and is responsible for a bunch of idiots deciding to saturate the line. It seems as though you're skewing the issue here. And I think the real issue has nothing to do with whether pastie.org was a paying customer. I'd be interested to know if RM would d…
Imagine for a moment that your million-dollar app on Amazon goes down. You file a ticket. They are currently absorbing a DoS attack, but they can't tell you that due to their privacy policy with the victim. So instead they tell you they are looking into it and it appears to be some kind of network issue. Nine hours pass. You get frustrated. You take to Twitter. Anybody else on Amazon down? you ask. You get several pe…
Re: Pastie.org host pulls hosting after DDoS attack
#80Earlier quoted context omitted.
Imagine for a moment that your million-dollar app on Amazon goes down. You file a ticket. They are currently absorbing a DoS attack, but they can't tell you that due to their privacy policy with the victim. So instead they tell you they are looking into it and it appears to be some kind of network issue. Nine hours pass. You get frustrated. You take to Twitter. Anybody else on Amazon down? you ask. You get several pe…
Yes, that.