Funny story from the Hosting company[1]: "Before the break of dawn on a morning in April, a full SWAT team was sent to execute a search warrant on CyberBunker's property." "It must not have occurred to the officers that the blast doors were designed to withstand a 20 megaton nuclear explosion from close range. When the SWAT team realized that the door was not being opened for them, they throw flashbangs and take othe…
Wouldn't it be easier to just take a backhoe to the data lines running to the bunker?
Global Internet slows after 'biggest attack in history'
41–50 of 159 posts
Re: Global Internet slows after 'biggest attack in history'
#42Earlier quoted context omitted.
Note that "close range" in this case is a 20Mt explosion 5km away: http://cyberbunker.com/web/bunker-specs.php Having said that, in the case of 20Mt nukes I suspect 5km does count as "close range".
According to a convenient nuclear effects calculator I found[1], 20MT at 5km and an optimal burst height will generate over 40psi of overpressure. The fireball itself will reach about 4km in radius. According to another site[2], 20psi is enough to severely damage or destroy heavily built concrete buildings, and the maximum wind speed at 40psi will be greater than the speed of sound. For comparison, 3psi is enough to…
Re: Global Internet slows after 'biggest attack in history'
#43Exactly why is this affecting non-spamhaus services? Is it just shared dns servers or actual IP traffic being throttled ?
Also, the DNS servers are being used to perform the attack via DNS amplification, the slowdown is not caused by clogged DNS servers.
I don't have the exact quote but one of the articles likens the situation to having a motorway with on-ramps and off-ramps to individual networks/hosts. The usual DDoS seeks to clog the on-ramp or off-ramp the target uses by sending too many cars their way. However, this attack is so big that it's clogging up the motorway itself not just on/off-ramps.
Re: Global Internet slows after 'biggest attack in history'
#44This story doesn't mention that Spamhaus is protected by CloudFlare and we took a beating from this attack. At some point I'm hoping the full technical story about how the attack morphed from our infrastructure to Internet infrastructure can be told. Also, http://openresolverproject.org PS Technical details: http://blog.cloudflare.com/the-ddos-that-almost-broke-the-in...
See poorly configured DNS servers and ISP's failing to configure their networks properly - so traffic with a source address which is not part of your allocated IP block is not allowed to leave your network. It is not that hard!
The Internet Infrastructure is working as designed.
Ref:
http://en.wikipedia.org/wiki/Ingress_filtering
http://tools.ietf.org/html/bcp38
Also:
If you run a DNS server - it is your responsibility to maintain and protect it so that it cannot be used to attack others, and by doing that you are helping the 'Internet infrastructure' remain intact as designed. By not doing this you are helping the 'attackers'
Re: Global Internet slows after 'biggest attack in history'
#45Earlier quoted context omitted.
My traffic has lots of spikes. Some days I download HD video, some days I don't. If I look at the logs, it's all connections to CDNs with weird hostnames. How do I know which ones are legit and which ones might be part of a DDOS? Also CC numbers are 16 bytes long, would just get lost in all the noise..
Maybe I should say, spikes in outgoing traffic. The internet is not safe for banking, and I don't see any way it can be made safe.
Re: Global Internet slows after 'biggest attack in history'
#46Spamhaus can be a real PITA to deal with, all in attitude "squeal like a pig, or you'll end up on the blocked list - bitch!" Been there, done that, got the t-shirt. What can I do to provide extra firepower in the ongoing ddos against them?
I'm truly curious on why the reaction to spamhaus being DDoS is so polarised.
Re: Global Internet slows after 'biggest attack in history'
#47This story doesn't mention that Spamhaus is protected by CloudFlare and we took a beating from this attack. At some point I'm hoping the full technical story about how the attack morphed from our infrastructure to Internet infrastructure can be told. Also, http://openresolverproject.org PS Technical details: http://blog.cloudflare.com/the-ddos-that-almost-broke-the-in...
It has an actual location. The name of the owner is known. It has evidentially been involved in legal disputes so it is on record with the government.
Much more likely is someone using the hosting system for something nefarious is retaliating against spamhaus. I don't think the hosting company should go down for that.
Re: Global Internet slows after 'biggest attack in history'
#48Exactly why is this affecting non-spamhaus services? Is it just shared dns servers or actual IP traffic being throttled ?
A lot of spam filters rely on spamhaus.
Re: Global Internet slows after 'biggest attack in history'
#49Earlier quoted context omitted.
According to a convenient nuclear effects calculator I found[1], 20MT at 5km and an optimal burst height will generate over 40psi of overpressure. The fireball itself will reach about 4km in radius. According to another site[2], 20psi is enough to severely damage or destroy heavily built concrete buildings, and the maximum wind speed at 40psi will be greater than the speed of sound. For comparison, 3psi is enough to…
Glad to know in the case of full scale nuclear war, the only survivors will be lunatics and data center admins.
Re: Global Internet slows after 'biggest attack in history'
#50The main problem is that some people decide what's good and what's not online and paint with the broadest brush possible. Spamhaus, sadly I say, is used by a lot of providers as gospel and a lot of innocent sites are hurt.
You seem to be taking the line of the attackers' spokesman, who accused, rather hysterically, Spamhaus of deciding what goes on the internet. Of course, all Spamhaus does is supply a list of hosts who are sending email spam, and other things like lists of dynamic IPs. Sounds like this hosting outfit was making money hosting spammers and their business is threatened by legitimate countermeasures.
Ummm, my ISP IPs hav been blocked several times for absolutely no fault of mine. I have a shared IP for browsing and turns out that cloudfare has blocked them. I also had issues with my sites, the IPs signed to me were blacklisted.
I understand that no one is forcing usage of spamhaus db but it seems unfair and white-listing is near impossible.