Live data from Hacker News

Global Internet slows after 'biggest attack in history'

bbc.co.uk

41–50 of 159 posts

Re: Global Internet slows after 'biggest attack in history'

#41
post #2

Funny story from the Hosting company[1]: "Before the break of dawn on a morning in April, a full SWAT team was sent to execute a search warrant on CyberBunker's property." "It must not have occurred to the officers that the blast doors were designed to withstand a 20 megaton nuclear explosion from close range. When the SWAT team realized that the door was not being opened for them, they throw flashbangs and take othe…

Wouldn't it be easier to just take a backhoe to the data lines running to the bunker?

Wouldn't it just be easier to, I dunno, unplug something? Or turn something off? Why would you fuck up the lines...

Re: Global Internet slows after 'biggest attack in history'

#42
post #21

Earlier quoted context omitted.

Note that "close range" in this case is a 20Mt explosion 5km away: http://cyberbunker.com/web/bunker-specs.php Having said that, in the case of 20Mt nukes I suspect 5km does count as "close range".

According to a convenient nuclear effects calculator I found[1], 20MT at 5km and an optimal burst height will generate over 40psi of overpressure. The fireball itself will reach about 4km in radius. According to another site[2], 20psi is enough to severely damage or destroy heavily built concrete buildings, and the maximum wind speed at 40psi will be greater than the speed of sound. For comparison, 3psi is enough to…

Glad to know in the case of full scale nuclear war, the only survivors will be lunatics and data center admins.

Re: Global Internet slows after 'biggest attack in history'

#43
post #17

Exactly why is this affecting non-spamhaus services? Is it just shared dns servers or actual IP traffic being throttled ?

According to the article(s) the DDoS is so big that it is not just clogging up spamhaus' links as it is intended to but also the backbone leading up to said links. That would affect everyone and not just spamhaus.

Also, the DNS servers are being used to perform the attack via DNS amplification, the slowdown is not caused by clogged DNS servers.

I don't have the exact quote but one of the articles likens the situation to having a motorway with on-ramps and off-ramps to individual networks/hosts. The usual DDoS seeks to clog the on-ramp or off-ramp the target uses by sending too many cars their way. However, this attack is so big that it's clogging up the motorway itself not just on/off-ramps.

Re: Global Internet slows after 'biggest attack in history'

#44

This story doesn't mention that Spamhaus is protected by CloudFlare and we took a beating from this attack. At some point I'm hoping the full technical story about how the attack morphed from our infrastructure to Internet infrastructure can be told. Also, http://openresolverproject.org PS Technical details: http://blog.cloudflare.com/the-ddos-that-almost-broke-the-in...

At some point I'm hoping the full technical story about how the attack morphed from our infrastructure to Internet infrastructure can be told.

See poorly configured DNS servers and ISP's failing to configure their networks properly - so traffic with a source address which is not part of your allocated IP block is not allowed to leave your network. It is not that hard!

The Internet Infrastructure is working as designed.

Ref:

http://en.wikipedia.org/wiki/Ingress_filtering

http://tools.ietf.org/html/bcp38

Also:

If you run a DNS server - it is your responsibility to maintain and protect it so that it cannot be used to attack others, and by doing that you are helping the 'Internet infrastructure' remain intact as designed. By not doing this you are helping the 'attackers'

Re: Global Internet slows after 'biggest attack in history'

#45
post #30

Earlier quoted context omitted.

My traffic has lots of spikes. Some days I download HD video, some days I don't. If I look at the logs, it's all connections to CDNs with weird hostnames. How do I know which ones are legit and which ones might be part of a DDOS? Also CC numbers are 16 bytes long, would just get lost in all the noise..

Maybe I should say, spikes in outgoing traffic. The internet is not safe for banking, and I don't see any way it can be made safe.

It is safe for banking. Have you heard of encryption?

Re: Global Internet slows after 'biggest attack in history'

#46
post #40

Spamhaus can be a real PITA to deal with, all in attitude "squeal like a pig, or you'll end up on the blocked list - bitch!" Been there, done that, got the t-shirt. What can I do to provide extra firepower in the ongoing ddos against them?

Could you elaborate on what happened in your case that you'd be so vehemently opposed to spamhaus(to the point of being willing to commit crime(s) to hurt them)?

I'm truly curious on why the reaction to spamhaus being DDoS is so polarised.

Re: Global Internet slows after 'biggest attack in history'

#47

This story doesn't mention that Spamhaus is protected by CloudFlare and we took a beating from this attack. At some point I'm hoping the full technical story about how the attack morphed from our infrastructure to Internet infrastructure can be told. Also, http://openresolverproject.org PS Technical details: http://blog.cloudflare.com/the-ddos-that-almost-broke-the-in...

Can you also describe exactly what the connection between CyberBunker and the attack is. Is there any indication that the hosting company is actually involved? It seems dubious but of course there are defunct hosting companies that have done such things (Russian Business Network comes to mind). However, this host does not seem shady in comparison to RBN.

It has an actual location. The name of the owner is known. It has evidentially been involved in legal disputes so it is on record with the government.

Much more likely is someone using the hosting system for something nefarious is retaliating against spamhaus. I don't think the hosting company should go down for that.

Re: Global Internet slows after 'biggest attack in history'

#48
post #17

Exactly why is this affecting non-spamhaus services? Is it just shared dns servers or actual IP traffic being throttled ?

A lot of spam filters rely on spamhaus.

This is true. However the reason this affects non-Spamhaus servers is because there is so much traffic that it is literally clogging the backbone.

Re: Global Internet slows after 'biggest attack in history'

#49
post #21

Earlier quoted context omitted.

According to a convenient nuclear effects calculator I found[1], 20MT at 5km and an optimal burst height will generate over 40psi of overpressure. The fireball itself will reach about 4km in radius. According to another site[2], 20psi is enough to severely damage or destroy heavily built concrete buildings, and the maximum wind speed at 40psi will be greater than the speed of sound. For comparison, 3psi is enough to…

Glad to know in the case of full scale nuclear war, the only survivors will be lunatics and data center admins.

They are not disjoint sets.

Re: Global Internet slows after 'biggest attack in history'

#50

The main problem is that some people decide what's good and what's not online and paint with the broadest brush possible. Spamhaus, sadly I say, is used by a lot of providers as gospel and a lot of innocent sites are hurt.

You seem to be taking the line of the attackers' spokesman, who accused, rather hysterically, Spamhaus of deciding what goes on the internet. Of course, all Spamhaus does is supply a list of hosts who are sending email spam, and other things like lists of dynamic IPs. Sounds like this hosting outfit was making money hosting spammers and their business is threatened by legitimate countermeasures.

You seem to be taking the line of the attackers' spokesman, who accused, rather hysterically

Ummm, my ISP IPs hav been blocked several times for absolutely no fault of mine. I have a shared IP for browsing and turns out that cloudfare has blocked them. I also had issues with my sites, the IPs signed to me were blacklisted.

I understand that no one is forcing usage of spamhaus db but it seems unfair and white-listing is near impossible.

Post reply on HN