[deleted]
Global Internet slows after 'biggest attack in history'
71–80 of 159 posts
Re: Global Internet slows after 'biggest attack in history'
#72As wel as the daily stats by the way: https://ams-ix.net/technical/statistics
Reading on through the article, they continue about Spamhaus. What's that got to do with slowing down the internet? And "But we're up - they haven't been able to knock us down." is factually incorrect, Spamhaus did go down. They're winning in the end, but they did go down.
> He added: "These attacks are peaking at 300 gb/s (gigabits per second).
Source? 300gbps would definitely be visible, and I think I remember hearing about something between 60 and 100gbps.
> Spamhaus is able to cope, the group says, as it has highly distributed infrastructure in a number of countries
AKA cloudflare
> We can't be brought down
We've seen that. Am I missing information or is this a lie?
Re: Global Internet slows after 'biggest attack in history'
#73Spamhaus can be a real PITA to deal with, all in attitude "squeal like a pig, or you'll end up on the blocked list - bitch!" Been there, done that, got the t-shirt. What can I do to provide extra firepower in the ongoing ddos against them?
Could you elaborate on what happened in your case that you'd be so vehemently opposed to spamhaus(to the point of being willing to commit crime(s) to hurt them)? I'm truly curious on why the reaction to spamhaus being DDoS is so polarised.
Trying to keep mail-servers running and keeping up with the different spam clearing houses different policies that kept changing without notice was a lot of work back then.
Once you got black-listed getting removed wasn't always an easy process no matter how quickly you tried fix whatever caused it. Methods of communicating were not always available and when it were, responses were not always helpful or even very polite.
I haven't managed mail servers for over ten years, and really hope that the conditions for being included on a blacklist and process for getting removed is more transparent by now.
Given the amount of trust that most people running mail servers are putting into the different blacklists organizations like spamhaus get a lot of power over the internet.
Judging from my experience with spam clearing houses it looks like that power have once more corrupted when I read the news stories about cyberbunker.
We need places like cyberbunker to keep the internet free and open. When all the pr0n, w4r3z and 1337 stuff have been cleaned out from the internet the infrastructure to stop anything at will on the internet will be in place and functional.
I wonder what would be the next thing to be removed from the internet?
Re: Global Internet slows after 'biggest attack in history'
#74Earlier quoted context omitted.
According to a convenient nuclear effects calculator I found[1], 20MT at 5km and an optimal burst height will generate over 40psi of overpressure. The fireball itself will reach about 4km in radius. According to another site[2], 20psi is enough to severely damage or destroy heavily built concrete buildings, and the maximum wind speed at 40psi will be greater than the speed of sound. For comparison, 3psi is enough to…
Indeed; if you really want to survive such effects, you need to do what they did in Cheyenne Mountain: build a tunnel through a mountain and install your blast doors etc. perpendicular to it some distance from the entrances; Wikipedia says it'll handle 600 psi. One of the reasons we deemphasized it and went to Boeing E-4s (747 command posts) in the early '70s was that we judged the Soviets had a good chance of landin…
Not even a large mountain is going to withstand multiple 20Mt hits.
http://en.wikipedia.org/wiki/R-36_%28missile%29
Tom Clancey described these missiles as having the mission to: "turn Cheyenne Mountain into Cheyenne Lake."
The novel "Arc Light" also has a description (probably not that accurate) of a limited strike by Russia against the US that includes destruction of the bunkers at Cheyenne Mountain, Raven Rock Mountain and Omaha:
Re: Global Internet slows after 'biggest attack in history'
#75Wikipedia seems to suggest that Spamhaus blocked a large chunck of Cyberbunkers IP allocation, when the problem originated with a subset. I suppose given the conditions, Wikipedia is perhaps not to be trusted, but it does make me think less of Spamhaus. In October, 2011, Spamhaus identified CyberBunker as providing hosting for spammers and contacted their upstream provider, A2B, demanding service be cancelled. A2B in…
Spamhous has a history of blocking much more than the offending IP's, sometimes whole ISPs. It effectively makes the issue a high priority one for the ISP, some call it blackmail. example: http://edpnetissues.blogspot.be/2012/10/22-october-2012.html
Re: Global Internet slows after 'biggest attack in history'
#76Earlier quoted context omitted.
If you ever tried to handle any mail server at all, you would recognize that you have choice in using spamhaus (or any other DNSBL). These people have put in place a high quality method to discriminate spammers. I've been around since their beginnings, and their list has been incredibly successful (very high quality) for me, compared to njabl and other "dynamic" lists based on honeypots, or backlash entirely (say hi…
I do not have any choice at all about what spam filters the recipients of my email may be using. I have never had this problem personally, but there are many, many accounts on webhostingtalk.com of IP ranges being banned Spamhaus without any evidence of spam; of IP addresses that remained banned after ownership changes hands and other problems. There are always two sides in every story. On balance I think Spamhaus is…
The hypothesis I came to was that we weren't using SPF records on the domain associated with our IP address for a long time.
Some spammers were taking advantage of this by sending emails from different IP ranges with the From: header spoofed to be from our domain.
So Spamhaus blocked our IP address on the grounds that spam filters would also be able to confidently block anything appearing to originate from a domain name that resolved to our IP address.
Re: Global Internet slows after 'biggest attack in history'
#77Re: Global Internet slows after 'biggest attack in history'
#78Earlier quoted context omitted.
You seem to be taking the line of the attackers' spokesman, who accused, rather hysterically, Spamhaus of deciding what goes on the internet. Of course, all Spamhaus does is supply a list of hosts who are sending email spam, and other things like lists of dynamic IPs. Sounds like this hosting outfit was making money hosting spammers and their business is threatened by legitimate countermeasures.
He's not the only one to do so. Spamhaus has engaged in some shady behaviour; even pg wrote about it once: http://paulgraham.com/spamhausblacklist.html (2005) I wanted to believe him. But before I could reply to his mail, I got first-hand evidence that the SBL has in fact gone bad. As of this writing, any filter relying on the SBL is now marking email with the url "paulgraham.com" as spam. Why? Because the guys at th…
Re: Global Internet slows after 'biggest attack in history'
#79Funny story from the Hosting company[1]: "Before the break of dawn on a morning in April, a full SWAT team was sent to execute a search warrant on CyberBunker's property." "It must not have occurred to the officers that the blast doors were designed to withstand a 20 megaton nuclear explosion from close range. When the SWAT team realized that the door was not being opened for them, they throw flashbangs and take othe…
I tried to tweet that link. But I guess SpamHaus's blacklist really works. Twitter gave me this error: Oops! A URL in your Tweet appears to link to a page that has spammy or unsafe content. Learn more
Re: Global Internet slows after 'biggest attack in history'
#80Earlier quoted context omitted.
If you ever tried to handle any mail server at all, you would recognize that you have choice in using spamhaus (or any other DNSBL). These people have put in place a high quality method to discriminate spammers. I've been around since their beginnings, and their list has been incredibly successful (very high quality) for me, compared to njabl and other "dynamic" lists based on honeypots, or backlash entirely (say hi…
I do not have any choice at all about what spam filters the recipients of my email may be using. I have never had this problem personally, but there are many, many accounts on webhostingtalk.com of IP ranges being banned Spamhaus without any evidence of spam; of IP addresses that remained banned after ownership changes hands and other problems. There are always two sides in every story. On balance I think Spamhaus is…
You constantly have to check if there is a chance that spammers noticed your honeypots so that they can avoid them or use them against you as well (the bigger you get the more sophisticated these attackers get too), you have to use tagged email addresses that can be linked back to the offenders. Methods to probe address ranges multiple times before validating them, and ways to automate the unlisting as well. False positives are basically unavoidable at some point, also because spammers themselves like to rotate their addresses based on their previous owners or known datacenters that are "too big to be blocked" wholesale for this exact reason. If they had a chance to know one of your trigger addresses, a common practice is to generate spam from a "safe" range into the trigger address, in an attempt to generate a false positive and thus, of course, backlash. It's sickening.
Exchanging digests of message contents among multiple server cooperatively became a good indicator of spammyness (vipul's razor), though you would catch bulk emails in the process, and spammers quickly adapted to random email contents so that the method became quickly ineffective.
The real problem here is that these assholes don't care as long as they can deliver the message, that's the only metric they have and care for. Maybe you don't care for it, because you can then use filtering later, but that's a huge volume of trash that needs to be shoveled around. I actually witnessed many cases in organizations bigger than a hundred eployees where several servers were used 24/7 just to churn messages through "dspam" or similar filters before delivering to the final mailbox. This is a huge cost in terms of measurable power wasted for a couple of assholes.