Live data from Hacker News

Global Internet slows after 'biggest attack in history'

bbc.co.uk

121–130 of 159 posts

Re: Global Internet slows after 'biggest attack in history'

#121
When it comes to DoS attacks, bandwidth is a much less meaningful metric than packets/s. 300Gbps could be anywhere from 200,000,000 PPS to 4,687,500,000 PPS. High bandwidth attacks just cause congestion issues, while high packets/s actually take networks and servers down.

Re: Global Internet slows after 'biggest attack in history'

#122
post #2

Funny story from the Hosting company[1]: "Before the break of dawn on a morning in April, a full SWAT team was sent to execute a search warrant on CyberBunker's property." "It must not have occurred to the officers that the blast doors were designed to withstand a 20 megaton nuclear explosion from close range. When the SWAT team realized that the door was not being opened for them, they throw flashbangs and take othe…

Nothing Sven Kamphuis says should be taken seriously. He's a raving lunatic and a fantasist with delusions of grandeur.

Everything he does however should be taken very seriously. He has the technical chops (old school hacker) and the means and criminal connections to back it up.

Re: Global Internet slows after 'biggest attack in history'

#123
post #110

Earlier quoted context omitted.

He's not the only one to do so. Spamhaus has engaged in some shady behaviour; even pg wrote about it once: http://paulgraham.com/spamhausblacklist.html (2005) I wanted to believe him. But before I could reply to his mail, I got first-hand evidence that the SBL has in fact gone bad. As of this writing, any filter relying on the SBL is now marking email with the url "paulgraham.com" as spam. Why? Because the guys at th…

any filter relying on the SBL is now marking email with the url "paulgraham.com" as spam. Impossible. The SBL lists only IP addresses; there is no content filtering at all. http://www.spamhaus.org/sbl/ Furthermore, there's a lot of FUD in this thread about Spamhaus listing people who don't emit spam. IF this is true, then Spamhaus would have an unacceptably high false positive rate, and we would be able to observe th…

You are incorrect. (Well, you're correct that Spamhaus doesn't filter content -- but they don't filter anything, they publish lists that various filtering software uses.)

http://www.spamhaus.org/faq/section/Spamhaus%20SBL#270

I hear the SBL can also block domains, how? What is "URIBL_SBL"?

Yes, the SBL can also be used as a URI Blocklist and is particularly effective in this role. In tests, over 60% of spam was found to contain URIs (links to web sites) whose webserver IPs were listed on the SBL. SpamAssassin, for example, includes a feature called URIBL_SBL for this purpose. The technique involves resolving the URI's domain to and IP address and checking that against the SBL zone.

And of course they also have the DBL (Domain Block List), though I don't know if that existed back when PG ran into problems.

Do you have a link to the false positive rankings? I'm curious as to how that is measured.

Re: Global Internet slows after 'biggest attack in history'

#124

Earlier quoted context omitted.

I do not have any choice at all about what spam filters the recipients of my email may be using. I have never had this problem personally, but there are many, many accounts on webhostingtalk.com of IP ranges being banned Spamhaus without any evidence of spam; of IP addresses that remained banned after ownership changes hands and other problems. There are always two sides in every story. On balance I think Spamhaus is…

I had a similar problem and never found out exactly why it happened. The hypothesis I came to was that we weren't using SPF records on the domain associated with our IP address for a long time. Some spammers were taking advantage of this by sending emails from different IP ranges with the From: header spoofed to be from our domain. So Spamhaus blocked our IP address on the grounds that spam filters would also be able…

It's extremely unlikely that spoofed headers or the lack of an SPF record would get you listed on an RBL, especially Spamhaus. I can't guess what happened in your case, but somehow your IP address obtained a bad reputation or was unlucky enough to be in a tainted block. FWIW, the very first thing I do after getting an IP allocation is run an RBL check on it and demand a replacement if it's listed anywhere.

Re: Global Internet slows after 'biggest attack in history'

#125
post #89
post #20

Earlier quoted context omitted.

I do not accept any of their claims at face value.

Is this the HN equivalent of "fake!" comments in YouTube videos? You can read that they were "operating from a Cold War era government command bunker that was purpose-built by the military to house sensitive electronic gear". This makes the story about the SWAT team very believable.

That makes the story possible. Believable is a different realm entirely.

Re: Global Internet slows after 'biggest attack in history'

#126
post #123
post #110

Earlier quoted context omitted.

any filter relying on the SBL is now marking email with the url "paulgraham.com" as spam. Impossible. The SBL lists only IP addresses; there is no content filtering at all. http://www.spamhaus.org/sbl/ Furthermore, there's a lot of FUD in this thread about Spamhaus listing people who don't emit spam. IF this is true, then Spamhaus would have an unacceptably high false positive rate, and we would be able to observe th…

You are incorrect. (Well, you're correct that Spamhaus doesn't filter content -- but they don't filter anything, they publish lists that various filtering software uses.) http://www.spamhaus.org/faq/section/Spamhaus%20SBL#270 I hear the SBL can also block domains, how? What is "URIBL_SBL"? Yes, the SBL can also be used as a URI Blocklist and is particularly effective in this role. In tests, over 60% of spam was found…

Good point; I think both of our statements are true due to ambiguous wording upstream. I also took it literally, "any filter relying on the SBL" -- I use the SBL (via ZEN) but don't use SpamAssassin. And so my mail servers wouldn't block any domain that resolves to an IP address in the SBL, as described in the link you provided.

As for DNSBL false positive rates, I haven't seen statistics in a few years, and by now they wouldn't be worth much. The only ones I saw were from 2005 or 2007. This one (linked to from the below article) from 2011 doesn't even test Spamhaus:

http://www.spamresource.com/2011/05/dnsbl-safety-report-5142...

This is just my personal experience saying (in 2013) that Spamhaus has the lowest FP rate, which isn't scientific. I'm kind of surprised there haven't been more FP comparison reports of major DNSBLs in recent years. If anyone has a link I'd love to see it.

Re: Global Internet slows after 'biggest attack in history'

#127
post #2

Funny story from the Hosting company[1]: "Before the break of dawn on a morning in April, a full SWAT team was sent to execute a search warrant on CyberBunker's property." "It must not have occurred to the officers that the blast doors were designed to withstand a 20 megaton nuclear explosion from close range. When the SWAT team realized that the door was not being opened for them, they throw flashbangs and take othe…

However, their weakness is that they do only have a limited supply of Fritos and Dr. Pepper inside said bunker.

Re: Global Internet slows after 'biggest attack in history'

#128
post #52
post #47

Earlier quoted context omitted.

Can you also describe exactly what the connection between CyberBunker and the attack is. Is there any indication that the hosting company is actually involved? It seems dubious but of course there are defunct hosting companies that have done such things (Russian Business Network comes to mind). However, this host does not seem shady in comparison to RBN. It has an actual location. The name of the owner is known. It h…

According to spamhaus these guys hosted the RBN: http://www.spamhaus.org/news/article/673

Thanks. It was totally unclear from the original article that it was in anyway actually a bad actor. It seems like these types of hosts are double edged swords.

Re: Global Internet slows after 'biggest attack in history'

#129
post #2

Funny story from the Hosting company[1]: "Before the break of dawn on a morning in April, a full SWAT team was sent to execute a search warrant on CyberBunker's property." "It must not have occurred to the officers that the blast doors were designed to withstand a 20 megaton nuclear explosion from close range. When the SWAT team realized that the door was not being opened for them, they throw flashbangs and take othe…

This would be more believable if they'd posted the surveillance video.

Re: Global Internet slows after 'biggest attack in history'

#130

This story doesn't mention that Spamhaus is protected by CloudFlare and we took a beating from this attack. At some point I'm hoping the full technical story about how the attack morphed from our infrastructure to Internet infrastructure can be told. Also, http://openresolverproject.org PS Technical details: http://blog.cloudflare.com/the-ddos-that-almost-broke-the-in...

What I am more interested in is their comment 'spamhaus should not be allowed to decide what goes on the internet'.

I abhore censorship. Does Spamhause engage in it?

Post reply on HN