Live data from Hacker News

Global Internet slows after 'biggest attack in history'

bbc.co.uk

141–150 of 159 posts

Re: Global Internet slows after 'biggest attack in history'

#141
post #40

Spamhaus can be a real PITA to deal with, all in attitude "squeal like a pig, or you'll end up on the blocked list - bitch!" Been there, done that, got the t-shirt. What can I do to provide extra firepower in the ongoing ddos against them?

Could you elaborate on what happened in your case that you'd be so vehemently opposed to spamhaus(to the point of being willing to commit crime(s) to hurt them)? I'm truly curious on why the reaction to spamhaus being DDoS is so polarised.

Every so often, spamhaus drops my mailserver/forwarder onto their policy blacklist. My mailserver forwards my mail on to where I actually pick it up, which unfortunately, uses the PBL. When that happens, I first have to notice (normally due to a lack of spam in my inbox), I have to jump through their hoops again.

Yeah, I could fix that, either by hosting my full stack of email, or not doing it at all. Either way, it's a pain.

Re: Global Internet slows after 'biggest attack in history'

#142

This story doesn't mention that Spamhaus is protected by CloudFlare and we took a beating from this attack. At some point I'm hoping the full technical story about how the attack morphed from our infrastructure to Internet infrastructure can be told. Also, http://openresolverproject.org PS Technical details: http://blog.cloudflare.com/the-ddos-that-almost-broke-the-in...

What I am more interested in is their comment 'spamhaus should not be allowed to decide what goes on the internet'. I abhore censorship. Does Spamhause engage in it?

That's a philosophically vexed question.

AIUI, as mhurron says, what Spamhaus does is publish a list.

The nominal purpose of that list is to identify spammers, so that people who wish to filter out spam can be assisted by that. People do, in fact, use that list, to filter email. The email recipient wants to be protected from spam, so the recipient's ISP attempts to perform that service, and Spamhaus contributes an opinion that the ISP takes seriously.

So, in practice, if Spamhaus adds you to their list, many many users will stop seeing email from you. Spamhaus has a great deal of power to mostly-silence domains.

I have no reason to believe that Spamhaus uses their power for anything other than good. But it's not quite as simple as "do they censor? no".

http://en.wikipedia.org/wiki/Spamhaus

http://en.wikipedia.org/wiki/DNSBL#Criticisms

Re: Global Internet slows after 'biggest attack in history'

#144
RBLs are a bad idea, they often end up in abuse.

To this day - with v4 exhausted and despite numerous delisting attempts - I have a /21 listed in Sorbs because it happened to be in the past part of an ISP's /18 dynamic range for customers.

They deserve all that's coming to them and more. Too bad other's get affected in the process.

Re: Global Internet slows after 'biggest attack in history'

#145

This story doesn't mention that Spamhaus is protected by CloudFlare and we took a beating from this attack. At some point I'm hoping the full technical story about how the attack morphed from our infrastructure to Internet infrastructure can be told. Also, http://openresolverproject.org PS Technical details: http://blog.cloudflare.com/the-ddos-that-almost-broke-the-in...

What I am more interested in is their comment 'spamhaus should not be allowed to decide what goes on the internet'. I abhore censorship. Does Spamhause engage in it?

It's not censorship; it's simple property rights and basic freedom. I don't consent to someone else using bandwidth that I have paid for, space on my hard disk, or my attention and time, for advertising. Hosting is cheap enough; they can get their own damn website and opt-in mailing list. And spamhaus subscriptions are completely voluntary and optional.

That being said, the problem with many BL's is that they are run by incompetents or extremists. They usually either end up blocking things that are not spam by accident (see lists of supposedly dynamic IPs), or block whole subnets (sometimes entire ISPs) to try and "teach them a lesson." or blackmail them into fixing the problem.

Re: Global Internet slows after 'biggest attack in history'

#146

Now we have a list of every zombie in their arsenal. Is that information we can use to reduce their impact in the future?

No because it was a DNS amplification attack so it was a bunch of DNS requests with spoofed source IPs. Best way to reduce their impact in the future would be to threaten to null route ISPs that don't do anything to stop spoofed packets.

Re: Global Internet slows after 'biggest attack in history'

#147
post #134
post #73

Earlier quoted context omitted.

A long time ago in a galaxy far away I was a sysadmin at a local university. Trying to keep mail-servers running and keeping up with the different spam clearing houses different policies that kept changing without notice was a lot of work back then. Once you got black-listed getting removed wasn't always an easy process no matter how quickly you tried fix whatever caused it. Methods of communicating were not always a…

Once you got black-listed getting removed wasn't always an easy process no matter how quickly you tried fix whatever caused it. I took a job in the year 2000, at a company with 3000 email users, listed by Spamhaus. First thing I did was close the open relay they were running. The listing was promptly removed, and the mail queue was back to normal within only a few days. I'm skeptical of your claim. I've never seen a…

(English is not my native language)

Open relays were at the time manageable, even the ones that suddenly appeared when someone installed an old OS-version, as were the process for getting removed from the blacklists due to open relays.

Once you had one a computer lab workstation hacked and used for spamming - not so easy to get whiteliested anymore.

The university had a class B-network, trying to get the staffs subnet whitelisted while keeping the computer-labs blacklisted was apparently not possible according to the spam clearing houses. Blocking port 25 for outgoing traffic not possible to check from the outside and didn't help.

I can understand that organizations like spamhaus are overworked don't have the resources to handle every non-standard case on the internet as quickly as the blocked ip-range would like, but the replies we got were truly unhelpful.

The fact that someone bothered to register the domain stophaus.com seems to indicate that my experiences isn't uniqueue.

Re: Global Internet slows after 'biggest attack in history'

#148
post #120

Earlier quoted context omitted.

At some point I'm hoping the full technical story about how the attack morphed from our infrastructure to Internet infrastructure can be told. See poorly configured DNS servers and ISP's failing to configure their networks properly - so traffic with a source address which is not part of your allocated IP block is not allowed to leave your network. It is not that hard! The Internet Infrastructure is working as designe…

Ingress Filtering is a rather vague concept. The actual application of blocking spoofed traffic is known as unicast reverse path forwarding. http://en.wikipedia.org/wiki/Reverse_path_forwarding http://tools.ietf.org/html/rfc3704

Thanks - that RFC seems to sum it up: rfc3704

   BCP 38, RFC 2827, is designed to limit the impact of distributed
   denial of service attacks, by denying traffic with spoofed addresses
   access to the network,

Re: Global Internet slows after 'biggest attack in history'

#149
post #66

Wikipedia seems to suggest that Spamhaus blocked a large chunck of Cyberbunkers IP allocation, when the problem originated with a subset. I suppose given the conditions, Wikipedia is perhaps not to be trusted, but it does make me think less of Spamhaus. In October, 2011, Spamhaus identified CyberBunker as providing hosting for spammers and contacted their upstream provider, A2B, demanding service be cancelled. A2B in…

How does Spamhaus block IP addresses? Don't they just public a blacklist?
Post reply on HN