Something along the lines of CloudFlare could be an option here. However, if the attacker does indeed know the actual IP of the Bootcamp servers (and Bootcamp allows traffic from IPs other than CF) that point is moot. Set up CF, only allow traffic from CF. On another note, having CF monitor an attack like this could help them do more research into mitigating these attacks in general and allow them to try and hunt the…
I personally wouldn't do any business with cloudflare, while they're still hosting the various booter sites where you can pay to run these attacks.
Basecamp was under network attack
111–120 of 194 posts
Re: Basecamp was under network attack
#112Is there something like cloudfare but more aggressive? Like something that tries to find exploits on the machines used in the attack and try to shut them down, close their internet connection or inject a self-targeting DNS or something of the sort?
This is a huge constraint for the people (e.g. at Microsoft) who work to identify and take down botnets: they expose themselves to significant legal/PR risk if they do anything harmful to the bots.
Re: Basecamp was under network attack
#113Earlier quoted context omitted.
"Worst thing is that 90% of customers have no clue what a DDoS is and how hard it is to handle." Otoh that's where the opportunity is. The fact that "customers have no clue". People pay you for something that they can't do themselves or that you make easier for them to do.
There's an oportunity if you're Cloudfare or similar service, not a time tracking and pm app. Most users will end up blaming you because you're not prepared enough etc..
Re: Basecamp was under network attack
#114Earlier quoted context omitted.
I personally wouldn't do any business with cloudflare, while they're still hosting the various booter sites where you can pay to run these attacks.
If you're going to make accusations like that, you should really back it up with extensive proof.
> As I noted in a talk I gave last summer with Lance James at the Black Hat security conference in Las Vegas, a funny thing happens when you decide to operate a DDoS-for-hire Web service: Your service becomes the target of attacks from competing DDoS-for-hire services. Hence, a majority of these services have chosen to avail themselves of Cloudflare’s free content distribution service, which generally does a pretty good job of negating this occupational hazard for the proprietors of DDoS services.
http://www.webhostingtalk.com/showthread.php?t=1235995 http://www.webhostingtalk.com/showthread.php?t=1285880 http://www.webhostingtalk.com/showthread.php?t=1182576
I could post more, but why bother?
Re: Basecamp was under network attack
#115Earlier quoted context omitted.
I personally wouldn't do any business with cloudflare, while they're still hosting the various booter sites where you can pay to run these attacks.
CloudFlare is hosting booter sites?
Re: Basecamp was under network attack
#116Re: Basecamp was under network attack
#117Is there something like cloudfare but more aggressive? Like something that tries to find exploits on the machines used in the attack and try to shut them down, close their internet connection or inject a self-targeting DNS or something of the sort?
Re: Basecamp was under network attack
#118Earlier quoted context omitted.
I have a service on OVH myself. Though a friend at another related service had been kicked from two VPS providers due to receiving a few DDoS attacks. These providers claimed it was against their Terms of Service and ejected him as a customer. That day he learned it is best to keep offsite-cross-company backups of everything, since he did not get a single byte from his machines.
Claiming it was against the terms might be an easy out for them but is silly since being a target is outside of your control, for the most part. Hosts will usually null route customers without sympathy to protect other customers so it's the price of doing business.
Re: Basecamp was under network attack
#119Earlier quoted context omitted.
Reasonable people realize that unforeseen things happen, and might empathize with someone being targeted by a criminal enterprise a bit more than someone who just forgot to pay the electricity bill. There is an entire movement in Sicily dedicated to highlighting and frequenting businesses that refuse to pay protection money, because in the past, paying was the norm. http://www.addiopizzo.org/ Since that's not the kin…
I more or less agree with you, but that's kind of a false dichotomy, isn't it? Signing up for cloudflare or using a CDN isn't giving in, it's taking measures to protect yourself (and that's ignoring the other benefits you get). The unfortunate fact is DDOS attacks are becoming a daily occurrence, and if you have something to lose you should probably take measures to counteract any possible threats. If 37Signals was a…
Re: Basecamp was under network attack
#120Is there something like cloudfare but more aggressive? Like something that tries to find exploits on the machines used in the attack and try to shut them down, close their internet connection or inject a self-targeting DNS or something of the sort?
IANAL, but I've seen this discussion come up multiple times, and the problem is that the counterattack would technically be illegal. The fact that somebody else has already broken the law in order to compromise an innocent bystander does not give anybody else the right to do the same thing. Vigilantism is as illegal on the internet as it is in the real world. This is a huge constraint for the people (e.g. at Microsof…