Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

131–140 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#131

> This attack lasted only 40 seconds but was roughly equivalent to streaming one million 4K videos simultaneously. Who is this for? Is there anyone reading the article that can't grasp what a terrabit is but can somehow conceptualise one million 4k videos streaming simultaneously? I don't think anyone sits in that venn diagram.

Yeah. That falls in the same bin as number of Olympic swimming pools or distance to the moon.

The best, meaningful comparison I've read is from Bill Bryson in A Short History of Nearly Everything. In it, he notes that there are 1M seconds in 11 days but 1B seconds takes 32 years.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#132
post #119

Earlier quoted context omitted.

IP spoofing is pretty uncommon nowadays because everyone has anti-spoofing mechanisms in place and most ASNs often don't forward spoofed addresses outbound. But as the sibling mentioned, even with spoofing, you can still follow the packet trail from your border routers upstream. I think the main thing we are lacking is just responsibility on the ISP side, if someone reaches out complaining that half of your customers…

This is clearly not true, or the CAIDA anti-spoofer project wouldn't exist. https://spoofer.caida.org/summary.php

Just because SOME ASNs don't have it in place doesn't mean it's not uncommon. In the link provided, 80% of all tracked network blocks for ipv4 are blocking spoofing. Though they only track 1000 ipv4 /24 blocks and their data is highly biased towards having spoofable ranges, considering their end goal is identifying spoofable networks!

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#133
post #73
post #46

Earlier quoted context omitted.

Through personal responsibility? That is not scalable; look at how many compromised devices there are. We need a better solution as an industry.

Yep. Manufacturers / distributors should be held responsible. Aligning the incentives is half the battle.

Yes, need to protect Azure from those evil manufacturers.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#134

A DDoS attack is often used to distract a company's security team. While the security staff is scrambling to get the website back online, the attackers use the chaos to conduct a more serious, stealthy attack.

I don't doubt there will have been sporadic examples of this, but what points to this "often" being the case? It seems like a tactic that wouldn't often pay off, since DDoS mitigation rarely involves relaxing security systems

Mistakes can be made during reconfigurations but you'd have to catch those while the issue is still live. Sounds like an advanced threat actor and not the run of the mill ransomware people (not that they're necessarily unsophisticated, but why'd they bother with these odds when there's low-hanging fruit to reliably exploit)

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#135

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

What countries do you think these bad actors reside? Russia, China, Iran, and NK will wipe their ass with any law enforcement request.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#136
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

Uh I used to get DDoSed by “booter” services whenever I would login to one of my Skype accounts. The script kiddie scene is that petty. In the private server scene one guy would DDoS competing servers that way everyone would funnel to his own.

Its just toxic behavior.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#137
post #115
post #96

Earlier quoted context omitted.

Bit-Reproducible infrastructure could also result in some of the wildest build distribution architectures if you think about it. You could publish sources and have people register like in APT mirrors to provide builds, and at the end of the day, the build from the largest bit-equal group is published. I do see the Tor-Issue - a botnet or a well-supplied malicious actor could just flood it. And if you flip it - if you…

The distribution system you're describing exists and has been in use for decades. You just distribute the build using bittorrent.

And if someone invests in having >90% of the peers offer a malicious file and serve DHTs matching that file?

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#138
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

The results are very public, it's the same way IRC is often targeted. They're easy targets, thousands of users are affected and the results are immediately noticeable.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#140
post #130

Earlier quoted context omitted.

do you really think for example America would allow say Chinese prosecutors to arrest Americans on American soil and take them abroad to sentence them in a court that America has no influence over and then throw them in a prison which America doesn’t control?

When the deed is illegal in both places, they can be tried under either jurisdiction and convicted instead of continuing to roam free and fuck up the open web for everyone else. Yes I do think we'd want that Borders currently get in the way but we needn't have law enforcement on foreign soil to solve that. Exchanging information and reliably acting upon it could be all these agencies need to do in their respective co…

Bad news, implied criticism of CCP policy (by acknowledging you'd change it) is an imprisonable offense. You're under arrest for violating the laws of China. You are not granted a trial. A joint unit comprised of the Ministry of State Security and the FBI will be at your house to pick you up and fly you to a Chinese black site tomorrow morning.
Post reply on HN