I can't imagine that DDOS are an effective competitive technique? Are people really buying these against their competitors? I would have assumed that they were mostly part of ransom campaigns.
Estimating the Revenue of a Russian DDoS Booter
21–30 of 56 posts
Re: Estimating the Revenue of a Russian DDoS Booter
#22Hi. I run a thing that uses a lot of bandwidth. Repeat after me: I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I've brought this u…
Re: Estimating the Revenue of a Russian DDoS Booter
#23Earlier quoted context omitted.
Use service like cloudflare, it's 250 dollars and you are UDP attacks completely free + a lot of TCP ones.
CloudFlare protection can be easily bypassed. These types of proxy services which offer decently cheap DDoS protection are fine for defending against small-time attacks, however, plenty of attackers have scripts capable of bypassing them.
Re: Estimating the Revenue of a Russian DDoS Booter
#24Hi. I run a thing that uses a lot of bandwidth. Repeat after me: I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I've brought this u…
Re: Estimating the Revenue of a Russian DDoS Booter
#25Hi. I run a thing that uses a lot of bandwidth. Repeat after me: I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I've brought this u…
Cloudflare is cheap, and you can easily stick Cloudflare in front of your AWS/GCS boxes.
How will you protect the origin?
Re: Estimating the Revenue of a Russian DDoS Booter
#26Hi. I run a thing that uses a lot of bandwidth. Repeat after me: I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I've brought this u…
Cloudflare is cheap, and you can easily stick Cloudflare in front of your AWS/GCS boxes.
Meanwhile, providers like OVH, Ramnode, Vultr and BuyVM offer various levels of integrated DDoS protection for their servers and VPS for free or a very reasonable cost ($5-10 per month). It's out there, you just need to look for it.
Re: Estimating the Revenue of a Russian DDoS Booter
#27Earlier quoted context omitted.
CloudFlare protection can be easily bypassed. These types of proxy services which offer decently cheap DDoS protection are fine for defending against small-time attacks, however, plenty of attackers have scripts capable of bypassing them.
What scripts are capable of bypassing CloudFlare/proxy services and how do they do it? Do they look for old DNS records that leak their Origin IP or something like that?
Re: Estimating the Revenue of a Russian DDoS Booter
#28Under $100 for a large-scale DDOS attack is ridiculously cheap. It's no wonder these are getting freakishly common. Does anyone have a best-practices for dealing with the more modern variants?
There really isn't any beyond having a large pipe connected to a network device capable of filtering a high volume of pps. That has always been the problem with competently executed DDoS attacks. You need a very large pipe as Step #1 which is simply not cost effective for most businesses. :/
Re: Estimating the Revenue of a Russian DDoS Booter
#29Earlier quoted context omitted.
What scripts are capable of bypassing CloudFlare/proxy services and how do they do it? Do they look for old DNS records that leak their Origin IP or something like that?
Frequently there will be MX records or something similar pointing directly to the server. Even error pages can potentially leak a direct, unprotected IP.
Re: Estimating the Revenue of a Russian DDoS Booter
#30Earlier quoted context omitted.
CloudFlare protection can be easily bypassed. These types of proxy services which offer decently cheap DDoS protection are fine for defending against small-time attacks, however, plenty of attackers have scripts capable of bypassing them.
What scripts are capable of bypassing CloudFlare/proxy services and how do they do it? Do they look for old DNS records that leak their Origin IP or something like that?