Seems useless, you might make a dent but why?
Azure hit by 15 Tbps DDoS attack using 500k IP addresses
271–280 of 318 posts
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#272This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…
I don't expect the big publisher games like PUBG to attack each other with DDoS attacks, but casino games? Or even sleazy Minecraft servers? I can totally see it.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#273Earlier quoted context omitted.
The idea is, the botnets are in control of someone else. Who "owns" them. And some of those will rent "their property" for money, like they would legitimately own them.
Ok, but that doesn’t change the fact that the price of renting them is completely disconnected from the price of bandwidth.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#274Are these IP addresses available somewhere so I can check if I'm part of it?
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#275Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#276Earlier quoted context omitted.
This is already the case in Germany and many other countries. Same for phone numbers. On the other hand, I get no spam calls, and I can't access the sites on https://cuiiliste.de/domains - censorship is amazing.
Yes, surely the German government telling it's people what to do has never gotten them in trouble in the past...
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#277Earlier quoted context omitted.
Why, OpenWRT firmware and packages are both signed, of course. You can manually and independently check the image signature before flashing an update. The build infrastructure is, of course, a juicy target: infect the artifact after building but before signing, and pwn millions of boxes before this is detected. This is why bit-perfect reproducible builds are so important. OpenWRT in particular have that: https://open…
> You can manually and independently check the image signature before flashing an update. Of course you can. You can also read the ToS before clicking accept, but who does that?
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#278Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#279Earlier quoted context omitted.
Ok, but that doesn’t change the fact that the price of renting them is completely disconnected from the price of bandwidth.
Depends. The more the owners use their bots, or let others use their botnets, the more attention there is to them and the less useful the botnet is (either blacklisted IPs or owners noticing). And a little bit of malicious bandwidth is easy to hide, a lot not. So there is a price to bandwith to the criminal owner.
Because the botnet operator is not paying for the bandwidth, directly or indirectly.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#280Earlier quoted context omitted.
That's really impressive finger pointing. If the vendor can't even secure their update server; how long do you think it would be until some RCE on these 100k un-patchable routers gets exploited? The only people to blame for this is the vendor, and they failed on multiple levels here. It's not hard to sign a firmware, or even just fetch checksums from a different site than you serve the files from...
the problem is that these laws just make the problem bigger - instead of having to compromise 100 thousand routers they can just compromise a single update server from a vendor that doesn't care about security. the fallout is some companies losing their revenue: https://status.neoprotect.net/ and other headaches for people all over the world
And the other option isn't that much better, because "don't do autoupdates because maybe the update server is compromised" leads to a bunch of unsecured devices everywhere.
The only "real" solution is also completely unrealistic: Every private person disables auto updates, then reads the change log, downloads updates manually, and checks them against some checksum.
The better solution would be to simply increase fines until morale improves.