Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

271–280 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#272
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

It may be for market manipulation. It may be extortion against the owning company. It may even be to take down a rival online game for a while.

I don't expect the big publisher games like PUBG to attack each other with DDoS attacks, but casino games? Or even sleazy Minecraft servers? I can totally see it.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#273
post #234

Earlier quoted context omitted.

The idea is, the botnets are in control of someone else. Who "owns" them. And some of those will rent "their property" for money, like they would legitimately own them.

Ok, but that doesn’t change the fact that the price of renting them is completely disconnected from the price of bandwidth.

it's not exactly, it depends on the provider, some services seem to display a cap in bandwidth usage.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#274

Are these IP addresses available somewhere so I can check if I'm part of it?

You can assume that you are part of it or another similar botnet if you have any IoT device exposed to the internet. You can use something like Shodan to see how your network looks like from the outside

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#276
post #80
post #63

Earlier quoted context omitted.

This is already the case in Germany and many other countries. Same for phone numbers. On the other hand, I get no spam calls, and I can't access the sites on https://cuiiliste.de/domains - censorship is amazing.

Yes, surely the German government telling it's people what to do has never gotten them in trouble in the past...

what does any government do besides tell its people what to do, and cause inflation?

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#277
post #260
post #72

Earlier quoted context omitted.

Why, OpenWRT firmware and packages are both signed, of course. You can manually and independently check the image signature before flashing an update. The build infrastructure is, of course, a juicy target: infect the artifact after building but before signing, and pwn millions of boxes before this is detected. This is why bit-perfect reproducible builds are so important. OpenWRT in particular have that: https://open…

> You can manually and independently check the image signature before flashing an update. Of course you can. You can also read the ToS before clicking accept, but who does that?

People who don't want to find themselves inadvertently participating in a botnet.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#279
post #270

Earlier quoted context omitted.

Ok, but that doesn’t change the fact that the price of renting them is completely disconnected from the price of bandwidth.

Depends. The more the owners use their bots, or let others use their botnets, the more attention there is to them and the less useful the botnet is (either blacklisted IPs or owners noticing). And a little bit of malicious bandwidth is easy to hide, a lot not. So there is a price to bandwith to the criminal owner.

Sure, but there’s still no link between what the botnet operator charges and what ISPs charge for bandwidth, that’s the point I’m trying to make.

Because the botnet operator is not paying for the bandwidth, directly or indirectly.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#280

Earlier quoted context omitted.

That's really impressive finger pointing. If the vendor can't even secure their update server; how long do you think it would be until some RCE on these 100k un-patchable routers gets exploited? The only people to blame for this is the vendor, and they failed on multiple levels here. It's not hard to sign a firmware, or even just fetch checksums from a different site than you serve the files from...

the problem is that these laws just make the problem bigger - instead of having to compromise 100 thousand routers they can just compromise a single update server from a vendor that doesn't care about security. the fallout is some companies losing their revenue: https://status.neoprotect.net/ and other headaches for people all over the world

But that's already true for most cases and devices. Most people using most devices let auto updates just happen.

And the other option isn't that much better, because "don't do autoupdates because maybe the update server is compromised" leads to a bunch of unsecured devices everywhere.

The only "real" solution is also completely unrealistic: Every private person disables auto updates, then reads the change log, downloads updates manually, and checks them against some checksum.

The better solution would be to simply increase fines until morale improves.

Post reply on HN