Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

301–310 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#301

> by exploiting compromised home routers and cameras, mainly in residential ISPs in the United States and other countries, Presumably it’s possible to log the residential IP of the source of these packets. Why isn’t there any industry group pushing for the ISPs to a) send the owners an email telling them or b) blocking off all traffic for a period to get them to do something - or is the economic cost higher than caus…

Some of these devices are controlled by the ISP. The TMobile 5G routers for example are pretty much black box devices controlled by TMobile. The home owner can't fix the device and has very limited access (via a mobile app) to 'manage' the device.

I don't think there's a strong overlap between ISP-controlled black boxes and compromised botnet nodes. However, if there is, that just means that the ISPs should be partially held liable.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#302
post #71

Earlier quoted context omitted.

Ok, I'll be a bit more specific, banning businesses and the trade of proxies that are purposefully marked as residential, in order to evade firewall blocks, and even to evade proxy blocks. You gotta draw the line in the sand somewhere, VPNs are already morally dubious, but if you ban the most shady of VPNs, residential proxies, then you can at least guarantee service providers the right to deny service to proxy users…

But the botnets don't use VPNs, they use IoT devices owned by people who don't even know there's a computer inside. It seems like you just don't like the idea of VPNs in general and are using an unrelated attack to argue for deprivatizing (And thus, surveilling) the citizenry.

Hey.

The way it works is that these pwned IoT devices sell themselves to paying customers as proxies. So the pwners are not the ones actually running the DDoS service/Ransomware distribution/malicious activities. Rather it's an economy where each malicious actor offers their specific service.

In this case IoT device pwners pwn the device, install a VPN server and place their devices on a marketplace where they charge cents per hour using cryptocurrency. Then whoever needs an anonymous IP address pays for a couple of hours of 10k ip residential addresses, and sends their traffic wherever they need to.

So both are true: DDoSers (and malicious actors in general) use pwned devices, but they also use VPNs

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#303
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

You are questioning the human nature.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#305
post #213

Earlier quoted context omitted.

I suppose ISPs could be more restrictive about which routers they allow their customers to use, but I'm not sure I'm a fan of further lockdown in that department.

I doubt that would do much, most people don't even know they can use a non ISP provided router

What do you mean "do much"? Wouldn't negatively impact users, or wouldn't help the botnet problem?

The article makes it sound like the issue is largely compromised routers and cameras -- and presumably cameras are less likely to be publicly-accessible to get compromised in the first place.

ISPs are able to update firmware on the routers they own, so it's my guess that it's customer-owned routers that are the main issue here.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#306
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

You have a Minecraft server. You generate money from it (selling VIP packages, et cetera). You could generate more money if you had more players. You can have more players if you consistently DDoS other more popular servers; the experience for these players will be horrible and they might give your server a chance.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#307
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

Mad salt. Imagine a fully grown man having a toddler tantrum. "If I can't play/win/get my way, nobody can" type mentality. It's also a method of coercion. Give me mod status or I'll DDOS your server and destroy your community. The other half comes from sever operators ddosing their competition. There is a lot of money to be made from paid cosmetics, ranks, moderator (demi-tyrant) status, etc on custom servers.

When I moderated a busy gaming forum long ago my most horrifying discovery was how many users I thought were children ... were very much "adults" by age.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#308

Earlier quoted context omitted.

That's really impressive finger pointing. If the vendor can't even secure their update server; how long do you think it would be until some RCE on these 100k un-patchable routers gets exploited? The only people to blame for this is the vendor, and they failed on multiple levels here. It's not hard to sign a firmware, or even just fetch checksums from a different site than you serve the files from...

the problem is that these laws just make the problem bigger - instead of having to compromise 100 thousand routers they can just compromise a single update server from a vendor that doesn't care about security. the fallout is some companies losing their revenue: https://status.neoprotect.net/ and other headaches for people all over the world

I tried to read this page, but it keeps refreshing itself and resetting the scroll position to the very top. Since I'm on mobile, I can't do anything about this easily and it's worse because it takes longer to figure out where to scroll to to continue.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#309
post #189

Earlier quoted context omitted.

Name a few.

https://en.wikipedia.org/wiki/XZ_Utils_backdoor https://medium.com/@aleksamajkic/fake-sms-how-deep-does-the-... https://blog.linuxmint.com/?p=2994 https://www.bleepingcomputer.com/news/linux/malicious-packag... https://www.cnx-software.com/2021/04/22/phd-students-willful... I could go on but I trust this is a sufficient number of examples.

I wonder why nowhere talked about who Jia Tan was. In my understanding, a few people already talked to that person. Now, does Jia Tan really vanish?

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#310
post #165
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

A satisfying theory for a lot of DDoS would be extortion or protection rackets. Pay up or we will DDoS you, or pay up or 'someone else' will DDoS you. That's enough to explain it. But if you wanted to go more full shadowy conspiracy theory, someone arranged for a protection service that just so happens to work by giving some entity cleartext surveillance over much of the internet. Perhaps as a response to HTTPS every…

I like the “some entity” bit.
Post reply on HN