Live data from Hacker News

Estimating the Revenue of a Russian DDoS Booter

arbornetworks.com

41–50 of 56 posts

Re: Estimating the Revenue of a Russian DDoS Booter

#42

Earlier quoted context omitted.

There really isn't any beyond having a large pipe connected to a network device capable of filtering a high volume of pps. That has always been the problem with competently executed DDoS attacks. You need a very large pipe as Step #1 which is simply not cost effective for most businesses. :/

DDoS is the antithesis to an open and free internet from a free market perspective because it drives people to a few select providers for hosting and CDN services. In the end, the big players in those spaces who have the bandwidth win. It's not so much about who has the best innovation either as DDoS tends to be all about brute-force.

DDoS is the very exemplar of Freedom Markets (tm). Probably its defining quality.

Functioning healthy markets require regulation, protection of property rights, fair and impartial court system, enforcement, etc, etc.

In other words, just like there's no free lunch, there's no such thing as "free markets".

Re: Estimating the Revenue of a Russian DDoS Booter

#43
post #24

Hi. I run a thing that uses a lot of bandwidth. Repeat after me: I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I've brought this u…

Cloudflare is cheap, and you can easily stick Cloudflare in front of your AWS/GCS boxes.

If you're using CloudFlare to protect your site against DDoS, you're essentially participating as part of a passive protection racket. "That's a pretty bold claim," you may reasonably contend. Here are the facts:

- A very large proportion (I would conservatively estimate >50%) of DDoS-for-hire sites are hosted on CloudFlare. I couldn't find a comprehensive survey of all attack service providers, but in a recent sample[1], 100% of the services were protected by CloudFlare. - CloudFlare will not discontinue service for customers offering DDoS-for-hire services unless you are the police and bring them a court order [2]. - If you are not the police and submit a report of someone operating an illegal service behind CloudFlare, they will forward you report, unredacted, to the owner of the IP range. They will not tell you who owns it prior to forwarding the report. It is highly likely that your identifying information will be passed to the (anonymous) individual operating the attack service and that their (likely bulletproof) hosting provider will do absolutely nothing.

"Why do all of these services use CloudFlare?", you ask. One simple reason: before CloudFlare, the market of DDoS-for-hire services was somewhat self-regulating via all of the providers DDoSing each other. Since the advent of CloudFlare, though, many have used its protection to avoid attacks from the others, which has led to an increase in DDoS-for-hire services and a reduction in prices as they attempt to compete with each other. CloudFlare providing DDoS protection to these DDoS-for-hire sites therefore effectively increases the supply of such services. On top of that, "just use CloudFlare like everyone else" doesn't work for everyone -- people who don't easily fit into CloudFlare's plans (particularly people offering services via protocols other than HTTP/HTTPS) can't use it at all, while some others have to pay for a higher tier of service. It sounds pretty convenient for CloudFlare that all of these DDoS services are around (and cheap to use), doesn't it?

Further reading: http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...

[1]: http://arxiv.org/abs/1508.03410 [2]: https://blog.cloudflare.com/thoughts-on-abuse/

Re: Estimating the Revenue of a Russian DDoS Booter

#44
post #24

Hi. I run a thing that uses a lot of bandwidth. Repeat after me: I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I've brought this u…

Cloudflare is cheap, and you can easily stick Cloudflare in front of your AWS/GCS boxes.

Cloudflare is MITM. It is unacceptable for any website that respects its users' privacy.

Re: Estimating the Revenue of a Russian DDoS Booter

#45

I can't imagine that DDOS are an effective competitive technique? Are people really buying these against their competitors? I would have assumed that they were mostly part of ransom campaigns.

People cheat. Especially if they think the cost is low and the chance of punishment is not high. Never assume that people are nice before lazy.

Re: Estimating the Revenue of a Russian DDoS Booter

#47

I'm no sure I understand why it was an error of forceful to show his MD5 and SHA1 hashes. Can anyone explain?

He uploaded the .exe of his malware to the malware checker sites (like virustotal) and then posted the hashes. You can look up the hashes on virus total and then get the executable.

Re: Estimating the Revenue of a Russian DDoS Booter

#48
post #7

Earlier quoted context omitted.

There really isn't any beyond having a large pipe connected to a network device capable of filtering a high volume of pps. That has always been the problem with competently executed DDoS attacks. You need a very large pipe as Step #1 which is simply not cost effective for most businesses. :/

There's a tiny bit of hope in there. The article claims that bots are polling CNC about once an hour (I suppose because they don't want to DOS themselves). So one option is to shift your service to a different domain name every hour, and notify your customers by email that they have to connect to a different host. This might be a lot of trouble, but may still allow you to support existing business relationships which…

My reading was that their C&C monitoring stuff was polling once an hour, not the bots themselves

Re: Estimating the Revenue of a Russian DDoS Booter

#49
post #28

Earlier quoted context omitted.

Actually there are providers which will sell you a port ACL as part of their DDoS mitigation service. These ACLs can block almost all of the BS volumetric attacks which will cripple you. Everything gets blocked on the provider side. NTT's pricing is especially reasonable. TWTC has a similar service.

Yes. But once again, that is someone with a large enough pipe. People sell DDoS mitigation but that isn't anything close to a business being able to mitigate things and caring about best practices.

A 1gig circuit is a large pipe?

Also, what are you talking about? Are you claiming that NTT nor TWTC can mitigate a DDoS attack? If so, you're massively wrong.

Re: Estimating the Revenue of a Russian DDoS Booter

#50
post #38

Earlier quoted context omitted.

Not always possible without expensive plans. For example, if you use websockets you will need a business/enterprise level plan in order to pipe through cloudflare. Non http/https services often fail to go through cloudflare as well. For example, you're gonna have to reveal origin to use ftp/sftp.

Not everyone needs websockets, and only the legitimate administrator needs to know the true IP address for ssh. Plenty of websites can be perfectly hidden behind CloudFlare as long as they don't have an MX record or unused subdomain that points to the same server.

>and only the legitimate administrator needs to know the true IP address for ssh

Again this is a blanket statement. I recently integrated with a service that required sftp access to function. Is this ideal? No, but if I could recreate the service efficiently I wouldn't be paying for it in the first place.

This and the websockets scenario were just two examples I can come up with from personal experience, I'm sure there are many other situations that I've never come across.

My point is that the above commenter was acting like cloudflare is a panacea for DDOS attacks.

>"A properly configured CF setup will mean your real server IP never gets revealed ever."

This makes it sound like only engineers who are inept with cloudflare are vulnerable to origin ip leaks which simply isn't true.

> Plenty of websites can be perfectly hidden behind CloudFlare as long as they don't have an MX record or unused subdomain that points to the same server.

I agree with you here 100%.

Post reply on HN