Live data from Hacker News

Second large Hetzner outage in a week caused by DDoS attack

status.hetzner.com

41–50 of 55 posts

Re: Second large Hetzner outage in a week caused by DDoS attack

#41

[spiderman-pointing-at-spiderman.gif] seriously, aren't they commonly the SOURCE of many DoS attacks... any hosting provider where some random person on the internet and $5 of credit on a prepaid visa card will have this problem.

There is also the annoying confusion that some attacks involve spoofing the victim's ip to other hosts so the reply goes to the victim while masking the attacker's ip(s).

Re: Second large Hetzner outage in a week caused by DDoS attack

#42
post #34

I thought OVH and Hetzner were the source of a ton of these DDoS attacks. Their IP ranges always seem to be in abuse logs. Cloudflare write in a recent attack: The top networks included the German provider Hetzner Online GmbH (Autonomous System Number 24940), Azteca Comunicaciones Colombia (ASN 262186), OVH in France (ASN 16276), as well as other cloud providers. https://blog.cloudflare.com/15m-rps-ddos-attack/

Hetzner operates a 5-10 Tbps network, roughly the same traffic volume as all of Spectrum/Charter Communications (the 2nd largest cable company in the US). They show up everywhere because they are a big part of the internet. A wise network operator once told me - never shit on people when they are under attack. Because in the not too distant future you are going to be the victim.

Umm.. AWS and GCP and friends dwarf these guys, but I zee Hetzner, OVH and DigitalOcean in these things.

Re: Second large Hetzner outage in a week caused by DDoS attack

#43

I thought OVH and Hetzner were the source of a ton of these DDoS attacks. Their IP ranges always seem to be in abuse logs. Cloudflare write in a recent attack: The top networks included the German provider Hetzner Online GmbH (Autonomous System Number 24940), Azteca Comunicaciones Colombia (ASN 262186), OVH in France (ASN 16276), as well as other cloud providers. https://blog.cloudflare.com/15m-rps-ddos-attack/

I mean that makes sense no? Attacks like that rely on compromised servers so it shouldn't be a big surprise large hosting provides are among the biggest attackers. Other large ISPs like digital ocean and Alibaba are among the top attackers in that attack also. I assume this attack is UDP based unlike the one you linked too.

Where are the AWS and GCP ranges then?

They aren't even in the top 10 here. Its the claim hetzner is larger than AWS? I find that highly unlikely.

Re: Second large Hetzner outage in a week caused by DDoS attack

#44

Earlier quoted context omitted.

I mean that makes sense no? Attacks like that rely on compromised servers so it shouldn't be a big surprise large hosting provides are among the biggest attackers. Other large ISPs like digital ocean and Alibaba are among the top attackers in that attack also. I assume this attack is UDP based unlike the one you linked too.

Where are the AWS and GCP ranges then? They aren't even in the top 10 here. Its the claim hetzner is larger than AWS? I find that highly unlikely.

We probably don't see AWS or Azure as source if these DDOS attacks because of egress costs.

Re: Second large Hetzner outage in a week caused by DDoS attack

#45

Earlier quoted context omitted.

Where are the AWS and GCP ranges then? They aren't even in the top 10 here. Its the claim hetzner is larger than AWS? I find that highly unlikely.

We probably don't see AWS or Azure as source if these DDOS attacks because of egress costs.

People aren't paying with their own money for DDoS machines normally. Well, maybe there are some small operations like that. But often the traffic comes from a hacked service that's a part of a bigger botnet. It may lead to a larger detection ratio on AWS/GCP, but the attackers are not paying the costs.

Re: Second large Hetzner outage in a week caused by DDoS attack

#46
post #11

Earlier quoted context omitted.

Not if the level of incoming bandwidth exceeds the available bandwidth of the circuits involved.. you can't filter it when the link is saturated. Cloudflare uses other techniques like global distribution so aggregate bandwidth is higher than the attack bandwidth

does anyone else have a network that can do what Cloudflare can do? seems like magic sometimes.

Yes, there's a few distributed DDoS protection services. For example Fastly, Akamai, GcoreLabs, and a few smaller ones. They're mostly less evil too as a bonus.

Re: Second large Hetzner outage in a week caused by DDoS attack

#47
post #34

Earlier quoted context omitted.

Hetzner operates a 5-10 Tbps network, roughly the same traffic volume as all of Spectrum/Charter Communications (the 2nd largest cable company in the US). They show up everywhere because they are a big part of the internet. A wise network operator once told me - never shit on people when they are under attack. Because in the not too distant future you are going to be the victim.

Umm.. AWS and GCP and friends dwarf these guys, but I zee Hetzner, OVH and DigitalOcean in these things.

I bet a big factor is that AWS and GCP charge obscene markups for bandwidth. Much harder to get away with.

Re: Second large Hetzner outage in a week caused by DDoS attack

#48
post #11

Earlier quoted context omitted.

Not if the level of incoming bandwidth exceeds the available bandwidth of the circuits involved.. you can't filter it when the link is saturated. Cloudflare uses other techniques like global distribution so aggregate bandwidth is higher than the attack bandwidth

does anyone else have a network that can do what Cloudflare can do? seems like magic sometimes.

The Netherlands has NaWas non-profit service that filters out DDOS attacks, in Q1’22 7,4 times per days with DDOS traffic up to 300Gbps. It’s a few man shop, costs of membership are low. From their FAQ https://www.nbip.nl/en/nawas/faq/ :

The NaWas infrastructure is designed as an on-demand service. After detecting an attack, the traffic is routed via BGP to the NaWas hardware and then the mitigation process starts. All traffic is then rerouted and the own connections can thus manage with less capacity and thus remain cheaper.

To connect to the NaWas, a port must be available from one of the following parties: AMS-IX, NL-IX, LINX, NET-IX, Top-IX, M-IX, V-IX or one of these cloud interconnects DCSPine, Epsilon, Megaport.

Re: Second large Hetzner outage in a week caused by DDoS attack

#49
post #34

Earlier quoted context omitted.

Hetzner operates a 5-10 Tbps network, roughly the same traffic volume as all of Spectrum/Charter Communications (the 2nd largest cable company in the US). They show up everywhere because they are a big part of the internet. A wise network operator once told me - never shit on people when they are under attack. Because in the not too distant future you are going to be the victim.

Umm.. AWS and GCP and friends dwarf these guys, but I zee Hetzner, OVH and DigitalOcean in these things.

Of course, no one could afford a ddos from AWS or GCP. Even in the case of compromised machines, the huge traffic bill is going to alert everyone pretty quickly.

Re: Second large Hetzner outage in a week caused by DDoS attack

#50

[spiderman-pointing-at-spiderman.gif] seriously, aren't they commonly the SOURCE of many DoS attacks... any hosting provider where some random person on the internet and $5 of credit on a prepaid visa card will have this problem.

Hetzner requires government ID to open an account
Post reply on HN