Live data from Hacker News

A DDoS in Asia Pacific

telegram.org

41–46 of 46 posts

Re: A DDoS in Asia Pacific

#41
post #19
post #14

Earlier quoted context omitted.

This tsunami TCP SYN attack uses 1000 byte SYN packets apparently. A good countermeasure for these would be rejection of all large SYN packets. Verisign DDoS protection services claim that they can withstand 2Tbps attacks of most types.

Unfortunately this would break TCP Fast Open, which transmits data with the initial SYN.

I can tell you that almost no one uses TCP Fast Open. It's a draft RFC that violates other RFCs. Google has given up on it in favor of QUIC. You should give up on it, too. It's not going to happen. It's a bad idea cooked up by ivory tower researchers who have never run a network.

Re: A DDoS in Asia Pacific

#42
post #2

200Gbps (if true) seems very high for a non reflection attack.

I'd normally say that doesn't seem that high for a botnet or collection of botnets. To put it in perspective, that's only twenty 10gig attached servers. Not that much when you think about it. Sure, you need transit to match the server but that's not uncommon at all these days.

The most unusual aspect of this attack was that it was an easily blocked, rudimentary attack using spoofed, big SYNs. Volumetric attacks have subsided and fallen out of favor over the past year. Everything now is layer 7 floods at high rates or low-and-slow to avoid detection. Either way it's mostly layer 7 these days. People I've talked with at Cloudflare and Prolexic have seen the same thing.

Also, we saw these big SYN floods about 3 years ago (before Radware coined the term). They are easy to block, the attackers went away, and we haven't really seen any since. I think this is a 3+ year old botnet run by an attacker who hasn't kept up with the times.

tl;dr this botnet is a bit long in the tooth

Re: A DDoS in Asia Pacific

#43
post #40

Earlier quoted context omitted.

They say they have facilities to clean 480Gbps of data, and 5Tbps of mostly spare inbound bandwidth, so their DDoS mitigation capacity is somewhere in that range ( http://www.ovh.com/ca/en/a1171.protection-anti-ddos-service-... ).

Customer testimony on places like Webhosting Talk have cast all of those numbers into serious doubt. OVH is more likely to nullroute your IPs than it is to fight off a 300gig attack.

Do you have a ref for that? I did quite a few searches and didn't find a single person on webhostingtalk saying they had been null-routed by OVH in the past year. Only one guy who worked for a competing hosting provider.

Re: A DDoS in Asia Pacific

#44
post #40

Earlier quoted context omitted.

Customer testimony on places like Webhosting Talk have cast all of those numbers into serious doubt. OVH is more likely to nullroute your IPs than it is to fight off a 300gig attack.

Do you have a ref for that? I did quite a few searches and didn't find a single person on webhostingtalk saying they had been null-routed by OVH in the past year. Only one guy who worked for a competing hosting provider.

Shut down this guy's account during an attack:

http://www.webhostingtalk.com/showthread.php?t=1467534&highl...

That said, I'm not a personal search engine. Here's a link to search results:

http://www.webhostingtalk.com/search.php?searchid=1555010

Re: A DDoS in Asia Pacific

#45
post #44

Earlier quoted context omitted.

Do you have a ref for that? I did quite a few searches and didn't find a single person on webhostingtalk saying they had been null-routed by OVH in the past year. Only one guy who worked for a competing hosting provider.

Shut down this guy's account during an attack: http://www.webhostingtalk.com/showthread.php?t=1467534&highl... That said, I'm not a personal search engine. Here's a link to search results: http://www.webhostingtalk.com/search.php?searchid=1555010

He said OVH didn't give a reason for shutting him down, which seems unusual. Perhaps he's breaking their ToS?

OVH themselves say they protect 24/7 against DDoS attacks, regardless of duration or size.

Re: A DDoS in Asia Pacific

#46
post #10

According to the founder [1], Telegram was even removed from Play Store for a few hours at the request of a South Korean competitor. For whatever reason, somebody in South Korea is seriously pissed off with Telegram. [1] https://twitter.com/durov/status/619486763032182784

They've been having DDoS attacks since September last year, so it seems unlikely that it's caused by a recent event. I'm surprised they haven't done anything about it before now.

The attack in September occurred just as a large number of Koreans suddenly moved to Telegram. The mass exodus was triggered by a surveillance scandal where a major Korean competitor was found to be handing over a large amount of user data to the government.

In recent days, there's been another exodus of Koreans from domestic IM services due to the revelation that the Korean army has been a customer of Hacking Team, the Italian spyware vendor who got hacked last week.

The two incidents might be related.

Post reply on HN