Earlier quoted context omitted.
This tsunami TCP SYN attack uses 1000 byte SYN packets apparently. A good countermeasure for these would be rejection of all large SYN packets. Verisign DDoS protection services claim that they can withstand 2Tbps attacks of most types.
Unfortunately this would break TCP Fast Open, which transmits data with the initial SYN.
A DDoS in Asia Pacific
41–46 of 46 posts
Re: A DDoS in Asia Pacific
#42200Gbps (if true) seems very high for a non reflection attack.
The most unusual aspect of this attack was that it was an easily blocked, rudimentary attack using spoofed, big SYNs. Volumetric attacks have subsided and fallen out of favor over the past year. Everything now is layer 7 floods at high rates or low-and-slow to avoid detection. Either way it's mostly layer 7 these days. People I've talked with at Cloudflare and Prolexic have seen the same thing.
Also, we saw these big SYN floods about 3 years ago (before Radware coined the term). They are easy to block, the attackers went away, and we haven't really seen any since. I think this is a 3+ year old botnet run by an attacker who hasn't kept up with the times.
tl;dr this botnet is a bit long in the tooth
Re: A DDoS in Asia Pacific
#43Earlier quoted context omitted.
They say they have facilities to clean 480Gbps of data, and 5Tbps of mostly spare inbound bandwidth, so their DDoS mitigation capacity is somewhere in that range ( http://www.ovh.com/ca/en/a1171.protection-anti-ddos-service-... ).
Customer testimony on places like Webhosting Talk have cast all of those numbers into serious doubt. OVH is more likely to nullroute your IPs than it is to fight off a 300gig attack.
Re: A DDoS in Asia Pacific
#44Earlier quoted context omitted.
Customer testimony on places like Webhosting Talk have cast all of those numbers into serious doubt. OVH is more likely to nullroute your IPs than it is to fight off a 300gig attack.
Do you have a ref for that? I did quite a few searches and didn't find a single person on webhostingtalk saying they had been null-routed by OVH in the past year. Only one guy who worked for a competing hosting provider.
http://www.webhostingtalk.com/showthread.php?t=1467534&highl...
That said, I'm not a personal search engine. Here's a link to search results:
Re: A DDoS in Asia Pacific
#45Earlier quoted context omitted.
Do you have a ref for that? I did quite a few searches and didn't find a single person on webhostingtalk saying they had been null-routed by OVH in the past year. Only one guy who worked for a competing hosting provider.
Shut down this guy's account during an attack: http://www.webhostingtalk.com/showthread.php?t=1467534&highl... That said, I'm not a personal search engine. Here's a link to search results: http://www.webhostingtalk.com/search.php?searchid=1555010
OVH themselves say they protect 24/7 against DDoS attacks, regardless of duration or size.
Re: A DDoS in Asia Pacific
#46According to the founder [1], Telegram was even removed from Play Store for a few hours at the request of a South Korean competitor. For whatever reason, somebody in South Korea is seriously pissed off with Telegram. [1] https://twitter.com/durov/status/619486763032182784
They've been having DDoS attacks since September last year, so it seems unlikely that it's caused by a recent event. I'm surprised they haven't done anything about it before now.
In recent days, there's been another exodus of Koreans from domestic IM services due to the revelation that the Korean army has been a customer of Hacking Team, the Italian spyware vendor who got hacked last week.
The two incidents might be related.