Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

61–70 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#61

Earlier quoted context omitted.

we were getting hit with attacks like this daily at some point and were forced to use cloudflare magic transit it's pretty random and you shouldn't read too deep into it as nearly every anti-ddos solution, host and isp has been hit with this botnet by now.

but why? For fun?

yep, there's no consistency to their actions - basically hit a target and keep it down for as long as possible causing heavy business loss. to my knowledge none of the target servers have ever received a ransom request.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#62
post #47
post #34

Earlier quoted context omitted.

You should talk to a network engineer before making claims like this. There are mechanisms to curtail DDOS attacks at origin. For a few reasons (political, economical) there’s little will to enact them, these attacks are so few and far between and you can pay your way out of them in most cases, so the incentives aren’t there for ISPs (whom are a commodity judged primarily on price and bandwidth)

How exactly would you keep the origin from sending a command to a botnet?

you don’t stop the message to the botnet, thats impossible:

You detect the behaviour downstream and send a signal to the ISP that there is traffic that needs to he rate limited.

One mechanism for this is called RTBH (Remote Triggered BlackHole) which relies on community tagged prefixes of addresses exceeding rate limited to be blackholed from forwarding traffic further in to the internet.

There’s also things like flowspec but a lot of things rely on proper trust between ASNs.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#63
post #52
post #33

Earlier quoted context omitted.

The international organisation for stopping wars, human trafficking, money laundering, drug distribution etc. however capable they might be, haven't managed to stamp out any of those things. I'd say a putative UN NetWatch would suffer from the same issues of funding and corruption and politics, but still we might have something better than this wild west lawlessness.

> have something better than this wild west lawlessness. Careful what you wish for. Before you know it you can't have an IP without your ID.

This is already the case in Germany and many other countries. Same for phone numbers. On the other hand, I get no spam calls, and I can't access the sites on https://cuiiliste.de/domains - censorship is amazing.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#64

> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?

I don't follow.

> run an army of security people

Do you think these private companies do this? They don't. They pay as little as humanly possible to cover their ass.

Botnets comprised of compromised routers is common and commercial/consumer routers are a far juicer target than openwrt.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#65
post #45
post #26

Earlier quoted context omitted.

Limit their upstream connection to the rest of the internet via allied countries. Literally the same as economic sanctions. The internet is a network of peers “trading” bits and bytes after all.

This won't do anything. The attacks are not from the offending countries they're from botnets of compromised devices. North Korea doesn't care if you limit their internet they already allow people to go outside their own.

perfect, then we just nullroute at source with Flowspec, even if we change the goalposts a thousand times in this thread there does exist a technical solution to this problem.

Just not enough economic or political incentive to pay for it.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#67
post #26
post #20

Earlier quoted context omitted.

How would you even enforce this if the offending country doesn't agree?

Limit their upstream connection to the rest of the internet via allied countries. Literally the same as economic sanctions. The internet is a network of peers “trading” bits and bytes after all.

America already limits its upstream to China and Russia through a private companies such as Cloudflare and Spamhaus. It's often the case that for Chinese users seeking to escape censorship, once they've worked their way through the Chinese Great Firewall, they find themselves in front of the American one.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#68
post #35

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

Since this is a distributed attack, I'm not really sure how that enforcement would look like? Am I missing something, are all these bots/zombies easily selectable and blockable?

Investigative powers should be able to at least find and seize the command and control servers, and hopefully track down people operating the command and control servers.

Some sort of international clearing house for ISPs to help identify and sequester compromised customers might be nice, too; but that doesn't need law enforcement powers; and maybe it already exists?

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#69

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

the real reason why these are a problem in the first place is because of cgnat and transit providers not implementing flowspec.

but these bad actors are not possible to track down in the first place since internet is unfortunately decentralized and things as simple as transactions submitted to bitcoin or etherium blockchain can be used as c&c

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#70
post #3

We should make residential proxies illegal

We really shouldn’t - this seems like perhaps one of the worst ideas one could propose in an era of rising authoritarian rule. Seems like a bad time to be putting silly restrictions on how folks route their traffic.

[flagged]
Post reply on HN