Earlier quoted context omitted.
we were getting hit with attacks like this daily at some point and were forced to use cloudflare magic transit it's pretty random and you shouldn't read too deep into it as nearly every anti-ddos solution, host and isp has been hit with this botnet by now.
but why? For fun?
Azure hit by 15 Tbps DDoS attack using 500k IP addresses
61–70 of 318 posts
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#62Earlier quoted context omitted.
You should talk to a network engineer before making claims like this. There are mechanisms to curtail DDOS attacks at origin. For a few reasons (political, economical) there’s little will to enact them, these attacks are so few and far between and you can pay your way out of them in most cases, so the incentives aren’t there for ISPs (whom are a commodity judged primarily on price and bandwidth)
How exactly would you keep the origin from sending a command to a botnet?
You detect the behaviour downstream and send a signal to the ISP that there is traffic that needs to he rate limited.
One mechanism for this is called RTBH (Remote Triggered BlackHole) which relies on community tagged prefixes of addresses exceeding rate limited to be blackholed from forwarding traffic further in to the internet.
There’s also things like flowspec but a lot of things rely on proper trust between ASNs.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#63Earlier quoted context omitted.
The international organisation for stopping wars, human trafficking, money laundering, drug distribution etc. however capable they might be, haven't managed to stamp out any of those things. I'd say a putative UN NetWatch would suffer from the same issues of funding and corruption and politics, but still we might have something better than this wild west lawlessness.
> have something better than this wild west lawlessness. Careful what you wish for. Before you know it you can't have an IP without your ID.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#64> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?
> run an army of security people
Do you think these private companies do this? They don't. They pay as little as humanly possible to cover their ass.
Botnets comprised of compromised routers is common and commercial/consumer routers are a far juicer target than openwrt.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#65Earlier quoted context omitted.
Limit their upstream connection to the rest of the internet via allied countries. Literally the same as economic sanctions. The internet is a network of peers “trading” bits and bytes after all.
This won't do anything. The attacks are not from the offending countries they're from botnets of compromised devices. North Korea doesn't care if you limit their internet they already allow people to go outside their own.
Just not enough economic or political incentive to pay for it.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#66We should make residential proxies illegal
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#67Earlier quoted context omitted.
How would you even enforce this if the offending country doesn't agree?
Limit their upstream connection to the rest of the internet via allied countries. Literally the same as economic sanctions. The internet is a network of peers “trading” bits and bytes after all.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#68I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.
Since this is a distributed attack, I'm not really sure how that enforcement would look like? Am I missing something, are all these bots/zombies easily selectable and blockable?
Some sort of international clearing house for ISPs to help identify and sequester compromised customers might be nice, too; but that doesn't need law enforcement powers; and maybe it already exists?
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#69I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.
but these bad actors are not possible to track down in the first place since internet is unfortunately decentralized and things as simple as transactions submitted to bitcoin or etherium blockchain can be used as c&c