Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

81–90 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#81

A DDoS attack is often used to distract a company's security team. While the security staff is scrambling to get the website back online, the attackers use the chaos to conduct a more serious, stealthy attack.

It was interesting to read that the record breaking attack caused no glitch whatsoever in the service MS provides. Which is so slow normally that I start to wonder if that is a strategy, having headroom for these kind of situations, no-one realizes slowdown when it is already slow. ;)

This is just a crazy thought, tangential to what are happening during an attack.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#82

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

I mean, America can’t do anything about scam phone calls aimed at seniors who forge caller ID of local hospitals.

As alluded to by morkalork, they definitely could if they wanted to, as the (most? of the) rest of the world doesn't seem to have this problem. As long as spammers keep paying telecoms & no law(s) forbidding this exist, it will continue.

edit: grammar

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#83

Earlier quoted context omitted.

I mean, America can’t do anything about scam phone calls aimed at seniors who forge caller ID of local hospitals.

Can't or won't?

I’ve decided there isn’t a difference.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#84

IoT is just wave after wave of unsecure devices. There's gotta be a better way.

fun fact, part of the reason this botnet exists is because europe required the ability to install security updates unattended that you cannot disable and they compromised one of the servers that had the capability to push these updates compromising hundreds of thousands of routers.

That's really impressive finger pointing.

If the vendor can't even secure their update server; how long do you think it would be until some RCE on these 100k un-patchable routers gets exploited?

The only people to blame for this is the vendor, and they failed on multiple levels here. It's not hard to sign a firmware, or even just fetch checksums from a different site than you serve the files from...

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#85

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

Because countries benefit from conducting cyber warfare, the most publicised of are north Korea and Russia which have large state sponsored hacking groups.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#86

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

Legal systems are so convoluted and so colossally heterogenous - also very protective of their ways - around the globe that miniscule collaborations require grandiose efforts to initiate and maintain. No chance these fast paced adversaries will be caught by the interplay of several dozens of reluctant dinosaur legal systems.

Tangential: once I was targeted by a pretty primitive scam. More than 10 years ago (after someone I love was naive and inexperienced, having a medium amount stolen in a sensitive and stressful time of this person's life). I recognised fast and having time and will I sarted to play along, pretending I bite the bait. Collecting info while acting. In parallel trying to connect local and international authorities to report an ongoing scam effort. I believe I tried 4 organizations in 3 different countries apparently involved, I believe one was dedicated to online scams, also trying to warn Western Union, they are about to be used for scam. I even went personally to a police station locally to get some advice on how to assist catching the criminals. Since all I encountered insisted to report my damages, so they could start an investigation on an actual loss happened, I furiously gave up and decided whenever I will be having financial trouble I will invest my efforts in scamming others. No-one cares catching those in act! So the thugs can be incredibly bold and dumb, like the one I encountered, it is no effort doing better.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#87
post #78
post #60

Earlier quoted context omitted.

Digital signing wouldn't defend you from a compromised build server.

What in that act says OpenWrt would be made illegal? If anything, OpenWrt would roll out automated security updates for a supported branched release to comply with these regulations. Also, if you actually read it, there are exceptions for open source software!

OP claims almost daily that some benign thing is actually illegal but practically never provides any useful proof when asked.

(please prove me wrong, Alex)

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#88
> This attack lasted only 40 seconds but was roughly equivalent to streaming one million 4K videos simultaneously.

Who is this for? Is there anyone reading the article that can't grasp what a terrabit is but can somehow conceptualise one million 4k videos streaming simultaneously? I don't think anyone sits in that venn diagram.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#89
post #62
post #47

Earlier quoted context omitted.

How exactly would you keep the origin from sending a command to a botnet?

you don’t stop the message to the botnet, thats impossible: You detect the behaviour downstream and send a signal to the ISP that there is traffic that needs to he rate limited. One mechanism for this is called RTBH (Remote Triggered BlackHole) which relies on community tagged prefixes of addresses exceeding rate limited to be blackholed from forwarding traffic further in to the internet. There’s also things like flo…

How do you know where it comes from, if they use UDP and change the src of the packets.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#90
post #71

Earlier quoted context omitted.

breaking the law by using wireguard to access my home network, hmm, great idea.

Ok, I'll be a bit more specific, banning businesses and the trade of proxies that are purposefully marked as residential, in order to evade firewall blocks, and even to evade proxy blocks. You gotta draw the line in the sand somewhere, VPNs are already morally dubious, but if you ban the most shady of VPNs, residential proxies, then you can at least guarantee service providers the right to deny service to proxy users…

yah, but how else am I going to create millions of youtube accounts to spam sex bot ads >:(

on a more serious note, it's just not really possible since most residential proxy sites are botnets :)

Post reply on HN