February 28th DDoS Incident Report
githubengineering.com
February 28th DDoS Incident Report
1–10 of 114 posts
Re: February 28th DDoS Incident Report
#2Re: February 28th DDoS Incident Report
#3Wow, 1.35Tbps? That's a lot for a DoS attack, right?
Edit: The attacker didn't need nearly that kind of bandwidth to execute this attack. See [1]
Edit: 1/50th -> 1/400th (bits vs bytes)
[0] http://www.internetlivestats.com/one-second/#traffic-band
Re: February 28th DDoS Incident Report
#4Wow, 1.35Tbps? That's a lot for a DoS attack, right?
According to [0] that is around 1/400th of total internet traffic per second. This begs the question: who has that kind of botnet at their disposal and why are they targeting Github? Edit: The attacker didn't need nearly that kind of bandwidth to execute this attack. See [1] Edit: 1/50th -> 1/400th (bits vs bytes) [0] http://www.internetlivestats.com/one-second/#traffic-band [1] https://news.ycombinator.com/item?id=1…
Re: February 28th DDoS Incident Report
#5Wow, 1.35Tbps? That's a lot for a DoS attack, right?
Re: February 28th DDoS Incident Report
#6Re: February 28th DDoS Incident Report
#7Wow, 1.35Tbps? That's a lot for a DoS attack, right?
According to [0] that is around 1/400th of total internet traffic per second. This begs the question: who has that kind of botnet at their disposal and why are they targeting Github? Edit: The attacker didn't need nearly that kind of bandwidth to execute this attack. See [1] Edit: 1/50th -> 1/400th (bits vs bytes) [0] http://www.internetlivestats.com/one-second/#traffic-band [1] https://news.ycombinator.com/item?id=1…
> The vulnerability via misconfiguration described in the post is somewhat unique amongst that class of attacks because the amplification factor is up to 51,000, meaning that for each byte sent by the attacker, up to 51KB is sent toward the target.
Re: February 28th DDoS Incident Report
#8Earlier quoted context omitted.
According to [0] that is around 1/400th of total internet traffic per second. This begs the question: who has that kind of botnet at their disposal and why are they targeting Github? Edit: The attacker didn't need nearly that kind of bandwidth to execute this attack. See [1] Edit: 1/50th -> 1/400th (bits vs bytes) [0] http://www.internetlivestats.com/one-second/#traffic-band [1] https://news.ycombinator.com/item?id=1…
memcached reflection: https://blogs.akamai.com/2018/03/memcached-fueled-13-tbps-at...
Rhetorical of course. Akamai should have logs of their offenders. Off to scan for offenders and notify their providers!
Re: February 28th DDoS Incident Report
#9Earlier quoted context omitted.
According to [0] that is around 1/400th of total internet traffic per second. This begs the question: who has that kind of botnet at their disposal and why are they targeting Github? Edit: The attacker didn't need nearly that kind of bandwidth to execute this attack. See [1] Edit: 1/50th -> 1/400th (bits vs bytes) [0] http://www.internetlivestats.com/one-second/#traffic-band [1] https://news.ycombinator.com/item?id=1…
memcached reflection: https://blogs.akamai.com/2018/03/memcached-fueled-13-tbps-at...
> The memcache protocol was never meant to be exposed to the Internet, but there are currently more than 50,000 known vulnerable systems exposed at the time of this writing. By default, memcached listens on localhost on TCP and UDP port 11211 on most versions of Linux, but in some distributions it is configured to listen to this port on all interfaces by default.
Yikes!
Re: February 28th DDoS Incident Report
#10Wow, 1.35Tbps? That's a lot for a DoS attack, right?
According to [0] that is around 1/400th of total internet traffic per second. This begs the question: who has that kind of botnet at their disposal and why are they targeting Github? Edit: The attacker didn't need nearly that kind of bandwidth to execute this attack. See [1] Edit: 1/50th -> 1/400th (bits vs bytes) [0] http://www.internetlivestats.com/one-second/#traffic-band [1] https://news.ycombinator.com/item?id=1…