TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Belgian ISP under 250 Gbps DDoS for days on end

497 点作者 laurensr超过 3 年前

21 条评论

s800超过 3 年前
I got hit with a ~40Gbps DDoS last week. These attacks are on the rise. Some responses to folks above: Success working with upstreams is quite varied. Some care, some don&#x27;t, and it can be difficult to get to folks that can help- even if their networks are impacted as well. Some carriers immediately turn this into a sales opp. - buy more bandwidth, buy more services.<p>In our case it was based on DNS reflection from a large number of hosts. I&#x27;ve contacted the top sources (ISPs hosting the largest number of attackers) and provided IPs and timestamps. I&#x27;ve received zero responses.<p>Geo-based approaches yielded no helpful reduction in source traffic.<p>Also, during this event we discovered an upstream of ours had misconfigured our realtime blackhole capability. As a result, I&#x27;m going to add recurring testing for this capability and burn a couple IPs to make sure upstreams are listening to our rtbh announcements.<p>Very concerned about the recent microtik CVE, as that is going to make for some very large botnets.<p>Personally this all is very disappointing because it creates an incentive to centralize &#x2F; de-distribute applications to a few extremely large infrastructure providers who can survive an attack of these magnitudes.
评论 #28581060 未加载
评论 #28581949 未加载
评论 #28578922 未加载
评论 #28581051 未加载
评论 #28579125 未加载
评论 #28580447 未加载
评论 #28579402 未加载
评论 #28581024 未加载
评论 #28588734 未加载
评论 #28580390 未加载
评论 #28583824 未加载
评论 #28580033 未加载
stingraycharles超过 3 年前
Since this is HN, it’s 2021 and DDoS’es are still a thing: why are they still a thing? Is there some fundamental “anonymity” to the Internet that makes it impossible to structurally prevent DDoS attacks? Apart from CloudFlare-like approaches, are there any R&amp;D in the pipeline that may kill this type of attack once and for all?<p>To me it’s incredibly infuriating to see the damage that still happens with these extremely simple techniques. Will it ever end?<p>Edit: to elaborate, I know that there are tons of insecure Internet devices and whatnot. I’m more interested in standards, and core protocol improvements that can fundamentally rid the world of these types of attacks.
评论 #28578595 未加载
评论 #28578629 未加载
评论 #28578696 未加载
评论 #28578637 未加载
评论 #28578620 未加载
评论 #28578608 未加载
评论 #28578869 未加载
评论 #28578642 未加载
评论 #28578847 未加载
评论 #28578578 未加载
评论 #28578756 未加载
评论 #28578819 未加载
评论 #28579319 未加载
评论 #28578754 未加载
评论 #28579011 未加载
评论 #28582219 未加载
ineedasername超过 3 年前
I&#x27;m very much not a network engineer, but I&#x27;d like to understand the magnitude of this issue because my intuition <i>is wrong</i>:<p>250 Gbps seems like it would definitely be a lot for a server or website but it also seem like a drop in the bucket for an ISP providing broadband for many customers.<p><i>Clearly I&#x27;m wrong</i> because it is an issue here. I&#x27;d like to understand <i>why</i> I&#x27;m wrong, and I hope that here, on HN, that&#x27;s taken in the spirit of curiosity intended and not negativism.<p>So, what am I missing? Maybe Belgian broadband is lower capacity than what I&#x27;m used to in a US metropolitan area? Maybe this particular ISP served a population too small to have a... um... &quot;fat pipe&quot;? I&#x27;d like to understand.
评论 #28579330 未加载
评论 #28579406 未加载
评论 #28579329 未加载
评论 #28580545 未加载
评论 #28580179 未加载
评论 #28579359 未加载
评论 #28580173 未加载
JackMcMack超过 3 年前
I&#x27;m an Edpnet subscriber currently suffering the effects of the DDOS. It&#x27;s annoying to say the least. Last year&#x27;s DDOS attack was relatively simple, pointed at the DNS servers. Simply using other dns servers was good enough to get back online. Edpnet also joined NaWas [0] at that time, a non-profit for ISPs to be able to redirect all trafic through big pipes when needed to deal with large attacks. Because the current attacks are rapidly shifting targets, it&#x27;s a game of cat and mouse to properly filter the ddos.<p>In practice, this means that some sites such as google and youtube keep working, but other services might not be available. It is extremely annoying when all of a sudden AWS api calls time out, or a Teams or Slack call suddenly drops to very low bandwith, and then drops entirely. I&#x27;ve had to resort to my phone&#x27;s hotspot multiple times in the last few days. Yes, I pay for SLA, but what&#x27;s the point in that? I&#x27;ve got priority in case of a cable break, and failover to 4G connection, but that&#x27;s no use if the upstream is congested.<p>The sad part is that the attack works because it it a small isp, 45000 customers. [1] It is the main reason I&#x27;m a customer, they offer good service for great prices. Kudos for not paying the ransom. If the attacks continue for much longer, I will probably switch to the bigger, more expensive, less customer friendly isp. I&#x27;m happy to support a local company instead of a big multinational coorporation. But if my clients can&#x27;t depend on me when working from home, I&#x27;ve got no choice but to pick the ISP with the bigger and more expensive pipes.<p>[0] <a href="https:&#x2F;&#x2F;www.nbip.nl&#x2F;en&#x2F;nawas&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.nbip.nl&#x2F;en&#x2F;nawas&#x2F;</a><p>[1] <a href="https:&#x2F;&#x2F;datanews.knack.be&#x2F;ict&#x2F;nieuws&#x2F;edpnet-al-dagen-getroffen-door-zware-ddos&#x2F;article-news-1779585.html" rel="nofollow">https:&#x2F;&#x2F;datanews.knack.be&#x2F;ict&#x2F;nieuws&#x2F;edpnet-al-dagen-getroff...</a>
评论 #28580665 未加载
评论 #28582205 未加载
评论 #28582193 未加载
评论 #28581335 未加载
ericbarrett超过 3 年前
&gt; EDIT 16&#x2F;09&#x2F;2021 10:12*: During the night we had two more attacks. We are working with the authorities, who have confirmed they are looking into it and are doing everything in their power to find the responsible individuals. We were contacted by an individual who verified he was behind the attacks, asking for a ransom.<p>Roughly how many criminal groups are active in DDoS ransoms (as opposed to data crimes, like cryptolockers and exfiltration)? How common is this nowadays? Clearly it happens, but I&#x27;ve no idea the general scale of the problem in 2021.
评论 #28578750 未加载
mfkp超过 3 年前
I wonder if this is related to the attack on voip.ms (ongoing for multiple days)<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;voipms" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;voipms</a>
leoc超过 3 年前
Mods, can the URL please be corrected to <a href="https:&#x2F;&#x2F;issues.edpnet.be&#x2F;?p=3507" rel="nofollow">https:&#x2F;&#x2F;issues.edpnet.be&#x2F;?p=3507</a> ? The current link to <a href="https:&#x2F;&#x2F;issues.edpnet.be&#x2F;" rel="nofollow">https:&#x2F;&#x2F;issues.edpnet.be&#x2F;</a> is likely to rot badly over the years.
tigerlily超过 3 年前
How can I check my home network for signs I have any devices participating in a botnet?
评论 #28578725 未加载
评论 #28578799 未加载
hda2超过 3 年前
Spamhus bad ISPs. Give them low QoS until they fix their problem.<p>If all major exchanges and service providers agree to punish IP blocks, ISPs will have no choice but to better police their networks.
forty超过 3 年前
Why are the people doing those attacks doing them? Ransom? Or are they just doing that to prove and advertise&#x2F;demo their capacity to harm?
评论 #28580331 未加载
ThinkBeat超过 3 年前
What is the motivation?<p>Extortion? Retribution? Censorship? Marketing? QA?<p>Are they asking for money stop?<p>Are they being paid by some actor to do this because they wishes to protest &#x2F; punish the company?<p>Are they demonstrating what they can do, in order to drum up business?<p>Are they testing what their system can accomplish? and iron out any bugs and learn how to best utilize it? So what mitigations they face and how to overcome them?
评论 #28581624 未加载
edoceo超过 3 年前
Don&#x27;t the peering agreements have to pay for bandwidth? Isn&#x27;t there a bigger cost for those flooding this one? Could they charge-back and encourage peers to throttle? Can peers fix this with pricing model changes?
blunte超过 3 年前
How often do we ever find the actual individual humans resonsible for these bad actions?<p>I would imagine if the individuals were identified, some harmed parties would spend money eliminating them to dissuade others doing the same thing.
评论 #28580607 未加载
r_singh超过 3 年前
I worked at an ISP AAA&#x2F;Radius provider and since we started offering a cloud offering to our customers we were DDoSed twice.<p>The source IPs were a Turkish university, I wrote to them a few times but they seemed clueless. Cloudflare&#x27;s protection suite was beyond our budget and our engineers really started moving the system between 5 different IP blocks thanks to the help of our customers.<p>We still don&#x27;t know who&#x27;s responsible, but we suspect it could be done by our competitor...<p>(PS - We&#x27;re based in India)
Aeolun超过 3 年前
It there no way to just completely block every IP sending you so much traffic?<p>You might end up blocking a few million, but your network remains uncongested.
评论 #28582113 未加载
teitoklien超过 3 年前
<a href="https:&#x2F;&#x2F;gnunet.org&#x2F;en&#x2F;gns.html" rel="nofollow">https:&#x2F;&#x2F;gnunet.org&#x2F;en&#x2F;gns.html</a>
评论 #28590571 未加载
vadfa超过 3 年前
A 250 Gbps attack is bringing an ISP down? How is this possible in the age of 1 Gbps connections in every home?
评论 #28579296 未加载
评论 #28578674 未加载
评论 #28578698 未加载
评论 #28578999 未加载
评论 #28583267 未加载
评论 #28580428 未加载
评论 #28578994 未加载
Havoc超过 3 年前
Unfortunately this works. Kills small ISPs on all fronts. Customer perception, technical and financial
pstuart超过 3 年前
I&#x27;m assuming that eBPF would be a potent tool for dealing with this, and it looks like CloudFlare agrees: <a href="https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;l4drop-xdp-ebpf-based-ddos-mitigations&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;l4drop-xdp-ebpf-based-ddos-mitig...</a>
评论 #28581071 未加载
评论 #28590276 未加载
bullen超过 3 年前
Why not just block the offending IPs in iptables?<p>Edit: as a Swede it&#x27;s very funny that customer is called klant in dutch!
pt_PT_guy超过 3 年前
and no one accountable :-)
评论 #28580713 未加载