‹ BackHN Continuity

Thread

Three Days in August: What a DDoS Attack Exposed in Our Network

19 points · 25 comments · nine_ch

  1. BLKNSLVR · · focus · HN ↗
    Naive question: services that can be used for amplification attacks, are they constantly getting patched to prevent the latest iteration of attack type?

    In other words, if there are a bunch of services prone to amplification attacks, can traffic from these services be upstream-blackholed for the duration of the attack?

    If it's not traffic coming directly from an IoT botnet, which is probably where the source of the spoofed traffic that initiates the amplification, then isn't there likely a smaller, more manageable number of services responsible for the attack traffic?

    Or are we talking services that form the substrate of the internet that have inherently exploitable protocols that it would take a large herd of organized cats in order to update in a way that doesn't break the internet, and will still take ~10 years?

    I still think in IPv4, so this may be a stupid question, but it's it known how many unique IP addresses were attempting to connect in the space of that time, and then it's there logging to identify those with unusually large amounts of individual traffic?

    1. nine_ch · · focus · HN ↗

      [dead]

    2. toast0 · · focus · HN ↗
      Ten years ago, when I worked on stuff that attracted DDoS, the memorable vectors were UDP chargen reflection and wordpress pingback reflection.

      Wordpress does get lots of patches, but I don't know how you really fix pingback, but it was easy enough to look for user-agent WordPress and drop requests before serving large files (or really anything... what do I have that WordPress should request). For a smaller site, the volume might have been high enough to overwhelm TLS handshaking, which is harder to solve.

      Chargen, wow. There's pretty much zero need for it to be on the internet. There's no need for anyone to run it. But evidence showed many instances running and it seemed to be the implementation Microsoft shipped in the Services for Unix package. Someone was trying to blocking the reflected traffic, but the servers were sending 64k responses (!) and that was being fragmented, and they only dropped the first fragment... fun times.

      I didn't spend time trying to get the hosts involved to stop sending this garbage... Writing abuse reports is herding cats, and networks that would be responsive probably already have taken these senders offline. I was also seeing short duration attacks consistent with people trying the free tier of DDoS as a service... so dealing with 90 seconds of garbage every once in a while was no big deal (as long as fragment reassembly didn't knock the machine over)

    3. jiveturkey · · focus · HN ↗
      > services that can be used for amplification attacks, are they constantly getting patched to prevent the latest iteration of attack type?

      unfortunately, no.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.