Results 1 to 21 of 21
-
09-20-2016, 10:04 PM #1
Large attacks targeting industry giants over the past few days
I made this post on the reliablesite down thread in the network issues forum. But I felt like it deserves it's own thread, and may give other providers the chance to comment if they've seen the same attacks recently on their network.
Some of the attacks are being claimed by LizardSquad/PoodleCorp. The others, such as the large attack that hit OVH/Choopa/Psychz haven't been publicly claimed that I could find.Psychz was attacked yesterday. (>100Gbps)
Cogent was attacked yesterday. (reportedly)
OVH was attacked yesterday (source: https://twitter.com/olesovhcom/statu...19962036314112)
Krebs was attacked today. (source: https://twitter.com/briankrebs/statu...98865619836928)
Blizzard was attacked today. (source: https://twitter.com/PoodleCorp/statu...34956456120320)
Choopa/Vultr were attacked today. (source: http://www.webhostingtalk.com/showthread.php?t=1599421)
Riot were attacked 3 days ago. (source: https://twitter.com/PoodleCorp/statu...73040434872321)
You can probably find more, someone is tossing around some seriously large attacks at the industry.
And an interesting write-up here as well: https://www.schneier.com/blog/archiv...e_is_lear.htmlLast edited by anon-e-mouse; 09-21-2016 at 12:28 AM.
Swiftnode.net − Performance VPS, Dedicated Servers & Game Servers
12 Global Locations − North America, Europe, Japan, India, and Australia
Always-On DDoS Mitigation (UDP & TCP) − Optimized Routing − 24/7 Support
-
09-20-2016, 10:27 PM #2
Akamai reporting a "network event." Possibly related.
Last edited by Swiftnode; 09-20-2016 at 10:27 PM. Reason: I couldn't edit my original post, sorry mods.
Swiftnode.net − Performance VPS, Dedicated Servers & Game Servers
12 Global Locations − North America, Europe, Japan, India, and Australia
Always-On DDoS Mitigation (UDP & TCP) − Optimized Routing − 24/7 Support
-
09-20-2016, 11:19 PM #3
Yeah, noticed this too and this is a bad business.
Specially 4 U
.
JoneSolutions.Com is on the net 24/7 providing stable and reliable web hosting solutions, server management and services since 2001
Jones.Solutions | Jones.Hosting | Estela.Cloud
-
09-22-2016, 06:28 PM #4
Some new updates, Akamai has dropped Brian Krebs (http://krebsonsecurity.com) indefinitely due to the scale of the attacks.
Voxility showing some large attacks.
http://i.imgur.com/N0rjL8P.png - Large TCP Flood (~530Mpps)
http://i.imgur.com/4yytOSN.pngLast edited by Swiftnode; 09-22-2016 at 06:34 PM. Reason: whoops ;)
Swiftnode.net − Performance VPS, Dedicated Servers & Game Servers
12 Global Locations − North America, Europe, Japan, India, and Australia
Always-On DDoS Mitigation (UDP & TCP) − Optimized Routing − 24/7 Support
-
09-22-2016, 07:17 PM #5
You're absolutely right - this is disconcerting to say the least. Thanks for the links.
█ ProlimeHost - Dedicated Server Hosting & KVM SSD VPS
█ Three Datacenter Locations: Los Angeles, Denver & Singapore
█ SuperMicro Hardware | Multiple Bandwidth Providers | 24/7 On-site Engineers
-
09-22-2016, 07:25 PM #6
The group behind the attacks appears to be "Ghost Squad" (as per https://twitter.com/BannedOffline/st...80149957423105 & https://twitter.com/BannedOffline/st...97938853261316)
Additionally,
WoW servers were offline this morning.
Verizon recently had serious network issues in Baltimore.
Xbox Live is being reported down in some regions. (some users are stating downtime has been 3-4 days which matches up with the window of when the large attacks began.)
PoodleCorp reporting they took down the Battlefield servers, EA posted a maintenance statement last night for the effected games. (https://twitter.com/PoodleCorp/statu...57323561123840)Swiftnode.net − Performance VPS, Dedicated Servers & Game Servers
12 Global Locations − North America, Europe, Japan, India, and Australia
Always-On DDoS Mitigation (UDP & TCP) − Optimized Routing − 24/7 Support
-
09-22-2016, 08:05 PM #7
Junior Guru
- Join Date
- Jul 2016
- Posts
- 182
At this rate, these attacks are totally no joke. I speculate we will soon read about a major vulnerability that has allowed this to happen way too easy, so the attacker/s don't even have to spend money on this, since attacks at this scale don't happen easily and usually there is a reason behind them. It's not very clear what the reason is this time.
-
09-22-2016, 08:10 PM #8
Junior Guru Wannabe
- Join Date
- Jul 2015
- Posts
- 75
Now that Akamai dropped krebs, maybe Cloudflare could help like it did with spamhaus?
And how is BCP38 still not followed by all hosts out there? Hopefully this gets coverage.
-
09-22-2016, 08:25 PM #9
Newbie
- Join Date
- Sep 2010
- Posts
- 11
Because of how hardware accelerated routing is usually implemented. To lookup the source address on the packet generally requires cycling the packet through again, effectively cutting capacity in half. Most people are more willing to just handle issues when they occur instead of properly securing their networks.
█ █ |
█ █ |
█ █ |
█ █ |
-
09-22-2016, 11:53 PM #10
Web Hosting Evangelist
- Join Date
- Nov 2009
- Location
- Auckland
- Posts
- 461
And now krebs is pointing the A Record of his site to 127.0.0.1

:~$ dig @ns1.prolexic.net krebsonsecurity.com +noall +answer
; <<>> DiG 9.8.3-P1 <<>> @ns1.prolexic.net krebsonsecurity.com +noall +answer
; (1 server found)
;; global options: +cmd
krebsonsecurity.com. 300 IN A 127.0.0.1
-
09-23-2016, 12:31 PM #11
I believe we are going to start to see attacks of this scale (and larger) become the new normal. These days we have the full spectrum of groups actively engaged in cyber warfare including black-hats, white-hats, grey-hats and even state-sponsored groups. As of right now there is no network on the planet, DDoS protected or otherwise, that is capable of defending itself from 1Tbps~ cyber attacks. DDoS, BGP hijacks, botnets, you name it.
Right now the Internet at it's core is in a state of disarray. Government and corporate entities are fighting for control, censorship, and monetization. While people and hacktivists are fighting for decentralisation, security/privacy, and the free and open Internet as we once knew.
I can only hope that the right people are at the table when we discuss & implement important topics around the stability & structure of the Internet such as encryption, BGP, DNS, IPv6, and others. Improvements to these core protocols that are literally the foundation of Internet are what is needed to ensure a sustainable and stable Internet into the future.
Unfortunately it has to get worse before it will get better.❄️❄️❄️ HOSTBLIZZARD.COM --- 100% Canadian Hosting Provider ❄️❄️❄️
• Shared Hosting • Reseller Hosting • Cloud Hosting • VPS Servers • Domain Names
a division of Sheernox Technology Group
-
09-23-2016, 12:47 PM #12
Sorry for the lack of updates here regarding the large attacks, after the last post I made it seems they decided my website was next on the list, so I had to spend a while resolving that last night before heading off.
OVH showing more than 25 attacks since the 18th that exceeded 100Gbps. (source: https://twitter.com/olesovhcom/statu...30571677978624)
As reported by Krebs the attack on him was a mix, most likely the majority being GRE. OVH is reporting a botnet of DVRs capable of sending 1.5Tbps. (https://twitter.com/olesovhcom/statu...97257199964160)
And even though I was attacked yesterday after posting the "Ghost Squad" group here, the attack was significantly smaller than what Krebs/OVH has seen. It seems like even though they claimed at least one of the attacks on Krebs, they may not be the group that launched the 650Gbps attack. PoodleCorp/LizardSquad have been silent over the past day or so, so surprisingly enough nobody reputable has claimed the attack. (using reputable very loosely here.)Swiftnode.net − Performance VPS, Dedicated Servers & Game Servers
12 Global Locations − North America, Europe, Japan, India, and Australia
Always-On DDoS Mitigation (UDP & TCP) − Optimized Routing − 24/7 Support
-
09-23-2016, 04:40 PM #13
Web Hosting Master
- Join Date
- Jan 2002
- Location
- UK
- Posts
- 1,035
-
09-23-2016, 04:44 PM #14
Web Hosting Evangelist
- Join Date
- Aug 2007
- Location
- Lincoln, UK
- Posts
- 489
I feel that it is important to note that Akamai have dropped Brian Krebs because they were providing the services pro-bono (i.e. for free) and felt that they were unable/unwilling to continue to incur the costs of defending attacks on this scale:
Originally Posted by https://twitter.com/briankrebs/status/779111614226239488
Freethought Internet Limited - Hosting, Servers and Connectivity
Freethought Internet Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP. VAT number GB 987 0952 66.
-
09-23-2016, 04:47 PM #15
Web Hosting Evangelist
- Join Date
- Aug 2007
- Location
- Lincoln, UK
- Posts
- 489
Freethought Internet Limited - Hosting, Servers and Connectivity
Freethought Internet Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP. VAT number GB 987 0952 66.
-
09-23-2016, 07:15 PM #16
Can we get a source on that? I haven't been able to find anything where Akamai/Prolexic have stated they could not/would not incur the costs.
The attack on Krebs caused issues at a global level for Akamai. Which they requested peers to route around them so they they wouldn't be impacted. I doubt money was much a factor for Akamai, at least more-so than their entire network being disrupted for a pro-bono client.
edit: Unless you were using costs to reference what I stated above. In which I apologize it's been a long 24 hours for me.
Last edited by Swiftnode; 09-23-2016 at 07:19 PM.
-
09-23-2016, 07:19 PM #17
Newbie
- Join Date
- Sep 2010
- Posts
- 22
Cloudflare has offered to pick up Krebs, but he'd lose face just a bit if he said yes. He's railed against them for hosting many of the DDoS-for-hire websites, thereby creating a market for their product.
ArkServers.io -- Ark: Survival Evolved Game Server Hosting
-
09-24-2016, 01:29 AM #18
Some large attacks still ringing off in the distance. Likely from a different source than what hit Krebs.
http://i.imgur.com/U4opmfr.png
-
09-25-2016, 11:25 AM #19
Probably not going to have too many more updates here. The more attention this thread gets the more attacks get sent towards my website. I don't understand the logic behind what they're doing, they publicly claim the attacks on twitter, but when someone else says they're the ones behind it on a forum, they attack that person.
They're not sure if they want attention or not. Some real next generation Einsteins we got pumping out these attacks.
edit: Forgot to post the update, Krebs is back online using Google Cloud. (Congrats to him, and hopefully he can stick around for a bit.)Swiftnode.net − Performance VPS, Dedicated Servers & Game Servers
12 Global Locations − North America, Europe, Japan, India, and Australia
Always-On DDoS Mitigation (UDP & TCP) − Optimized Routing − 24/7 Support
-
09-26-2016, 08:55 AM #20
Web Hosting Evangelist
- Join Date
- Aug 2007
- Location
- Lincoln, UK
- Posts
- 489
There's a couple of quotes from Akamai in this article by The Boston Globe:
And:
Originally Posted by https://www.bostonglobe.com/business/2016/09/23/cybercrooks-akamai/qOAhvHoohJcmkxIwg5ChKO/story.html
Originally Posted by https://www.bostonglobe.com/business/2016/09/23/cybercrooks-akamai/qOAhvHoohJcmkxIwg5ChKO/story.html
Freethought Internet Limited - Hosting, Servers and Connectivity
Freethought Internet Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP. VAT number GB 987 0952 66.
-
09-27-2016, 01:14 PM #21
Web Hosting Guru
- Join Date
- Sep 2016
- Posts
- 253
Similar Threads
-
[statscheck] Stats/Server Overload For the Past few Days
By xmiccyx in forum Systems Management RequestsReplies: 4Last Post: 10-12-2009, 07:36 PM -
Anyone experiencing lower traffic the past few days?
By Postmaster in forum Web Design and ContentReplies: 5Last Post: 07-29-2004, 12:12 PM -
anyone experiencing lower traffic the past few days?
By Postmaster in forum Web Design and ContentReplies: 15Last Post: 07-15-2004, 01:09 AM -
United.Colo -- how have they been over the past month?
By travisbell in forum Dedicated ServerReplies: 13Last Post: 01-28-2003, 08:32 AM



Reply With Quote




