Estimating the Revenue of a Russian DDoS Booter
arbornetworks.com
arbornetworks.com
Repeat after me:
I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem. I can not safely use usage-based pricing clouds like AWS and GCS until they get serious about the DDoS problem.
I've brought this up before: https://news.ycombinator.com/item?id=11261882 https://news.ycombinator.com/item?id=11000086
Many people that are in denial about this. This article is not an outlier, this is exactly how DDoS is now. DDoSes are cheap to execute and devastating to the host. Your competitor will chip in a little Bitcoin and get these people to attack your site. Or they'll just do it because they're bored and it's basically free for them. I knew a guy that worked on a site, he told me they always got DDoSed every time his site put on a sale. Guaranteed DDoS.
Who gets the $30,000+ bandwidth bill for the attack? Well, if you're using AWS or GCS, you do of course (it happened to Greatfire, why won't it happen to you?)
30x market bandwidth markups, zero DDoS mitigation. Good luck.
Edit: Oh, and VPS providers (DigitalOcean, Linode) that just null route servers for hours or days during a DDoS: you're not off the hook either.
Meanwhile, providers like OVH, Ramnode, Vultr and BuyVM offer various levels of integrated DDoS protection for their servers and VPS for free or a very reasonable cost ($5-10 per month). It's out there, you just need to look for it.
BuyVM promises 500Gbps protection for $3/mo, whereas Vultr offers only 10Gbps protection for $10/mo. The pricing is all over the place. I would naturally assume that the quality is all over the place, too.
- A very large proportion (I would conservatively estimate >50%) of DDoS-for-hire sites are hosted on CloudFlare. I couldn't find a comprehensive survey of all attack service providers, but in a recent sample[1], 100% of the services were protected by CloudFlare. - CloudFlare will not discontinue service for customers offering DDoS-for-hire services unless you are the police and bring them a court order [2]. - If you are not the police and submit a report of someone operating an illegal service behind CloudFlare, they will forward you report, unredacted, to the owner of the IP range. They will not tell you who owns it prior to forwarding the report. It is highly likely that your identifying information will be passed to the (anonymous) individual operating the attack service and that their (likely bulletproof) hosting provider will do absolutely nothing.
"Why do all of these services use CloudFlare?", you ask. One simple reason: before CloudFlare, the market of DDoS-for-hire services was somewhat self-regulating via all of the providers DDoSing each other. Since the advent of CloudFlare, though, many have used its protection to avoid attacks from the others, which has led to an increase in DDoS-for-hire services and a reduction in prices as they attempt to compete with each other. CloudFlare providing DDoS protection to these DDoS-for-hire sites therefore effectively increases the supply of such services. On top of that, "just use CloudFlare like everyone else" doesn't work for everyone -- people who don't easily fit into CloudFlare's plans (particularly people offering services via protocols other than HTTP/HTTPS) can't use it at all, while some others have to pay for a higher tier of service. It sounds pretty convenient for CloudFlare that all of these DDoS services are around (and cheap to use), doesn't it?
Further reading: http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...
[1]: http://arxiv.org/abs/1508.03410 [2]: https://blog.cloudflare.com/thoughts-on-abuse/
How will you protect the origin?
Again this is a blanket statement. I recently integrated with a service that required sftp access to function. Is this ideal? No, but if I could recreate the service efficiently I wouldn't be paying for it in the first place.
This and the websockets scenario were just two examples I can come up with from personal experience, I'm sure there are many other situations that I've never come across.
My point is that the above commenter was acting like cloudflare is a panacea for DDOS attacks.
>"A properly configured CF setup will mean your real server IP never gets revealed ever."
This makes it sound like only engineers who are inept with cloudflare are vulnerable to origin ip leaks which simply isn't true.
> Plenty of websites can be perfectly hidden behind CloudFlare as long as they don't have an MX record or unused subdomain that points to the same server.
I agree with you here 100%.
Although there was one interesting case cited here that's sort of "the competition" - some criminals' forum admin removed the botnet's ad, so they attacked the forum. And then the forum turned around and reported them to the police.
Does anyone have a best-practices for dealing with the more modern variants?
That has always been the problem with competently executed DDoS attacks. You need a very large pipe as Step #1 which is simply not cost effective for most businesses. :/
It get even better if you're publishing through a mobile app - that one can simply switch from one host to another on the fly without customer even being aware of the problem beyond a slight delay in connection. The list of hosts of would need to be distributed out of band as a tiny payload, either through a high-cost high-bandwidth channel (but in a very low volume, obviously, just the name of the new host), or via DNS TEXT records so that they are hard to decipher reliably and require custom programming and raise the cost of the attack. There might even be hosts that will hold your alternate host list for free, such as the iTunes App Store (app description or even an in-app purchase "description" field).
Speaking of high-cost high-bandwidth providers, I think another option would be to host a CAPTCHa there, and those who solve it, or have cookies to prove that they did, or have logged in with a valid account, get redirected to one from the rotating lists of your normal hosts, with names and IP addresses changing every few minutes. An AJAXy application can then try different hosts in turn or in parallel before following a link.
Functioning healthy markets require regulation, protection of property rights, fair and impartial court system, enforcement, etc, etc.
In other words, just like there's no free lunch, there's no such thing as "free markets".
People sell DDoS mitigation but that isn't anything close to a business being able to mitigate things and caring about best practices.
Also, what are you talking about? Are you claiming that NTT nor TWTC can mitigate a DDoS attack? If so, you're massively wrong.
Both are in possession of large networks which allow them to mitigate DDoS attacks.
The small business with the 1gbps pipe isn't "mitigating" the attack. Their provider is mitigating the attack in return for payment.
Spin up a hefty AWS instance and connect to every single IPv4 IP while sending a HTTP get request on successful connects with a Host matching that of the domain. There are only 4 billion IPs. Look for successful code 200's with the same headers and content as the original website. Easier said than done though.
Btw, this attack can be prevented if you run a drop-all firewall and only whitelist the IPs listed here: https://www.cloudflare.com/ips/
>ASERT keeps tabs on DDoS botnets and their attack activity with our BladeRunner botnet monitoring system and kypitest[.]ru is no exception.