The penultimate guide to stopping a DDoS attack – A new approach
blog.unixy.net
blog.unixy.net
I like that they've got the ghetto version of the technique documented. Better that you should rig this up on a couple VM hosting providers for a few hundred bucks than that you spend tens of thousands of dollars to get the same level of service from someone with slick marketing.
The obvious problem here is that it's hard to keep a determined attacker from finding your real address space, and as soon as that happens, you're done; attackers just skip the DNS and whack you directly.
This is a useful trick, but it's not the end of the story.
Of course, there are (D)DoS attacks that don't consist of sending lots of bits/packets at a host, and this does assume you're hiring a dedicated server or somesuch.
Of course, they could try to sniff network traffic at one of the providers/on the backbone/..., but that's a lot harder to carry out than a basic DDoS attack.
[1] E.g. don't try to receive e-mail at this host while it's being attacked; you'll need to point an MX record at it, which pretty much defeats the purpose. [2] IP spoofing will break the next defense; if the entire provider can be taken down, you have serious problems. [3] If you accept all traffic, nmap/curl will easily find the host, after which the attack resumes. For bonus points, serve up an uninteresting-looking page.
Cue Inigo Montoya.
That said, the only person I ever heard use the word correctly in person was a Brazilian. I don't think that is a coincidence.
If they were thinking rationally about what they were doing, they'd (a) be demanding money to let up, and (b) breezing right past DNS-based defenses like this.
The attacker, noticing your round-robin approach, decides to drop the DNS server and then only has one host to deal with.
There are a lot of weak points that can be attacked. Certain sites will have features that can be taken advantage of. If you have a long timeout/keepalive, the attacker could launch lots of quick requests with no proper tear-down. If you have a zillion servers setup like this - perhaps they can take out a major link before the traffic even gets to you.
I also don't think this is a new approach - unfortunately it is much harder to stop attacks than to create various approaches. The number of compromised machines is just too high - that is the ultimate solution.
Speaking of DNS DDoS, DNS Made Easy saw a 40Gbit DNS DDoS a few weeks back.
I agree that there's probably a way to break things; but an attacker would need to actually do some work for most of them (e.g. create lots of accounts?)
DDoS attacks make the most sense for the attacker when they are an extortion attempt. The economics works in favor of the attacker. It costs the site dearly to be down, and they set a price that makes sense based on your site. Unfortunately, you may not hear about a lot of these attacks, and the attacker is never found or can't be arrested.
unixy.net sells DDoS insurance. You never know if the insurance policy was worth the monthly payments until an attack happens.
Note: I've never used unixy.net and can't speak to their effectiveness, but I don't like how they grossly oversimplify a complex problem
Best
They're talking about $5-10/month VPSes and want them to handle 100Mbps each? Sure those providers love that traffic.
Purely out of curiosity, how do people go about finding such nefarious characters?
Your "mitigation" is also useless - yes, tarpitting for antispam purposes can work, but a specialized DDoS tool likely uses raw socket access (i.e. the OS doesn't keep track of the connections). If you can't take the number of bits/packets thrown at you, you will be unreachable. And even if not - we're still talking about 10,000 machines talking to your one server. The bad guys have a lot more memory.