Is there an economically positive criminal activity that involves DDoSing an AWS-hosted UDP service (probably video calls... probably like Zoom)?
Is there an economically positive criminal activity that involves DDoSing an AWS-hosted UDP service (probably video calls... probably like Zoom)?
One time a customer came to us and asked us to PenTest their server, checking it stands up to a DDoS. They said they owned the server and it was their network, so we said "we can run a small one for you which should give us an idea of some pain points".
We run the "mini" DDoS against the server, it takes a little more to sink the server than expected, but we just ramp up a few more connections and it is fine. We lift off on the test attack, but customer site doesn't come back up. We contact them and they say they will contact the VPS host. * Heart sinking moment *
We test other websites running on their cloud from a different connection - we had taken out their entire cloud infrastructure (this was a small provider). After a short while they were back up, but not before another few conversations with the customer. I really don't even want to know how badly positioned we were legally that day.
Lesson learned: Always double check.
There was a Windows vulnerability that came out in 2010-2011ish, when I was working there, that I had to deal with. I ran an nmap scan of the entire network looking for the bug, and accidentally BSOD'd half the office...
I believe they are more like an attempt to discover limits in the network or some targeted systems. Some systems are also vulnerable while they reboot, so attackers only need a one-time reboot.
From what I've been told, you're right. DDOS attacks can routinely expose information through failure modes the ops team never prepared for. What happens when your failsafes fail? If they didn't test for it and put mitigations in place then it's rather likely that sensitive error messages or service details, or whatever, is being exposed over the wire. So aws mitigated this attack. Does aws know for a certainty that they revealed nothing sensitive in the process? Maybe, maybe not. If the attacker is good, and 2.3tbps is pretty fing good, then could the victim even be positioned to know what to look for? In uncharted territories the attacked is always down from the attacker.
That used to be the case, but with the popularity and widespread use of IoT devices it won't hold true for long. If you can hack home appliances you could hold an attack for hours, if not days.
History has, the company used to be DDoS'ed regularly, sometimes offline for days, before moving to cloudflare.
https://interconnected.blog/why-zoom-chose-oracle/
See previous HN thread here: https://news.ycombinator.com/item?id=23032029
https://www.datacenterdynamics.com/en/news/most-zoom-runs-aw...