Microsoft’s Azure portal down following new claims of DDoS attacks
bleepingcomputer.com
bleepingcomputer.com
They got in via a Back Door.
A lot of places sell DDoS protection. Most of it only ever cover the basics. With the size of botnets, hacked computers, etc that are easily and cheaply available for rent - a lot of so called DDoS protection services can't compete.
You really need to dig deep into what they mean by DDoS protection.
What layers are covered? What type of services are covered?
Also e.g. when they mention they cover volumetric attacks, it's often marketing more than the real deal.
E.g. a provider sells $x of total protection (that number means across all PoPs, so usually $x / 30 or less). It can still go down if you focus all your attacks on a few PoPs that matter.
Really important for game servers to have active DDoS protection, like what OVH offers. Not one that kicks in after the attack is detected, otherwise your players get booted, which is the goal of the attacker.
You can't even detect the attack. I've seen 1s that are well disguised or the patterns are so short there's not enough data to tell if it's an attack or real traffic. And yet it's enough to crash your connection or the service itself.
But I can't create a new session, even when remoted into an Azure-hosted VM. All our servers and services seem to be running fine; it just seems to be the portal.azure.com website that is impacted.
An easy way to validate this would be using fidler or similar to analyze the traffic that happens in the loaded page.
The APIs are now so complex there are lots of layers - load balancers, gateways, kubernetes, etc etc. The attackers can exploit any amount of them until they find it. It could be a bug e.g. integer overflow on a specific header or the lower TCP layers, etc.
It can also be very tricky to detect and stop. You may imagine the attacks to be constant but they are not. They do enough to deny service but not enough to be detected. It makes it very hard to differentiate from real traffic.