Free Speech and DDOS Attacks
blog.name.com
blog.name.com
Hopefully next time they dont demand name.com reveal private whois or something else. Good on them for not suspending the domain/user, but this was NOT the customers problem. They had a legitimate website and you chose to take the easy way out. You should not have asked the customer to leave to another host, you should have fixed the problem yourself.
It is your responsibility as a infrastructure provider to have adequate DDoS prevention in place. Passing the buck to every extortionist that comes in is not acceptable behavior.
Now that people know that name.com is easy to push around, I suspect much more of these attacks will be likely. Best not to use name.com nameservers apparently.
If DDOS attacks are now being organized by nation states, how would you keep your business running? I don't think Name.com did anything wrong here.
Having adequate defenses in place to withstand any attack, even one of unprecedented scale, would of course be the ideal. Are you offering to pay higher fees to finance this?
Any small company would do the same (hosting etc) to stop everything going offline. You can't blame name.com for being overwhelmed, because this sounds like a DDoS from an organized group who knew what they were doing, which is quite hard to mitigate against.
I sure hope that my registrar would never give in to anything like this, and would actually know how to defeat DDOS.
http://registrar.schlund.info these fine people, apparently.
Which sadly means that ISPs around the world will need to watch out for attacks every time there's political turmoil in China.
Anyone can go to www.hackforums.net for a free UDP flooder (called shell booters there), or rent one capable of over 1 gb/s for $5.
Or if you want to do it yourself, pick a cheap throwaway vps from www.lowendbox.com, go to www.gametracker.com and grab IPs from COD4, Wolfeinstein ET, Medal of Honor, etc... and send UDP query packets with your IP spoofed as the victim. This will amplify the size of your attack 20x or more and hide your IP address. You can easily get 10-20 gb/sec attacks like this.
Why is the US government not doing anything to stop the attackers ?
Seems a bit off to pass a customer with a lot of baggage over to a competitor, AND actively help them do so.
> Error establishing a database connection
I feel like if every network engineer cared about DoS attacks and actually watched traffic leaving their AS for such attacks (they're relatively easy to identify), the world would be a much better place. I can't tell you how many times I've e-mailed abuse contacts in APNIC regions and heard nothing but silence -- or, occasionally, the attack intensified. And you can't tell me the big telcos like Comcast don't already have packet sniffing gear in place to penalize BitTorrent and so forth; can't you quickly identify LOIC and the other bullshit and yank that customer offline or shape the hell out of them?
This is ridiculous, and might have a solution as simple as, "if your network DoS attacks mine and you don't deal with it, I reserve the right to depeer you. Good luck explaining to your customers why they can't hit Google any more."
I might have high expectations, though, since countless ASNs still let packets with forged addresses out.
Short(er) explanation: we no longer use the internet primarily for the purpose of communicating between two parties. But the infrastructure of the internet forces us to obtain data by having a conversation with a supposedly trusted party, even though a line of communication is not really what we want; we want a specific piece of data (an internet page, the latest exchange rate of USD to EUR, the ISO for the daily image of Ubuntu 12.04, etc.). It doesn't matter where we get it from (location is irrelevant), it only matters that it's the right data. Our use of the internet today is all about data. Yet, the infrastructure of the internet (TCP/IP) is location-centric; not data-centric. Data is shuttled between computers based, not on the data, but on the location of the computers. This creates the possibility of DoS attacks. The TCP/IP protocol is designed to efficiently route packages from a source to a destination, and a DoS attack simply uses this feature maliciously. When someone is hit by a DoS attack, the routers aiding in this are just following the rules of TCP/IP: routing packages to a destination. That's their job. What we need is a data-centric infrastructure. An infrastructure where data is not obtained via a connection to some location, but an infrastructure where data is simply accessed by sending a request for a specific piece of data into the cloud, and receiving the data from someone (and verifying that piece of data via its hash and signature).
Instead of me obtaining the NY Times front page like this:
* Wireless USB dongle sends out signal. Signal is picked up by my router (and everyone else's routers in near proximity, but all these other routers discard the signal). Router sends out a signal which my dongle (and all other routers/dongles pick up), but only my dongle uses this signal to obtain an IP address that the router knows. Over this connection I tell the router I want to connect to nytimes.com. Router connects to a server (name server) and asks it what the IP address is for nytimes.com. Router establishes a connection to nytimes.com, based on the IP it got from the nameserver. I send some commands over this connection where I ask for data, nytimes.com sends data, router hands it over to me. I now assume that I have the correct data - the front page of the NY Times, because some name sever said some IP address corresponds to nytimes.com, and this IP address sent me this data.
I would obtain it like this:
* Wireless USB dongle sends out a "data ID" for the NY Times front page. Any of the routers in my near vicinity that has a copy of the NY Times front page sends out a signal containing this data. My USB dongle pick up this data (and all other routers/dongles do so as well, the difference is that they are able to use this data as well, if they're looking for it). My computer checks if the data is signed using the public key of the New York Times. If the "date" field of the data is equal to or newer than, say, "now minus on hour", I accept this data as the NY Times' current front page.
A DoS attack is easy in the former case, because there is a connection. Not so easy in the latter case, because routers don't willingly forward any data; they are data-aware and if they receive a copy of the NY Times that isn't signed by the NY Times' signature, it's discarded/ignored.
If you want to understand it better, watch that video. It's an excellent talk. Really puts things in perspective.
https://en.wikipedia.org/wiki/Freenet#Distributed_storage_an...
Trust is still needed for a variety of reasons including the prevention of a DoS attack on global storage capacity (injecting 10Tb/s of junk into the peer-to-peer data store).
However, named data networking would push a cache to every network device between the requester and the provider for every piece of data. Unless an attacker is very close to the provider, they won't be able to take down the resource. The best they could do is take down the resource for themselves and their nearest neighbors.
Are they? Are you talking about a trivial "let's use the whole bandwidth everywhere" attack, or a more sophisticated "find a bug in website X and make every visitor do one request to DDOS target" class? While any brute-force attack is easy to spot, how do you propose dealing with well organised attack relying on involving random unsuspecting users? (suppose you don't have the Referer header like in the website attack scenario)
Of course this depends on the destination. If you want to DDOS the network, you need lots of traffic and a small, well organised attack may not be possible. But if you want to kill someone running a couple of servers on a 100mb connection, that's trivial.