Large DDoS strikes US, Europe
itnews.com.au
itnews.com.au
A lot of private trackers lately have been getting hit by DDOS attacks. To the point that a few have taken on extra developers/admins which have openly stated their primary goal is to deal with said attacks.
One in particular that has a large user base (35,000 active users) has been experiencing difficulties and is also customer of CloudFlare. This might be one reason why CloudFlare is hesitant to give out details.
The "French networking host" (OVH) that is mentioned in the article is one of the largest suppliers of seedboxes I known of. Usually indirectly through smaller companies who buy from OVH and then provide support and server management services. In fact, this is so widely known within the private P2P community that "being on the OVH network" is actually a selling point due to the sheer amount of peers that you'll be getting ridiculously high speeds with.
Of course, it could all just be a coincidence too.
Here's a description of the necessary configuration changes: http://www.meinbergglobal.com/english/news/meinberg-security...
Anyway, I'd encorage anybody to read the link and check, maybe you are not using the default, or maybe you are using an earlier version.
Surely enforcing this would prevent any IP spoofing, which would cut down on these types of attacks?
(As far as I'm aware in this type of attack you send packets purporting to be from your target, to anything on the internet that will blindly send back a reply. Hopefully the reply will be bigger/more packets than your request was, thus amplifying the bandwidth).
If I'm mistaken please explain why...
That said, source address spoofing is needed for some one-way satellite internet providers.
There are also some really cool advanced load balancing tricks you can do with it. It even comes in handy (ironically) when doing DDoS mitigation.
My experience has been that the majority of the countries where attacks come from do not really care.
You need relatively low capacity to start an amplification attack, so a server at some ISP which doesn't care is enough. There are some ISPs which knowingly allow this, like Ecatel in The Netherlands which is probably the most notorious example.
Post $5-$10M bounty to find those responsible, make their buddies to salivate to give them up and then make the public case out of them for others to think 10 times more before engaging in stupidity.
lol.
As for the targets of these attacks. They're still happening. It's honestly a pretty stupid attack. The connections from victim:80 to ntpserver:123. The attackers don't seem to understand that port 80 is not a commonly used UDP port. I'm seeing the following targets in my ntp server's logs:
37.187.133.51 (OVH) 216.33.93.214 (edline.com) 23.9.97.251 (akamai) 59.7.146.69 (Korea Telecom) 198.50.139.161 (OVH) 217.236.16.131 (Deutsche Telekom)
[1] https://blogs.akamai.com/2013/03/how-big-is-300-gbps-really.... [2] http://www.techweekeurope.co.uk/news/prolexic-ceo-scott-hamm...
Edit : French customer, use cloudflare and OVH. Is strongly attacked by ddos since yesterday
who cares about those guys anyway.