3 ms·
DDoS attacks today are such a commodity. It takes next to nothing to launch them. You can get upwards of 200Gbps for 1/6 of a bitcoin. It is very easy to setup
by andrem 11y ago
DDoS attacks today are such a commodity. It takes next to nothing to launch them.
You can get upwards of 200Gbps for 1/6 of a bitcoin. It is very easy to setup and you can DDoS your favourite site in a matter of minutes.
These are not very smart attacks and can be mitigated even using the free tier of cloudflare.
I don't have the background on the mail provider attacks but 6.5k ransom seems to come from attackers who use easily available booters. Hushmail switched to Cloudflare throughout their attacks and that seemed to have helped, not sure what fastmail will do.
But any public web service should not be in a position where they are vulnerable to off the shelf DDoS attacks.
DDoS attack as suffered by for example Githuh with heavy coordination and nation states behind them require more specialised defenses. There are commercial alternatives out there that go from anywhere between 9k-40k per month depending on bandwidth and technology - see Imperva, Prolexic, Neustar, Nexusguard, Blacklotus, Incapsula, etc..
Apart from the initial setup which is more involved than Cloudflare's there is not much to do apart from throwing money at it. Quite the money making business really :)
- jonahx 11y agoWhat's a good setup for a medium sized site to use that would protect it from off the shelf attacks?
- joshmn 11y agoIf you're only web, you should be perfectly fine behind CloudFlare.
- toast0 11y agoThe only real defense is to serve your site from somewhere with more incoming bandwidth than incoming abuse. Afaik, the only type of filtering you're likely to get from an upstream provider is null routing of attacked ips, which helps protect their network, but doesn't help you serve users (you can switch ips, but abusers will likely switch too)
- giancarlostoro 11y agoWe used to use TCP proxies when I ran a game server where skiddies would try to attack it. I know buyvm.net is where we got one small $15 a year VPS with $3 a month "DDOS protection", not sure if we ever had issues after that with DDoS or not, we kept getting more and more proxies. We would give users a different one upon refreshing the page (it was a browser based game, but they would connect to a game server via TCP). I know the Minecraft community offers proxies as well. If you're on HTTP though, cloudflare is one of the cheaper options.
- brongondwana 11y agoIf we were pure web we would have ducked behind Cloudflare immediately. Since we do SMTP/IMAP/POP3 as well, we've had to go with a more complex (and costly) solution. This is our theory for why they're currently attacking email providers. We're not "just a web site", and attackers realise that the situation is more complex for email sites, we can't just hide behind Cloudflare. We're not sure who's actually attacking us, the ransom note comes from a freemail provider and a connection from a tor exit node. We can only guess at their total capabilities.
- ramidarigaz 11y agoBummer to hear that :( Keep up the good work! I'm a very satisfied customer, and I wish you all the best.
- andrem 11y agoSorry to hear about that... Do get in touch with one of the providers listed above, they may be able to help you out in the short term for free in exchange for publicity.
- brongondwana 11y agoYep, thanks - we've already spoken to a few of them and got some things in place. Obviously don't want to spell out all our measures in public.
- cat-dev-null 11y ago0. Place an HA pfSense CARP or OpenBSD pf CARP setup as a pair of transparent proxies in front of everything (eg at the edge on the other side of HA network gear with either 2 (or 3, if deploying a private, admin network too) NIC teams for isolating traffic). This will let you do raw L3 traffic measurements on each side with graphite/collectd, cacti, rrdtool, etc. and L2/L3 IP/network banning (if you don't own/admin the network gear or don't want to touch it in production). These are super cheap and only need ~128 MiB RAM each and very little CPU and disk (except for logging, you want a dedicated PCIe SSD or SSD partition if possible). (Your public IP(s) should point to these boxen.) 1. Definitely get stuff behind reverse SMTP/IMAP/POP3 proxy like nginx or haproxy. nginx: Compile it from source if that's all you need, and reduce your attack surface. http://nginx.org/en/docs/mail/ngx_mail_proxy_module.html http://nginx.org/en/docs/mail/ngx_mail_proxy_module.html haproxy: http://blog.haproxy.com/2012/06/30/efficient-smtp-relay-infrastructure-with-postfix-and-load-balancers/ http://blog.haproxy.com/2012/06/30/efficient-smtp-relay-infr... 2. Setup something like fail2ban: https://rtcamp.com/tutorials/nginx/fail2ban/ https://rtcamp.com/tutorials/nginx/fail2ban/ 3. There are many other tweaks and there are some appliancized VMs for anti-spam and DDoS that can be dropped behind the trusted network-side. (I would advise against Cloudflare-like services for most mature and non-web apps because they are add'l points of failure and increase latency, and they duplicate what good sys/netadmins implement routinely, especially if you're already deployed to multiple DCs servicing multiple continents and/or geodns.) Pedigree: I'm a founder and once-upon-a-time security researcher & sysadmin whom sold out and became SRE manager and then a consultant. I used to maintain multiple deployments of commercial Zimbra (from m&a activities) for clients including hi-ed, non-profits, VIP individuals, and enterprises.