4 ms·
Simply set up your firewall to drop outgoing packets with source address not belonging to your subnet. The DDOS slaves are usually sending packets with spoofed
by vadiml 10y ago
Simply set up your firewall to drop outgoing packets with source address not belonging to your subnet.
The DDOS slaves are usually sending packets with spoofed source ip addresses
- ge0rg 10y agoThis is usually only true for amplification attacks. The new 1Tbps and 600+Gbps attacks reported about are direct traffic attacks from the actual bot IP addresses.
- slig 10y ago> The DDOS slaves are usually sending packets with spoofed source ip addresses I don't understand why this works. Why doesn't my ISP simply block outgoing packages with "fake" source IPs?
- Dylan16807 10y agoPure laziness.
- hannob 10y agoMost of them do that already. It's called BCP38. ~20-30% of ISPs however don't.
- FoeNyx 10y agoTo quote Krebs [1] on that subject: > BCP38 is designed to filter such spoofed traffic, so that it never even traverses the network of an ISP that’s adopted the anti-spoofing measures. However, there are non-trivial economic reasons that many ISPs fail to adopt this best practice. This blog post [2] from the Internet Society does a good job of explaining why many ISPs ultimately decide not to implement BCP38. [1] https://krebsonsecurity.com/2016/09/the-democratization-of-censorship/ https://krebsonsecurity.com/2016/09/the-democratization-of-c... [2] http://www.internetsociety.org/deploy360/blog/2014/07/anti-spoofing-bcp-38-and-the-tragedy-of-the-commons/ http://www.internetsociety.org/deploy360/blog/2014/07/anti-s...
- LeifCarrotson 10y agoI read the article. The reasons are trivial. First, old (>10 years) networking hardware may be unable to support it. All new hardware can do it, but some old stuff can't, and some ISPs haven't budgeted for the update. Response: 10 years is forever in the hardware cycle. This isn't a woodworking business, where old heavy iron is a good thing. Sensible businesses budget for returns on investment and mean time between failure on shorter time scales. Second, the labor to install network hardware replacements and perform configuration updates is expensive. Response: That's literally your job, you don't get paid to sit around and collect money. Third, and most importantly, the costs of the DDOS are not felt by the ISP. It's a tragedy of the commons. Response: Regulation, obviously, is required. If your network causes damage that the industry says you should have prevented, you should pay.
- pixl97 10y agoISP > you don't get paid to sit around and collect money. I don't think you understand the purposes of ISPs in the US :)
- beached_whale 10y agoMaybe some of the larger providers should stop pairing with these networks? Clean up their acts or have no business
- pixl97 10y agoFake where, and block where? If you fake your neighbors IP address then the hacked IoT device never gets taken down, and innocents get bothered unless the ISP does a good job investigating. Will the ISPs monitor faked packets inside their own network? And if they do at what level? Individual modems, entire segements? Entire regions?
- r1ch 10y agoNo home network or consumer ISP should allow spoofed source packets beyond the edge. The spoofing problems come from cheap / shady dedicated + VPS providers.
- e40 10y agoCorrect. I use # deny spoofers extinput="iptables -t filter -A INPUT -i wan" $extinput -s 127.0.0.0/8 -j REJECT $extinput -s 10.0.0.0/8 -j REJECT $extinput -s 172.16.0.0/12 -j REJECT $extinput -s 192.168.0.0/16 -j REJECT