7 ms·
On the other hand, the schools should be thankful that some 9 year old children are exploiting their system rather than some state actor or the like. The 9 year
by bArray 5y ago
On the other hand, the schools should be thankful that some 9 year old children are exploiting their system rather than some state actor or the like. The 9 year old is unlikely to really do much damage, whereas the experienced hacker could do much worse.
In reality, the school systems are likely just really old/awful and need to be updated with some basic protections before something bad does happen. The school children should be encouraged to perform responsible disclosure and to request permission before testing something.
- kbuck 5y agoA DDoS attack is not a security exploit. DDoS attacks overload internet connections to knock websites and users offline. There is nothing particularly technically exotic about them (most people are launching them with a cheap "booter" account that consists of a webpage with a "target" entry field and a "start attack" button). The only "solution" for DDoS attacks is to buy a dedicated DDoS protection service or upgrade your bandwidth to the point that the strength of the attack cannot saturate it. This is very expensive and isn't where schools should be spending their money.
- rubatuga 5y agoThe solution is to optimize your code and have rate limiting
- crtasm 5y agoWhen your network bandwidth is overloaded with traffic that isn't going to make a difference.
- TYMorningCoffee 5y agoWhat if the request rate exceeds the capacity of the network, before the rate limiter is even invoked?
- stevenicr 5y agoWhile those things may be good and me be helpful to a degree - the solution is generally to move your dns and pipes to the internet to a provider that can handle a larger spike in traffic - things like cloudflare and specialty ddos hosting center may be necessary - unless it's a short and cheap ddos - like a 30 minute attack - then just wait it out. A decent ddos attack, even ones that you can buy for 20 dollars on the clearnet, is going to overwhelm the most optimized code base since it will disrupt most of the average data centers, regardless of the rate limiting that you try to make happen on the box itself. at least in my experiences and from the things I was forced to learn on the fly for some time.
- 908B64B197 5y ago> There is nothing particularly technically exotic about them Nor is their mitigation. I honestly wouldn't brag online about my software being vulnerable to… 9 years old script kiddies!
- goatsi 5y agoThe software has nothing to do with it, the "vulnerability" is that they probably have a 1Gbps port that is getting 5Gbps of reflected UDP thrown at it. I'd love to see your software mitigation for that.
- willcipriano 5y agoHave a connection broker on another IP address that you authenticate against prior to getting connection details for the real system. Rotate the IP addresses the real system uses every couple of days. Let brokered connections live for 48 hours so the DDOS attack has to last that long to do anything. If the real system gets attacked, drop that IP and pick up a new one, noting what users received that IP address as they are potentially the attacker. Not perfect but it would probably stop these kids.
- goatsi 5y agoUnless the connection broker has more bandwidth than the server, the attack will just take it out instead, still denying access to the site. Either it doesn't work or it's just adding more bandwidth with extra steps. Your solution might help people already connected to the server, but anyone else is still out of luck.
- willcipriano 5y agoIt will help anyone who connected to the server within 48 hours, it will also eventually reveal who is responsible for the attacks to some degree. This won't work if anyone on the internet can make a account, but this situation is a finte group of people that you can eliminate.
- 5y ago
- bArray 5y ago> A DDoS attack is not a security exploit. DDoS attacks overload internet connections to knock websites and users offline. If we're entirely honest, they say 'DDoS' but likely mean an application layer DoS. Half these websites run on Moodle [1] or similar, which can be super slow because everything run through a database. I know for example that Moodle can be easily overloaded by students refreshing their pages on exam results day [+]. All an attacker needs is wget/curl in an infinite loop and it can be enough to knock some of these servers offline. > The only "solution" for DDoS attacks is to buy a dedicated DDoS protection service or upgrade your bandwidth to the point that the strength of the attack cannot saturate it. Sure, but even then there is more that can be done is this space. Most of the UK's education internet runs via JANET [2] which even boasts DDoS protection. > This is very expensive and isn't where schools should be spending their money. Well this is where the likes of GCHQ should be helping to secure infrastructure/businesses rather than constantly trying to backdoor it. [1] https://moodle.org/ https://moodle.org/ [2] https://www.jisc.ac.uk/janet https://www.jisc.ac.uk/janet [+] A workaround for the exam results day DoS was apparently to put people in a waiting queue. It worked, but felt quite hacky and would be easily overwhelmed.
- horsawlarway 5y agoThey aren't really exploiting the system in any meaningful or clever way. This is akin to ripping down all the posters in the hallway. It's not a thing to be thankful for - it's a thing assholes do.
- hffftz 5y ago