5 ms·
PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you
by anonacct37 3y ago
PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.
- Jeff_Brown 3y agoThe botnet is probably the critical thing. Even if the PR (or "avenge the global south", or whatever) value might not be enormous, the cost to a bad actor of having other peoples' computers do something is almost negligible.
- endergen 3y agoDoesn't using your botnet expose your botnet IP addresses/devices?
- mrweasel 3y agoYes, but currently that has zero consequences. Say you infect 500.000 Windows XP machines or consumer routers, the owners of those devices isn't going to be informed, nor is their ISPs. In many cases the manufacturer of those devices also aren't going to provide security update, but those probably wasn't going to be applied anyway.
- jrockway 3y agoAre you positive that "tell nobody" is the mitigation strategy that Google used here? They could have easily asked router vendors to patch their devices, asked ISPs to blackhole those customers until they're patched, etc.
- soperj 3y agoPatch what though? They know that they're getting hit with unprecedented traffic, not how those computers were infected.
- menscher 3y agoIt's mostly not infected computers, but rather poorly configured proxies that are open for anyone to bounce malicious traffic through. Convincing everyone to clean up their open proxies is a long-term, hard problem. But I plan to tackle it soon....
- deleted 3y ago[deleted]
- superjan 3y agoHow? I suppose the most effective way is to have those proxies attack each other. But don’t, it’s likely illegal.
- menscher 3y agoGet a few companies to agree that open proxies are a scourge that needs to be stopped. They each apply some action to open proxies (user-facing messaging, loss of functionality, captcha, or complete block), and the users of those proxies will get the problem fixed. The hard part (and it truly is hard!) is convincing a few companies to do this. It risks user complaints in the short term, to solve a problem that may not be very acute for the largest companies (who can simply absorb these attacks).
- superjan 3y agoHow about downgrading all connections from said proxies to http 1.1? This can be done in coordination, but it ought not to be too hard to embed such ‘graylisting’ functionality in a webserver. (No I don’t expect any response but I am just leaving this thought for those who stumble on this thread in the future).
- soperj 3y agothe most efficient way would be to write a script that gains root on those open proxies and then fixes the issue.
- ExoticPearTree 3y agoSo you're saying Google and Cloudflare, just as an example, should block consumers of other ISPs because they run "unpatched" software or they have malware running on their devices? Lol, this is a very absurd and narrow minded view how the internet works. You deal with the traffic, you don't randomly block eyeball networks because they're attacking you.
- c0pium 3y ago> you don't randomly block eyeball networks because they're attacking you. ISPs do this literally all the time. They sell services that do this.
- KomoD 3y ago> the owners of those devices isn't going to be informed, nor is their ISPs not necessarily true
- WelcomeShorty 3y agoBut these ISPs that give something and inform and even isolate their infected customers are few and far between. Shout out to Dutch ISP XS4ALL who was (is?) very very strict and active in this space.
- mensetmanusman 3y agoGoogle should start using their ad network to silently update people’s security!
- KomoD 3y agoAnyone can claim that, there's no link to a specific actor
- v-erne 3y agoI'm guessing you would do this in advance - "pay attention to tech news next week - our botnet will unleash hell"
- jekude 3y agoStep 1: Put message on blockchain beforehand with exact date/time and characteristics of DDoS Step 2: Execute DDoS Step 3: Prove to others you are responsible by using private key
- darkwater 3y agoAnd Google and Cloudflare also get good PR because how insanely good their are at deflecting those huge attacks. It's a win-win situation here... oh wait /s (the /s is just on the "oh wait" part, not the whole post)
- gowld 3y agoWhy not attack a target that can actually be harmed? Are they afraid? It's not obvious what's the value of having the largest ineffective attack.
- lazide 3y agoWhy not roll a couple defenseless grannies in the streets for pocket change, rather than throw rocks at the cops and then get away unscathed? One gets you more money in the short term. The other one gets you more street cred - which gets you more money in the long term.
- ehsankia 3y agoWell in this case it seems like they blew their "0-day" and Google worked with other providers to patch this type of attack.