5 ms·
Law enforcement takes down 'DDoS-for-Hire' sites in Operation PowerOFF
- wisdomalfred 2y ago[dead]
- aaron695 2y ago[dead]
- Alifatisk 2y ago327 arrested operation-poweroff.com
- move-on-by 2y agoYour link specifically says 4 arrested. There are ‘327 identified users’, but it does not say they have been arrested.
- Alifatisk 2y agoYou're right, I used the wrong word, can't edit it sadly
- musicale 2y agoI am still puzzled as to why we don't do a better job at DDoS mitigation in 2024. For example, it is surprising to me that it still seems to be difficult or impossible to deploy IP source address validation (although the situation may be improving). And there seems to be no easy way for UDP flood victims to ask (or pay) their ISPs to block UDP packets? (Most web-based services don't need random UDP packets from the internet. DNS and NTP can use TLS, etc.) Why are exploitable reflection-amplification vectors still in wide use? There do seem to be bad incentives for companies like Cloudflare which sell DDoS "protection" services.
- h4ck_th3_pl4n3t 2y agoThe underlying issue is how BGP and peering works behind the scenes. BGP relies heavily on mutual trust that nobody claims an ASN they are not supposed to have and that have no overlaps. But, if you analyze the registry datasets, there will be always two culprits that claim ownership of networks for surveillance reasons :) Then there is the fact that cloudflare is hosting sooo many malicious actors in the field that their own business model shifted into hosting crime as a service, while also offering "protection" against their own customers. There was this one guy that ran a custom DNS resolver to expose this, you can search the web archive for the "crimeflare" website where he hosted it (and got DDoSed by cloudflare, too, btw). And then there is the problem with peering. As you said, peering providers could have just checked whether or not the source comes from within one of their networks, but they don't do that. Most amplification attacks cross those peering lines/ASNs, yet we see cloudflare's DNS being the single most DDoSing server on the internet, while simultaneously providing said protection from exactly that attack type. [1] http://web.archive.org/web/20240000000000*/http://crimeflare.org:82 http://web.archive.org/web/20240000000000*/http://crimeflare... [2] http://web.archive.org/web/20190620030133/http://www.crimeflare.org:82/cfs.html#box http://web.archive.org/web/20190620030133/http://www.crimefl...
- iscoelho 2y agoThe largest DDoS attacks recorded are un-amplified and un-spoofed. The sources are malware (see Mirai and its variants) via legitimate internet connections. Even the largest ISPs generally do not have enough spare capacity to just "block UDP packets," as the largest attacks are now measured in Tbps. There is also nothing stopping attackers from just sending TCP packets. As consumer internet speeds grow, DDoS grows.
- duskwuff 2y ago> Most web-based services don't need random UDP packets from the internet. HTTP3 is UDP-based. If you're running a modern web service, blocking UDP isn't a viable option. > DNS and NTP can use TLS, etc. No, they can't. DoH is only used for recursive resolvers (like those operated by ISPs); if you want to run an authoritative DNS server for your domain, you still need to respond to queries on UDP port 53. NTS (RFC 8915) still uses UDP for time synchronization packets; only the initial key exchange is over TCP.
- Kurtcheng 2y ago[dead]
- bonamonsolomon 2y ago[dead]