5 ms·
3000 computers means each one is putting out a full 100Mb/s, which unless those 3000 computers are in data centers seems unlikely. Seems like 30,000 nodes at 1
by criley 14y ago
3000 computers means each one is putting out a full 100Mb/s, which unless those 3000 computers are in data centers seems unlikely.
Seems like 30,000 nodes at 10Mb/s would be more likely?
But I don't have experience in botnets, just curious.
- ominous_prime 14y agoThis was mainly a DNS amplification attack, so each node doesn't need to put out the total traffic. I'm not sure what the highest achievable return is, but doubling the traffic this way is pretty straightforward.
- random_ind_dude 14y agoFrom what I understood, these attacks used DNS amplification. I am no expert on botnets either, but here is the basic idea: they basically send a small request to a DNS server with the source spoofed. The server sends a much larger response to the spoofed source, which in this case is Spamhaus. This happens on those DNS servers that don't check whether the request originated from inside their own network. So the botnets involved don't have to send 300 Gbps of traffic to Spamhaus. The DNS servers being much more powerful will take care of that. I have no idea about the going rate for a botnet, though.
- entropy_ 14y agoI think the onus for this one is on ISPs who don't properly filter outgoing traffic. It's pretty simple, really, you have a block of IP addresses you allocate to your customers, any outgoing traffic with a source outside of this block should be dropped. A simple iptables rule on the router handling that block would suffice. There is no legitimate use case for sending traffic with a spoofed source IP. I'm simply amazed that ISPs who should have the technical knowhow still haven't eradicated all kinds of network attacks that rely on spoofed source addresses(of which DNS amplification is only one).