5 ms·
I'm not sure why someone would attack GitHub. Extortion? But aren't there more valuable targets? Showing off their botnet, perhaps? These attacks seem frequent.
by robgering 13y ago
I'm not sure why someone would attack GitHub. Extortion? But aren't there more valuable targets? Showing off their botnet, perhaps? These attacks seem frequent.
- Zikes 13y agoUnfortunately there may not be a "good" reason. It's not hard for me to imagine that someone could do it for kicks, or perhaps to test some new attack vectors against a reasonably hardened target.
- ansible 13y agoIt's not hard for me to imagine that someone could do it for kicks, or perhaps to test some new attack vectors against a reasonably hardened target. Though when you try out a new attack vector, the community (hopefully) publishes enough details about the attack to help the next target more effectively deal with that particular attack. If someone is attacking whitehouse.gov or a similar target, I somewhat understand their reasons why (though I don't agree with them). github.com, on the other hand, while a for-profit corporation, is also a valuable bit of Internet infrastructure that makes the world a better place. Attacking targets like github.com, Wikipedia, and others helps no one, and forwards no coherent political agenda. So I'm going with the "for kicks" / jerkwad theory.
- bestdayever 13y agoA lot of times, amateur "hacking" groups will require new members to prove their worth in some way and I'm sure github is a great target to test their "skills"
- nenolod 13y agoUsually it's some kid who wants to show off their botnet (or, more likely their $5 booting service investment) to their friends on hackforums. I deal with this crap all the time.
- leakybucket 13y agoPerhaps the attackers are drawn to sites they believe will later publicly document the attack, to learn whatever they can on how the operations team responded.
- natch 13y agoJust as anti-virus providers are sometimes suspected of creating viruses to help drum up business, I wonder if this could be a case of anti-DDOS service providers either doing some nasty marketing, or, looked at another way, running a protection racket.
- AYBABTME 13y agoLots of businesses heavily relies on Github for their operations. Sure, Git is distributed, but there's more to Github than just Git; think of continuous integration/deployment tools that integrate with the service, PRs. Attacking Github means you deny many more than only Github as a target. Which I guess, makes it more valuable than another target.
- trentmb 13y agoIt surprises me that GitHub doesn't sell/license a 'GitHub Appliance' that can get installed locally, but mirrors with something on their side too.
- eli 13y agoIsn't that Github Enterprise? You install it fully on your own servers.
- nathan_f77 13y agoThey do [1] [1] https://enterprise.github.com/ https://enterprise.github.com/
- VeejayRampay 13y agoI always wonder this myself. Were I skilled enough to be able to execute such big scale attacks against someone or something, I wouldn't think of Github as a potential target. Github is just some code, it doesn't bear any political or financial weight. But then again, some people get a kick out of ruining stuff so why not.