6 ms·
The linked issue isn't "we need to patch Shellshock". It's "we have 800 hacked machines on the network, they are DDoSing like crazy, and it's saturating the int
by Wilya 12y ago
The linked issue isn't "we need to patch Shellshock". It's "we have 800 hacked machines on the network, they are DDoSing like crazy, and it's saturating the internal network". Their problem isn't that servers have been hacked. It's that it's overloading the network.
OVH isn't responsible for what people do with the servers. They provide the initial installation, networking, hardware monitoring and some management tools, but that's it. If they detect that a server is sending too much traffic, they can guess that it has been hacked, so what they usually do is disable it and notify the owner to fix it. But they don't do more, that's not their business. If you want a host that does more for you, it's managed hosting you want, not a dedicated server provider.
- aroch 12y agoThey actually tout their anti-hacking and anti-DDOS services when you sign up...
- funkyy 12y agoIts on network/hardware level. The issues with internal DDOS is that they are software related. OVH cannot access your server (or it shouldn't) so the only choice they have is to shut the server and wait till you will fix it. But if you receive DDOS attack to your server from outside, they can defend you using network resources.
- Wilya 12y agoTheir anti-DDOS system is mostly designed to protect against external attacks. It works at the network level, probably at the connection between their network and the outside world. Because that's the most efficient way: detect them and block them where you have the most bandwidth available. This is an internal attack, which requires different mitigation measures, and is seen less often in the wild (compromising 500 servers from a specific provider is more difficult than 500 random servers on the internet, and you're pretty much guaranteed that the provider will deactivate most of them after the first attack), so I guess their protection systems aren't as developped against it.
- dwild 12y agoYeah their anti-DDOS is actually to null route everything to your server. It's been a long time since I've seen that but that how they did it in the past (which is actually making any ddos against you really effective but your neighbors won't be as affected). If it's actually your server that actually attack another server, they will shutdown your server and give you a warning. They will let you boot in their recovery os that let you access your file system but if your server does it again, they terminate your account.
- spindritf 12y agoYeah their anti-DDOS is actually to null route everything to your server No, it's not. They have a proper anti-ddos solution in place for attacks from outside of their network[1]. [1] https://www.ovh.co.uk/anti-ddos/ddos-attack-management.xml https://www.ovh.co.uk/anti-ddos/ddos-attack-management.xml
- dwild 12y agoLike I said, maybe it's different from the last time I saw an attack on an OVH server, however when I saw it, it was literally impossible to reach the server even though it was still up. Using their ip failover system was the only way.
- scragg 12y agoActually if they detect a server is compromised, they will put your server in a FTP only data recovery mode and usually the only way to get your server back is to do a fresh install of the OS. Luckily OS reloads are fast and provisioning dedicated servers takes minutes.