@GossiTheDog @briankrebs the attack earlier was to Cloudflare (at least tens of Gbps of HTTPS requests from >60k bots I could see).
I had also noticed the origin server exposure and let them know as it was going on — they’re aware.
@GossiTheDog @briankrebs the attack earlier was to Cloudflare (at least tens of Gbps of HTTPS requests from >60k bots I could see).
I had also noticed the origin server exposure and let them know as it was going on — they’re aware.
@GossiTheDog Might be location-dependent — haven't had an error message since
@GossiTheDog Sadly, already over, like a beautiful rainbow in the storm https://infosec.exchange/@jmeyer/115571243852832673
@GossiTheDog I had a look at network traffic from today and some of them are proxy exit nodes; some do broad IoT scanning.
Two of them really stick out as they seem to exclusively target Citrix endpoints: 78.128.113.30 and 38.54.59.96
@GossiTheDog Done — and truly sorry to hear. Sending you strength and support.
About this X DDoS campaign: I've seen reports of attribution to Ukraine, and at least based on attack data at network level — I just don't see it. (And I should note: attribution is hard, so I am generally skeptical.)
Top contributors are 🇺🇸🇲🇽🇪🇸🇮🇹🇧🇷, and as with most botnets: very geographically distributed.
Most of the source IPs intersect with #Eleven11bot as we started seeing them on 26 February.
OK, now back to regularly scheduled skiing.
Supposed to be enjoying a week off skiing, but the X DDoS-related outage brought me back a bit.
Hint: that attack has been botnet-driven.
@GossiTheDog The target is a subnet in X own network. Haven’t had a chance to look at what those hosts might be exactly.
@F_kZ_ @GossiTheDog Looks like their shiny new bot (and even their main English channel) just disappeared — all while they closed the DDoSia English support channel
@GossiTheDog Most of the traffic stopped a few hours ago, it's now down to a trickle.
The website from one of the big US telcos still partially loads elements from Edgio even though most of the website is now on Akamai.
@GossiTheDog I was looking around for services still using Edgio in traffic delivery today, and for the most notable ones: Amazon Prime Video, Disney+, Samsung apps. (most other big players, like Microsoft for Xbox Live/updates, Paramount+, Playstation, and even Redtube stopped using them in early/mid December).
@GossiTheDog Also, worth noting that nearly all adult content sites stopped using Edgio in the second half of December, so in a way — they're better run than Amazon Prime Video or Samsung Bixby 🤷🏻♂️
@GossiTheDog Overall traffic from Edgio seems to be about a tenth of what it was a month ago. Definitely interesting to see what traffic continues or suddenly stops, and indeed Microsoft is a bit all over the place with LinkedIn continuing still but Office mostly stopped yesterday.
Germany is NoName’s focus again today, with a mix of government websites and industrial/energy company sites being targeted.
About two thirds of the websites are affected so far. (And the two sites from the federal government are still standing, thanks to an anti-bot challenge/rate limiting.)
#DDoS #threatintel https://social.circl.lu/@NoName57Bot/113666772362281488
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.