Re: [tor-relays] Exit Nodes under DDoS attacks
Since I started operating the Torland1/Torland2 nodes in 2011 I noticed less than 20 DDOS attacks that lasted usually only a couple of minutes. I was never contacted by my provider. regards, torland On Monday 04 August 2014 14:53:12 Tyler Durden wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Hi > > I just wanted to know from others how often your nodes are being DDoSed? > Because this month one of our nodes has been targeted twice. > > > Because DDoS sucks and most providers aren't very happen when this > happens often. ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
Re: [tor-relays] Exit Nodes under DDoS attacks
Tyler Durden schreef op 04/08/14 19:10: My ISP detected it. They didn't specify which kind of traffic. I guess that it was a SYN-DDoS On 2014-08-04 19:04, Anders Andersson wrote: On Mon, Aug 4, 2014 at 2:53 PM, Tyler Durden wrote: I just wanted to know from others how often your nodes are being DDoSed? Because this month one of our nodes has been targeted twice. What kind of figures are you talking about here, and how did you detect it? What kind of traffic? I've seen several big ddoses on my exit nodes. They're generally UDP spams, focusing on saturating the network link, often 1Gbps+. They usually don't last long (10 min max), but I see them once every few weeks. Tom smime.p7s Description: S/MIME-cryptografische ondertekening ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
Re: [tor-relays] Exit Nodes under DDoS attacks
My ISP detected it. They didn't specify which kind of traffic. I guess that it was a SYN-DDoS On 2014-08-04 19:04, Anders Andersson wrote: > On Mon, Aug 4, 2014 at 2:53 PM, Tyler Durden wrote: >> I just wanted to know from others how often your nodes are being DDoSed? >> Because this month one of our nodes has been targeted twice. > What kind of figures are you talking about here, and how did you > detect it? What kind of traffic? > ___ > tor-relays mailing list > tor-relays@lists.torproject.org > https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
Re: [tor-relays] Exit Nodes under DDoS attacks
On Mon, Aug 4, 2014 at 2:53 PM, Tyler Durden wrote: > > I just wanted to know from others how often your nodes are being DDoSed? > Because this month one of our nodes has been targeted twice. What kind of figures are you talking about here, and how did you detect it? What kind of traffic? ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
Re: [tor-relays] Exit Nodes under DDOS attacks
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I receive several DDOS's per month, between 5 and 10 (I suspect that is because I run a higher volume of relays than most so don't take that as a normal figure). I have a 20Gbps connection with my ISP and Tor uses perhaps 4Gbps of it so the DDOS's haven't had any real effect on my servers other than perhaps a bit of extra traffic. - -T On 04/08/2014 16:00, Tyler Durden wrote: > I don't think so because RX traffic skyrocketed, not TX traffic. > > > > Greetings > > On 2014-08-04 16:17, t...@t-3.net wrote: >> We never had our exit nodes become the targets of DDOS attacks >> HOWEVER, we occasionally see abuse complaints due to someone >> abusing Tor to DDOS attack other targets. Perhaps that's what >> you're seeing? >> >> >> >> >> ___ tor-relays >> mailing list tor-relays@lists.torproject.org >> https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays > > ___ tor-relays mailing > list tor-relays@lists.torproject.org > https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays > -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.22 (MingW32) iQIcBAEBAgAGBQJT36RVAAoJEE2uQiaesOsLXHIQAKcXuNyWL5yZOd8CxJO9Oa/X bWx9sbUzsWU0OtdrVMB9HyZrKMWQpMj8xkY2x4M3oTVZDXktPpGjXqav+kQxFyTi VVpHYoa4pHWg385hLr8dYpK84yFUQloIx95z040AKto0Vm9RcuZqvY6xEafZX5o+ jurviq/1jIMvKKrwzeXZ71dQtWAZVUINR2QhugZPc3Y7llT3HCpySrS6ubxibhRr Aq7JdehrXbfS+z3vMXCrM/LVRX9Rt+bcnA8G5XGc3k3AVEJVTbDH3IWeOSsn9MCg nJ3+401JkS8U7qBxV5inKkZQGpmoLBJGaX4ybEbHNSkxQn5KOI3TbrZ9k56AWaGd sJ29qsC1UaJxscDU0MsVD3LBkTorR/nwWnvSEzb1V8AJOmmIKe85uAANgVA9cems pEs+1GzkI/uo3MFHzlhbFg4b3fpGxfxNfPE7oElblNFeaY/jpx1F62z/nTqNYjPs WN+9GtiGtkEIumKDdzb95+ce32abywFelSshDmqKYUOyYMDoVnh6x6HXiJQPB3Rk rFA2HQC529yz35HcGH6Kzaf35uU9NdOQ6QEVpN2eXEibRLAgbqzhVY1dF0pJIlYg XKolMsupb2Dm7Q+jMUyoVx3hxTJR93i9HDvtrc9oce3vZWXvc5tVOCROoqEvCtNQ KLhmpE/LDGMIiSbDRzzQ =qOit -END PGP SIGNATURE- ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
Re: [tor-relays] Exit Nodes under DDOS attacks
I don't think so because RX traffic skyrocketed, not TX traffic. Greetings On 2014-08-04 16:17, t...@t-3.net wrote: > We never had our exit nodes become the targets of DDOS attacks > HOWEVER, we occasionally see abuse complaints due to someone abusing > Tor to DDOS attack other targets. Perhaps that's what you're seeing? > > > > > ___ > tor-relays mailing list > tor-relays@lists.torproject.org > https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
Re: [tor-relays] Exit Nodes under DDoS attacks
On Mon, 04 Aug 2014 14:53:12 +0200, Tyler Durden wrote: > Hi Hello, > I just wanted to know from others how often your nodes are being > DDoSed? Because this month one of our nodes has been targeted twice. Speaking of Nos oignons [0], since we have our nodes (3 IPs) (in October, or November 2013 iirc) we had a DDoS only once (at least of what we know). [0] : https://nos-oignons.net/ Cheers, -- Vigdis signature.asc Description: PGP signature ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
Re: [tor-relays] Exit Nodes under DDOS attacks
We never had our exit nodes become the targets of DDOS attacks HOWEVER, we occasionally see abuse complaints due to someone abusing Tor to DDOS attack other targets. Perhaps that's what you're seeing? ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
Re: [tor-relays] Exit Nodes under DDoS attacks
Hello, With my 2 servers at Digicube it's pretty often (every month ?) The ISP's protection system is often disconnecting the server for the network because of this. Sometimes it's just false detection (or packets sended by a Tor user), invisible on bandwidth graphs but causing the network going offline. So it's disconnected serveral times per month (each time it happens, I send them an email and the server is reconnected). Because I'm not annoying at all with them, they aren't annoying with me. The user interface that provides a way to change reverse DNS doesn't work anymore for my second server (digi00666.digicube.fr - 2x 15MB/s), it have much more DDoS problems that the other one (with customised reverse DNS - 2x 12.5MB/s). Once, at Online.net, a DDoS attack (high amount of packet incoming) made my server send back a lot of answers. It was banned several days for sending flood! But as Tor Relay Operators we are strong and combatives ;) - Mail original - De: "Tyler Durden" À: tor-relays@lists.torproject.org Envoyé: Lundi 4 Août 2014 14:53:12 Objet: [tor-relays] Exit Nodes under DDoS attacks -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi I just wanted to know from others how often your nodes are being DDoSed? Because this month one of our nodes has been targeted twice. Because DDoS sucks and most providers aren't very happen when this happens often. Greetings virii - enn.lu -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.14 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iF4EAREIAAYFAlPfgjcACgkQzowS8yos8Rt1LQD/Rj2zZJpdmCyQhCmG3enWL6Z5 J0tbnnG2FS1GelACY74BAKIYRK8EVUt/pYfuuRzlBWWI84kuzcOmOiehqm6iyVjS =/ay4 -END PGP SIGNATURE- ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
[tor-relays] Exit Nodes under DDoS attacks
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi I just wanted to know from others how often your nodes are being DDoSed? Because this month one of our nodes has been targeted twice. Because DDoS sucks and most providers aren't very happen when this happens often. Greetings virii - enn.lu -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.14 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iF4EAREIAAYFAlPfgjcACgkQzowS8yos8Rt1LQD/Rj2zZJpdmCyQhCmG3enWL6Z5 J0tbnnG2FS1GelACY74BAKIYRK8EVUt/pYfuuRzlBWWI84kuzcOmOiehqm6iyVjS =/ay4 -END PGP SIGNATURE- ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays