Re: [tor-relays] DDOS

2016-06-14 Thread Petrusko
Thx all for those useful tools, time to try some ;) About the main subject, nothing about DDOS on my node... (no mails, no spikes on my graphs) Thx Le 14/06/2016 à 19:49, Steven Jones a écrit : > iftop might be better to see > > On Tue, Jun 14, 2016 at 8:59 AM, Petrusko

Re: [tor-relays] DDOS

2016-06-14 Thread Steven Jones
iftop might be better to see On Tue, Jun 14, 2016 at 8:59 AM, Petrusko wrote: > Hey, > > Little noob question inside :) > If possible to learn quickly how to detect a DDOS attack ? > > I got Munin running behind, can it be useful with the "netstat" and > "firewall

Re: [tor-relays] DDOS

2016-06-14 Thread Green Dream
I have relays on Digital Ocean as well, and occasionally get the same emails. Notice the contradiction in the email: "Once the attack subsides, networking will be automatically reestablished to your droplet. The networking restriction is in place for three hours and then removed." Which one is

Re: [tor-relays] DDOS

2016-06-14 Thread Roman Mamedov
On Tue, 14 Jun 2016 15:39:30 +0200 Markus Koch wrote: > Or you get e-mails ... Getting these once every few days. However I'm almost certain the issue is just a misdetection by them of some pattern from the regular operation of a Tor relay (for example the large

Re: [tor-relays] DDOS

2016-06-14 Thread Markus Koch
Or you get e-mails ... --- Hi there, Our system has automatically detected an inbound DDoS against your droplet named niftyguineapig with the following IP Address: 178.62.71.57 As a precautionary measure, we have temporarily disabled network traffic to your droplet to protect our

Re: [tor-relays] DDOS

2016-06-14 Thread Toralf Förster
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 06/14/2016 02:59 PM, Petrusko wrote: > So if the server is attacked, I think it will show some big spikes in > those graphs...? My ISP provides traffic data/graphs. And I do use sysstat[1] to monitor my server, which gives among other

Re: [tor-relays] DDOS

2016-06-14 Thread Petrusko
Hey, Little noob question inside :) If possible to learn quickly how to detect a DDOS attack ? I got Munin running behind, can it be useful with the "netstat" and "firewall throughput" plugins graphs to see it ? So if the server is attacked, I think it will show some big spikes in those

Re: [tor-relays] DDOS

2016-06-14 Thread Toralf Förster
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 06/14/2016 07:03 AM, Markus Koch wrote: > 4 of my 5 tor servers are under a incoming DDOS attack. Am I the only > one or is anyone else feeling the "love"? > attacks with about 100 MBit/sec over a minute or so happen here nearly daily, attacks

Re: [tor-relays] DDOS

2016-06-14 Thread I
not at the moment but now and then yes ___ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays