[Resolved] 2 GBPS+ DDoS on Fresco Server - Attack affecting entire network intermittenly.
#1
Posted 03 November 2011 - 03:07 AM
If you have any questions, feel free to ask them, however we may not be able to reveal certain details of the attack publicly and I may respond to you via PM with specifics after addressing your question generally here in this thread.
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#2
Posted 03 November 2011 - 03:32 AM
#3
Posted 03 November 2011 - 03:56 AM
Edited by MikeDVB, 03 November 2011 - 03:26 PM.
Updated original post with more accurate details.
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#4
Posted 03 November 2011 - 07:21 AM
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#5
Posted 03 November 2011 - 07:41 AM
If you have any questions at all, let us know.
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#6
Posted 03 November 2011 - 07:52 AM
I appreciate the information!We have applied a dedicated IP to each account that was on the new IP that came under attack, and once the attack moves (it will likely take 1 to 4 hours) we'll know exactly which customer is under attack and will contact them at that point to discuss their options. For now the IP under attack is null-routed until DNS updates for the world for the accounts that were moved, and then the attack will shift again for the last time. This means we will likely face another 2 to 5 minutes of network issues sometime today. We are standing by and monitoring the servers and traffic for this attack shift so that we can quickly take the necessary actions to ensure our network integrity.
If you have any questions at all, let us know.
#7
Posted 03 November 2011 - 07:53 AM
Absolutely.I appreciate the information!
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#8
Posted 03 November 2011 - 09:58 AM
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#9
Posted 03 November 2011 - 04:00 PM
#10
Posted 03 November 2011 - 04:09 PM
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#11
Posted 03 November 2011 - 06:58 PM
#12
Posted 03 November 2011 - 09:11 PM
The networking hardware itself can handle around 90 million packets per second if I'm not mistaken but it's only gigabit right now (so the pipe just got flooded).Thanks, that reassures me about the issue I was seeing this AM. It wasn't really bad, but was a slow down I couldn't resolve. I guess that many packets coming through the pipe affects everyone.
We're looking at going to a 10 GBPS core Q1 2012 and then running probably dual redundant 10 GBPS links to each cabinet and then distributing that to the servers via a 24 port 1 GBPS switch for public networking. Right now it's 1 GBPS end to end which is fine as we average 100 MBPS across our entire network
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#13
Posted 04 November 2011 - 08:53 AM
#14
Posted 04 November 2011 - 01:22 PM
The width of the pipe has no bearing on speed unless the pipe gets full which only happens during an extremely large DDoS attack.Wow! The network is certainly fast right now; I never get any complaints about it from any of my clients. But fatter pipes are better.
We're upgrading the core/network in Q1 for a new project that I can't really reveal anything publicly about just yet, but we will be needing a lot more bandwidth so we don't want to put undue stress on our network or cause issues.
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
#15
Posted 09 November 2011 - 02:55 PM
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
█ http://www.mddhosting.com/ - Follow us on Twitter!
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users












