why LJ was down last night…

from lj-maint – (profanity edited out)

We got SYN flooded by a DDoS. 50 Mbps of incoming SYN packets isn’t good. Things broke.

We setup a bunch of firewall and rate limiting rules on the BIG/ip now, though. Shouldn’t happen (as easily?) again.

Whoever did it is a punk. These little d-less morons can’t break into the car, so they decide instead to slash its tires. Well now our tires have metal guards. incompetent sysadmins at the sites where the hacked machines were flooding from didn’t have their routers configured correctly, so the packets got out onto the net with forged source addresses.
– end quote

for more info about this sort of stuff –

http://packetstorm.securify.com/papers/contest/
http://staff.washington.edu/dittrich/misc/ddos/
http://packetstorm.securify.com/distributed/

the first link was back towards the very begining of DDoS existance. the latter are updated…

Weird.. I just did a post about good firewall software and DDos attacks… Maybe I should post about LJ’ers being given huge sacks of money?

Related Posts

Leave a Reply