Saturday, April 30th 2022

Cloudflare: Blockchain Platform Targeted by One of Most Powerful DDoS Attacks in History

Internet services provider Cloudflare has announced that it has successfully protected one of its clients from one of the most powerful DDoS (Distributed-Denial-of-Service) attacks in history. According to the services provider, an undisclosed cryptocurrency platform was targeted by a botnet comprising around 6,000 "zombie" computers distributed throughout 112 different countries. The botnet ultimately generated a collective 15.3 million requests per second. While that's still shy of the largest recorded metric - set at 17.2 million requests per second - the fact that the DDoS attack occurred through HTTPS likely pushed its complexity above the record-setting attack, due to the higher computational workload of secure HTTP. The attack lasted 15 seconds.

DDoS attacks aim to flood a network with requests and data packets in a bid to overload and paralyze it. The attack also showcases the ingenuity of bad actors, as the originated from cloud-based ISPs, as attackers leverage more complex and capable networking hardware than what's usually offered by last-mile ISPs. According to Cloudflare, the botnet seems to have mostly compromised systems with Java-based applications that were still open to the recently-discovered CVE-2022-21449 vulnerability.
Source: Wired
Add your own comment

16 Comments on Cloudflare: Blockchain Platform Targeted by One of Most Powerful DDoS Attacks in History

#1
eidairaman1
The Exiled Airman
No wonder simplyaweeb.to was down for a moment.
Posted on Reply
#2
R-T-B
eidairaman1No wonder simplyaweeb.to was down for a moment.
Yes, totally related. /s
Posted on Reply
#3
zlobby
Is it just me or this sounds more like an ad than an article?
Posted on Reply
#4
X71200
It does sound like it's boasting Cloudflare for preventing a DDoS attack, but the attack is seemingly of a very large size so there's that...
Posted on Reply
#5
ThrashZone
Hi,
Could of let it go it's only a undisclosed crypo group most gamers would cheer :laugh:
Posted on Reply
#6
eidairaman1
The Exiled Airman
R-T-BYes, totally related. /s
They use cloudflare
Posted on Reply
#7
bonehead123
Perhaps this was some sort of a "proof of concept" type of attack, just to demonstrate the attacker's abilities.......

Now they will probably sit back for a while, analyze the results, and then, after everyone thinks enough time has passed that the threat is gone, BOOOOM, they will come roaring back with a vengeance and do some REAL damage to some major systems somewhere...
Posted on Reply
#8
Mussels
Freshwater Moderator
My internet was utter ass yesterday, i blame this
Posted on Reply
#9
R-T-B
eidairaman1They use cloudflare
Ah. I guess it could actually be related then...
Posted on Reply
#10
Jism
zlobbyIs it just me or this sounds more like an ad than an article?
Nah.

With HTTPS request, a handshake is performed, which cost some resources at a server in general. When you send 15 million requests per second, you do understand that no VPS is able to even furfill these tasks without chrashing.

Basicly; cloudflare works as a man in the middle, sorting good vs bad traffic. I use it too for over 90 websites. Not because of the DDOS, but more for the CDN feature.

Lets say i have a english website aimed at both Dutch and US traffic. In Google US my website woud'nt rank well because it will favour US based servers or sites. When i use a CDN basicly a copy of my website is running now in the US in a datacenter on various locations, provided by Cloudflare. The visitor and google now get a "local" website up there without having to rent or hire a special server in the US for that case.

You can also offload quite alot with Cloudflare, if your server is getting quite busy. It filters the nasty traffic out for you.
Posted on Reply
#12
SirB
Wish you better luck next time DDos guys. Nice work.
Posted on Reply
#13
R-T-B
SirBWish you better luck next time DDos guys. Nice work.
Next time isn't necessarily going to be blockchain, so be careful what you wish for...
Posted on Reply
#14
Solaris17
Super Dainty Moderator
JismNah.

With HTTPS request, a handshake is performed, which cost some resources at a server in general. When you send 15 million requests per second, you do understand that no VPS is able to even furfill these tasks without chrashing.

Basicly; cloudflare works as a man in the middle, sorting good vs bad traffic. I use it too for over 90 websites. Not because of the DDOS, but more for the CDN feature.

Lets say i have a english website aimed at both Dutch and US traffic. In Google US my website woud'nt rank well because it will favour US based servers or sites. When i use a CDN basicly a copy of my website is running now in the US in a datacenter on various locations, provided by Cloudflare. The visitor and google now get a "local" website up there without having to rent or hire a special server in the US for that case.

You can also offload quite alot with Cloudflare, if your server is getting quite busy. It filters the nasty traffic out for you.
It's a monumental feat that much traffic could even be pushed in a DDoS; its no doubt the landscape is changing, but I think people are overlooking simple tcp/ip. DDoS on the most plain level is literally having a pipe big enough to eat it first and foremost. All the packet inspection or filtering does nothing if you are ingesting more traffic then your ingress can handle.

The fact that CF took this to the face is the real testiment. That said you can always take it stright from the horses mouth instead of second or third hand.

blog.cloudflare.com/15m-rps-ddos-attack/

I encourage anyone to check out the actual engineering blogs, CF is one of the most transparent by far and their post-mortems are top top notch everyone should take note. I would also take a look at the meta (facebook) and twich engineering pages. If your in the space really crazy shit and they generally are not shy about making public how their stuff works or even contributing to open source.

Shit iv setup entire ultra precise NTP ecosystems based off of their stack using chrony and an NTP appliance.

engineering.fb.com/2020/03/18/production-engineering/ntp-service/

super neat stuff. lots of people here would rather play valorant or some shit, but some of the engineering that makes the world function is absolutely wild. in breadth and scope.
Posted on Reply
#15
TheUn4seen
zlobbyIs it just me or this sounds more like an ad than an article?
Cloudflare did something genuinely impressive so they boast about it to anyone who will listen, in this way it's an ad - at least it's an honest one and I mean it in the most positive way possible. Mitigating an attack on this scale with minimal collateral damage speaks a lot about their infrastructure.
ThrashZoneHi,
Could of let it go it's only a undisclosed crypo group most gamers would cheer :laugh:
Gamers are modern day Luddites? Fitting, to be honest.
Posted on Reply
#16
R-T-B
ThrashZoneHi,
Could of let it go it's only a undisclosed crypo group most gamers would cheer :laugh:
Yeah that would make cloudflare look really swell to their customer base, which is often those needing protection from internet mobs...
Posted on Reply
Add your own comment
Dec 21st, 2024 22:44 EST change timezone

New Forum Posts

Popular Reviews

Controversial News Posts