<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Denial of Service Attack in Sonic.net</title>
<link>http://www.dslreports.com/forum/r19743379</link>
<description></description>
<language>en</language>
<pubDate>Wed, 20 Aug 2008 20:38:48 EDT</pubDate>
<lastBuildDate>Wed, 20 Aug 2008 20:38:48 EDT</lastBuildDate>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19850414</link>
<description><![CDATA[<A HREF="/useremail/u/838846"><b>veloslave</b></A> : FWIW... from just one customer/user<br><br>I would rather put up with some occasional grief while you guys support someone getting slammed by the scum of the net.<br><br>[/FWIW]<br><small>--<br>Mom was right.... I NEED fiber!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19850414</guid>
<pubDate>Tue, 22 Jan 2008 02:45:40 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19842421</link>
<description><![CDATA[<A HREF="/useremail/u/456408"><b>DaneJasper</b></A> : We see more and more of them, and they're getting bigger and bigger.  To cause us any troubles here, they have to be pretty big - well over a gigabit of traffic.  We have about six gigabits of total transit in place today, but no single link is more than one gigabit.<br><br>We'll be talking here about what we can do to automate further our response to these type of attacks.  These two recent ones both caused brief outages, and this is something we've got to address.<br><br>-Dane]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19842421</guid>
<pubDate>Sun, 20 Jan 2008 22:08:54 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19841810</link>
<description><![CDATA[<A HREF="/useremail/u/358304"><b>guhuna</b></A> : I've got a feeling it was a botnet. You get about 900 machines hammering one machine and its connection is done for.<br><br>&raquo;<A HREF="http://en.wikipedia.org/wiki/Botnet" >en.wikipedia.org/wiki/Botnet</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19841810</guid>
<pubDate>Sun, 20 Jan 2008 20:38:52 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19840909</link>
<description><![CDATA[<A HREF="/useremail/u/838846"><b>veloslave</b></A> : Hey Dane... just wondering if this latest one on Saturday was the same customer... I thought my modem was getting weird on me again :)<br><br>Would seem that some body has an axe to grind... especially if it is the same party.<br><br>I have been working part-time in IT since real estate is so dang slow.  Sure is amazing what a different world the "tubes" would be if everyone employed a good AV and anti-spy regimen on a clean patched machine right from the start AND always kept it up to date.  There would be so few bots out there... the hackers might actually have to get a legit job.<br><br>Must not be too much fun for the big guy to see these DDOS attacks and have to try and decide if they should cut a customer loose... I guess that must be considered if it is a regular problem huh?<br><br>How often do you guys see these attacks?  There were these two that were substantial enough to be felt downsteam... are there a lot of others that we users do not notice?<br><small>--<br>Mom was right.... I NEED fiber!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19840909</guid>
<pubDate>Sun, 20 Jan 2008 17:50:36 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19755579</link>
<description><![CDATA[<A HREF="/useremail/u/456408"><b>DaneJasper</b></A> : Thanks folks for the support.  It's rare that we have a failure, but we subscribe to the concept of being totally honest with customers about what went wrong.  It's the least we can do.  It's also a key way that we can be different that the cable and telcos - they often hide the real facts from customers.<br><br>-Dane]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19755579</guid>
<pubDate>Mon, 07 Jan 2008 14:37:37 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19745252</link>
<description><![CDATA[<A HREF="/useremail/u/838846"><b>veloslave</b></A> : <div class="bquote"><small>said by  JohnInSJ <A HREF="/useremail/u/878241"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Wow.<br><br>I was both laughing at the frank, even humorous description of the firefight, and simultaneously feeling your pain - on a crappy weather day, to have both a nasty rainstorm and a nasty data storm sucked - with the data storm coming at the "end" of the day to boot.<br><br>Good job guys, and as always I appreciate the transparency on what's going on behind the scenes.<br><br>Back in the bad old SBC/Yahoo days, I'd only get info on what was happening through unofficial channels (usually via PMs on this site, of all things ;) )<br> </div>Ditto<br><br>X 2<br><br>Exactly<br><br>Keep up the good work!<br><small>--<br>Mom was right.... I NEED fiber!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19745252</guid>
<pubDate>Sat, 05 Jan 2008 17:56:46 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19743379</link>
<description><![CDATA[<A HREF="/useremail/u/358304"><b>guhuna</b></A> : I'm very thankful for S.net having a MOTD.<br><br>Keep up the good work guys!  <IMG SRC="http://i.dslr.net/check1.gif"> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19743379</guid>
<pubDate>Sat, 05 Jan 2008 11:52:02 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19743052</link>
<description><![CDATA[<A HREF="/useremail/u/878241"><b>JohnInSJ</b></A> : Wow.<br><br>I was both laughing at the frank, even humorous description of the firefight, and simultaneously feeling your pain - on a crappy weather day, to have both a nasty rainstorm and a nasty data storm sucked - with the data storm coming at the "end" of the day to boot.<br><br>Good job guys, and as always I appreciate the transparency on what's going on behind the scenes.<br><br>Back in the bad old SBC/Yahoo days, I'd only get info on what was happening through unofficial channels (usually via PMs on this site, of all things ;) )<br><small>--<br>My place : &raquo;<A HREF="http://www.schettino.us" >www.schettino.us</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19743052</guid>
<pubDate>Sat, 05 Jan 2008 10:42:13 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19741531</link>
<description><![CDATA[<A HREF="/useremail/u/757663"><b>burrowowl</b></A> : From our Message of the Day:<br><br><blockquote>Fri Jan 4 19:53:00 PST 2008 -- Widespread network outage. At approximately 5pm today we logged a massive amount of inbound traffic headed toward one of the colocation customers in our Santa Rosa datacenter. This distributed denial of service attack (DDoS) consisted of well over a gigabit of traffic aimed at this customer, sourced by thousands of zombie computers likely part of a massive botnet. This attack caused two of our gigabit transit links to flap wildly, which caused routing instability inside and outside of our network. This flapping was curtailed by a controlled shutdown and bring-up of these transit links. During this attack, most traffic continued to flow normally, but connectivity to some sites was significantly degraded or unavailable. <br><br>Further complicating matters was the rather confusing loss of a Santa Rosa datacenter router. In the middle of the DDoS, one of the two core routers that services our Santa Rosa datacenter suffered a hard drive failure. In addition to contributing a bit of red herring to the mess, this router seems to have spewed some incorrect routing information during the confusion, further complicating our restoration. At this time the router is still down pending hardware replacement. We've got on-site spares for this unit, and will be swapping them in around midnight tonight during a maintenance window. There are no customers directly connected to this router, and it's set up with a redundant neighbor that can take over its duties as necessary. No customers are affected by this router being off-line. <br><br>As if that wasn't enough, one of our network engineers made an unfortunate typo in the heat of battle, the end result of which was a nearly network-wide loss of routing protocol packets. This occurred at around 6:20pm, after internet-wide connectivity was almost fully restored. Emergency roll-back procedures were set into motion, and rapid service restoration required usage of our out-of-band management system to remotely console the affected devices and deactivate the change. Even with these procedures, fully restoring network connectivity took around 25 minutes. <br><br>We'll be discussing this outage at length internally to put policies and procedures in place to prevent any possibility of recurrence, as well as investigating why the routing instability caused such an impact to our network core. Our apologies for the downtime! <br><br>-Nathan, Jared, Matt, and the Sonic.net NOC</blockquote><br><br>--<br>John Fitzgerald<br>Sonic.net Technical Support]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19741531</guid>
<pubDate>Fri, 04 Jan 2008 23:42:26 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19741223</link>
<description><![CDATA[<A HREF="/useremail/u/736699"><b>succotash</b></A> : Ahh! So that's what it was. I thought it was weather-related too (it's supposed to be the wettest weekend in years here in the L.A. area). I was just about to call tech support when service was restored. Must have been a pretty massive DOS attack, alright.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19741223</guid>
<pubDate>Fri, 04 Jan 2008 22:38:47 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19741099</link>
<description><![CDATA[<A HREF="/useremail/u/901425"><b>treyadams</b></A> : You guys rock!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19741099</guid>
<pubDate>Fri, 04 Jan 2008 22:17:29 EDT</pubDate>
</item>

<item>
<title>Re: Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19741001</link>
<description><![CDATA[<A HREF="/useremail/u/233618"><b>Djdeadly</b></A> : Its been isolated and we should have internet back now. Its not uncommon to have DDoS attacks on ISPs but this must have been extremely massive to knock out most the backbone.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19741001</guid>
<pubDate>Fri, 04 Jan 2008 21:58:34 EDT</pubDate>
</item>

<item>
<title>Denial of Service Attack</title>
<link>http://www.dslreports.com/forum/remark,19740994</link>
<description><![CDATA[<A HREF="/useremail/u/901425"><b>treyadams</b></A> : If you are a Sonic customer, you noticed that your service went down tonight at around 6:30 PM Pacific.  I called tech support.  I thought it was probably weather related, but wondered why it effected me in SoCal.  Turns out they are experiencing a system wide denial of service attack.  Have you heard of anyone else (other ISP's) experiencing similar issues?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19740994</guid>
<pubDate>Fri, 04 Jan 2008 21:57:37 EDT</pubDate>
</item>

</channel>
</rss>
