tdp_org,
@tdp_org@mastodon.social avatar

One of the botnets we see as the source frequent attacks against us very often has IPs which Shodan et al list as running Squid (often v4.14). I don't know for sure if this is related but it could be:
https://www.theregister.com/2023/10/13/squid_proxy_bugs_remain_unfixed/

#Squid #Proxy #InfoSec #DDOS #BotNet

gsuberland,
@gsuberland@chaos.social avatar

@tdp_org are the botnets ever actually effective at impacting service to users in a meaningful way? I always presumed that an org the size of the BBC has more than enough frontend anycast, blackholing, and dynamic scaling stuff going on to make the attacks rather like pissing into the wind, if you'll pardon the expression.

tdp_org,
@tdp_org@mastodon.social avatar

@gsuberland Haha, we usually do pretty well - as you say, we have many layers of defence. Some are more effective than others but we do our best to stay ahead of or at least up with the curve.
The size of the attacks has grown massively in the last year or so, that's been a real standout observation.
I can't really say much more than that in public though, sorry🙌🏻

  • All
  • Subscribed
  • Moderated
  • Favorites
  • infosec
  • DreamBathrooms
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • tacticalgear
  • JUstTest
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • megavids
  • lostlight
  • All magazines