Skip to content

Comment on 300k Chinese bots currently abusing Ubuntu's torrents

Comments

After a short time serving one of those torrents, I have lots of connections from China, each pulling down about 130KiB/s. My outgoing bandwidth has been rising slowly, from only 400KiB/s when I started writing this comment to 3MiB/s now.

https://emergent.unpythonic.net/files/sandbox/Screenshot_202...

    % Information related to '117.188.0.0/14AS9808'

    route:          117.188.0.0/14
    descr:          China Mobile communications corporation

And 112.6 and 27.192, also in China, are connecting at a few MiB/s each client IP. However, its clients aren't serving up the "\0" client IDs and are connecting with encryption. https://emergent.unpythonic.net/files/sandbox/Screenshot_202...

Those are legitimate peers. The bots are all unencrypted with the \0 client ID. You must also have your torrent port open for them to connect to you because they don’t have ports open. This fact is the only reason one is still able to download these torrents.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.