Skip to content

Comment on Understanding the recent DDoS attack against Read the Docsparent

Comments

The problem is most of the botnet zombies are in places with very little rule of law like eastern europe/russia/south america/china. It is an exercise in futility and the richest customers just opt to just spend money on more protection than shutting down the zombies.

If the zombie is in the US, hosts like Google or Amazon will take 1+ month to respond.

Then IP-range block those places until they get their affairs in order.

Author here. This attack was extremely broad. I saw parts of this attack come from my own home ISP's ASN, though not my IP thankfully. If we just "blocked those places" there would be a lot of collateral damage. As it stood, we did temporarily bump up rate limiting for the biggest attack ASNs and we absolutely heard from real, regular users about it (Sorry to those affected).

Either it's coming from certain places and you can block those places, or it's coming from everywhere including some that are within your legal jurisdiction.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.