EDIT: An investigative reported from "The Australian" newspaper has picked it up and ran with this story - another to come tommorow about the telco's and their inability to handle the situation - Telstra are refusing to talk to her.
The head of the Australian High Tech Crimes Unit has told the NT commisionor of Police to investigate the story based upon the AHTCU being mentioned in what he sees as a derogatory light.
New article: http://www.theaustralian.news.com.au/common/story_page/0,5744,10654530%255E2702,00.html
Thought about you when I read this story, cos I remember a while back when you spoke to me about the Russian mafia hijacking the website - so Telstra obviously couldn't help out then?
A good bookie can rake it in, if they understand the maths and follow a system. It's a lot like insurance, gambling: a market in risk and probabilities.
A more interesting factoid is that for the last two elections, Centrebet's odds have been better predictors of election results than major opinion polls. Incidentally, the current odds show the Coalition well out in front. I'd have expected it to run closer. Go figure.
Quote from OverDrive: Easy to prevent?!? No offence, but if it melted the core routers in Sydney for Australias biggest ISP, I fail to see what you could've done...
So you are saying it took out the Australian leg of the Net ? or is that what the ISP told you ?
Ever hear of CERT or AUSCERT ?
If you have forensic evidence of the attack(s) then they can be prevented and if you really want to be nasty reply in kind ....
Mate, I've been dealing with http://www.ahtcc.gov.au/ and http://www.nhtcu.org/ .
It's not a matter of skill or great hardware in stopping this - its purely a question of pipe size, and based upon your location (Perth) you'd have sfa chance - there just isn't a pipe big enough going into the whole WA.
But please, by all means impart me with your wisdom...
We weren't sitting in the NT, we were sitting in Sydney, at the front door to the internet for Australia. I used WA as an example as you said you could've handled it, and I noticed your in Perth (as I said in my message "and based upon your location (Perth) you'd have sfa chance").
It was a multi-gig attack, and the head of Telstra Security told me they couldn't handle the capacity in Sydney without seriously degrading the performance of the network for the rest of the country and that we were to go offshore if we wanted protection that would actually WORK.
So, I restate my previous argument - "you would've done what exactly?" - and don't give me this $250/hr shit...
hehe ... what sort of attack ? I am assuming ( maybe incorrectly ) it was a DOS or DDOS attack against your Sydney based site ?
And I further assume is was a web server(s) that was the target ?
Define multi-gig attack plz - was it a syn flood ? or just a whole pile of simultaneous connections ?
Provide more details and I can offer advice - it is not rocket surgery this type of attack and am suprised Telstra were unable to mitigate it .... but knowing Telstra I am not suprised ... all too hard for them ...
DDOS, spoofed ips, syn flood USING multi gig, and if you know anything about synfloods you'd know that each packet is extraordinarily small, so picture how many packets it took per second (i'll leave you to do the math).
Toppy these Russian Mafia have access to thousands if not 10 times that number of rooted boxes and ISP's.
They can throw more data at the general .au domain then our whole international pipe can handle. And when its all directed at a single domain/hosting service.....ouch.
So banning IP's is useless too many + they can spoof and change easily. You can't block out the whole of Russia to au for any period of time. When your talking this many packets its way too freaking hard for any software to keep up with bad/good for diversion purposes. I don't believe Aus has any of these nifty Cisco gear that can try and sort it out on the hardware level. At the same time your CPU is maxing trying to host all the connections or decide good/bad/oh dear wtf is that one.
An internal attack from the .au domain is much easier to deal with but yeah, these guys do this for a living. :)
We had them try take us on as well. We ended shutting down our international traffic whilst we couldnt withstand the barrage. Eventually Optus took some affirmative action and used Radware equipment to post a big F*ck 0ff sign on the door in Sydney. We already had two of these boxes on our site in Darwin but I figure that our pipe couldnt cope with it. Optus also ended up seconding our DNS and a few other tricks. We didnt pay a single cent to the extortionists (that I'm aware of) but we had the pull with Optus to ensure that they were looking after us. We havent had any trouble with them now for about 4 months that we've felt here in Darwin.