Postmortem DDoS Attack of May 28th, 2026

Null

Ooperator
kiwifarms.net
Registrado
14 de Nov, 2012
Do not speculate on who, what, when, where, or why. I don't care. Neither should you.

Tor will remain the most consistent way to connect.


Right at midnight last night the site went down. Tartarus was overwhelmed. It's now 6pm and I've gotten about 4 hours of sleep in that time.

This is one of the largest attacks we've ever received. We have 5 different providers in 8 different locations. One of them reported that he was eating 800Gbps of attack traffic. If that's an even split across published IPs, this could have topped more than 6Tbps of attack traffic. It's highly likely the attack was between 160Gbps up to 1Tbps, as I believe that host is smoking crack or something.

Symptoms of the attack:
  • Automatically followed DNS changes. Due to how I advertise IPs for Tartarus, I suspect that the volumetric attack could have totaled 10Tbps.
  • The attack is a true "kitchen sink".
    • Terabits of volumetric flood, hundreds of megabits of clean volumetric traffic on each node.
    • Conntable flooding.
    • TLS handshake abandonment.
    • Slowloris.
    • HTTP2 (not sure exactly what, maybe some form of rapid reset, but I turned it off).
  • Actual Tartarus PoW Captcha resolution proving that it is a true crafted attack and not a regular booter.
  • Few IPv6 in attack traffic due to what I suspect is a botnet mostly coming from Brazil and China where IPv6 adoption is weak.

Successes:
  • Turtling into IPv6 space.
  • An entire new suite of mitigations and rate limits.
  • Increasing Tartarus PoW challenge difficulty.
  • More computer.

The core issue is that our proxy network is a bunch of very small VPSs. The strongest of our servers is the only IPv4 entry point I am currently exposing. Surprise, it's able to handle the entire attack traffic OK by itself. The smaller servers stand no chance even if the attack traffic is split between 8 points of presence. One server with 32 cores on an old AMD is better than 8 servers with 64 cores between them.

So on that note, thanks to the generous donations we've received recently, I can afford to throw more computer at the problem to absorb the attack. I will be moving to do that soon.



Morning of May 29th: The attack is so massive that some providers are blackholing our IPs which only intensifies the attack on surviving VMs.
Evening of May 29th: Tartarus version 85353b0b fixed kernel level filtering which should see significantly improved attack resilience.

Latest as of 2:30pm May 30th: The transgender individual attacking us is singularly focused on this task. I'm mostly just waiting for server orders to come in. Rumble's team has reached out to me so that front improve. We'll see.
 
Última edición:
Atrás
Top Abajo