[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] How is this attack causing 900 Mbps download and 100 Mbps upload?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hello.

I'm experiencing a very strange high-bandwidth attack against my exit
F79C822281CB1001E589296C80ABA6EA5DC7E36A. At first it was a directory
fetch attack, slowing it to a crawl due to upload exceeding 700 Mbps
(while download was never over 50 Mbps). I added "DirCache 0" to torrc
as a stop-gap measure, but after reloading, the attack has changed and
now *download* is excessive, showing 900 Mbps down and 100 Mbps up.

How is this possible? What kind of attack could cause such asymmetric
load in the *download* direction? I confirmed with nyx that it was
downloading at nearly 10x the rate that it was uploading. This relay
rarely exceeds 100 Mbps bidirectionally under normal conditions.

Of the 60 relays I operate, this is the only one that appears affected.
I'm urgently in need of advice for troubleshooting this.

Regards,
forest
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCaqCn9gAKCRAw+TRLM+X4
xuy7AQCmmd6TvF4MSr8c04pbHVl3Emw0SufRO0Vxg4XFnz7jtQEAnE7u4Y653gn6
vdzmiDOP9VJT9fDDSP4LXqu64XHh9gE=
=9jHQ
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx