[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?



On 2026-09-09 00:27, forest via tor-relays wrote:
Hello.

I'm experiencing a very strange high-bandwidth attack against my exit
F79C822281CB1001E589296C80ABA6EA5DC7E36A. At first it was a directory
fetch attack, slowing it to a crawl due to upload exceeding 700 Mbps
(while download was never over 50 Mbps). I added "DirCache 0" to torrc
as a stop-gap measure, but after reloading,

I am experiencing the very same attack on two of my relays. At first my upload is 4-8 times upload. When I add DirCache 0, I then get download 2:1 over upload.

Likely repeated directory fetch requests which are being denied once DirCache 0 is specified, hence the massive upload to download before DirCache 0 and the 2:1 download to upload after.

This is a very serious attack, it is clearly through well planned and carefully coded malicious tor instances and does not require repeated connections and thus bypasses firewall connection rate rules.

One relay currently under this attack is $3370227A57DFC88D3CE68AA6B4FC4E13438F0AC7.
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx