[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
On 2026-09-09 23:05, Red Oaive wrote:
> I am experiencing the very same attack on two of my relays. At first
> my upload is 4-8 times upload. When I add DirCache 0, I then get
> download 2:1 over upload.
I tried a little troubleshooting while the attack was occurring, but had
to give up eventually because my SSH connection was so slow and because
I would soon exceed my provider's CPU fair-use-policy (CPU was 100%). I
found that setting "BandwidthRate" does _not_ help reduce CPU usage. The
asymmetric traffic is still there yet CPU usage remains 100%.
The fact that limiting traffic does not reduce CPU usage even though it
does reduce traffic is both interesting and very concerning.
> This is a very serious attack, it is clearly through well planned and
> carefully coded malicious tor instances and does not require repeated
> connections and thus bypasses firewall connection rate rules.
When Tor was in the shutting down state and not accepting new circuits,
the attack immediately became ineffective. I suspect it's involving a
large number of new but short-lived connections rather than several
long-lived connections doing fetches over and over. When trying to find
out which IPs were involved, I had to give up because no IP transferred
over 2 MiB over a 10 second period, even during the attack.
I also use a firewall to limit connection rates, based on toralf's but
with some significant modifications. It's stricter in some ways, as it
will block all IPs from a /24 if more than 8 connections/minute or 32
connections/hour are made, and it disallows more than 20 simultaneous
connections from a single /24 regardless of connection rate. But it's
only measuring new connections as "tcp flags & (syn | ack) == syn" (nft
syntax), so if the attacker is keeping connections established or if
they simply use a larger set of malicious IPs, they'll bypass it. I have
not tried adjusting my firewall's limits to see if it would help.
Can someone find a few IPs that are participating in this attack and
send tcpdump output (with timestamps)? I'm curious if there's a timing
pattern that could be exploited for detection.
> One relay currently under this attack is
> $3370227A57DFC88D3CE68AA6B4FC4E13438F0AC7.
By shutting down Tor and restarting it 15 minutes later, I was able to
get the attack to stop. In another case when I realized it was targeting
another relay of mine, I had to wait over an hour with Tor off before it
stopped. If I restarted Tor any sooner, it would immediately resume. I
don't know if this is because the attack determined that my relay was
down and stopped attempting connections, or if each attack was set to be
run for a predetermined amount of time and that time happened to elapse.
Regards,
forest
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCaqIIhwAKCRAw+TRLM+X4
xq+QAQCJh3IO5eYWGx4+MFx6YmL05hUP3bqZiPmxiTv09IZTWgD+L0Ad55qWZTVX
BklFuz+6PUZkdTMiu77n/uoPTly6bAw=
=x9Y+
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx