[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?
On 2026-09-13 03:26, Red Oaive wrote:
I now have a repeat customer re-attacking a relay I manage in the same
way. I'm going to do what I can to trace it before I turn off the
DirCache again.
Ok, the attack seems to be distributed, but it looks to have a
relatively small number of participating relays. Here are relays that
look like they are participating:
74.106.232.4
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/BCFE548EA3FF8A0B3610779C238350124A8ED6DE
107.173.7.218
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/369CC0E726E53B8566F25EEB7A72E4F88A217B9B
45.137.100.160
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/19D0F028BADD11B79DC5846C1D75497672E85511
136.243.175.182
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/2687B8534A40D4E1E56B8D93B9009349EA6BF19A
172.104.234.114
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/5FFB97B399ED07472056EEDF2236EA6F265858CA
213.95.55.63
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/B51FAC83BD8CEE69933D9ECA07CAC6A8FF990754
82.126.182.66
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/1C5E491735E906F2A06DA1AE2D26EC0C0494A771
192.186.127.123
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/658239B07EE89F25A9E9B15EFC2B83769209C91D
109.255.184.38
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/77748F5FDA2A5221234CB2100FF4EE9A557F412C
78.43.117.254
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/175D59B37F65EFEB2B9B6B33E53D4754680BBCF9
172.233.242.114
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/7A76496C257941C7D07699525D35F96D868E92F1
207.180.192.66
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/0BA30A3D11B73F95D1447CC9B35BE5F0681D5A1C
172.232.111.152
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/E678A23F9D3E4B0E0934714E03D417E8F8B49A16
[2600:3c01:e000:3a0::] ??? Cannot find a relay with this address in the
consensus but shows up in my list.
Notes:
1) MOST but not all are reporting they are outdated Tor versions.
2) They all self-report as low bandwidth servers and show data graphs
with low data flow. However, my relay is at this moment sending
multiple megabytes per second to each one, enough to single handedly far
exceed their entire reported data flow.
3) Many of them have very similar data graph shapes
4) The above are not all nodes that are participating, but all the ones
that are that I have high confidence. There are less than 40 in total
that are participating.
Lastly, there are a few nodes that are participating which are odd:
140.78.100.35
http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/F97CF76D9121AC28727C22902681A9B539ABAE99
140.78.100.28, 37, 38
These self report as being part of a large tor research project for
looking into onion services and each identifies a URL for the research
project:
https://www.digidow.eu/experiments/onion-stats/
The URL looks legitimate but the nodes in question are absolutely
showing the exact same characteristic data graph shape, shows a data
flow of 80k/s but where they are actually sinking about 1-2MiB/s from my
relay as I write this.
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx