[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?



On 2026-09-13 03:26, Red Oaive wrote:

I now have a repeat customer re-attacking a relay I manage in the same way. I'm going to do what I can to trace it before I turn off the DirCache again.

Ok, the attack seems to be distributed, but it looks to have a relatively small number of participating relays. Here are relays that look like they are participating:

74.106.232.4 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/BCFE548EA3FF8A0B3610779C238350124A8ED6DE 107.173.7.218 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/369CC0E726E53B8566F25EEB7A72E4F88A217B9B 45.137.100.160 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/19D0F028BADD11B79DC5846C1D75497672E85511 136.243.175.182 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/2687B8534A40D4E1E56B8D93B9009349EA6BF19A 172.104.234.114 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/5FFB97B399ED07472056EEDF2236EA6F265858CA 213.95.55.63 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/B51FAC83BD8CEE69933D9ECA07CAC6A8FF990754 82.126.182.66 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/1C5E491735E906F2A06DA1AE2D26EC0C0494A771 192.186.127.123 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/658239B07EE89F25A9E9B15EFC2B83769209C91D 109.255.184.38 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/77748F5FDA2A5221234CB2100FF4EE9A557F412C 78.43.117.254 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/175D59B37F65EFEB2B9B6B33E53D4754680BBCF9 172.233.242.114 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/7A76496C257941C7D07699525D35F96D868E92F1 207.180.192.66 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/0BA30A3D11B73F95D1447CC9B35BE5F0681D5A1C 172.232.111.152 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/E678A23F9D3E4B0E0934714E03D417E8F8B49A16

[2600:3c01:e000:3a0::] ??? Cannot find a relay with this address in the consensus but shows up in my list.

Notes:
1) MOST but not all are reporting they are outdated Tor versions.
2) They all self-report as low bandwidth servers and show data graphs with low data flow. However, my relay is at this moment sending multiple megabytes per second to each one, enough to single handedly far exceed their entire reported data flow.
3) Many of them have very similar data graph shapes
4) The above are not all nodes that are participating, but all the ones that are that I have high confidence. There are less than 40 in total that are participating.

Lastly, there are a few nodes that are participating which are odd:
140.78.100.35 http://hctxrvjzfpvmzh2jllqhgvvkoepxb4kfzdjm6h7egcwlumggtktiftid.onion/rs.html#details/F97CF76D9121AC28727C22902681A9B539ABAE99
140.78.100.28, 37, 38

These self report as being part of a large tor research project for looking into onion services and each identifies a URL for the research project:
https://www.digidow.eu/experiments/onion-stats/

The URL looks legitimate but the nodes in question are absolutely showing the exact same characteristic data graph shape, shows a data flow of 80k/s but where they are actually sinking about 1-2MiB/s from my relay as I write this.
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx