[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 2026-09-14 08:58, Georg Koppen via tor-relays wrote:
> By participating you mean the relays are doing some attack here? How
> do you know that not some custom Tor clients are using those relays to
> fetch directory information from your relay?

That's what I suspected as well, given how different the "participating"
relays are. The real issue is that relays are vulnerable to whatever is
occurring. Already one of my VPSes got suspended due to FUP violations.

> And you are sure as well that it's directory requests they are sending
> and your relay responds to instead of non-directory related traffic?

The behavior of the attack changes when directory caching is disabled,
with the attack suddenly causing an ingress flood rather than an egress
flood, and CPU usage, while high, isn't pegged at 100% anymore.

I plan to deploy a metrics-collecting script across my fleet (with some
privacy safeguards to ensure the VPS never stores more than a couple of
minutes worth of metrics unencrypted). Hopefully that will give me more
information if it's running while an attack is occurring.

Regards,
forest
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCaqe/DwAKCRAw+TRLM+X4
xg9kAQD8jkRnH6rp9dbQo+SKnUyuPA7rXsJ7lQnnv3MO10FgLAD/bidKC4uTpuAx
icGPffC0jroRMlSo+t6e8Yh4pPALpQ0=
=zEEv
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx