[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
The attack has gotten so bad that even MetricsPort hangs for 10+ seconds
before responding while the attack is ongoing.
On 2026-09-16 15:26, boldsuck via tor-relays wrote:
> DoSStreamCreation* options are useful only for a exit relay.
It appears it is not useful against this attack on exits. I tried it on
an exit of mine that was under attack at the time, even lowering rate to
25 and burst to 50 (down from the default of 100 and 300) but Prometheus
samples still showed zero mitigation events. I continued to get nearly
700 BEGIN_DIR requests per second, but only 2 BEGIN requests per second.
I suppose there is no mitigation which specifically limits BEGIN_DIR? If
that would fix this, it should be a priority to send out a new emergency
update with such a feature.
Regards,
forest
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCarHSOAAKCRAw+TRLM+X4
xij5AP90xJuVVK3bu4Uo4e5lh7rejZXh73BOsdmDYnpFhIsZoAD9FtL9iPHXh5iA
sUUe08dKH9AH63zRpwPcdTD2zdIeMAw=
=ZCFT
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx