[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-relays] Re: reply to: 5 to 10 times more outgoing than incoming traffic
- To: tor-relays@xxxxxxxxxxxxxxxxxxxx
- Subject: [tor-relays] Re: reply to: 5 to 10 times more outgoing than incoming traffic
- From: Chappie via tor-relays <tor-relays@xxxxxxxxxxxxxxxxxxxx>
- Date: Sat, 01 Aug 2026 11:22:44 -0000
- Cc: Chappie <chappie7@xxxxxxxxxx>
- In-reply-to: <178545948314.550551.271259759469076616@lists-01.torproject.org>
- List-id: "support and questions about running Tor relays (exit, non-exit, bridge)" <tor-relays.lists.torproject.org>
- References: <178545948314.550551.271259759469076616@lists-01.torproject.org>
- Reply-to: "support and questions about running Tor relays (exit, non-exit, bridge)" <tor-relays@xxxxxxxxxxxxxxxxxxxx>
- User-agent: HyperKitty on https://lists.torproject.org/
A simple mitigation I used while my relay was under attack was the following. After noticing the unusual traffic, I enabled the option shown in [1] and then reloaded the affected Tor instance using the command in [2]. I left the instance in this state for approximately five minutes.
Immediately after the reload, the abnormal traffic stopped. I then commented out the option shown in [1] in the torrc configuration file and reloaded the instance once again using the command in [2]. In this way, the attack was effectively interrupted.
During this short interval of approximately ten minutes, my relay did not lose any of its flags. It appears that the attack tool was unable to determine that it should resume targeting the relay after the temporary interruption.
[1]
DirCache 0
[2]
systemctl reload tor@relay2.service
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx