[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: If the IPv6 ORPort can't be reached, will clients/relays fall back to the IPv4 ORPort?



Am 21.07.26 um 02:52 schrieb forest-relay-contact--- via tor-relays:
The reason I ask is because I'm considering implications of the toralf
tor-ddos script on relays that use IPv6. By its very design, there are a
number of hosting providers that will provide, say, a routed /48 for a
low cost which could then be used to completely overwhelm the IPv6 anti-
DDoS firewall rules (unlike the IPv4 rules where an attacker would need
to buy a costly new IPv4 just to get an additional 8 connections).

Build an escalation system.
E.g. a single IPv6 will be blocked first, if more come from the same /64, the entire /64 is blocked. If more come from the same allocation (either use /48 or even bigger if you can query the BGP data) to block the entire ISP.



--
Gruß
Marco

Junk-Mail bitte an trashcan@xxxxxxxxxxxxxxxxxxxxxx

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx