Naive question: services that can be used for amplification attacks, are they constantly getting patched to prevent the latest iteration of attack type?
In other words, if there are a bunch of services prone to amplification attacks, can traffic from these services be upstream-blackholed for the duration of the attack?
If it's not traffic coming directly from an IoT botnet, which is probably where the source of the spoofed traffic that initiates the amplification, then isn't there likely a smaller, more manageable number of services responsible for the attack traffic?
Or are we talking services that form the substrate of the internet that have inherently exploitable protocols that it would take a large herd of organized cats in order to update in a way that doesn't break the internet, and will still take ~10 years?
I still think in IPv4, so this may be a stupid question, but it's it known how many unique IP addresses were attempting to connect in the space of that time, and then it's there logging to identify those with unusually large amounts of individual traffic?
"We found three concrete gaps during this incident, and we would rather be upfront about them than gloss over them." claudism?
> There was no unauthorised access and no compromised systems. This was an overload attack, not an intrusion.
"AI said it's all good. There are no attackers within our walls."
8. 80.239.216.210. 0.0% 78 123.2 64.6 42.9 141.8 30.6
9. vl202.zur-itx1-dist-1.cdn77.com. 0.0% 78 60.1 58.8 43.7 136.5 24.2
10. 89-187-165-194.bunnyinfra.net. 0.0% 78 45.9 63.5 41.8 131.9 31.0
so cdn77.com and bunny.net[dead]
[flagged]
> Use a CNAME or ALIAS record instead of an A record. An A record ties your domain to one specific IP address on our platform.
I don't understand how this helps. CNAMES have TTLs like A records and they eventually have to terminate at an A record somewhere so why have the extra hop?