ISPs in Mumbai under cyber attack: Police

6pack

ex-Mod
Source: http://www.thehindu.com/news/cities...r-attack-police/article8889478.ece?ref=tpnews

Small and medium Internet Service Providers (ISPs) in the state are under attack on an unprecedented scale, leading to their subscribers being affected, police sources told The Hindu on Friday.

The attack, known as a Distributed Denial Of Service (DDOS), involves facilitating a surge in activity of the target server at a very high speed. In a DDOS attack, a miscreant can programme multiple Internet Protocol (IP) addresses to log on to a server at the same time, causing the server to crash due to the load.

Explaining a DDOS attack, a police officer said, “If a particular server is equipped to handle 100 users at a time, a DDOS attack will create 1,000 log-ins at one time. This can be done by simply pre-programming 1,000 IP addresses to hack into and log on to the server at the specified time.”

Another officer, who is part of the investigation, said, “What makes this attack all the more serious is that the culprits are targeting ISPs who have commercial entities as subscribers. According to our information, this DDOS attack is being carried out at a dizzying speed of 200 gigabytes (GB) per second, and small and medium ISPs who do not have the infrastructure to ward off such attacks are being targeted.”

The Cyber Crime branch of the Maharashtra police received information that the DDOS attack has been on since Monday, after which it began contacting affected parties, asking them to share information on the attack. The police have appealed to affected parties to contact them atig.cbr-mah@gov.inorsp.cbr-mah@gov.in

IGP (Cyber Crime) Brijesh Singh confirmed a DDOS attack had been detected and was being looked into.
 
Oh yeah, we were affected, both office and home. Here is the extract of the email given

Dear Customer,

There is a Ddos attack on us

All the issues have been resolved except surfing speed issues

Speed issues will be resolved soon and our team is working on the issue
on war footing

We are unable to take all calls as there is lot of call flood in our
control room

Please be patient and we assure you that we are working hard to recover
the situation ASAP

So services may hamper till Sunday.

We will update you on the issue once resolved

The list of affected home ISP vendors include 7Star.
 
Our building gets it's internet through our local cable guy who uses Joister as his backend.
The only website that we could access reliably since Wednesday evening was youtube. Everything else was inaccessible till Saturday, including email, whatsapp etc. On Saturday we could access a few Indian websites, and this morning I could access a few foreign ones as well.
Come to think of it, the internet was really iffy at my place since Sunday.

My cable guy mentioned the hacker attack when he called me 20 minutes ago to let me know that we're back online now.
I think it was the worst 5 days of his life. Poor guy went house to house to explain and apologise for the downtime, and to let people know that he was trying to get a backup line.
 
Last edited:
Yeah I felt the same thing, but couldn't get it since our dumb local service provider tele caller knows nothing.
She just said, restart your router/laptop and try again :banghead:

Its good that I saw this thread.
 
People are equating DDoS attack = network hacked. They have no idea what has happened. The best analogy I gave was that during any major issue when the mobile networks jam because everyone is calling at the same time, similarly normally, only a few devices connect to the main routers, now there is a rogue set of computers which is calling the main routers, causing a DDoS.
 
I don't know why hackers would waste their valuable time and resources DDoS'ing Indian ISPs.

The contention ratios on Indian ISPs are so bad, it's like a perpetual and self-inflicted DDoS that lasts all year round.
 
I don't know why hackers would waste their valuable time and resources DDoS'ing Indian ISPs.

The contention ratios on Indian ISPs are so bad, it's like a perpetual and self-inflicted DDoS that lasts all year round.
Yeah, I have a feeling that maybe some one downloaded some virus or malware from some site and that malware must have propagated to local peers somehow through file sharing or an attack. Computers that are almost always online like in cyber cafes or small offices must be the ones doing the DDOS'ing. Normal people at home would just shut off their comps to save electricity when they see no internet access and do something else.
 
200GBps = 1.6Tbps? Try doing that to Airtel na?

Pretty sure that's 200 Gbps. And if they do it to Airtel, initially there will be an issue, but Airtel will be able to shrug off the attack in sometime. The only thing that needs to be done is to inform all edge and upstream routers to discard packets from such IPs.
 
Yeah, I have a feeling that maybe some one downloaded some virus or malware from some site and that malware must have propagated to local peers somehow through file sharing or an attack. Computers that are almost always online like in cyber cafes or small offices must be the ones doing the DDOS'ing. Normal people at home would just shut off their comps to save electricity when they see no internet access and do something else.

Also include servers, IOT devices/cameras/etc which have been rooted/pwned. These are some of the most vital attack tools since they have a static IP, allowing them to be turned into a C&C server, and also having higher bandwidth, send more packets.
 
Even i thought it could be 200Gbps and not Tbps. These ISP's might hardly have some 100-150Gbps so migitation is not at possible. IP Null routing is kinda temporary measure.
Best thing for them looks like cloudflare or for time being, they were successful in handling 300+ Gbps ddos.

Anyone got any theories as to why one would DDOS Mumbai ISP's that too Small and Medium Sized?
 
Even i thought it could be 200Gbps and not Tbps. These ISP's might hardly have some 100-150Gbps so migitation is not at possible. IP Null routing is kinda temporary measure.
Best thing for them looks like cloudflare or for time being, they were successful in handling 300+ Gbps ddos.

Anyone got any theories as to why one would DDOS Mumbai ISP's that too Small and Medium Sized?
ambani and airtel doing it to spoil small player service levels and gain monopoly
 
Even i thought it could be 200Gbps and not Tbps. These ISP's might hardly have some 100-150Gbps so migitation is not at possible. IP Null routing is kinda temporary measure.
Best thing for them looks like cloudflare or for time being, they were successful in handling 300+ Gbps ddos.

Anyone got any theories as to why one would DDOS Mumbai ISP's that too Small and Medium Sized?

I wasnt talking about IP Null routing.

Cloudflare will not do much here probably.

They went after a biggie, which supplies bandwidth to Tier 3/2.5 providers.
 
Some reports say Chinese were behind this, after all the hostility surrounding NSG and expelling of spies/journalist issue, it makes sense to attack India's financial capital in whatever way possible, they have been doing the same to Americans since ages. Mumbai is the Financial heart of India and that is the reason even Pakistanis decided on Mumbai for 26/11 and not some other city.
 
DDoS is very common threat, this is going to happen to ISP's if they are not prepared for such attacks
 
Last edited:
Back
Top