Up front, I am not a conspiracy theorist.
New to the list, I run a Tor exit node from my small cable modem connection in Honolulu, as well as for a short time on a few on VPS's to prove to myself that it wasn't "just me."
Over the last several weeks, I have collected substantial evidence indicating that a botnet is degrading the Tor anonymity network in its entirety via a sustained denial of service attack. I believe it is made to blend in with all the other crazy packets that an exit node generates, but it is pretty easy to spot if you just look at the RST's or drops coming off your node, all from a static unused destination port. If you change the IP address of your node, it will take about 90 minutes before they identify your IP and you start getting attacked again. I will submit to you the headers of a few hundred packets, and the full list of perps involved in separate emails because of the size thing. Do a whois lookup on a few of those VPS IP addresses and you will see the country involved.
Here are the last few hundred packet headers showing the two bigger ISP's. Wasn't able to show perp list since first two messages held for the moderator because of the size.
Wondering what other folks are seeing with their relays.
UTC DATE UTC TIME IP SRC-ISP SPT DST DST-ISP DPT Flags 2013-03-28 7:33:38 173.208.95.126 Nobis Technology Group, LLC 2571 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:39 173.208.95.126 Nobis Technology Group, LLC 2571 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:39 74.63.192.36 Limestone Networks 1274 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:39 108.177.168.156 Nobis Technology Group, LLC 3471 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:39 173.208.95.126 Nobis Technology Group, LLC 2571 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:39 23.19.67.28 Nobis Technology Group, LLC 3866 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:40 74.63.192.36 Limestone Networks 1274 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:40 108.177.168.156 Nobis Technology Group, LLC 3471 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:40 74.63.192.36 Limestone Networks 1598 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:40 23.19.67.28 Nobis Technology Group, LLC 3866 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:40 108.177.168.156 Nobis Technology Group, LLC 3471 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:40 74.63.192.36 Limestone Networks 1274 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:41 74.63.192.36 Limestone Networks 1598 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:41 23.19.67.28 Nobis Technology Group, LLC 3866 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:41 74.63.192.36 Limestone Networks 1598 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:44 173.208.44.42 Nobis Technology Group, LLC 1358 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:45 173.208.44.42 Nobis Technology Group, LLC 1358 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:45 64.120.60.121 Nobis Technology Group, LLC 4001 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:45 69.147.233.52 Nobis Technology Group, LLC 2291 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:45 173.208.44.42 Nobis Technology Group, LLC 1358 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:45 64.120.60.121 Nobis Technology Group, LLC 4001 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:46 69.147.233.52 Nobis Technology Group, LLC 2291 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:46 64.120.60.121 Nobis Technology Group, LLC 4001 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:46 69.147.233.52 Nobis Technology Group, LLC 2291 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:47 64.120.60.139 Nobis Technology Group, LLC 2078 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:47 23.19.54.243 Nobis Technology Group, LLC 1281 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:48 64.120.60.139 Nobis Technology Group, LLC 2078 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:48 23.19.54.243 Nobis Technology Group, LLC 1281 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:48 64.120.60.139 Nobis Technology Group, LLC 2078 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:48 23.19.54.243 Nobis Technology Group, LLC 1281 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:48 64.120.60.106 Nobis Technology Group, LLC 3004 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:49 64.120.60.106 Nobis Technology Group, LLC 3004 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:49 64.120.60.106 Nobis Technology Group, LLC 3004 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:50 69.162.117.205 Limestone Networks 1273 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:50 23.19.63.204 Nobis Technology Group, LLC 2769 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:50 69.162.117.205 Limestone Networks 1273 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:51 23.19.63.204 Nobis Technology Group, LLC 2769 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:51 23.19.54.57 Nobis Technology Group, LLC 2633 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:51 69.162.117.205 Limestone Networks 1273 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:51 23.19.63.204 Nobis Technology Group, LLC 2769 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:51 23.19.54.57 Nobis Technology Group, LLC 2633 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:52 23.19.54.57 Nobis Technology Group, LLC 2633 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:53 173.208.95.106 Nobis Technology Group, LLC 2337 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:53 108.62.33.54 Nobis Technology Group, LLC 1322 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:54 23.19.130.121 Nobis Technology Group, LLC 2389 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:54 108.62.33.54 Nobis Technology Group, LLC 1322 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:54 173.208.95.106 Nobis Technology Group, LLC 2337 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:54 23.19.130.121 Nobis Technology Group, LLC 2389 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:54 108.62.33.54 Nobis Technology Group, LLC 1322 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:54 173.234.116.251 Nobis Technology Group, LLC 2873 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:54 173.208.95.106 Nobis Technology Group, LLC 2337 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:55 23.19.130.121 Nobis Technology Group, LLC 2389 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:55 173.234.116.251 Nobis Technology Group, LLC 2873 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:56 173.234.116.251 Nobis Technology Group, LLC 2873 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:56 173.234.145.205 Nobis Technology Group, LLC 2549 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:56 23.19.131.10 Nobis Technology Group, LLC 2273 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:56 69.147.233.52 Nobis Technology Group, LLC 4112 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:57 173.234.145.205 Nobis Technology Group, LLC 2549 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:57 69.147.233.52 Nobis Technology Group, LLC 4112 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:57 23.19.131.10 Nobis Technology Group, LLC 2273 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:57 23.19.63.204 Nobis Technology Group, LLC 4430 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:57 173.234.145.205 Nobis Technology Group, LLC 2549 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:58 23.19.131.10 Nobis Technology Group, LLC 2273 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:58 69.147.233.52 Nobis Technology Group, LLC 4112 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:58 23.19.63.204 Nobis Technology Group, LLC 4430 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:58 23.19.63.204 Nobis Technology Group, LLC 4430 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:59 173.208.57.54 Nobis Technology Group, LLC 3250 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:33:59 173.208.57.54 Nobis Technology Group, LLC 3250 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:00 23.19.130.91 Nobis Technology Group, LLC 2751 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:00 173.208.57.54 Nobis Technology Group, LLC 3250 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:00 23.19.130.91 Nobis Technology Group, LLC 2751 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:01 23.19.131.11 Nobis Technology Group, LLC 1828 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:01 23.19.130.91 Nobis Technology Group, LLC 2751 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:01 23.19.131.11 Nobis Technology Group, LLC 1828 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:02 23.19.131.11 Nobis Technology Group, LLC 1828 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:02 23.19.67.28 Nobis Technology Group, LLC 4607 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:03 23.19.67.28 Nobis Technology Group, LLC 4607 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:03 23.19.130.92 Nobis Technology Group, LLC 1398 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:04 23.19.67.28 Nobis Technology Group, LLC 4607 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:04 23.19.130.92 Nobis Technology Group, LLC 1398 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:04 70.32.43.188 Nobis Technology Group, LLC 3669 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:04 23.19.130.92 Nobis Technology Group, LLC 1398 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:05 70.32.43.188 Nobis Technology Group, LLC 3669 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:05 64.120.60.122 Nobis Technology Group, LLC 4518 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:05 70.32.43.188 Nobis Technology Group, LLC 3669 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:06 173.234.188.204 Nobis Technology Group, LLC 2505 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:06 64.120.60.122 Nobis Technology Group, LLC 4518 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:06 173.208.16.248 Nobis Technology Group, LLC 3296 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:06 173.234.188.204 Nobis Technology Group, LLC 2505 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:06 23.19.131.10 Nobis Technology Group, LLC 4396 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:07 23.19.67.28 Nobis Technology Group, LLC 1378 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:07 173.208.16.248 Nobis Technology Group, LLC 3296 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:07 64.120.60.122 Nobis Technology Group, LLC 4518 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:07 173.234.188.204 Nobis Technology Group, LLC 2505 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:07 23.19.131.10 Nobis Technology Group, LLC 4396 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:07 173.208.16.248 Nobis Technology Group, LLC 3296 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:07 23.19.67.28 Nobis Technology Group, LLC 1378 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:07 23.19.131.10 Nobis Technology Group, LLC 4396 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:08 23.19.67.28 Nobis Technology Group, LLC 1378 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:09 147.255.224.134 Nobis Technology Group, LLC 2361 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:09 147.255.224.134 Nobis Technology Group, LLC 2361 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:10 64.120.60.106 Nobis Technology Group, LLC 1518 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:10 70.32.43.190 Nobis Technology Group, LLC 2963 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:10 147.255.224.134 Nobis Technology Group, LLC 2361 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:10 64.120.60.106 Nobis Technology Group, LLC 1518 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:10 70.32.43.190 Nobis Technology Group, LLC 2963 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:11 64.120.60.106 Nobis Technology Group, LLC 1518 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:11 173.234.145.205 Nobis Technology Group, LLC 3493 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:11 70.32.43.190 Nobis Technology Group, LLC 2963 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:11 173.234.145.206 Nobis Technology Group, LLC 2492 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:11 173.234.145.205 Nobis Technology Group, LLC 3493 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:12 173.234.145.206 Nobis Technology Group, LLC 2492 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:12 173.234.145.205 Nobis Technology Group, LLC 3493 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:12 23.19.50.46 Nobis Technology Group, LLC 2827 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:12 173.234.145.206 Nobis Technology Group, LLC 2492 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:13 23.19.50.46 Nobis Technology Group, LLC 2827 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:13 23.19.50.46 Nobis Technology Group, LLC 2827 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:13 64.120.60.105 Nobis Technology Group, LLC 1194 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:14 64.120.60.105 Nobis Technology Group, LLC 1194 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:14 64.120.60.105 Nobis Technology Group, LLC 1194 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:15 173.234.116.237 Nobis Technology Group, LLC 4363 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:16 173.234.116.237 Nobis Technology Group, LLC 4363 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:16 64.120.60.174 Nobis Technology Group, LLC 2369 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:17 173.234.116.237 Nobis Technology Group, LLC 4363 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:17 64.120.60.174 Nobis Technology Group, LLC 2369 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:17 23.19.131.10 Nobis Technology Group, LLC 2648 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:17 64.120.60.174 Nobis Technology Group, LLC 2369 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:17 23.19.131.10 Nobis Technology Group, LLC 2648 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:18 23.19.131.10 Nobis Technology Group, LLC 2648 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:18 173.234.145.206 Nobis Technology Group, LLC 4154 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:19 23.19.130.121 Nobis Technology Group, LLC 3782 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:19 173.234.145.206 Nobis Technology Group, LLC 4154 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:19 23.19.130.121 Nobis Technology Group, LLC 3782 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:19 64.120.60.122 Nobis Technology Group, LLC 2141 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:19 173.234.145.206 Nobis Technology Group, LLC 4154 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:20 23.19.130.121 Nobis Technology Group, LLC 3782 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:20 64.120.60.122 Nobis Technology Group, LLC 2141 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:21 64.120.60.122 Nobis Technology Group, LLC 2141 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:21 173.208.95.126 Nobis Technology Group, LLC 3208 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:21 173.208.95.126 Nobis Technology Group, LLC 3208 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:21 64.120.60.174 Nobis Technology Group, LLC 3193 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:22 173.208.95.126 Nobis Technology Group, LLC 3208 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:22 64.120.60.174 Nobis Technology Group, LLC 3193 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:22 64.120.60.174 Nobis Technology Group, LLC 3193 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:22 64.120.44.150 Nobis Technology Group, LLC 3211 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:23 64.120.44.150 Nobis Technology Group, LLC 3211 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:23 108.62.33.51 Nobis Technology Group, LLC 3383 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:23 108.62.33.51 Nobis Technology Group, LLC 3383 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:23 64.120.44.150 Nobis Technology Group, LLC 3211 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:24 23.19.50.46 Nobis Technology Group, LLC 4534 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:24 108.62.33.51 Nobis Technology Group, LLC 3383 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:24 23.19.50.46 Nobis Technology Group, LLC 4534 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:25 23.19.130.86 Nobis Technology Group, LLC 3654 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:25 23.19.50.46 Nobis Technology Group, LLC 4534 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:25 23.19.130.86 Nobis Technology Group, LLC 3654 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:25 23.19.130.93 Nobis Technology Group, LLC 2090 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:26 23.19.130.86 Nobis Technology Group, LLC 3654 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:26 23.19.130.93 Nobis Technology Group, LLC 2090 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:26 69.147.233.52 Nobis Technology Group, LLC 4623 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:26 23.19.130.93 Nobis Technology Group, LLC 2090 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:26 64.120.60.121 Nobis Technology Group, LLC 1486 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:27 69.147.233.52 Nobis Technology Group, LLC 4623 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:27 64.120.60.121 Nobis Technology Group, LLC 1486 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:27 69.162.117.206 Limestone Networks 1906 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:27 173.234.116.232 Nobis Technology Group, LLC 4393 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:27 173.208.44.46 Nobis Technology Group, LLC 2169 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:28 69.147.233.52 Nobis Technology Group, LLC 4623 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:28 173.208.95.125 Nobis Technology Group, LLC 1316 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:28 64.120.60.121 Nobis Technology Group, LLC 1486 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:28 69.162.117.206 Limestone Networks 1906 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:28 173.234.116.232 Nobis Technology Group, LLC 4393 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:28 173.208.44.46 Nobis Technology Group, LLC 2169 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:28 108.177.157.70 Nobis Technology Group, LLC 1659 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:28 173.208.95.125 Nobis Technology Group, LLC 1316 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:28 69.162.117.206 Limestone Networks 1906 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:28 173.234.116.232 Nobis Technology Group, LLC 4393 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:29 173.208.95.106 Nobis Technology Group, LLC 1650 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:29 108.177.157.70 Nobis Technology Group, LLC 1659 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:29 173.208.95.125 Nobis Technology Group, LLC 1316 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:29 173.208.44.46 Nobis Technology Group, LLC 2169 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:29 23.19.131.10 Nobis Technology Group, LLC 1104 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:29 23.19.131.10 Nobis Technology Group, LLC 1132 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:29 108.177.157.70 Nobis Technology Group, LLC 1659 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:29 173.208.95.106 Nobis Technology Group, LLC 1650 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:29 23.19.131.10 Nobis Technology Group, LLC 1104 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:29 23.19.67.211 Nobis Technology Group, LLC 1884 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:30 23.19.131.10 Nobis Technology Group, LLC 1132 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:30 23.19.67.214 Nobis Technology Group, LLC 1295 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:30 173.208.95.106 Nobis Technology Group, LLC 1650 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:30 23.19.131.10 Nobis Technology Group, LLC 1104 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:30 23.19.131.10 Nobis Technology Group, LLC 1132 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:30 23.19.67.211 Nobis Technology Group, LLC 1884 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:30 23.19.67.214 Nobis Technology Group, LLC 1295 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:30 64.120.60.118 Nobis Technology Group, LLC 2075 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:31 23.19.67.211 Nobis Technology Group, LLC 1884 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:31 23.19.67.214 Nobis Technology Group, LLC 1295 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:31 64.120.60.120 Nobis Technology Group, LLC 4950 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:31 69.162.119.4 Limestone Networks 2862 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:31 64.120.60.118 Nobis Technology Group, LLC 2075 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:31 64.120.60.120 Nobis Technology Group, LLC 4950 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:31 69.162.119.4 Limestone Networks 2862 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:32 64.120.60.118 Nobis Technology Group, LLC 2075 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:32 147.255.224.134 Nobis Technology Group, LLC 1603 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:32 64.120.60.120 Nobis Technology Group, LLC 4950 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:32 69.162.119.4 Limestone Networks 2862 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:32 147.255.224.134 Nobis Technology Group, LLC 1603 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:33 173.208.44.36 Nobis Technology Group, LLC 3290 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:33 147.255.224.134 Nobis Technology Group, LLC 1603 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:33 64.120.60.118 Nobis Technology Group, LLC 2677 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:33 173.208.44.36 Nobis Technology Group, LLC 3290 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:34 173.208.44.36 Nobis Technology Group, LLC 3290 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:34 64.120.60.118 Nobis Technology Group, LLC 2677 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:34 173.208.16.250 Nobis Technology Group, LLC 1802 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:35 173.208.16.250 Nobis Technology Group, LLC 1802 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:35 64.120.60.118 Nobis Technology Group, LLC 2677 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:35 173.208.16.250 Nobis Technology Group, LLC 1802 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:38 108.177.168.156 Nobis Technology Group, LLC 2832 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:38 108.177.168.156 Nobis Technology Group, LLC 2832 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:38 23.19.130.93 Nobis Technology Group, LLC 4597 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:39 108.177.168.156 Nobis Technology Group, LLC 2832 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:39 23.19.130.93 Nobis Technology Group, LLC 4597 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:39 69.162.117.206 Limestone Networks 3681 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:39 23.19.130.93 Nobis Technology Group, LLC 4597 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:40 69.162.117.206 Limestone Networks 3681 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:40 69.162.117.206 Limestone Networks 3681 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:40 64.120.60.121 Nobis Technology Group, LLC 3356 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:41 64.120.60.121 Nobis Technology Group, LLC 3356 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:42 64.120.60.121 Nobis Technology Group, LLC 3356 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:42 64.120.79.221 Nobis Technology Group, LLC 1410 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:42 108.62.237.205 Nobis Technology Group, LLC 2969 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:42 64.120.79.221 Nobis Technology Group, LLC 1410 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:42 108.62.237.205 Nobis Technology Group, LLC 2969 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:43 64.120.79.221 Nobis Technology Group, LLC 1410 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:43 108.62.42.18 Nobis Technology Group, LLC 2158 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:43 23.19.130.93 Nobis Technology Group, LLC 1789 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:43 108.62.237.205 Nobis Technology Group, LLC 2969 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:43 173.208.44.40 Nobis Technology Group, LLC 1441 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:43 108.62.42.18 Nobis Technology Group, LLC 2158 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:44 173.234.12.178 Nobis Technology Group, LLC 2411 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:44 173.208.44.40 Nobis Technology Group, LLC 1441 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:44 23.19.130.93 Nobis Technology Group, LLC 1789 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:44 108.62.42.18 Nobis Technology Group, LLC 2158 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:44 23.19.130.93 Nobis Technology Group, LLC 1789 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:44 173.208.44.40 Nobis Technology Group, LLC 1441 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:44 173.234.12.178 Nobis Technology Group, LLC 2411 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:45 173.234.12.178 Nobis Technology Group, LLC 2411 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:47 64.120.79.222 Nobis Technology Group, LLC 4601 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:47 69.162.80.59 Limestone Networks 3514 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:48 69.162.80.59 Limestone Networks 3514 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:48 64.120.79.222 Nobis Technology Group, LLC 4601 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:48 173.234.145.205 Nobis Technology Group, LLC 4688 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:48 64.120.79.222 Nobis Technology Group, LLC 4601 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:48 69.162.80.59 Limestone Networks 3514 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:48 173.208.44.46 Nobis Technology Group, LLC 4835 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:49 173.234.145.205 Nobis Technology Group, LLC 4688 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:49 173.208.44.46 Nobis Technology Group, LLC 4835 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:49 74.63.192.36 Limestone Networks 1339 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:49 173.234.145.205 Nobis Technology Group, LLC 4688 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:49 64.120.60.146 Nobis Technology Group, LLC 3668 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:50 173.208.44.46 Nobis Technology Group, LLC 4835 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:50 74.63.192.36 Limestone Networks 1339 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:50 23.19.131.11 Nobis Technology Group, LLC 3868 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:50 64.120.60.146 Nobis Technology Group, LLC 3668 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:50 74.63.192.36 Limestone Networks 1339 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:50 70.32.43.189 Nobis Technology Group, LLC 4246 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:50 23.19.131.11 Nobis Technology Group, LLC 3868 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:50 64.120.60.146 Nobis Technology Group, LLC 3668 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:51 23.19.131.11 Nobis Technology Group, LLC 3868 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:51 70.32.43.189 Nobis Technology Group, LLC 4246 66.8.214.196 Road Runner 8118 [S], 2013-03-28 7:34:51 64.120.60.139 Nobis Technology Group, LLC 1105 66.8.214.196 Road Runner 8118 [S],
On 28.03.2013 11:13, Kent Backman wrote:
Over the last several weeks, I have collected substantial evidence indicating that a botnet is degrading the Tor anonymity network in its entirety via a sustained denial of service attack.
I don't have much time right at the moment (sorry), and I don't outright reject your observations. Maybe you are interested in our exit relay statistics (cpu/memory/etc). We have US exits as well (axigy1/axigy2). If there was something out of the ordinary happening to these servers, I am sure the ISP would have told me (we are in daily contact via Instant Messenger).
https://www.torservers.net/munin/
How do you know if it's a DDOS attack rather than normal traffic?
On Thu, Mar 28, 2013 at 11:42 AM, Moritz Bartl moritz@torservers.netwrote:
On 28.03.2013 11:13, Kent Backman wrote:
Over the last several weeks, I have collected substantial evidence indicating that a botnet is degrading the Tor anonymity network in its entirety via a sustained denial of service attack.
I don't have much time right at the moment (sorry), and I don't outright reject your observations. Maybe you are interested in our exit relay statistics (cpu/memory/etc). We have US exits as well (axigy1/axigy2). If there was something out of the ordinary happening to these servers, I am sure the ISP would have told me (we are in daily contact via Instant Messenger).
https://www.torservers.net/munin/
-- Moritz Bartl https://www.torservers.net/ _______________________________________________ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
New to the list, I run a Tor exit node from my small cable modem connection in Honolulu, as well as for a short time on a few on VPS's to prove to
Over the last several weeks, I have collected substantial evidence indicating that a botnet is degrading the Tor anonymity network in its entirety via a sustained denial of service attack. I believe it is made to blend in with all the other crazy packets that an exit node generates, but it is pretty easy to spot if you just look at the RST's or drops coming off your node, all from a static unused destination port. If you change the IP address of your node, it will take about 90 minutes before they identify your IP and you start getting attacked again. Do a whois lookup on a few of those VPS IP addresses and you will see the country involved.
Wondering what other folks are seeing with their relays.
UTC DATE UTC TIME IP SRC-ISP SPT DST DST-ISP DPT Flags 2013-03-28 7:33:38 173.208.95.126 Nobis Technology Group, LLC 2571 66.8.214.196 Road Runner 8118 [S]
I believe 8118 is polipo/privoxy gateway and that you are simple seeing usual internet 'bot' scans for that proxy and box is returning normal closed reset to syns.
You may collate this flow data by ip and report the unwanted traffic to the arin netblock and ptr domain contacts. Or ignore it as waste of time if packet rate is acceptable loss to internet noise.
On 28/03/13 17:21, grarpamp wrote:
New to the list, I run a Tor exit node from my small cable modem connection in Honolulu, as well as for a short time on a few on VPS's to prove to Over the last several weeks, I have collected substantial evidence indicating that a botnet is degrading the Tor anonymity network in its entirety via a sustained denial of service attack. I believe it is made to blend in with all the other crazy packets that an exit node generates, but it is pretty easy to spot if you just look at the RST's or drops coming off your node, all from a static unused destination port. If you change the IP address of your node, it will take about 90 minutes before they identify your IP and you start getting attacked again. Do a whois lookup on a few of those VPS IP addresses and you will see the country involved. Wondering what other folks are seeing with their relays. UTC DATE UTC TIME IP SRC-ISP SPT DST DST-ISP DPT Flags 2013-03-28 7:33:38 173.208.95.126 Nobis Technology Group, LLC 2571 66.8.214.196 Road Runner 8118 [S]
I believe 8118 is polipo/privoxy gateway and that you are simple seeing usual internet 'bot' scans for that proxy and box is returning normal closed reset to syns.
You may collate this flow data by ip and report the unwanted traffic to the arin netblock and ptr domain contacts. Or ignore it as waste of time if packet rate is acceptable loss to internet noise. _______________________________________________ tor-relays mailing list tor-relays@lists.torproject.org https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
There is definitely a large number of hits on the privoxy port that does seem to correlate with being in a published directory. That said lots of tor users also use privoxy so it makes sense that those looking for open proxies may well be prioritizing tor relay IP addresses for scanning attempting to find poorly configured privoxy instances that can be used for arbitrary connections. Scanning of tor nodes also seems to be higher than background in general especially at higher bandwidth levels but this is frequently the case for any kind of server or other node that stands out as clearly controlling larger amounts of bandwidth because they are naturally more valuable targets for a variety of criminal activities (DDoS, Spamming etc).
That said while the ports vary I believe that a large amount of the high port activity is in fact probably related to such as bittorrent, namely users attempting to use BT over tor, client detecting the exit's IP as it's public IP and reporting that to the tracker resulting in large numbers of machines attempting to make TCP connections with the system, usually significant UDP traffic also.
In general I'd say that getting a large amount of hits on your firewall is pretty much expected as a result of this. For a DDoS by far a more effective tactic would be to hit an open port and all relays are advertising at least one of these so I do not believe this is a DDoS there are much more effective methods to perform a DDoS attack on the network including several that are not merely more effective due to amplification but also would be a lot more subtle because they would blend into the normal traffic better using standard protocols and features available on the network, need I mention DNS for example.
tor-relays@lists.torproject.org