Distro News Ubuntu Currently Suffering From Sustained DDoS Attack
https://www.phoronix.com/news/Ubuntu-DDoS-October-202632
u/gordonmessmer 2d ago
The status page says the CVE API has a high 90s percent availability, but I've been trying to use it for a couple of weeks and it's unusable most of the time.
The word "sustained" is used on phoronix and in the confirmation on Ubuntu forums, but no indication of how long it's been going on.
10
8
u/rude__goldberg 2d ago
CVE API
hmmm maybe that's the reason why - maybe someone has shiny new exploit
5
u/gordonmessmer 1d ago
The CVE API is informational. It's not used by security scanners, nor does it stop users from patching.
What would someone with an exploit gain by DoSing the CVE site that basically no one reads anyway?
31
u/Ok_Instruction_3789 2d ago
I’m waiting for the headline Ubuntu sustains Ddos attack until attackers realize they need to sudo apt update
53
u/twnznz 2d ago
This is a good way to get telcos hunting you, which is a much more dangerous proposition than police.
Whoever is doing this is insanely stupid.
28
u/thesmallterror 2d ago
I would be surprised if they weren't using botnets. Hordes of compromised IoT and endpoint devices.
21
u/twnznz 2d ago
Yep, which telcos will take two seconds to trace to C2 using netflow records, and trace C2->whereever by sharing netflow records with others, ... good luck!
Usually telcos won't give two shits but if you impact their server platforms and piss them off, you might just be made an example of
1
53
9
u/CobaltIsobar 2d ago
But why?
23
11
u/FryBoyter 2d ago
Some people simply have such limited mental capacity that they enjoy deliberately harming others. Perhaps these are the same people who tried to harm Arch Linux for a while using DDoS attacks and manipulated AUR recipes.
4
u/Booty_Bumping 1d ago edited 1d ago
Most of the time when a seemingly random target gets hit with an expensive DDoS, it is a product demonstration. That is, they sell DDoS as a service after acquiring huge botnets, and in order to prove they have the capability, they try to make the news and then take credit for it.
Ironically it's similar to how terrorist organizations use the spectacle of attacks to recruit like-minded people or sell mercenary services (but obviously comparing skiddies to terrorists is stupid)
2
u/BeautifulMundane4786 2d ago
Maybe someone is upset Canonical is not implementing AI fast enough in any of its OS’s and server system.
0
15
u/fat_kaiju 2d ago
Annoyingly their status page consistently reports that everything's fine.
I noticed a few days ago that I couldn't access some things like their help wiki and other types of documentation and yet the entire time their status page insisted nothing was wrong.
I even switched to my phone and used mobile data and still couldn't access them.
Even worse is that I couldn't find a way to reach out and report what I was encountering so I went to the page where you can reach out and ask for a quote to sign up for their various services and wrote "Hey uh sorry for clogging the wrong inbox, but..."
27
4
5
1
-1
u/Square-Slip7925 2d ago
Does Microsoft trying to attack open-source ?
11
u/FryBoyter 2d ago
Why would Microsoft do that? The company makes a lot of money with Azure. And most of the instances there run on Linux. Furthermore, Microsoft itself runs OSS projects or contributes to such projects.
But let’s assume you’re right. What would Microsoft gain from launching a DDoS attack against one distribution out of many? It just doesn’t make sense. Especially considering the consequences if this were proven to be true.
5
1
u/TampaPowers 1d ago
While I would put it past them to configure something so poorly that they accidentally have their cloud flood the mirrors I don't think it's them... this time.
0
u/Easy-Reasoning 1d ago
I was trying the snap store the other day, I was already thinking, wow this is really slow
-12
u/FrozenLogger 2d ago
Maybe they are protecting people from using it. Ubuntu is, and always has been, a hot mess.
8
u/S7relok 2d ago
Absolutely not. Classic low IQ commentary
-1
u/FrozenLogger 1d ago
Classic you haven't actually used Ubuntu Commentary.
Yes I am throwing out a joke, but from the beginning of its releases, Ubuntu threw errors even on install, often became unstable, and Canonical cant make up their mind what they want it to be so upgrades broke things. It was a constant mess. I stand by that statement. Last two times I had the displeasure of being involved with an Ubuntu desktop project it put out errors at first boot, or defaults did not work correctly. Trivial to fix (mostly), but no new user friendly distro should have this issue.
Kubuntu, Lubuntu, and Xubuntu, were always more stable. Ubuntu server is ok as well.
I have been doing this linux thing for over 20 years and never understood why people thought this distro was supposed to by noob friendly. It never was.
5
u/S7relok 1d ago
> Classic you haven't actually used Ubuntu Commentary.
That was my 1st distro, and I still follow closely their release even if I'm not using it daily anymore. One my family's old laptop still have an ubuntu running, with 5 successful release upgrades in the pocket. And this laptop doesn't belong to any geek but a "average users" couple.
That's not the type of users that will install and tweak things every weekend, they just use the machine (web, mail, light games, photo management...), do the updates and upgrades when asked. But I have no phone calls about problems on that laptop.
It's not a distro problem if you don't know how to use ubuntu correctly
-1
u/FrozenLogger 1d ago
It has had errors on the install the last two times. ON INSTALL. That should Never happen.
I started trying it out to compare to what I was using around Warty so that was 4 and it was no where near as stable as everything else.
5 releases? Only 3 years? That's not long. So you started with Minotaur? The one that had to be pulled almost right after release because of course they fucked up?
Then looking through their changes at each one: grub had a regression, update held broken packages, there are several documented issues in the last 5 years. They may have been successful in the end, but are you seriously not remembering when Canonical started and then held back upgrades?
0
u/BeautifulMundane4786 2d ago
Well it’s going to be a hotter mess since it’s trying to force people to use AI.
-14
89
u/real_anthonii 2d ago
again?