GitHub hit with the largest DDoS attack ever seen (2024)

Video: Security - what's next for ransomware

See also

Ransomware: An executive guide to one of the biggest menaces on the web Everything you need to know about ransomware: how it started, why it's booming, how to protect against it, and what to do if your PC is infected. Read now

GitHub has revealed it was hit with what may be the largest-ever distributed denial of service (DDoS) attack.

The first portion of the attack against the developer platform peaked at 1.35Tbps, and there was a second 400Gbps spike later. This would make it the biggest DDoS attack recorded so far. Until now, the biggest clocked in at around 1.1Tbps.

In a post on its engineering blog, the developer platform said that, on Feb. 28, GitHub.com was unavailable from 17:21 to 17:26 UTC and intermittently unavailable from 17:26 to 17:30 UTC due to the DDoS attack.

Github said that at no point "was the confidentiality or integrity of your data at risk."

SEE: Special report: Cybersecurity in an IoT and mobile world (free PDF)

"Between 17:21 and 17:30 UTC on February 28th we identified and mitigated a significant volumetric DDoS attack. The attack originated from over a thousand different autonomous systems across tens of thousands of unique endpoints. It was an amplification attack using the memcached-based approach described above that peaked at 1.35Tbps via 126.9 million packets per second," GitHub said.

GitHub hit with the largest DDoS attack ever seen (2)

The DDoS attack featured an unusual way of amplifying its power, relying on UDP-based memcached traffic.

Memcached is a tool meant to cache data and reduce strain on heavier data stores, like disk or databases. It is only intended to be used on systems that are not exposed to the internet, as there is no authentication required. However, there are currently more than 50,000 known vulnerable systems, according to Akamai.

When a system receives a memcached get request, it forms a response by collecting the requested values from memory and then sending them back in an uninterrupted stream.

must read

Cyberwar: A guide to the frightening future of online conflict Every device had become a battleground. Here's everything you need to know. Read now

However, DDoS attackers have now realised they can use this protocol to launch attacks. First, the attacker implants a large payload on an exposed memcached server. Then, the attacker spoofs the "get" request message with a target's source IP, and thus, a short request to the exposed server can result in a pile of traffic arriving at the victim.

"15 bytes of request can trigger a 134KB of response sent to the unfortunate target. This is amplification factor of 10,000x! In practice we've seen a 15 byte request result in a 750kB response (that's a 51,200x amplification)," said Cloudflare in a post explaining the potential threat.

GitHub explained how such an attack could generate vast amounts of traffic: "Spoofing of IP addresses allows memcached's responses to be targeted against another address, like ones used to serve GitHub.com, and send more data toward the target than needs to be sent by the unspoofed source. The vulnerability via misconfiguration described in the post is somewhat unique amongst that class of attacks because the amplification factor is up to 51,000, meaning that for each byte sent by the attacker, up to 51KB is sent toward the target," it said.

GitHub said that, because of the scale of the attack, it decided to move traffic to Akamai, which could help provide additional edge network capacity. It said it is now investigating the use of its monitoring infrastructure to automate enabling DDoS mitigation providers and will continue to measure its response times to incidents like this -- with a goal of reducing mean time to recovery.

Akamai said: "Because of its ability to create such massive attacks, it is likely that attackers will adopt memcached reflection as a favorite tool rapidly. Additionally, as lists of usable reflectors are compiled by attackers, this attack method's impact has the potential to grow significantly."

Read more on security

  • What is malware? Everything you need to know about viruses, trojans and malicious software
  • Hit by ransomware? This new free decryption tool for GandCrab might help
  • Sophisticated Android malware spies on smartphones users and runs up their phone bill too
  • Ransomware: Get ready for the next wave of destructive cyberattacks
  • How to protect Macs from malware threats (TechRepublic)
GitHub hit with the largest DDoS attack ever seen (2024)

FAQs

GitHub hit with the largest DDoS attack ever seen? ›

One of the largest verifiable DDoS attacks on record targeted GitHub, a popular online code management service used by millions of developers. This attack reached 1.3 Tbps, sending packets at a rate of 126.9 million per second. The GitHub attack was a memcached DDoS attack, so there were no botnets involved.

What was the largest DDoS attack of all time? ›

In August, Google Cloud intercepted what is now known as the largest DDoS attack in history. Google noted in the announcement, “for a sense of scale, this two minute attack generated more requests than the total number of article views reported by Wikipedia during the entire month of September 2023.”

Did Google block the largest Web DDoS attack? ›

In a blog post outlining its work, Google says the blocked attack was 7.5 times larger than the largest-ever recorded DDoS incident. This latest record-setter peaked at 398 million requests per second (rps), up from 46 million rps which was the previous record, established last year.

How did GitHub recover from the DDoS attack? ›

Within 10 minutes it had automatically called for help from its DDoS mitigation service, Akamai Prolexic. Prolexic took over as an intermediary, routing all the traffic coming into and out of GitHub, and sent the data through its scrubbing centers to weed out and block malicious packets.

Is DDoS illegal? ›

How illegal is a DDos attack? Yes, a DDoS attack is a crime in most countries. In the U.S., for example, they can be prosecuted under the Computer Fraud and Abuse Act of 1986, and in the UK under the Computer Misuse Act 1990.

What is the biggest DDoS GitHub? ›

One of the largest verifiable DDoS attacks on record targeted GitHub, a popular online code management service used by millions of developers. This attack reached 1.3 Tbps, sending packets at a rate of 126.9 million per second. The GitHub attack was a memcached DDoS attack, so there were no botnets involved.

What is the biggest DDoS attack in 2024? ›

The attack commenced at 8:05 UTC on 15 July 2024, and was unusual for both the length of the assault and the sophistication of the methods used. The attack utilised a globally distributed botnet, targeting over 278 IP addresses simultaneously, indicating a highly sophisticated aggressor with substantial resources.

Has GitHub ever had a data breach? ›

In March 2024, GitHub experienced a security breach involving unauthorized access to code repositories. This incident potentially compromised sensitive information within the repositories and highlighted the ongoing threats facing online platforms.

When was the GitHub attack? ›

On Feb. 28, 2018, GitHub, a platform for software developers, was hit with a DDoS attack that clocked in at 1.35 terabits per second and lasted for roughly 20 minutes. According to GitHub, the traffic was traced back to “over a thousand different autonomous systems (ASNs) across tens of thousands of unique endpoints.”

Do DDoS attacks still work? ›

Hundreds of thousands of unnamed, undocumented, yet successful DDoS attacks continue daily. In fact, it is these attacks that are the most effective and costly.

Can a VPN stop DDoS? ›

VPN companies could have poorly implemented DDoS protection, and attackers might already have your IP address, in which case there's not much a VPN can do. However, when used correctly and set up in advance of an attack, VPNs are one of the best tactics to prevent DDoS attacks.

Can someone DDoS my WIFI? ›

Yes, someone can DDoS you with just your IP address. With your IP address, a hacker can overwhelm your device with fraudulent traffic causing your device to disconnect from the internet and even shut down completely.

Can I sue someone for DDoS? ›

Due to a subsequent DDoS attack, a time-sensitive transaction of a client of the brokerage could not be executed, and the client suffers losses. The wronged client may file a civil suit against the negligent vendor, the brokerage for failing to prevent the attack, as well as the attacker.

What is the oldest DDoS attack? ›

A Brief History of DDoS Attacks

The first known distributed denial of service attack occurred in 1996 when Panix, now one of the oldest internet service providers, was knocked offline for several days by a SYN flood, a technique that has become a classic DDoS attack.

What is the max sentence for a DDoS attack? ›

The use of booter services and stressers also violates this act. If you're found guilty of causing intentional harm to a computer or server in a DDoS attack, you could be charged with a prison sentence of up to 10 years.

What is the most expensive DDoS attack? ›

Mafiaboy Attack (2000): $1 Billion

A DDoS attack was launched in 2000 against well-known websites like Amazon, CNN, eBay, Yahoo!, and Dell by 15-year-old Michael Calce, alias Mafiaboy.

What is the ping of death? ›

The ping of death is a form of denial-of-service (DoS) attack that occurs when an attacker crashes, destabilizes, or freezes computers or services by targeting them with oversized data packets. This form of DoS attack typically targets and exploits legacy weaknesses that organizations may have patched.

Top Articles
185 Really Good Truth or Dare Questions (Fun, Funny, Embarrassing)
Great Truth or Dare Questions, Even Better Dares
Benchmark Physical Therapy Jobs
Moonrise Tonight Near Me
Ssm Health Workday App
Diego Balleza Lpsg
Https Paperlesspay Talx Com Boydgaming
Peralta's Mexican Restaurant Grand Saline Menu
Site : Storagealamogordo.com Easy Call
Python Regex Space
Creepshot. Org
Best Taq 56 Loadout Mw2 Ranked
Halo AU/Crossover Recommendations & Ideas Thread
Grand Rapids Herald-Review Obituaries
Real Estate Transfers Erie Pa
Einfaches Spiel programmieren: Schritt-für-Schritt Anleitung für Scratch
Wmlink/Sspr
Sunday Td Bank
Buncensored Leak
Craigslist Quad Cities
Tamilyogi. Vip
Stellaris Wargoal
Autotrader Ford Ranger
Prey For The Devil Showtimes Near Amc Ford City 14
Craigslist Scranton Pennsylvania
Frederik Zuiderveen Borgesius on LinkedIn: Amazingly quick work by Arnoud💻 Engelfriet! Can’t wait to dive in.
Boys golf: Back-nine surge clinches Ottumwa Invite title for DC-G
Kentuky Fried Chicken Near Me
Guide:How to make WvW Legendary Armor
Slmd Skincare Appointment
Craigslist Caldwell Id
Horned Stone Skull Cozy Grove
Panty Note Manga Online
Clash of Clans: Best Hero Equipment For The Archer Queen, Ranked
I-80 New Jersey Traffic and Road Conditions
How to Learn Brazilian Jiu‐Jitsu: 16 Tips for Beginners
Barber Gym Quantico Hours
Courtney Callaway Matthew Boynton
How To Get Coins In Path Of Titans
$200K In Rupees
The "Minus Sign (−)" Symbol in Mathematics
Magma Lozenge Location
Brian Lizer Life Below Zero Next Generation
Matrizen | Maths2Mind
What is IXL and How Does it Work?
Faze Teeqo Wiki
How to Survive (and Succeed!) in a Fast-Paced Environment | Exec Learn
Gowilkes For Rent
Thoren Bradley Lpsg
Us 25 Yard Sale Map
168 Bus Schedule Pdf 2022
'Selling Sunset' star Alanna Gold said she owned a California desert town. Now, she says she doesn't.
Latest Posts
Article information

Author: Barbera Armstrong

Last Updated:

Views: 6053

Rating: 4.9 / 5 (59 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Barbera Armstrong

Birthday: 1992-09-12

Address: Suite 993 99852 Daugherty Causeway, Ritchiehaven, VT 49630

Phone: +5026838435397

Job: National Engineer

Hobby: Listening to music, Board games, Photography, Ice skating, LARPing, Kite flying, Rugby

Introduction: My name is Barbera Armstrong, I am a lovely, delightful, cooperative, funny, enchanting, vivacious, tender person who loves writing and wants to share my knowledge and understanding with you.