Don’t do SECURITY. Do business SECURELY.

Spamhaus hit by one of the largest DDoS attacks yet seen

Anti-spam group Spamhaus weathered a DNS amplification attack reported to peak at around 300Gbps, prompting warnings about open DNS resolvers.

The anti-spam organisation Spamhaus was hit by a distributed denial of service (DDoS) attack described at the time as among the largest ever seen, reported to peak at around 300 gigabits per second. Mitigation firm CloudFlare helped keep Spamhaus online.

What happened

  • The attack began around 18 March 2013 and escalated over the following days, becoming public news on 27 March.
  • Attackers used DNS reflection and amplification, sending spoofed requests to tens of thousands of open DNS resolvers so that large responses flooded the target.
  • The traffic put strain on internet exchange points and upstream networks in Europe.
  • Reports at the time linked the attack to a dispute with a Dutch hosting company that Spamhaus had added to its blocklist.

Why it mattered

The attack showed how badly configured internet infrastructure could be turned into a weapon, and it pushed network operators to close open resolvers and adopt anti-spoofing controls.

Lessons for organisations

Organisations should make sure their own DNS servers and other internet-facing services cannot be abused for amplification, and should have a DDoS response plan agreed with their providers before it is needed.

Source: The Register

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights