Skip to content

OVHcloud handled a 40 Gbps attack on a $7 plan — impressed

Reviews by danfra 1 replies 161 views
13 #1

40 Gbps volumetric, mixed UDP reflection and TCP SYN flood. Target was a €7 KVM in OVHcloud's Vint Hill zone.

Timeline:

  • T+0: traffic spike detected by their edge
  • T+12s: automatic nullroute lifted, traffic diverted to scrubbing
  • T+45s: clean traffic back on GRE tunnel to my VPS
  • T+3min: attack peaked at 39.7 Gbps, held for 8 minutes
  • T+11min: attacker gave up

Filtering layers: 1) Anycast sinkhole for >30 Gbps, 2) XDP-based SYN cookie validation, 3) rate limit per /24. No false positives on my end. SSH stayed up, HTTP latency went from 18ms to 34ms during peak.

For context, my last provider nullrouted me for 4 hours on a 12 Gbps attack. This is the first time I've seen sub-minute mitigation on a budget plan without paying for a separate DDoS IP.

mitigated 800Gbps before breakfast
#2

To be honest, we got lucky the attack was so dumb.

What fired:

  • Edge trigger: 5 Gbps over baseline, anycast withdraw to scrubbing POPs
  • XDP layer dropped 94% of SYNs without hitting conntrack
  • UDP reflection: source port validation + payload length heuristics
  • Remaining 6% passed to userspace filter, then GRE back to hypervisor

Specs on that $7 plan:

  • 1 vCPU (E5-2680v4, fair share)
  • 1 GB RAM
  • 20 GB NVMe (rdma disabled, ~800 MB/s seq)
  • 1 IPv4 + /64 IPv6
  • 1 Gbps port, 2 TB monthly
  • DDoS: included, no separate "protected IP" upsell

The GRE tunnel adds ~0.3 ms. As said, we don't do scrubbing in Amsterdam itself. Traffic goes to Frankfurt or London depending on RTT. During this event Frankfurt took 78% of the dirty pipe.

Dry fact: that attack cost us roughly 11 EUR in transit overage. We ate it.

https://www.ovhcloud.com/en/vps/

Containers before it was cool

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft