-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 2026-09-09 23:05, Red Oaive wrote:
I am experiencing the very same attack on two of my relays. At first my upload is 4-8 times upload. When I add DirCache 0, I then get download 2:1 over upload.
I tried a little troubleshooting while the attack was occurring, but had to give up eventually because my SSH connection was so slow and because I would soon exceed my provider's CPU fair-use-policy (CPU was 100%). I found that setting "BandwidthRate" does _not_ help reduce CPU usage. The asymmetric traffic is still there yet CPU usage remains 100%. The fact that limiting traffic does not reduce CPU usage even though it does reduce traffic is both interesting and very concerning.
This is a very serious attack, it is clearly through well planned and carefully coded malicious tor instances and does not require repeated connections and thus bypasses firewall connection rate rules.
When Tor was in the shutting down state and not accepting new circuits, the attack immediately became ineffective. I suspect it's involving a large number of new but short-lived connections rather than several long-lived connections doing fetches over and over. When trying to find out which IPs were involved, I had to give up because no IP transferred over 2 MiB over a 10 second period, even during the attack. I also use a firewall to limit connection rates, based on toralf's but with some significant modifications. It's stricter in some ways, as it will block all IPs from a /24 if more than 8 connections/minute or 32 connections/hour are made, and it disallows more than 20 simultaneous connections from a single /24 regardless of connection rate. But it's only measuring new connections as "tcp flags & (syn | ack) == syn" (nft syntax), so if the attacker is keeping connections established or if they simply use a larger set of malicious IPs, they'll bypass it. I have not tried adjusting my firewall's limits to see if it would help. Can someone find a few IPs that are participating in this attack and send tcpdump output (with timestamps)? I'm curious if there's a timing pattern that could be exploited for detection.
One relay currently under this attack is $3370227A57DFC88D3CE68AA6B4FC4E13438F0AC7.
By shutting down Tor and restarting it 15 minutes later, I was able to get the attack to stop. In another case when I realized it was targeting another relay of mine, I had to wait over an hour with Tor off before it stopped. If I restarted Tor any sooner, it would immediately resume. I don't know if this is because the attack determined that my relay was down and stopped attempting connections, or if each attack was set to be run for a predetermined amount of time and that time happened to elapse. Regards, forest -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCaqIIhwAKCRAw+TRLM+X4 xq+QAQCJh3IO5eYWGx4+MFx6YmL05hUP3bqZiPmxiTv09IZTWgD+L0Ad55qWZTVX BklFuz+6PUZkdTMiu77n/uoPTly6bAw= =x9Y+ -----END PGP SIGNATURE-----