[tor-relays] DDoS attack targeted on my exit node

Toralf Förster toralf.foerster at gmx.de
Mon Dec 22 20:41:21 UTC 2014

On 12/22/2014 06:44 PM, Michael Renner wrote:
> Hi,
> my tor exit node was targeted with two DDoS attacks, one on 2014-12-20
> 01:00 CET and one on 2014-12-22 18:00 CET [1], both lasting about 5
> minutes each.

Not sure if this is related too, but somebody uses my exit relay for port scans (>15000 scans per minute at ports 22, 80 and 443). It started slowly in December and became heavier over the time.

Last Saturday this yielded into the situation that my ISP claimed to have a problem with a network segment. The ISP "helped" me to solve the problem by cutting the network connections to my exit relay.

Currently it just takes few seconds after I open the ports that the port scans will continue.

