Afrihost - Pure Fibre Feedback Thread

Status
Not open for further replies.
Let me give a bit of perspective. I joined Afrihost at the beginning of the month (or rather the middle once we sorted out some Openserve issues). The reason I moved ISPs was because my previous provider had been hammered for close on a month by DDoS attacks - similar pattern, waves that tended to converge during heavy usage periods, probably because the existing traffic made it an easier target.

My previous provider was smaller than Afrihost, and they couldn't manage to keep international up at all during the attacks. They did everything they could, but it's a resource-heavy problem. In the end I left because there was no end in sight, but I don't blame them for it.

Liquid telecom is a larger player, with attendant resources available. You can see that in the fact that they're managing to keep things mostly rolling. Yes, it's tremendously frustrating for those of us who use latency-dependent applications like gaming, but we're at least not seeing total failure since the first wave.

tl;dr: it could be much worse, and I think you should re-evaluate the degree of responsibility that you're assigning on the provider side here.

Thanks for this. Totally agree - the guys at Liquid are doing the very best that can be done.
 
Let me give a bit of perspective. I joined Afrihost at the beginning of the month (or rather the middle once we sorted out some Openserve issues). The reason I moved ISPs was because my previous provider had been hammered for close on a month by DDoS attacks - similar pattern, waves that tended to converge during heavy usage periods, probably because the existing traffic made it an easier target.

My previous provider was smaller than Afrihost, and they couldn't manage to keep international up at all during the attacks. They did everything they could, but it's a resource-heavy problem. In the end I left because there was no end in sight, but I don't blame them for it.

Liquid telecom is a larger player, with attendant resources available. You can see that in the fact that they're managing to keep things mostly rolling. Yes, it's tremendously frustrating for those of us who use latency-dependent applications like gaming, but we're at least not seeing total failure since the first wave.

tl;dr: it could be much worse, and I think you should re-evaluate the degree of responsibility that you're assigning on the provider side here.
I spoke to a liquid telecoms WAN Manager on this situation, I won't mentioned he's name or how close he is to me, he said to mitigate these risks was easy and their cyber security team shouldn't have taken so long to mitigate these risks and he also said liquid telecoms needs a new cyber sec department...

Let's be honest with open ports and not closing ports down you will get situations like this.
 
Let me give a bit of perspective. I joined Afrihost at the beginning of the month (or rather the middle once we sorted out some Openserve issues). The reason I moved ISPs was because my previous provider had been hammered for close on a month by DDoS attacks - similar pattern, waves that tended to converge during heavy usage periods, probably because the existing traffic made it an easier target.

My previous provider was smaller than Afrihost, and they couldn't manage to keep international up at all during the attacks. They did everything they could, but it's a resource-heavy problem. In the end I left because there was no end in sight, but I don't blame them for it.

Liquid telecom is a larger player, with attendant resources available. You can see that in the fact that they're managing to keep things mostly rolling. Yes, it's tremendously frustrating for those of us who use latency-dependent applications like gaming, but we're at least not seeing total failure since the first wave.

tl;dr: it could be much worse, and I think you should re-evaluate the degree of responsibility that you're assigning on the provider side here.

Thanks for this. Totally agree - the guys at Liquid are doing the best that can be done.
 
I spoke to a liquid telecoms WAN Manager on this situation, I won't mentioned he's name or how close he is to me, he said to mitigate these risks was easy and their cyber security team shouldn't have taken so long to mitigate these risks and he also said liquid telecoms needs a new cyber sec department...

Let's be honest with open ports and not closing ports down you will get situations like this.

That's a pretty big statement and I would definitely say that the team is doing their best. I am sure if the person was dealing with the issue directly they would realise the challenges and complexities involved.
 
That's a pretty big statement and I would definitely say that the team is doing their best. I am sure if the person was dealing with the issue directly they would realise the challenges and complexities involved.
Agree the team's are doing their best no doubt we all appreciate them im just saying with open ports and not closing them.down before it tends to lead to all of these situations,

Do you mind me doing an external pay level domain vulnerability scan on AH website to see how vulnerable is the website just out of curiosity. It will also help you guys a lot i will provide the report to you?.
 
Up in JHB today... haven't been on my AH connection since last night - is everything back to normal? Network status page still all full of red but says it has been mitigated?
 
Up in JHB today... haven't been on my AH connection since last night - is everything back to normal? Network status page still all full of red but says it has been mitigated?
Local services are up, youtube Netflix and dstv
 
Agree the team's are doing their best no doubt we all appreciate them im just saying with open ports and not closing them.down before it tends to lead to all of these situations,

Do you mind me doing an external pay level domain vulnerability scan on AH website to see how vulnerable is the website just out of curiosity. It will also help you guys a lot i will provide the report to you?.

I don't know if I am the right person to chat to in that regard. Can I get your details on PM and send through to the network manager?
 
Up in JHB today... haven't been on my AH connection since last night - is everything back to normal? Network status page still all full of red but says it has been mitigated?

Things are looking close to normal right now. We can't say it's 100% over - depends if we see more attacks later today. But at least for now things are pretty stable.
 
The status page severity has been downgraded, and now says you're still monitoring "after" the DDoS attacks. However, I'm still getting a ton of packet loss to EU. Are the attacks still ongoing?

EDIT: nm, appears to have been temporary. Will keep an eye on it.
 
Seems stable. London latency is 13-15ms higher than usual and I'm guessing it's because of the mitigation or changes they made. Hopefully it will drop to below 160ms like before

731613
 
Based on previous experience I'm expecting heavy issues between 7.30ish and 10.30. That's going to be the real test of how Liquid will weather this attack going forward.
 
The status page severity has been downgraded, and now says you're still monitoring "after" the DDoS attacks. However, I'm still getting a ton of packet loss to EU. Are the attacks still ongoing?

EDIT: nm, appears to have been temporary. Will keep an eye on it.

The attacks have ceased for now and we're seeing things stabilise. Hopefully things will stay that way :)
 
Helping out my uncle with his new Frogfoot connection, Afrihost fibre up and running but I see the DIR-825 (Hardware revision R1) is at Firmware 1.0.0

Does anyone have experience updating the firmware for this and where did you download it?
I'm doing this remotely so don't want to chance it.
 
Helping out my uncle with his new Frogfoot connection, Afrihost fibre up and running but I see the DIR-825 (Hardware revision R1) is at Firmware 1.0.0

Does anyone have experience updating the firmware for this and where did you download it?
I'm doing this remotely so don't want to chance it.

You should be able to download the firmware automatically from the router. Not usually a good idea to enable remote access on the router unless you have a very specific plan around that.

You can also try here: https://www.d-link.co.za/for-home/dir-825 (but best to use the device so it grabs the right firmware for this specific region).
 
You should be able to download the firmware automatically from the router. Not usually a good idea to enable remote access on the router unless you have a very specific plan around that.

You can also try here: https://www.d-link.co.za/for-home/dir-825 (but best to use the device so it grabs the right firmware for this specific region).

Your WhatsApp support told me to download from http://link.co.za/DIR/dir825 (new)/firmware/G1_BlueWhiteGui/ but I mentioned to them this one says Vendor Russia and it is a revision R1, I managed to find the correct firmware for it @ http://ftp.dlink.ru/pub/Router/DIR-825/Firmware/RevR1/ which worked.

So you're saying it's a bad idea to leave remote access open on port 80 with default password? ;-) don't worry I am aware of the security concerns.
 
Your WhatsApp support told me to download from http://link.co.za/DIR/dir825 (new)/firmware/G1_BlueWhiteGui/ but I mentioned to them this one says Vendor Russia and it is a revision R1, I managed to find the correct firmware for it @ http://ftp.dlink.ru/pub/Router/DIR-825/Firmware/RevR1/ which worked.

So you're saying it's a bad idea to leave remote access open on port 80 with default password? ;-) don't worry I am aware of the security concerns.

LOL - I guess I am speaking to an expert. You never know.

Chatting to someone on another thread who had his router hacked, so just covering the basics :)
 
Your WhatsApp support told me to download from http://link.co.za/DIR/dir825 (new)/firmware/G1_BlueWhiteGui/ but I mentioned to them this one says Vendor Russia and it is a revision R1, I managed to find the correct firmware for it @ http://ftp.dlink.ru/pub/Router/DIR-825/Firmware/RevR1/ which worked.

So you're saying it's a bad idea to leave remote access open on port 80 with default password? ;-) don't worry I am aware of the security concerns.

until you post things like this


:laugh::laugh::laugh:
 
Status
Not open for further replies.
Top
Sign up to the MyBroadband newsletter
X