Hi there,
regarding the current attack on the network, I can only add that my suspicion is some kind of amplification attack.
As other operators also noticed, I see normal inbound traffic flows but excessive outbound flows (even exceeding my line rate by far..), when my Guard is under attack.
I noticed in my Logs, just before the last OOM Crash of the Tor Process occurred, this warning is spammed excessively:
[warn] Service descriptor has an invalid signature length.Expected 86 but got 88
However, the OS did not report any resource exhaustion in that particular moment, and Tor could use ~12GBs out of the 16GB System Memory. That’s different from the last crash I had some time ago, where the whole OS triggered resource exhaustion alarms.
With the Information others provided (disable Directory Services solves the issue) I would suspect some issue with the services directory, where a malformed request triggers multiple outgoing requests from the relay itself, overloading it in the process.
I’m not deep in the functionality of the directory services, but maybe this can be triggered when registering a malformed service or querying the directory with malformed packets.
This month my biggest uptime enemy was Microsoft itself, ignoring the GPO’s for Update related-restarts and just rebooted twice because of the emergency update that was released. So no more crashes so far.
I’ve attached the Tor Logs when the Relay died, but I don’t think it’ll help much.
Best regards and let’s hope for the best!
Joker
(attachments)
Attack.txt (192 KB)