Botnet Attack on BSNL Broadband network

  • Thread starter Thread starter Sushubh
  • Start date Start date
  • Replies Replies 121
  • Views Views 12,265
Well not actually. Line contention for home broadband is anywhere from 20:1 to 50:1. So on a 1 G port, you can put about 400 (20:1) users to about 1000 users each having 50Mbps speed.
 
Bharat Ix and Extreme IX were built on keeping smaller isps in mind.
They might provide higher capacity ports to content players like Google, Clouflare etc.
But usually higher capacity like 40G or 100G usually are peered at private facilities like Tata VSB in Chennai or Bharthi airtel Santhome in Chennai.
@philip Yes Jio has great capacity even internationally and I wouldn't be suprised if they start to provide transit services for other ISPs.
 
Not only bb users onts affected, nib people using windows 7 directly connected to the pe router which has backhaul capcity of 100G.

I complained about ping spike in working hours 10am-5pm, most of our customers streaming and watching Netflix YouTube after office hours which pings are very low 14ms to Chennai server.i suspect bsnl computers are causing these network spikes, tomorrow second saturday if I get normal pings in office hours then bsnl nib pcs are main culprits.


Thanks @airforce. BSNL's public IP ranges are public information, probably when the attackers noticed increased success rate for BSNL IP ranges, they may have targetted BSNL IP ranges more extensively.

Also, once you insert a malicious DNS resolver, they can potentially hijack your traffic elsewhere for non HTTPS traffic.

I'm still curious to know, how the attack itself worked, and what kind of workload the affected PC's or networks were being made to do.
 
@airforce how do you know this, also can they use PE router to have that bandwidth(reassoanble a part of it like 1 Gbps-10Gbps ) for their personal use(say at office)?(just like it happens in other govt offices where ppl use a lot of stuff for their personal use)

Also if you have followed mine or others user post in bsnl ffth forum , we hhave reported TB+ usage and haeavy daily data usage beyond the limits of what 2 MBps allows, do you happen to know if BSNL guys have some problem with speed-capping systems which are getting bypassed , selfcare is not even registering my usage since internet cam back)
 
@Realme I visited there , these Babu's have unrestricted access to their core network, one guy who was working there retired recently he used to access these network from his home from teamviewer and anydesk.

They have upgraded their backhaul recently from 10G to 2 x 50G

We are the first lco in my district and one of the very few lcos tied up with bsnl when they started tsp program in my state .

Usually BSNL send new lcos to our network for training and troubleshooting.
 
@airforce: Like if they want to download 1 TB file can they use their unrestricted access to do so? also since they have unrestricted access can they monitor us without any lawful warrant?

Also that guy is retired but he does have contacts there, so can he ask his mates at BSNL to uncap his home port above what is available to retail customer(say 500mbps/1 Gbps altho 500 mbps is more reasonable without getting in higher authority eye as their PON cables are max 1.125 Gbps)

I see you are an LCO, can you access customer logs at OLT(see what they are doing) , what bandwidth do you get max from BSNL(is it permacap or provisioned as you go) , btw as an LCO can you uncap you ports for personal use.

(Sorry for pestering you with so much question, I am going to have a fierce debate with my guy who accused me what was I doing that I consumed TB of data in 10 days, it really go on my nerves and made me ferociously angry)

If you don't mind can I talk to you in DM(s)?
 
@airforce do you have any status update about botnet situation? any idea by when it will be resolved?
 
Back