News: 1686663068

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft keeps quiet amid talk of possible DDoS attack against Azure

(2023/06/13)


Microsoft has provided comment on an "anomalous spike" in Azure traffic at the end of last week, which sparked several hours of service disruption.

The incident took place between 15:10 and 17:10 UTC on June 9 when customers faced error notifications when trying to access the Azure portal, and also affected other services including Microsoft Entry Admin Center and Microsoft Intune.

At the time, Anonymous Sudan [1]claimed responsibility for a DDoS attack that it alleges was behind the Azure issues.

[2]

The official version of the story, as outlined by Microsoft in a [3]preliminary post-incident review , is that internal telemetry highlighted an "anomaly with increased request rates and the Azure portal displaying a 'service unavailable' message in multiple geographies."

[4]

[5]

"Traffic analysis showed an anomalous spike in HTTP requests being issued against Azure portal origins, bypassing existing automatic preventive measure and triggering the service unavailable response."

[6]Microsoft's Azure mishap betrays an industry blind to a big problem

[7]Microsoft battles through two 365 outages in one day

[8]Microsoft breaks geolocation, locking users out of Azure and M365

[9]Microsoft admits Azure Resource Manager failed after code change

Subsequently, engineers across the Azure portal and networking were dispatched to make quick work of adjusting firewall rules to block the traffic, tweaking traffic throttling rules, adding more Azure portal server instances, and rebooting unhealthy Azure portal instances.

Microsoft says it is trying to make the Azure portal startup process faster and "improving our internal Azure portal monitoring to detect such indicators more quickly and efficiently."

Of Anonymous Sudan's alleged involvement, Microsoft said in a statement that it was "aware of these claims and are investigating."

[10]

"We are taking the necessary steps to protect customers and ensure the stability of our services," it added.

Readers may have some sympathy with Microsoft over the latest Azure service degradation – particularly if it was attacked – but there was likely less understanding over a [11]previous outage of Microsoft Azure DevOps , a line of application lifecycle services that was downed for 10 hours by a typo. ®

Get our [12]Tech Resources



[1] https://www.bleepingcomputer.com/news/microsoft/microsofts-azure-portal-down-following-new-claims-of-ddos-attacks/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZIiSnHy4S39uU@7XzT6U6wAAAQM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://azure.status.microsoft/en-us/status/history/#:~:text=Preliminary%20Post%20Incident%20Review%20(PIR)%20%E2%80%93%20Azure%20Networking%20%E2%80%93%20Global%20WAN%20issues%20(Tracking%20ID%20VSG1%2DB90)

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZIiSnHy4S39uU@7XzT6U6wAAAQM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZIiSnHy4S39uU@7XzT6U6wAAAQM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/06/12/comment/

[7] https://www.theregister.com/2023/06/06/microsoft_365_outages/

[8] https://www.theregister.com/2023/03/24/microsoft_geolocation_fail_uzbekistan/

[9] https://www.theregister.com/2023/03/23/microsoft_admits_azure_resource_manager/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZIiSnHy4S39uU@7XzT6U6wAAAQM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2023/06/03/microsoft_azure_outage_brazil/

[12] https://whitepapers.theregister.com/



Zippy´s Sausage Factory

" Readers may have some sympathy with Microsoft over the latest Azure service degradation – particularly if it was attacked – but there was likely less understanding over a previous outage of Microsoft Azure DevOps, a line of application lifecycle services that was downed for 10 hours by a typo. "

A typo is unfortunate and can happen to anybody. So can a DDoS attack. It does say a lot for Micros~1 that they are (at least giving the appearing of) being honest about this, but the fact that configuration errors keep downing Azure, and that they don't appear to have thought about the possibility of a DDoS attack on the status pages does somewhat erode my sympathy for them.

Where's the "something's up here but I can't tell what" icon?

This seems likely

Gordon 10

Both my company and Missus O365 went squiffy about this time last week.

I think it was a break away group.

TimMaher

Anonymous South Sudan?

A full belly makes a dull brain.
-- Ben Franklin

[and the local candy machine man. Ed]