HomeLatest NewsCyber SecurityWhat is GitHub DDoS Attack; here’s all you need to know

What is GitHub DDoS Attack; here’s all you need to know

/* Container for the button */ .tech-google-wrapper { display: inline-block; margin: 0px 0; /* If you want it to fill the block width like the comment button: */ /* width: 100%; */ } .tech-google-btn { display: inline-flex; align-items: center; gap: 5px; padding: 8px 5px; border: 1px solid #dcdcdc; /* Image has subtle rounded corners, not a pill shape */ border-radius: 4px; background: #ffffff; font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Helvetica, Arial, sans-serif; font-size: 12px; /* Matches the visual scale of the image */ font-weight: 400; color: #121212; text-decoration: none; cursor: pointer; transition: background 0.2s, border-color 0.2s; white-space: nowrap; box-sizing: border-box; } /* If you want the button to be full width: */ /* .tech-google-btn { width: 100%; justify-content: center; } */ .tech-google-btn:hover { background: #f8f9fa; border-color: #c6c6c6; } /* SVG Logo Styling */ .google-logo-svg { width: 18px; height: 18px; display: block; }

Github was hit by one of the largest DDoS attack ever recorded in history

Preferred Source of Google

Recently, was hit by one of the largest attack ever recorded in history. The DDoS attack lasted only for nine minutes, but the servers were flooded with volumes reaching almost 2Tbps. According to the GitHub Engineering team, the attack caused the site to shut down from 17:21 to 17:26 UTC on February 28.

What is a DDoS attack?

A DDoS or distributed-denial-of-service attack is a type of attack where multiple computer/servers/IoT devices are used to send a massive amount of requests to a target server/service. When the server starts processing these requests and tries to reply to them with a response containing the requested information, its causes the service/server to become unavailable for even the legitimate users as the resource get exhausted on replying to the mass requests.

Advertisement
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

How did the hackers manage to send such huge amount of data to the server?

In case of traditional DDoS attack, hackers compromise multiple computer, servers or IoT devices and use those devices to send a huge amount of request to a target server. For instance, if one system sends data of 1 MB to the server, 1 million compromised systems will together send 1 Terabyte of data to the server. The server won’t be able to process such huge amount of data at once and therefore will crash.

Was this the case with GitHub DDoS attack?

Advertisement

However, in this case, hackers were able to achieve the DDoS attack by compromising few systems and amplifying the data send by those systems using an exposed memcached server. Memcached is a free and open-source, distributed memory object caching system that is intended for use in speeding up dynamic web applications by reducing database load.

It means that if one system was supposed to send a data of 1 MB to the server, the hackers amplified the data 51,000 times, therefore, 1 MB was amplified to 51 GB of data. Thus the hackers were able to carry out the DDoS attack by using a few compromised devices.

The DDoS attacks were able to flood the server with huge data by using a reflection/amplification vector that exploited numerous memcached servers to amplify the attack without the need of too many hacked devices amplifying the threshold to almost 51000 times the real attack bandwidth.

Advertisement

How to stay safe from GitHub like DDoS attack?

The general users should update their antivirus/anti-malware software. They should only use a legitimate antivirus software and update it with the latest signatures in order to protect their system from getting targeted. Also, you should keep an eye on the installed programs and software. If you see an application that seems to be unknown/unwanted, remove it, especially if the publisher of the software is unknown. Always keep your Operating system up to date.

On the other hand, Server Admins, must use proper Intrusion Detection Systems (IDS) and Log monitoring services to constantly track the kind of access server is granting to users. Also, web admins must carry out proper auditing and Vulnerability Assessment & Penetration Testing(VAPT) exercises to close as many loopholes as possible so that it isn’t extremely easy to hack your servers and web applications to upload malicious miners/malwares.

According to Ankush Johar, Director at Ventures, in most cases, hackers carry out DDoS attacks by affecting vulnerable devices /servers at mass and making them a part of their botnet. They further use these compromised systems to carry out malicious attacks like cryptocurrency mining or distributed-denial-of-service attack

He said, “Consumers are suggested to take necessary security measures such as installing a legitimate antivirus and updating the OS regularly to prevent their system from getting targeted. System Admins, on the other hand, are advised to keep the servers secure by configuring an Intrusion detection system with firewalls and a proper auditing to mitigate such risks.”

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Sanjay Singh
Sanjay Singh
Sanjay Singh covers startups, consumer electronics and telecom for TechObserver.in
Advertisement
- Advertisement -
- Advertisement -

Dyson launches V16 Piston Animal vacuum in India at ₹79,900

Dyson’s ₹79,900 V16 Piston Animal brings stronger suction, automatic floor sensing, anti-tangle cleaning and a dust-compacting bin to its premium cordless range.

RELATED ARTICLES

window._taboola = window._taboola || []; _taboola.push({ mode: 'alternating-thumbnails-a', container: 'taboola-below-article-thumbnails', placement: 'Below Article Thumbnails', target_type: 'mix' });