> ## Content Index
> Fetch the complete content index at: https://maartenweyns.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# DDoS-for-Hire services prove their power on exposed monitoring servers
- URL: https://maartenweyns.com/ddos-for-hire-services-prove-their-power-on-exposed-monitoring-servers/
- Published: 2026-10-05T13:20:54.000Z
- Updated: 2026-10-05T13:22:12.000Z
- Description: Within the DDoS ecosystem, DDoS-for-Hire services have become increasingly popular. With many providers trying to attract the most customers, it is important for service providers to showcase their attack power. This is done with so-called DDoS “Power Proofs”.
- Author: Maarten Weyns

Within the DDoS ecosystem, DDoS-for-Hire services (often called *Booters*) have become increasingly popular, allowing anyone to launch a DDoS attack with the click of a button. With many providers trying to attract the most paying customers, it is of value for service providers to showcase and advertise their attack power. This is done with so-called DDoS “Power Proofs”: a method to add trust in DDoS attack power showcases.

Read the full paper  
****"** **Botnet Boasting: Investigating DDoS Power Proofs** **"**  
ACM CCS 2026, The Hague

[Full paper PDF ](https://gsmaragd.github.io/publications/CCS2026-DStat/CCS2026-DStat.pdf?ref=maartenweyns.com) 

![](https://maartenweyns.com/content/images/2026/10/show-proof-1.png) 

## The Trust Problem in the DDoS-for-Hire Community

To attract as many paying customers as possible, DDoS-for-Hire providers often boast their attack power on their website or on social media. Booters that claim “>1Tbps attack power” are commonplace in the DDoS ecosystem nowadays. However, from a potential client's perspective, there is no reason to trust these claims, and no reason to verify the power before buying an attack.

Booter providers have thought of a way to add this missing element of trust. By creating a platform called “DStat”, named after the Linux tool [dstat](https://linux.die.net/man/1/dstat?ref=maartenweyns.com), booter providers can attack an endpoint and observe the generated attack traffic while the attack is taking place. Using this data, the claims become a reflection of a real-world attack. A claim based on this data is called a “Power Proof” in the community. These proofs are often shared on platforms like Telegram, where providers can reach a wide audience of potential customers.

![](https://maartenweyns.com/content/images/2026/10/power-proof.png)

A Power Proof published on Telegram.

There are many DStat websites, functioning as platforms that aggregate data from a set of DStat endpoints and showing a live view of the incoming bandwidth. These DStat endpoints are DDoS attack targets which measure incoming traffic at the endpoint and report real-time statistics of this traffic. These endpoints differ in their specifications, with some having a maximum bandwidth of 1 Gbps, while others can handle over 1 Tbps.

DStat websites often include advertisements to booter services. From Telegram conversations with administrators, such banner advertisements cost around $40/month.

![](https://maartenweyns.com/content/images/2026/10/dstat-ca-peak-75g-20260327.png)

A screenshot of a DStat website, showing an attack of 100Gbps.

## Power Proofs to test DDoS mitigation

Some specific DStat endpoints are protected by DDoS mitigation. These allow users and DDoS-for-Hire providers to test the effectiveness of their attacks against protected endpoints. These Power Proofs show the number of accepted and blocked requests.

![](https://maartenweyns.com/content/images/2026/10/cloudflare-powerproof.png)

A Power Proof showing blocked and allowed requests.

In our dataset, all of these Power Proofs target Cloudflare specifically. In these reports, the reason why traffic is being blocked is shown. We observe "requests coming from known bad sources" as the most matched Cloudflare DDoS mitigation rule.

![](https://maartenweyns.com/content/images/2026/10/Screenshot-2026-10-05-at-11.49.46-2.png) 

## Abused infrastructure backing DDoS Power Proofs

With some attacks exceeding 27 Tbps, the infrastructure backing Power Proofs needs to be powerful enough to both sustain but also measure and report these attack volumes. Because of the large uplink and heavy compute needed, the cost of hosting such infrastructure is significant. On the contrary, there is very little upside to hosting this infrastructure, as they primarily serve to demonstrate attack capabilities rather than generate revenue.

By investigating the targets used to measure DDoS attacks in [Censys](https://www.censys.com/?ref=maartenweyns.com), we find that many of them expose monitoring tools publicly to the internet, such as [Prometheus](https://www.prometheus.io/?ref=maartenweyns.com), [Netdata](https://www.netdata.cloud/?ref=maartenweyns.com), or SNMPv1\. When not properly secured, these tools can be easily scraped for data without authentication needed.

## **2,000,000**

According to data from Censys, there are around 2 million targets exposing these monitoring suites on the internet:

> **50,000+** are exposing Netdata  
> **1,000,000+** are exposing Prometheus Node Exporter  
> **900,000+** are exposing SNMPv1

This large number of possible targets allows maintainers of DStat platforms to easily switch around targets when needed. On average, we observed a target to be listed on these platforms for 24 days.

![](https://maartenweyns.com/content/images/2026/10/bg-data.png) 

## What the data shows

Between August of 2025 and April of 2026, we collected **70,390 Power Proofs** from 41 distinct chats on Telegram. From this data, we can create the following overview.

![](https://maartenweyns.com/content/images/2026/10/main_overview-copy.png)

An overview of Power Proof activity over time.

On average, we observe 276 generated Power Proofs per day, with 75 unique users per day performing attacks. During our measurements, we observed a peak of 754 Power Proofs published on the 11th of April, 2026.

> The largest attack in terms of bandwidth measured **27.98 Tbps**  
> The largest attack in terms of packet rate measured **3.14 Bpps**

Some more detailed Power Proofs show attack types. From the 2,539 of these in our dataset, we see 96.2% of the attacks containing a UDP element, 21.1% containing a TCP element, and 15.8% containing an ICMP element.

A full analysis of the dataset can be found in our paper: ***"Botnet Boasting: Investigating DDoS Power Proofs"**

[Full paper PDF ](https://gsmaragd.github.io/publications/CCS2026-DStat/CCS2026-DStat.pdf?ref=maartenweyns.com) 

## Summary

- The ease with which hosts on the internet can be abused to generate "Power Proofs" drives the competitive market within the DDoS-for-Hire ecosystem.
- The option to perform DDoS "test attacks" simplifies improving the effectiveness of an attack. This makes DDoS attacks more powerful and disruptive.
- Power Proofs can be a valuable dataset for defenders (improving mitigation), law enforcement (linking Telegram users to attacking infrastructure) and researchers (attack characteristics).
- Take care when using Netdata, Prometheus, or SNMPv1 for system monitoring. Make sure proper firewall rules are in place to prevent abuse.