Epic ongoing BATTLE with Singaporean botnet; UPDATE #2 - it's over...for now!

Forum rules
If you forgot your password, please use the password reset feature.

For profile changes or private issues, please contact a moderator by email or PM (use "The team" link at the bottom of the page)
Post Reply
User avatar
w-u-2-o
Posts: 6157
Joined: Fri Mar 10, 2017 1:47 pm

Epic ongoing BATTLE with Singaporean botnet; UPDATE #2 - it's over...for now!

Post by w-u-2-o »

All,

My apologies for the interruptions in service, but the board is currently engaged in an epic battle with a botnet or other bad actors located in Singapore.

Whatever their goals it has essentially amounted to a denial of service attack.

The board had reached 300,000 :o guest users and ground to a halt.

I have enabled a much stricter IP address block list, but now that total is only down to 37,000!

At this point I'm going to have to block the entire IP range of Singapore. My further apologies to any members who might be located there. All I can tell you is that you may wind up having to use a VPN to overcome that geo-restriction.

More to follow as the battle progresses...

73,

Scott
User avatar
w-u-2-o
Posts: 6157
Joined: Fri Mar 10, 2017 1:47 pm

Re: Epic ongoing BATTLE with Singaporean botnet

Post by w-u-2-o »

Update #1: making some progress.

I've got the number of established connections at the firewall output down to < 100, and the number of page pulls in a 1 minute period to < 300. The AIs tell me this is pretty good.

You can see where the attack started on 9 Feb. We are now headed into the 20th hour of the attack and it continues unabated.


Capture.JPG
Capture.JPG (44.75 KiB) Viewed 134 times


I now have to make the changes to the firewall (iptables) persistent across reboots, create scripts for the blocklists to auto-update, and I think that I will add country blocking for both Russia and China as well.

The bots tend to make between 6 and 8 simultaneous connections to the forum per IP address. I will also probably modify the web server to limit it to 4.

As this is not my "day job" it's probably going to take me another two or three days to get this done.

The battle continues!
User avatar
KA5KKT
Posts: 171
Joined: Thu Aug 06, 2020 6:51 pm

Re: Epic ongoing BATTLE with Singaporean botnet; UPDATE #1 posted

Post by KA5KKT »

JJ4SDR
Posts: 564
Joined: Fri Jul 30, 2021 10:09 pm
Location: TEXAS, USA

Re: Epic ongoing BATTLE with Singaporean botnet; UPDATE #1 posted

Post by JJ4SDR »

Thank you for your efforts Scott!!

Juha
NI2M
PC: 8 Core i7-10700 CPU @ 2.90GHz, NVMe SK Hynix 512 GB SSD, 32GB RAM
Windows 10 Home, Version 22H2
Thetis v2.10.3.4 x64
Protocol 2 v2.2.2a
User avatar
w-u-2-o
Posts: 6157
Joined: Fri Mar 10, 2017 1:47 pm

Re: Epic ongoing BATTLE with Singaporean botnet; UPDATE #1 posted

Post by w-u-2-o »

Update #2: it looks like the attack is over.
Capture.JPG
Capture.JPG (38.64 KiB) Viewed 59 times

That's nice, because now work to increase the forum's defenses can proceed in a more leisurely manner. Because there WILL be a next time. :?

I appreciate everyone's patience yesterday, thank you.

Please note: as improvements to the firewall are made it may be necessary to restart the server and/or restart the forum. This may kick people off and/or log them out. Please continue to be patient. I will post again when the work is complete. In the meantime, things should be 90% back to normal.

Thanks,

Scott
K1LSB
Posts: 770
Joined: Wed Feb 05, 2020 5:25 pm

Re: Epic ongoing BATTLE with Singaporean botnet; UPDATE #2 - it's over...for now!

Post by K1LSB »

Thank you very much, Scott!

This incident makes me wonder why on earth would anyone decide to devote any resources to a directed attack against this website?

Mark
PH7R
Posts: 34
Joined: Thu Dec 15, 2022 9:59 am

Re: Epic ongoing BATTLE with Singaporean botnet; UPDATE #2 - it's over...for now!

Post by PH7R »

Is it an attack or CN downloading all info to feed AI models?
Post Reply

Return to “Forum Problems (like posting photos, etc.)”