Oky Posted May 6 Posted May 6 I’ve been having trouble accessing the site since these attacks. It simply will not load at all for me. Quote
aFrInati0n Posted May 8 Author Posted May 8 Little generic update: Seems we are still getting DDoS'ed, I can see attempts starting ~7-9 pm, lasting till ~11 pm CEST. From the load I can observe in our monitorings we shall be fine. I can just encourage anybody having slowness to report back - can only help me adjusting things in pro-active ways. @Oky, thanks for the report - sorry for me just replying now! Is that ongoingly happening for you still? I just looked up your latest I IP address which has been logged. Please send us a mail when this happens again to admin@eurobricks.com, just mentioning your nick and you being blocked - as this allows me to look up your used & logged IP address and allowing more insights for me understanding why it may have hit you accidentally. For now I can only say "sorry for the inconveniences we created for you" *sigh. Quote
aFrInati0n Posted May 8 Author Posted May 8 Checked further on @Oky's issue, it was limited to the 19th of April - sent a private message with more details. I expect that was still my 1st set of rules, known to have acted too strictly - I have not seen any other bans for him after my amendment of my rules. Quote
aFrInati0n Posted May 8 Author Posted May 8 Little Update: Over the last days we received some more DDoS-ish attacks. Interestingly the pattern seems to have shifted a bit. Observing the situation currently. Quote
aFrInati0n Posted May 8 Author Posted May 8 Patterns seems to be timed between 7-10pm CEST. Seems like such services are offering timeslots to be selected for them to work on one's "project" :D We will discuss the situation internally and decide for other mititation measurements. Quote
Toastie Posted May 8 Posted May 8 @aFrInaTi0n There is another option before going rogue: Just ... wait. When I get email notifications about new posts to a topic I replied to, and click on the link in the email, it sometimes takes some time. Knowing what is going on, I just "wait" (Well, do something else). And then eventually the topic opens. It's an about max. 60s window of calmness, i.e., a black window, and then all is good. There is absolutely nothing wrong with this. In my universe, it is called comfort time. Let them DoS as long as these idiots want, and fight back as you do! And maybe some should recall that time is relative. Some sites may respond in no time, others, being under attack, in some time. There is this "mass" in the equation, that may stretch time. Mass as in DoS. I am just happy that you do what really helps all of us! All the best, have a nice weekend Christoph - and rock on, dude. Yours Thorsten Quote
aFrInati0n Posted May 8 Author Posted May 8 Not succient enough for me being admin here.. I am happy for your calm mind here. It is just we still have options and I am willing to implement them - as I can learn a new thing while doing so.. I am not anyhow mad, but see it as an oppertunity to improve my skills and possibly our service reliability as well idealy.. Quote
Toastie Posted May 8 Posted May 8 18 minutes ago, aFrInaTi0n said: I am not anyhow mad, but see it as an oppertunity to improve my skills and possibly our service reliability as well idealy.. Fight for it. It makes total sense. Best Thorsten Quote
MKJoshA Posted May 9 Posted May 9 I noticed lag around the hours you mentioned yesterday @aFrInaTi0n But it wasn't too bad. Quote
Johnny1360 Posted May 11 Posted May 11 I have been unable to view the site at all for at least a week now, the only way I was even able to post this was to wait several minutes for the page to load. Hopefully it gets cleared up soon because as it is I consider the site unnavigable. I am using my phone maybe that is part of it but I have used this phone for years and have done all I can think of on my end. Quote
Wapata Posted May 13 Posted May 13 Ddos attack have evolved, I've seen in the news that a bad guy used a looooooooot of computers hacked around the world to generate traffic... But no too much. He have so many slave computers that each one can send a unique traffic, pause for minutes, and goes back. This way it ever been under the radar of the protection program, but real humans did see a pattern and been able to take down the attack. .... Why bad guys are so clever... Why is it easier to break something than to make it work... Who give money to put down some web sites ?.. Quote
Johnny1360 Posted May 13 Posted May 13 Seems to have been resolved, for the time being, as I can actually navigate the site. Yay Quote
aFrInati0n Posted May 27 Author Posted May 27 Since yesterday afternoon we are hit again by what seems to be a DDoS / Botnet again. We are actively overwatching the situation and working to mitigate the pressure to allow the forums to be available. Sorry for the inconveniences for partial not (all the time fastly) responding site. Quote
Yperio_Bricks Posted May 27 Posted May 27 Since yesterday evening I can not post in the forum. When i hit 'submit reply' I always loose connection to the forum immediately. Let's see if it works now.... Quote
Rogue Redcoat Posted May 28 Posted May 28 Strangely, the only time I can't get Eurobricks to load at all is when I'm on my community college's Wi-Fi; other than that, it seems to be working fine for me. Quote
aFrInati0n Posted May 28 Author Posted May 28 @Yperio_Bricks That is unfortunately one of the effects of an DDoS - they are basically putting a jam on all traffic lines, so your delivery can be send, but it will never reach its destination in time.. @Rogue Redcoat It may be a shared external IP - if you have the possibilities while being on the Wifi, may I ask to open some page to show your public IP and send it to me in am private message? I may take further looks on the exact IP., chances are high more than you alone are browing from the same shared public IP from your community's WiFi. This may then be seen as "likeliky to be part of the attack" and may got a ban. Nevertheless again we are sorry for the inconveniences you had to endure - as told by the other announcement, we are in the preparations for allowing the regularly known loading performance & availability. Quote
Rogue Redcoat Posted May 29 Posted May 29 17 hours ago, aFrInaTi0n said: It may be a shared external IP - if you have the possibilities while being on the Wifi, may I ask to open some page to show your public IP and send it to me in am private message? I may take further looks on the exact IP., chances are high more than you alone are browing from the same shared public IP from your community's WiFi. This may then be seen as "likeliky to be part of the attack" and may got a ban. Unfortunately, I will not be there for the following 3 months. I will DM you if problems persist in the fall. Quote
aFrInati0n Posted May 29 Author Posted May 29 I hope by fall we have solved and forgotten all this. Happy to hear then. Quote
aFrInati0n Posted May 29 Author Posted May 29 Little Update of 29th of May: We are still getting constantly flooded with requests since some days. We fiine tuned the mitigation measures to work better to filter out any attacking IPs, implemented since 28th of May. It has been ~18k-20k IP addresses (doing more than one request per IP..) simultaneous hammering at our server, since the fine tuning we got it down by 1/3. I consider the site load performance ok for the load we are still under, should definitely be felt better than before the 28th of May with the new tuned rules. Edit: From my system engineer background it is a funny situation, like playing chess with the attackers.. So I would call my current turn ended, waiting for their next move, but already having our winning strategy in mind.. So "Your next turn please attackers". Edit2: Seems the DDoS has suddenly ended around the time I was writing this posting, removed the notice at the frontpage. Please come back soon attackers, as you are sponsoring us the distributed load / performance testing for improving our setup. Quote
aFrInati0n Posted May 31 Author Posted May 31 Next stage of DDoS protection implemented - may the attackers be so kind to throw some more coins in the DDoS machine please?! Would really help us to see how we are performing now.. Quote
aFrInati0n Posted June 8 Author Posted June 8 Just to add a post here: The next step of our mitigation measurements has been implemented today. There are 2-3 more next steps needed until we are at the point I would like to see us with our setup. Quote
aFrInati0n Posted June 15 Author Posted June 15 Latest Update after 1 week of having the new mitigations enabled: No signs of any DDoS reaching through. So I would consider "Project Ganesha" successfully implemented, as I like the idea of having him as a patron who allows only those with good intentions to pass. Quote Ganesha , the Lord of Obstacles, is popularly worshipped as a remover of obstacles, though traditionally he also places obstacles in the path of those who need to be checked. Namasté (नमस्ते) * Image has been created with Gemini. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.