jema
|
Server is being attackedSorry but this is causing severe issues
|
sean
|
I wondered what was going on last night. Seems OK this morning, touch wood.
|
jema
|
| Quote: |
As I suspected, the traffic was directed at udp port 0, which runs no services - they were merely sending as much traffic as possible to the server in hopes to saturate its uplink connection (which it did - the traffic was over 200mb/s for most of its duration, which is double the connection speed of your server to the switch).
|
That is really a very large attack
|
Penny
|
I thought it was my computer again Is it OK now Jema?
|
Northern_Lad
|
Sounds like a common-or-garden D.O.S. attack.
Do we know if it was specifically DS that was targetted, or the whole farm?
|
ken69
|
Hope it's not me, Jema, trying to put Downsizer.net on Google Reader.
|
jema
|
| Northern_Lad wrote: | Sounds like a common-or-garden D.O.S. attack.
Do we know if it was specifically DS that was targetted, or the whole farm? |
I think it was probably my forums system under attack I am taking some more defensive measures.
|
Jonnyboy
|
That'll teach you for banning the neo nazi's.
joking aside, sorry to hear about the problems.
|
jema
|
| Jonnyboy wrote: | That'll teach you for banning the neo nazi's.
joking aside, sorry to hear about the problems. |
It is all quite odd no one has layed claim to doing this and aside from casino sites that were hijacking the system, I have not actually banned very much at all recently.
|
Mrs Fiddlesticks
|
showing my ignorance here but is it traceable?
|
jema
|
| Mrs Fiddlesticks wrote: | | showing my ignorance here but is it traceable? |
Not really constantly shifting addresses used in the attack, probably from hijacked PCs. All you can do is live and learn and adopt more measures to reduce the impact.
I think this is about the 3rd serious incident in a year
|
cab
|
Did everything just break for a while there?
|
Northern_Lad
|
And again?
Just editing this one at 18:41, let's see what time the server thinks it is...
|
Northern_Lad
|
| cab wrote: | | Did everything just break for a while there? |
I'm guessing that that's a big YES. Date-times are all wanky-yanky at the mo. Maybe American cleaners are just as daft as British ones.
|
Mrs Fiddlesticks
|
I've just posted something and it says I did so at 1.37pm, but its not that in real life. Time warp stuff, weird!
|
Mrs Fiddlesticks
|
| Mrs Fiddlesticks wrote: | | showing my ignorance here but is it traceable? |
oddly when I posted this originally Jema's answer
| Jema wrote: | Not really constantly shifting addresses used in the attack, probably from hijacked PCs. All you can do is live and learn and adopt more measures to reduce the impact.
I think this is about the 3rd serious incident in a year |
was directly under it, now there are about 3 posts that have slotted in between.
time of writing this 7.02pm
|
Northern_Lad
|
Seeing as you canny change the laws a' physics, Jema, can you bring us up to speed on what just happened?
|
jema
|
I am not entirely sure, I submitted a support ticket on the server relating to a defense against this attack, they clearly did "something" and reset the clock in the process
I am awaiting some explanation.
|
gil
|
Just for the record, I tried logging on to DS about 11.30 - 11.45pm last night, Tuesday 27th June, and couldn't.
|
Northern_Lad
|
| gil wrote: | | Just for the record, I tried logging on to DS about 11.30 - 11.45pm last night, Tuesday 27th June, and couldn't. |
Too drunk?
|
gil
|
| Northern_Lad wrote: | | gil wrote: | | Just for the record, I tried logging on to DS about 11.30 - 11.45pm last night, Tuesday 27th June, and couldn't. |
Too drunk? |
Kept getting the 'Could not find server' screen.
|
jema
|
| gil wrote: |
Kept getting the 'Could not find server' screen. |
Not doubting your report for a second, but it does not quite fit in with the "facts" as I have been informed by the engineers. I have a feeling that I am missing a few pieces of the overall puzzle as to what went on
|
Northern_Lad
|
| gil wrote: | | Northern_Lad wrote: | | gil wrote: | | Just for the record, I tried logging on to DS about 11.30 - 11.45pm last night, Tuesday 27th June, and couldn't. |
Too drunk? |
Kept getting the 'Could not find server' screen. |
Itsh over ver, nesh to the table thingy.
|
dougal
|
| jema wrote: | | gil wrote: |
Kept getting the 'Could not find server' screen. |
Not doubting your report for a second, but it does not quite fit in with the "facts" as I have been informed by the engineers. I have a feeling that I am missing a few pieces of the overall puzzle as to what went on  |
I suspect Gil was seeing the result of some timeout on his browser or system.
1145-ish last night I got nothing but "waiting for " messages in Firefox's status bar and couldn't even get as far as getting a window title... seemed to be the forum (I could reach other sites) so thought "nowt I can do" and toddled off.
Apart from leaving things for a bit rather than constantly retrying, is there anything users can do to help?
There was something a bit strange earlier, 530-ish? On clicking "view latest posts" I got a message about not being able to search *again* so soon... Again? Huh? Left it for a couple of minutes and got the exact same message. Thought uh-oh and left things to straighten out.
Things seemed to have been running very smoothly.
I'm just trying to imagine what sort of a halfwit would try to deny service at around midnight... which makes me kinda think that the halfwit might be on a US timezone, or attacking a US site and mistyped an IP address. Or is a real dunce.
Anyway, I'm sure Gil and all my fellow insomniacs, shiftworkers and antipodean readers won't take it too personally...
|
jema
|
The search issue earlier was caused by a server reboot and the bios time and system time not being in sync. So a reboot set the time way too early.
As you say the DOS attack is odd.
|
Bernie66
|
I would love to be able to say something interesting and relevant but i can't so I will shut up and try to learn something.
|
Cathryn
|
It's because you have all created something significant and therefore worth attacking. (I got the same as Gil and Dougal last night)
(I know - I know b******** all about what you are talking about but I like to be annoyingly positive about life )
|
jema
|
| ruby wrote: | It's because you have all created something significant and therefore worth attacking. (I got the same as Gil and Dougal last night)
(I know - I know b******** all about what you are talking about but I like to be annoyingly positive about life ) |
Either that or Dougals cockup theory anyway
Still live and learn, and I am a good part of the way to sorting out a system that will at least help a bit next time crap like this happens
|