Close
Page 3 of 11 FirstFirst 12345678 ... LastLast
Results 21 to 30 of 108
  1. #21
    COAR SpecOps Team Leader theGinsue's Avatar
    Join Date
    Mar 2008
    Location
    Colo Spr
    Posts
    21,955
    Blog Entries
    4

    Default

    Quote Originally Posted by Zundfolge View Post
    Yeah, my guess is a real weak sauce DDOS attempt by some script kiddie with a real lame bot-net.
    Quote Originally Posted by buffalobo View Post
    I saw Ginsue cruise through a little bit ago. Admins be fixin.

    I alerted J on this earlier and he tweaked the firewall a bit, but it was an attempt at a DDoS using Chinese bots coming through US provider with multiple weaknesses. I see spam accounts coming trough the same provider often and have tried to block those IP subnets, but that provider has a LOT of them.

    Just got off of the phone with J and, as you can see, he seems to have tweaked the firewall enough to block most, if not all of the subnets. He's going to shoot me a list of the blocked subnets so I can run it against the forum to see if this will affect any of our members. We'll adjust as needed.

    This thread was a good idea, but always remember that the quickest way to reach the staff is by using the "Report" icon.
    Ginsue - Admin
    Proud Infidel Since 1965

    "You can't spell genius without Ginsue." -Ray1970, Apr 2020

    Ginsue's Feedback

  2. #22
    Banned
    Join Date
    Sep 2009
    Location
    Denver, CO
    Posts
    1,454

    Default

    Quote Originally Posted by theGinsue View Post
    I alerted J on this earlier and he tweaked the firewall a bit, but it was an attempt at a DDoS using Chinese bots coming through US provider with multiple weaknesses. I see spam accounts coming trough the same provider often and have tried to block those IP subnets, but that provider has a LOT of them.

    Just got off of the phone with J and, as you can see, he seems to have tweaked the firewall enough to block most, if not all of the subnets. He's going to shoot me a list of the blocked subnets so I can run it against the forum to see if this will affect any of our members. We'll adjust as needed.

    This thread was a good idea, but always remember that the quickest way to reach the staff is by using the "Report" icon.
    Thanks, Ginsue & J - you guys rock!

  3. #23
    Say "Car RAMROD!" J's Avatar
    Join Date
    Sep 1983
    Location
    Westminster, CO
    Posts
    4,012

    Default

    I've been fighting with this a good bit this afternoon/evening. It might continue to be a bumpy ride for a bit, until our attacker gets a tired of his hijinx.

    It seems that someone has found a vulnerability in a large colocation provider. We have received several moderate level DoS attacks at various times today. Unfortunately, the provider that has been compromised has many servers, over almost a dozen locations, so it has been difficult to lock that host out of the firewall entirely in a preventative process. Like many CoLo providers, they have acquired sporadic/random class Bs and Cs from their upstream (and LARGE) ISPs as needed, that would lock out many members with a wide scale rule in the firewall.

    We have been locking out individual class C subnets reactively as attacks present themselves. I am also contracting this provider with what data I have, in hopes they can assist. Unfortunately, it probably isn't servers directly administered by this provider, but those of a client that rents space from them.

    Hopefully it starts performing better with the newest round of firewall drop rules.
    --J
    My Feedback

    "Praise be to our prophet, John Moses Browning, who hath bestowed upon us the new testament of shooting. Delivered unto us, his disciples, on 29 March 1911 A.D."



  4. #24
    I blame everything on Tummy Aches
    Join Date
    Sep 2011
    Location
    Brighton
    Posts
    7,688

    Default

    Quote Originally Posted by argonstrom View Post
    Thanks, Ginsue & J - you guys rock!
    +1

  5. #25
    COAR SpecOps Team Leader theGinsue's Avatar
    Join Date
    Mar 2008
    Location
    Colo Spr
    Posts
    21,955
    Blog Entries
    4

    Default

    J did the work, I just gawked. (Window licker sort of thing)
    Ginsue - Admin
    Proud Infidel Since 1965

    "You can't spell genius without Ginsue." -Ray1970, Apr 2020

    Ginsue's Feedback

  6. #26
    Iceman sniper7's Avatar
    Join Date
    Mar 2008
    Location
    Brighton
    Posts
    16,987

    Default

    Much faster now!

    please send the attackers an attack of gay porn if possible to let them know our displeasure of their actions.
    All I have in this world is my balls and my word and I don't break em for no one.

    My Feedback

  7. #27
    GLOCK HOOKER hurley842002's Avatar
    Join Date
    May 2009
    Location
    Tucson, AZ
    Posts
    8,021

    Default

    Much better, thanks J and everyone else involved.

  8. #28
    Gives a sh!t; pretends he doesn't HoneyBadger's Avatar
    Join Date
    Feb 2012
    Location
    C-Springs again! :)
    Posts
    14,821
    Blog Entries
    1

    Default

    Thanks J, Much better now.


    Maybe this is a good opportunity to remind everyone that this is a FREE forum with NO BANNER ADS. Maybe we can express our thanks to J and others with a nice "thank you" gift of some sort.

    J, Ginsue, other Mods/Admins: who pays for the hardware (servers and such) as well as other miscellaneous expenses to keep the site running? Can we donate directly to this person(s) via paypal or similar means?
    My Feedback

    "When law and morality contradict each other, the citizen has the cruel alternative of either losing his moral sense or losing his respect for the law." -Frederic Bastiat

    "I am a conservative. Quite possibly I am on the losing side; often I think so. Yet, out of a curious perversity I had rather lose with Socrates, let us say, than win with Lenin."
    ― Russell Kirk, Author of The Conservative Mind

  9. #29
    OtterbatHellcat
    Join Date
    Feb 2013
    Location
    Central Arizona
    Posts
    21,941

    Default

    Quote Originally Posted by argonstrom View Post
    Thanks, Ginsue & J - you guys rock!
    Plus 1

    Quote Originally Posted by HoneyBadger View Post
    Thanks J, Much better now.


    Maybe this is a good opportunity to remind everyone that this is a FREE forum with NO BANNER ADS. Maybe we can express our thanks to J and others with a nice "thank you" gift of some sort.

    J, Ginsue, other Mods/Admins: who pays for the hardware (servers and such) as well as other miscellaneous expenses to keep the site running? Can we donate directly to this person(s) via paypal or similar means?
    I've brought this up before.....about donating to the contribution thread list..thingy.

    You'd think I'd have told every member they were going to get a pay cut in their salary for a year. Deaf ears, HB.

    I should kick a buck though, it's been a bit.


    ΜΟΛ
    ΩΝ ΛΑΒΕ

    My Feedback

  10. #30
    QUITTER Irving's Avatar
    Join Date
    Nov 2008
    Location
    Denver, CO
    Posts
    46,527
    Blog Entries
    1

    Default

    Thank you guys.
    "There are no finger prints under water."

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •