It is currently 20 Jul 2025, 01:41




 Page 3 of 3 [ 44 posts ]  Go to page Previous  1, 2, 3
Author Message
 Post subject: Re: Sessions table crashed, forum was offline (Botnet attack
PostPosted: 12 Jun 2025, 19:13 
Jedi Knight
Jedi Knight
User avatar

Joined: 14 Jan 2010, 09:44
Posts: 6397
Location: Ann Arbor
Has thanked: 1635 times
Been thanked: 1379 times
I think my home connection is blocked but my mobile is not. Should I email you my IP or something?
_________________
All about LD care, inner sleeves, shrink wrap, etc.

https://youtu.be/b3O-vHpHRpM
Offline
 Profile  
 
 Post subject: Re: Sessions table crashed, forum was offline (Botnet attack
PostPosted: 12 Jun 2025, 23:41 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 5036
Location: Tokyo
Has thanked: 363 times
Been thanked: 1473 times
signofzeta wrote:
I think my home connection is blocked but my mobile is not. Should I email you my IP or something?


YES -> see a few messages above.

I removed the firewall rule because the booby-trap seems to be working!!!
Flood almost completely stopped.

Julien
_________________
HARDWARE DATABASE
HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G
LDD-1 MSC-4000 R2144 PONTUS II C45 MC257
Offline
 Profile  
 
 Post subject: Re: Sessions table crashed, forum was offline (Botnet attack
PostPosted: 14 Jun 2025, 10:26 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 5036
Location: Tokyo
Has thanked: 363 times
Been thanked: 1473 times
admin wrote:
Let the Hunter Games... begin!


It only took *4 hours* to get the bobby-trap to stop the botnet!

I guess the MCP (Master Control Program) didn't like seeing all the compromised hosts crashing or not responding anymore after a reboot.

Idea was provided here: https://idiallo.com/blog/zipbomb-protection

If a bot is detected: don't serve the normal page or block it... but offer a 10MB gzip-compressed file filled of only zeros that decompresses to 10GB.

Small hosts like phones, IoT devices, internet boxes don't have that much memory and -- if there is no counter-measure to avoid crashes -- will try to extract 10GB of zeros to their own demise.

Only took 4 hours to stop the flood. Served over 45GB or this 10MB payload, that potentially decompressed for them into 45 petabytes of memory.

Either most of them crashed... or whoever controls the botnet decided that it was not worth wasting so many compromised hosts on us.

Hopefully I've been blacklisted as a target for now!

Julien
_________________
HARDWARE DATABASE
HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G
LDD-1 MSC-4000 R2144 PONTUS II C45 MC257
Offline
 Profile  
 
 Post subject: Re: Sessions table crashed, forum was offline (Botnet attack
PostPosted: 14 Jun 2025, 15:35 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 5036
Location: Tokyo
Has thanked: 363 times
Been thanked: 1473 times
Scratch that.

I removed the protection and they came back a few hours later.

So... back in booby-trap mode for now.

Julien
_________________
HARDWARE DATABASE
HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G
LDD-1 MSC-4000 R2144 PONTUS II C45 MC257
Offline
 Profile  
 
Display posts from previous:  Sort by  
 Page 3 of 3 [ 44 posts ]  Go to page Previous  1, 2, 3


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to: