|
It is currently 16 Feb 2026, 19:06
|
View unsolved topics | View unanswered posts
 |
|
 |
|
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 12 Jun 2025, 23:41 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5211 Location: Tokyo Has thanked: 406 times Been thanked: 1637 times
|
signofzeta wrote: I think my home connection is blocked but my mobile is not. Should I email you my IP or something? YES -> see a few messages above. I removed the firewall rule because the booby-trap seems to be working!!! Flood almost completely stopped. Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 14 Jun 2025, 10:26 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5211 Location: Tokyo Has thanked: 406 times Been thanked: 1637 times
|
admin wrote: Let the Hunter Games... begin! It only took *4 hours* to get the bobby-trap to stop the botnet! I guess the MCP (Master Control Program) didn't like seeing all the compromised hosts crashing or not responding anymore after a reboot. Idea was provided here: https://idiallo.com/blog/zipbomb-protectionIf a bot is detected: don't serve the normal page or block it... but offer a 10MB gzip-compressed file filled of only zeros that decompresses to 10GB. Small hosts like phones, IoT devices, internet boxes don't have that much memory and -- if there is no counter-measure to avoid crashes -- will try to extract 10GB of zeros to their own demise. Only took 4 hours to stop the flood. Served over 45GB or this 10MB payload, that potentially decompressed for them into 45 petabytes of memory. Either most of them crashed... or whoever controls the botnet decided that it was not worth wasting so many compromised hosts on us. Hopefully I've been blacklisted as a target for now! Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 15 Dec 2025, 06:35 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5211 Location: Tokyo Has thanked: 406 times Been thanked: 1637 times
|
I still get flooded but now I'm serving Error 403 (Unauthorized access) instead for a 1-month long IP block. Most, if not all, users should be able to access the Forum freely again. If you get an error 403, make sure to access the forum via the main LDDb link => https://www.lddb.com/forum.phpJulien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 24 Jan 2026, 05:05 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5211 Location: Tokyo Has thanked: 406 times Been thanked: 1637 times
|
Another botnet/AI robot has been crashing the web server repeatedly this morning. Sending hundreds of searches in a few seconds from IPs all around the world. No obvious pattern, it comes from all kinds of randomized User-Agent from many countries (but mostly the USA). To let the web server breath, if the search is not coming from a human visitor simply clicking on links or making search box queries, you will be greeted with: Quote: Direct search detected - possibly botnet/AI bots. Please use the human search box on the main page. In the first 10 minutes alone, I blocked 11,600 hits. They come in flooding every 20 seconds or so. Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 27 Jan 2026, 16:51 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5211 Location: Tokyo Has thanked: 406 times Been thanked: 1637 times
|
mukewarrah wrote: Hello. I am a network engineer by trade. Oh it's already quite documented with a GUI => https://banhammer.lddb.com/Just Fail2ban with ipset and various rules to ban certain types of traffic based on User-Agent, Referrer, hitting non-existing URLs, trying wrong passwords too many times, etc I block China, Iran, North Korea, most of the Chinese/HK/Singapore cloud hosting and AI companies. Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
mukewarrah
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 27 Jan 2026, 22:13 |
| Knows how to post |
 |
 |
Joined: 24 Jan 2026, 06:32 Posts: 15 Location: United States Has thanked: 1 time Been thanked: 6 times
|
Very cool setup. I'm used to the more old school approaches. I may look into supplementing my home lab firewall with fail2ban for the sites I host. It's also good to know that URL surfing could get me banned Long live lddb
_________________ Repair, don't replace. I am buying broken AV equipment and video game consoles.
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 28 Jan 2026, 04:02 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5211 Location: Tokyo Has thanked: 406 times Been thanked: 1637 times
|
mukewarrah wrote: Very cool setup. I'm used to the more old school approaches. Static list of blocked IPs does not work anymore (like RBL for spammers)... most of the hits come from compromised smartphones/TV/STB/IoT/computers and they regularly change IPs. Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 29 Jan 2026, 10:44 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5211 Location: Tokyo Has thanked: 406 times Been thanked: 1637 times
|
Slightly changing strategy... A dynamic blocking of IPs on seemingly random external searches is also blocking a lot of good people. Allowing any search anytime also brings my server CPU/resource to crash or make using the website painfully slow. I will add a mid-point: This way, when the traffic is reasonable, I will play nicely. But when things get heavier, I will only serve users using the website as intended. Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 30 Jan 2026, 06:50 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5211 Location: Tokyo Has thanked: 406 times Been thanked: 1637 times
|
The CPU load protection seems to be working very well! I even removed all the 315K IPs blocked because suddenly the flood stopped. I am 99% sure this was related to: They were over 9M IPs unknowingly participating in this botnet via Trojan code present in cheap VPNs and games mobile phone apps from Chinese companies. Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 03 Feb 2026, 02:25 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5211 Location: Tokyo Has thanked: 406 times Been thanked: 1637 times
|
admin wrote: The CPU load protection seems to be working very well! And it keeps holding up. Sadly the botnet rebooted itself and came back to life after 48h. Requests blocked due to the CPU load heating up: 1/24 320 518 1/25 42 554 1/26 11 495 1/27 0 * Google publicly announced shutting down the botnet 1/28 0 1/29 126 932 1/30 57 881 1/31 176 138 2/1 291 419 2/2 50 069 2/3 129 908
So I'll keep the CPU load throttling on CPU-heavy requests + block IPs from obvious liars pretending to be using an OS or a Browser that has been obsolete for more than 15 years. Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 05 Feb 2026, 03:41 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5211 Location: Tokyo Has thanked: 406 times Been thanked: 1637 times
|
takeshi666 wrote: This thread really demonstrates why message boards have died off in favor of social media spaces like reddit or facebook; this is what they all have to deal with. You can check phpBB3 forum, the webmasters are hard at work on how to stop such floods (or just give up because the monthly bill becomes unsustainable). Problem of LDDb is that it's 20+ years old, well documented, well referenced, sitemap up-to-date, high Page Ranking on Google. Very easy to find, very easy to automate. For 2026, we had so far 3,207,325 unique visitors over 35 days. For 2024 (a normal year for traffic), we have about 300,000 unique visitors over the whole year. We're looking at a 100x traffic increase coming in burst of 500 requests in one second each time the proxy botnet gets a payload request. I will strongly look into Anubis ( https://anubis.techaro.lol/) to try to manage load balancing/bots/AI agents on an industrial scale and not applying bandages each time their strategy shifts. But all this distraction makes the server migration a moving target... it should have happened a year ago, still not fully ready EDIT: I'm tired of this flood so I'm creating an IPSET big enough to hold all 16,192,295 proxy botnet IPs + the ones that newly joined the botnet. If your phone can't connect anymore... maybe you have installed an app participating silently to this chaos!Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
|
 |
|
 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum
|
|