|
It is currently 15 May 2026, 00:13
|
View unsolved topics | View unanswered posts
 |
|
 |
|
| Author |
Message |
|
signofzeta
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 03 Mar 2026, 09:16 |
| Jedi Knight |
 |
 |
Joined: 14 Jan 2010, 09:44 Posts: 6574 Location: Ann Arbor Has thanked: 1773 times Been thanked: 1478 times
|
admin wrote: signofzeta wrote: Its occurred to me that I have a iPhone 17. Apple introduced the iCloud Private Relay from iOS 15, iPadOS 15, and macOS Monterey from what I read. I only have an iPhone 13 mini, can't test it. CloudFlare also made adjustments: https://blog.cloudflare.com/icloud-private-relay/From what they are describing, my best option was to pre-allow the Private Relay official subnets (already done). These users should not even see the Anubis girl. signofzeta, could you try to re-enable your privacy on your phone and test again? Julien I switched it back on. I’ll update if anything interesting happens.
_________________ All about LD care, inner sleeves, shrink wrap, etc.
https://youtu.be/b3O-vHpHRpM
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 04 Mar 2026, 03:48 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5340 Location: Tokyo Has thanked: 422 times Been thanked: 1733 times
|
After spending some time analyzing the botnet flood, it seems to be composed of 2 different strategies. 1] phpBB forums are attracting IA crawlers like honeyLLMs need "fresh, human, organic" data to avoid re-hashing IA-generated stuff and quickly jump into hallucinations. Websites flagged as old, maintained, text forum are the ideal targets for resource-intensive scraping. Long threads here: What is going on? Is this some kind of widespread attack? (phpbb.com) Some webmasters just block entire countries when attacks start mounting (China, Vietnam, Brazil, etc.) but doing this also block honest people, it's too wide. Others (like myself, initially), tried to block static lists of "bad" IPs ( https://billauer.se/blog/2025/05/phpbb-attack-bots-ip-addresses/) but the profile of a "bad" IP changed over time. It used to be the source of an attack/crawl, now with the residential proxy botnets, it could be anyone coming from any IP. So profiling/challenging is needed and the solution for all these forums was to use CloudFlare or Anubis. 2] Spawning scam shopping websites by leveraging contents, page ranking, then DDOs'ing the original websiteThis is more speculative as I have found no research/analysis/security paper fully documenting this behavior yet. I setup a Google Alert for "Laserdisc Database" a long time ago. It would initially trigger on the website's or forum's URLs. But over time, it would find very, very weird websites offering LDDB's LaserDisc or Hardware entry pages to Google. Recent ones -- last few days: - Siouxsie & The Banshees /レーザーディスク LaserDisc Database on jordanianschoolqatar.com - takes you to sebdi.lcbyfgnt.club
- LaserDisc Database - Hardware - Denon - DCD-1650AE on cardioser.com.br - takes you to lues.tradese.shop
- LaserDisc Database - Hardware - Sony - HIL-C2EX on cartecadeaupf.com - takes you to janty.kiloar.hair
- LaserDisc Database Hardware Sony MDP-V7 on tomek-vyroba.cz - takes you to blikeuhij.click
- LaserDisc Database - Hardware - CLD-A100 on nstitutoorange.com.br -- website has been disarmed
- Etc.
You get the picture. Obviously something is off. I think this is how the scam works: - Hack a website (preferred target being badly maintained/configured WordPress sites) - Site A
- Harvest legit contents like LD or Hardware from LDDb - Site B
- Allow Google known IPs to retrieve Site B's contents as if it was just a clone website (Google will understand that) on Site A
- Site A's scam URLs get added to Google search/IA leaning base, maybe even leveraging the Page Ranking from Site B
- When a visitor comes a specific country (by IP), redirect them over the scam website - Site C
- When a visitor comes from an un-handled country, just show an empty page.
- Use a cheap residential proxy server to try to DDOS the original Site B to bring it down and make Site C look more legit to Google.
The scam websites are looking like a typical eCommerce website with KILLER prices, many ways to pay, and leverage contents found on eBay, Yahoo Auction, etc. to populate their fake inventories. The domains are very recently registered for cheap and probably existing in thousands, with disposable subdomains. I'm sure your payment will be gladly accepted... and nothing delivered. Or the credit card data will be immediately used for something else, or sold to another scam team as "fresh". One more reason to block bots from harvesting LDDb.com! and... 3] Automated forum account creation + SPAM postingBecause of the way LDDb forum is organized as sub-section or LDDb and automatically creates/syncs forum accounts with your LDDb account, we are not subject to this kind of attack. You simply cannot create a separate forum account. Some poor countries (Bangladesh, Cambodia, India, etc.) sometimes take the time and effort to manually setup a LDDb accoun just to be able to post a few SPAM links but we usually detect them quickly and the post/accounts are promptly deleted. It's a minor nuisance compared to the botnets. Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
chrisw6atv
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 04 Mar 2026, 19:47 |
| True fan |
 |
 |
Joined: 28 Sep 2023, 06:27 Posts: 365 Location: Hayward, California USA Has thanked: 226 times Been thanked: 141 times
|
|
It is really sad, the levels of complexity that disgusting people will go to, to damage or ruin the experiences of people worldwide in sleazy attempts to steal from even a tiny percentage of them. I just cannot understand the complete lack of basic human decency such people have. How do these people "sleep with their own knowledge at night"? No matter how hungry, or how "poor", or how jealous anyone is, their parent(s) must have taught them better behavior, most of us would think.
Julien, I have a new, higher level of respect and appreciation of everything you do to keep this site and community going. You (and your assistants/partners, if you have any) are a wonderful "antidote" to the knowledge that the people I mentioned above exist. --Thank you!--
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 09 Mar 2026, 16:24 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5340 Location: Tokyo Has thanked: 422 times Been thanked: 1733 times
|
and... the botnets found a way to pass through Anubis and hammer the forum again :-/ This is the global traffic on the forum (humans + bots): Attachment:
forum-all.png [ 20.86 KiB | Viewed 115 times ]
And previously Anubis was filtering 99.5% of the traffic... not anymore, the logs starting filling up almost immediately after I restart Anubis to force re-challenge... Attachment:
forum-anubis.png [ 24.12 KiB | Viewed 115 times ]
It's never-ending. Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 11 Mar 2026, 02:23 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5340 Location: Tokyo Has thanked: 422 times Been thanked: 1733 times
|
benmbe wrote: I received a couple of emails conveying that there had been issues with Singapore server problems etc. Singapore server?? Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
admin
|
Post subject: Re: Sessions table crashed, forum was offline (Botnet attack  Posted: 14 Apr 2026, 10:26 |
| Site Admin |
 |
 |
Joined: 07 Aug 2002, 23:37 Posts: 5340 Location: Tokyo Has thanked: 422 times Been thanked: 1733 times
|
The good news is that the aggressive botnets slowed down to a reasonable level in the past few weeks. That's a relief. We are only blocking ~140K IPs on average from the usual suspicious probes/scans/hits. The (soon-to-be) bad news is that the test Forum on the news server was only up for a few weeks before being put offline... But we are already getting constants hits from botnets to harvest everything under the sun they can take from the forum. Since the forum is offline, I block these obviously impossible hits on non-existing URLs with impossible referrer URLs. And we are already blocking ~300K IPs even though there is *nothing* to harvest there anymore! I guess any website identified as a phpBB3 forum will be put on the "archive it all" botnet list  Julien
_________________ HARDWARE DATABASE HLD-X0/9 LD-S9 OPPO 105/205 SL-1200G MSD4 MSC-4000 R2144 PONTUS II C45 MC257
|
|
|
|
 |
|
|
 |
|
 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum
|
|