Home  |  Forums  |  914 Info  |  Blogs
 
914World.com - The fastest growing online 914 community!
 
Porsche, and the Porsche crest are registered trademarks of Dr. Ing. h.c. F. Porsche AG. This site is not affiliated with Porsche in any way.
Its only purpose is to provide an online forum for car enthusiasts. All other trademarks are property of their respective owners.
 

Welcome Guest ( Log In | Register )

5 Pages V < 1 2 3 4 5 >  
Reply to this topicStart new topic
> Another DDoS attack on the site, Just in time for the new year
SirAndy
post Feb 14 2025, 11:58 AM
Post #41


Resident German
*************************

Group: Admin
Posts: 42,429
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(technicalninja @ Feb 14 2025, 09:52 AM) *

@SirAndy
What is the purpose of a DDoS attack on a site like this?
Looks like work with no gain to me.
Why is it worth their time to jack up a niche site?

My guess is they are probably doing a test run for some major attack on some valuable targets.
These are quite literally distributed attacks from thousands of hacked computers all around the world.

They're probably doing these tests to make sure they still have control over those computers before launching the real attack.
(IMG:style_emoticons/default/dry.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
emerygt350
post Feb 14 2025, 12:08 PM
Post #42


Advanced Member
****

Group: Members
Posts: 3,457
Joined: 20-July 21
From: Upstate, NY
Member No.: 25,740
Region Association: North East States



QUOTE(SirAndy @ Jan 3 2021, 03:17 AM) *

QUOTE(nathanxnathan @ Jan 2 2021, 11:56 PM) *
With all the hacker issues 914world has had over the years, I've often wondered why it's still "not secure" like it won't load as https:, and says not secure in my browser. -no ssl certificate.

I'm not sure if that would help this specific kind of attack.

One thing it does cause that seems odd is when Chrome browser puts it up on the homepage of frequently viewed sites, it won't click through because it defaults to https and https://www.914world.com oddly doesn't go to the site - it doesn't even redirect.

HTTPS does not make the site any more "secure", all it means is that the data is encrypted on the way from the site to your computer.

And since we're not dealing with sensitive information, unlike your bank for example, i don't see any reason to pay for a SSL certificate.

It literally does *nothing* to make the site less vulnerable to any of these attacks.
(IMG:style_emoticons/default/shades.gif)

My college got hit yesterday and this morning as well. They ended up blocking several countries in order to stop it.

After 24 years I finally updated my servers to ssl last week, solely because many browsers do their best to not allow you to see old http no matter how non-sensitive the content. I get free certificates from the EFF and use the certbot to update the ssl certs automatically. I was surprised at how easy it all was. Pretty much four lines of instructions and that was done. This was on linux and apache2.

As far as the bad guys... I use a perl script to watch requests in the auth_log and when I cared the access.log for apache2. Somebody asks for something stupid I would block them from all ports in iptables. I don't really care about idiots on the webserver so I don't bother with it now but if they try to log in on ssh I block them from everything.

Even that won't protect you from ddos of course but at least it makes me feel good. I free them after a few days to keep the iptables sane.


Attached Image
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
technicalninja
post Feb 14 2025, 12:10 PM
Post #43


Advanced Member
****

Group: Members
Posts: 2,531
Joined: 31-January 23
From: Granbury Texas
Member No.: 27,135
Region Association: Southwest Region



Thank you for the reply.

Also THANK YOU for being our defense!

Seems silly IMO to target such a site as 914world.

Like mugging an 85-year-old woman!
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
ClayPerrine
post Feb 14 2025, 12:12 PM
Post #44


Life's been good to me so far.....
***************

Group: Admin
Posts: 16,542
Joined: 11-September 03
From: Hurst, TX.
Member No.: 1,143
Region Association: NineFourteenerVille



QUOTE(emerygt350 @ Feb 14 2025, 12:08 PM) *

QUOTE(SirAndy @ Jan 3 2021, 03:17 AM) *

QUOTE(nathanxnathan @ Jan 2 2021, 11:56 PM) *
With all the hacker issues 914world has had over the years, I've often wondered why it's still "not secure" like it won't load as https:, and says not secure in my browser. -no ssl certificate.

I'm not sure if that would help this specific kind of attack.

One thing it does cause that seems odd is when Chrome browser puts it up on the homepage of frequently viewed sites, it won't click through because it defaults to https and https://www.914world.com oddly doesn't go to the site - it doesn't even redirect.

HTTPS does not make the site any more "secure", all it means is that the data is encrypted on the way from the site to your computer.

And since we're not dealing with sensitive information, unlike your bank for example, i don't see any reason to pay for a SSL certificate.

It literally does *nothing* to make the site less vulnerable to any of these attacks.
(IMG:style_emoticons/default/shades.gif)

My college got hit yesterday and this morning as well. They ended up blocking several countries in order to stop it.

After 24 years I finally updated my servers to ssl last week, solely because many browsers do their best to not allow you to see old http no matter how non-sensitive the content. I get free certificates from the EFF and use the certbot to update the ssl automatically. I was surprised at how easy it all was. Pretty much four lines of instructions and that was done. This was on linux and apache2.

As far as the bad guys... I use a perl script to watch requests in the auth_log and when I cared the access.log for apache2. Somebody asks for something stupid I would block them from all ports in iptables. I don't really care about idiots on the webserver so I don't bother with it now but if they try to log in on ssh I block them from everything.

Even that won't protect you from ddos of course but at least it makes me feel good. I free them after a few days to keep the iptables sane.


Attached Image


I actually prefer to firewall off the outside world, only allowing HTTP and HTTPS to the server. Then forcibly redirect the HTTP to HTTPS. Any SSH access comes in from the internal network.


User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Feb 14 2025, 12:17 PM
Post #45


Resident German
*************************

Group: Admin
Posts: 42,429
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(emerygt350 @ Feb 14 2025, 10:08 AM) *
... Somebody asks for something stupid I would block them from all ports in iptables ...

The problem with the IP based approach is that they have hundreds of thousands of different computers at their disposal. Each one having a different source IP. And that's before taking IP spoofing into account.

For example, last nights attack came from about 280,000 unique IPs.
Not sure your iptable would be able to handle that.

I've given up on IP based rejection or filtering a long time ago and moved on to other measures.

The one last night did catch me by surprise though as they have been changing their tactics lately.
(IMG:style_emoticons/default/shades.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Shivers
post Feb 14 2025, 12:20 PM
Post #46


Senior Member
****

Group: Members
Posts: 3,259
Joined: 19-October 20
From: La Quinta, CA
Member No.: 24,781
Region Association: Southern California



QUOTE(SirAndy @ Feb 14 2025, 10:17 AM) *

QUOTE(emerygt350 @ Feb 14 2025, 10:08 AM) *
... Somebody asks for something stupid I would block them from all ports in iptables ...

The problem with the IP based approach is that they have hundreds of thousands of different computers at their disposal. Each one having a different source IP. And that's before taking IP spoofing into account.

For example, last nights attack came from about 280,000 unique IPs.
Not sure your iptable would be able to handle that.

I've given up on IP based rejection or filtering a long time ago and moved on to other measures.

The one last night did catch me by surprise though as they have been changing their tactics lately.
(IMG:style_emoticons/default/shades.gif)


This may be a silly question Andy, but why would they do this to you? Because they can?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Feb 14 2025, 12:22 PM
Post #47


Resident German
*************************

Group: Admin
Posts: 42,429
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(Shivers @ Feb 14 2025, 10:20 AM) *
This may be a silly question Andy, but why would they do this to you? Because they can?

Answered above:
http://www.914world.com/bbs2/index.php?s=&...t&p=3191875
(IMG:style_emoticons/default/bye1.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
ClayPerrine
post Feb 14 2025, 12:24 PM
Post #48


Life's been good to me so far.....
***************

Group: Admin
Posts: 16,542
Joined: 11-September 03
From: Hurst, TX.
Member No.: 1,143
Region Association: NineFourteenerVille



Keeping hackers, spammers and script kiddies out of any IT system is like playing whack-a-mole. You legally cannot attack. All you can do is play defense and kill their attack when it pops up. If the government would allow us to make retaliatory attacks and actually go after them on their home systems without us get prosecuted, it would deter the hackers from a lot of their attacks.

But we are the good guys, so we can't.

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
technicalninja
post Feb 14 2025, 12:42 PM
Post #49


Advanced Member
****

Group: Members
Posts: 2,531
Joined: 31-January 23
From: Granbury Texas
Member No.: 27,135
Region Association: Southwest Region



QUOTE(ClayPerrine @ Feb 14 2025, 12:24 PM) *

Keeping hackers, spammers and script kiddies out of any IT system is like playing whack-a-mole. You legally cannot attack. All you can do is play defense and kill their attack when it pops up. If the government would allow us to make retaliatory attacks and actually go after them on their home systems without us get prosecuted, it would deter the hackers from a lot of their attacks.

But we are the good guys, so we can't.


This is disturbing...

The internet COULD be more secure if it was "fair".

This is something that should be looked into.

In a modern country the weakest link IS the Internet.

Take it out and chaos would result.

It SHOULD have oversite from an organization that can use ANYTHING to promote stability.

Setting up that organization might be difficult.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Feb 14 2025, 12:46 PM
Post #50


Resident German
*************************

Group: Admin
Posts: 42,429
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(technicalninja @ Feb 14 2025, 10:42 AM) *

The internet COULD be more secure if it was "fair".

LoL and who would you trust to decide what "fair" means?

Hitting them back isn't an easy task by any means.
The days of script kiddies doing this in their parents basements are long gone.
Today, these attacks are run by organized crime and governments (sometimes one and the same).

And just to reiterate my point above, the computers these attacks come from belong to ordinary people who have no clue their computer/device is even hacked.

So you can't go after the individual sources of the attacks. You have to find who is controlling them. And that part is exceedingly difficult.
(IMG:style_emoticons/default/shades.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Feb 14 2025, 01:12 PM
Post #51


Resident German
*************************

Group: Admin
Posts: 42,429
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



And they are back ...
(IMG:style_emoticons/default/ar15.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
emerygt350
post Feb 14 2025, 03:26 PM
Post #52


Advanced Member
****

Group: Members
Posts: 3,457
Joined: 20-July 21
From: Upstate, NY
Member No.: 25,740
Region Association: North East States



Yeah, ip level is tough. At one point I was blocking whole blocks. I can't keep ssh internal only but having 23 and 443 as the only ports help.

I remember back in the past century trying stuff like sending back Christmas tree scans on attacking ips but nowadays there is nobody home to care if your prey is trying to fight back. What are you going to do? Crack 250000 computers?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
ClayPerrine
post Feb 15 2025, 05:49 AM
Post #53


Life's been good to me so far.....
***************

Group: Admin
Posts: 16,542
Joined: 11-September 03
From: Hurst, TX.
Member No.: 1,143
Region Association: NineFourteenerVille



QUOTE(emerygt350 @ Feb 14 2025, 03:26 PM) *

Yeah, ip level is tough. At one point I was blocking whole blocks. I can't keep ssh internal only but having 23 and 443 as the only ports help.

I remember back in the past century trying stuff like sending back Christmas tree scans on attacking ips but nowadays there is nobody home to care if your prey is trying to fight back. What are you going to do? Crack 250000 computers?



The trick would be taking over one of the attacking machines and using that to find the control computer. Then go after it.

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
JamesM
post Feb 15 2025, 02:45 PM
Post #54


Advanced Member
****

Group: Members
Posts: 2,180
Joined: 6-April 06
From: Kearns, UT
Member No.: 5,834
Region Association: Intermountain Region



QUOTE(technicalninja @ Feb 14 2025, 11:42 AM) *


This is disturbing...

The internet COULD be more secure if it was "fair".

This is something that should be looked into.

In a modern country the weakest link IS the Internet.

Take it out and chaos would result.

It SHOULD have oversite from an organization that can use ANYTHING to promote stability.

Setting up that organization might be difficult.



What is your favorite flavor of kool-aid? Hopefully the one you have been getting served.

Seriously though as someone who has spent the last 30 years in tech including for major internet and streaming providers, what you are bringing up is money driven politics. Unfortunately though, from a technical standpoint, giving huge monopolistic companies the ability to throttle traffic of their competitors would do very little to increase anyone's site security no matter how much Fox News and Newsmax say otherwise.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Feb 15 2025, 05:38 PM
Post #55


Resident German
*************************

Group: Admin
Posts: 42,429
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



We're still being attacked ...
(IMG:style_emoticons/default/sad.gif)

I'm going to take the site offline for a while and try something that hopefully will solve some of our crashing issues.

Fingers crossed i won't break anything.
(IMG:style_emoticons/default/popcorn[1].gif)

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Feb 15 2025, 06:17 PM
Post #56


Resident German
*************************

Group: Admin
Posts: 42,429
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(SirAndy @ Feb 15 2025, 03:38 PM) *

We're still being attacked ...
(IMG:style_emoticons/default/sad.gif)

I'm going to take the site offline for a while and try something that hopefully will solve some of our crashing issues.

Fingers crossed i won't break anything.
(IMG:style_emoticons/default/popcorn[1].gif)

Anyone having any weird issues with the site?
(IMG:style_emoticons/default/idea.gif)

Seems to be working OK for now.
(IMG:style_emoticons/default/chowtime.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
windforfun
post Feb 15 2025, 06:58 PM
Post #57


Advanced Member
****

Group: Members
Posts: 2,091
Joined: 17-December 07
From: Blackhawk, CA
Member No.: 8,476
Region Association: None



QUOTE(SirAndy @ Feb 14 2025, 09:58 AM) *

QUOTE(technicalninja @ Feb 14 2025, 09:52 AM) *

@SirAndy
What is the purpose of a DDoS attack on a site like this?
Looks like work with no gain to me.
Why is it worth their time to jack up a niche site?

My guess is they are probably doing a test run for some major attack on some valuable targets.
These are quite literally distributed attacks from thousands of hacked computers all around the world.

They're probably doing these tests to make sure they still have control over those computers before launching the real attack.
(IMG:style_emoticons/default/dry.gif)


Is my PC going to get hijacked?

(IMG:style_emoticons/default/dry.gif) (IMG:style_emoticons/default/dry.gif) (IMG:style_emoticons/default/dry.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Feb 15 2025, 07:00 PM
Post #58


Resident German
*************************

Group: Admin
Posts: 42,429
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(windforfun @ Feb 15 2025, 04:58 PM) *
Is my PC going to get hijacked?

(IMG:style_emoticons/default/confused24.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
mgp4591
post Feb 15 2025, 07:10 PM
Post #59


914 Guru
*****

Group: Members
Posts: 5,882
Joined: 1-August 12
From: Salt Lake City Ut
Member No.: 14,748
Region Association: Intermountain Region



If that's what needs to be done, shut er down for a bit. Any idea when or how long? It's not a big deal so whenever you need to.
Thanks for keeping us as safe as you can! (IMG:style_emoticons/default/beerchug.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post Feb 15 2025, 07:15 PM
Post #60


Resident German
*************************

Group: Admin
Posts: 42,429
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



QUOTE(mgp4591 @ Feb 15 2025, 05:10 PM) *

If that's what needs to be done, shut er down for a bit. Any idea when or how long? It's not a big deal so whenever you need to.
Thanks for keeping us as safe as you can! (IMG:style_emoticons/default/beerchug.gif)

Already done ... (IMG:style_emoticons/default/biggrin.gif)
Waiting for the next attack to see if it makes a difference.

I think i'm going to pour myself some medicinal Jägermeister.
(IMG:style_emoticons/default/beer3.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

5 Pages V < 1 2 3 4 5 >
Reply to this topicStart new topic
3 User(s) are reading this topic (3 Guests and 0 Anonymous Users)
0 Members:

 



- Lo-Fi Version Time is now: 15th February 2026 - 05:41 AM
...