Author Topic: Forum was DDOS'ed, by... frustrated.?. (cr)/hackers...  (Read 6389 times)

0 Members and 1 Guest are viewing this topic.

Offline Wolvenar

  • Senior Moderator
  • Hero Member
  • *******
  • Posts: 1474
  • Karma: +40/-0
  • Mr. Murphys pawn
Forum was DDOS'ed, by... frustrated.?. (cr)/hackers...
« on: September 09, 2012, 01:07:15 am »
It appears that someone does not like us much.

Yesterday morning at about  3:30AM CDT someone with access to what is likely a botnet decided either this forum is unworthy, or they did not like me personally. The logs are huge, and I have not slept  in 2 days, mostly up all last night trying to remotely figure out why this was down.
It seems from skimming and some work with awk searching the logs,
The site was hit with a number of attacks not just a DDOS

My overall thoughts on this are it was done by a script kiddy with either friends in low places, or he otherwise has access to a botnet.
I do not think that if this were a very serious hacker he would have been so easily defeated.

This all seems to have began with a single chinese IP -
 (listed here) http://www.projecthoneypot.org/ip_123.156.184.43
-crawling the site for poster names.
Then a large number of other IP addresses were attempting the normal stupid passwords people use like password, and then a short lived dictionary attack on a few users ( I was one),
This appears to have failed at getting them any sort of user access, but it did lock out all the users on the system.
 
While this was going on, a number of other things were happening such as automated registration attempts.

 Thanks to some of RossW's keen scripting skills early in the initial deployment of this forum there was a bit of added security that was banning the IPs of pretty much all these bot attempts.
These failed at the gates as well because of those hard things it makes you do and everyone complains about it when registering.

Other things like cross site scripting vulnerabilities were being tested.
Judging by the random nature and timing, these were likely being performed by hand.
Other vulnerabilities in packages that may or may not be installed on here were being searched out by bots as well.
This is common but at this particular time it was not the hit and miss stuff every half hour to couple of hours it was a consistent onslaught buried in the other things going on.

I had a database backup of only an hour before hand, so I took a backup of the live one after this event, and then rolled back to that recent earlier backup in order to unblock all the users, and fix a few other things that were kinda made a mess from all the data generated.

None of these troubles were serious, but all added up to a significant amount of repair/recovery time and would leave annoying relics.
Restoring  the backup easily avoided all of this, without any major loses, if any.

I have not gotten all the details worked out but to sum it up.
In under an hour of the initial attack looking for server vulnerabilities the log files racked up a couple hundred meg of data.
It seems that these attack(s) failed to get what they wanted.
Frustrated the attacker decided to DDOS'ed the site to take it offline,, as it remained until just seconds after midnight when the entire attack completely halted.

Now to make matters worse I was on a trip across the state when this all went down.
My first thoughts and concerns were that the RE system failed. ( nope rock solid).
I also had fears the house had caught fire, so I woke up the neighbors at 4 in the morning to go check on my house   
(sorry, and thank you)

I have to thank RossW for his help and offers in this matter, I very much appreciate all your help always.

Plus thank and also apologize to my bandwidth provider for helping to get back online once I got home and the help plus coordination letting me know when the attack had seemed to actually stop.
I had to know so I could reverse certain things I did to try to stop some of the data flow that was even hurting their massive pipe..

They REALLY took a major hit over this one.. MASSIVE amounts of data where launched at this site.
Hopefully they don't decide I am somehow liable for any costs they might have incurred. (YIPE)

I sincerely hope whomever did this leaves us alone in the future.
We have nothing here of interest that is worth your time or the resources you expended to do this. 


Sorry to all of you that had to go the day wondering..
Thanks for sticking it out those of you.


Trying to make power from alternative energy any which way I can.
Just to abuse what I make. (and run this site)

Offline WooferHound

  • Technowhiz
  • Global Moderator
  • Hero Member
  • ******
  • Posts: 897
  • Karma: +40/-3
  • Huntsville Alabama USA
    • My personal webpage
Re: Forum was DDOS'ed, by... frustrated.?. (cr)/hackers...
« Reply #1 on: September 09, 2012, 11:48:09 am »
I could'nt sleep last night and I was trying to login around 3:AM-central last night.
Kept saying "can't connect, time out" or something like that.
I did sound & lights for a music festival yesterday and was too exhausted to try and alert the IRC channel.
Glad to hear that there was a very recent backup.
----- W o o f e r h o u n d -----
My Renewable Energy Projects

Offline MadScientist267

  • Impossible Condition Curator
  • Hero Member
  • *****
  • Posts: 1514
  • Karma: +44/-4
  • Rules? What rules?
Re: Forum was DDOS'ed, by... frustrated.?. (cr)/hackers...
« Reply #2 on: September 09, 2012, 01:01:32 pm »
Tis ok Woof - I alerted them, but there was little that could be done on any kind of immediate level.

It was quite a mess as viewed on IRCtv last night and yesterday. Looks like its back up and going, with the exception of a few hiccups I hit this morning, and confirmed by a few others.

The question still left in my mind (and a few besides me) is why AP? There were several theories that got tossed around, but we may never know the truth for sure.

Lets just hope they've had their fun, whoever it was, and the last of it is done and over with.

 :-\

Steve
Wanted: Schrödinger's cat, dead and alive.

Offline Wolvenar

  • Senior Moderator
  • Hero Member
  • *******
  • Posts: 1474
  • Karma: +40/-0
  • Mr. Murphys pawn
Re: Forum was DDOS'ed, by... frustrated.?. (cr)/hackers...
« Reply #3 on: September 09, 2012, 01:09:51 pm »
Fyi the hiccups were intentional by me.
 There were some things I found in the logs of the occurance that concerned me.
 I took it down until I could work out a propper defence

Nothing seemed breached.
Just I dont want to take the chance in the future it wouldnt be .
Still going on little sleep here...  :-\
Trying to make power from alternative energy any which way I can.
Just to abuse what I make. (and run this site)

Offline Watt

  • Sr. Member
  • ****
  • Posts: 261
  • Karma: +11/-1
  • Over qualified in the inexperience department!
Re: Forum was DDOS'ed, by... frustrated.?. (cr)/hackers...
« Reply #4 on: September 10, 2012, 09:42:37 pm »
Thank you for your hard work Wolv, Ross and everyone else involved.   ;)
CEO of this Dis-Organization....

Offline Norm

  • Sr. Member
  • ****
  • Posts: 475
  • Karma: +26/-0
  • Today is the day you worried about yesterday.
Re: Forum was DDOS'ed, by... frustrated.?. (cr)/hackers...
« Reply #5 on: September 10, 2012, 10:34:10 pm »
Thanks guys....this is all the forum I got and I want to keep it !
Norm.

Offline Wolvenar

  • Senior Moderator
  • Hero Member
  • *******
  • Posts: 1474
  • Karma: +40/-0
  • Mr. Murphys pawn
Re: Forum was DDOS'ed, by... frustrated.?. (cr)/hackers...
« Reply #6 on: September 10, 2012, 10:45:21 pm »
Well today Godaddy got hit, the registrar of this site..
I did not notice it if the site was affected, but many others I have out there were.
So yet another day of ppl breathing down my neck, and I was again close to helpless to do anything about it.

This is getting old.


--EDIT--

This site was NOT affected, as I also host the DNS, it was GoDaddy's DNS servers that were targeted yesterday.
The registrar system that changes the records in the root servers was apparently unaffected,  with exception of the inability to access them and make changes.

Trying to make power from alternative energy any which way I can.
Just to abuse what I make. (and run this site)

Offline tomw

  • Not as bad as you might think
  • Senior Moderator
  • Hero Member
  • *******
  • Posts: 739
  • Karma: +35/-0
  • hoplophobic people will fear my lifestyle
    • Zubbly's photos!
Re: Forum was DDOS'ed, by... frustrated.?. (cr)/hackers...
« Reply #7 on: September 11, 2012, 06:49:46 am »
Godaddy seems to spend more cash on busty cutie pie advertisements than competent techs, I guess.

Do NOT mistake me for any kind of "expert".

( ?° ?? ?°)


24 Trina 310 watt modules, SMA SunnyBoy 7.7 KW Grid Tie inverter.

I thought that they were angels, but much to my surprise, We climbed aboard their starship and headed for the skies