HomeNotesBoonEx.com under DDoS attack. UPDATED.
721 days ago in 
Tags: boonex, ddos, admin
 

BoonEx.com under DDoS attack. UPDATED.

As of now, we are at the second day of fighting with an ongoing DDoS attack. Alex and HFW team managed to relief the situation, but there're still some issues (forum feed, occasional slowdowns), and if the patterns happen to change BoonEx.com may be unavailable for some time.

Fret not though, whatever doesn't kill us, makes us stronger. And this is certainly not a kind of thing/people that may kill BoonEx.

UPDATE:

We have finally managed to take the attack under control. Due to some changes we had to make to traffic management some subdomains didn't work, including those that serve licences verification, download, etc. We're fixing it all now. Some of you may have been unable to login to your admin panel, since BoonEx data couldn't load. This problem occurred before due to BoonEx News RSS and license verification. We removed this dependancy some time ago, so Admin panels do not depend on RSS feed or license check. Unfortunately we have overlooked version checking mechanism, which still depends on BoonEx.com. We are really sorry about that. Long time ago our intent was to free your admin panel completely, and this is a misfortunate mistake. We are fixing it in 7.0.2 and in your current installation you may use this workaround: ------- set the following setting option to 0: [8/06/10 9:27:16 AM] Alex Trofimov: Admin -> Settings -> Advances Settings -> Other -> Show boonex news in admin panel ------- NOTE: version check and RSS feed in your admin panel are there for good reason. It is the way for us to notify you if there's something urgent, like a security update or a new version. This is not to spam you, but to inform you, and it can be turned off.

--------------

--------------

Yeah, weekend sucked, but we've learned a great deal. At the very peak they were firing 50Mbps of traffic at us for a few hours. Somebody must have ordered an expensive botnet attack. We almost feel flattered. 

Takeaways from this weekend:

1. We found a few spots that needed improvement. That will help us writing software that performs better.
2. We learned a few performance-tuning tricks for our dedicated server.
3. Found a good 3rd party protection service.
4. Found that pesky version-checking in admin panel.
5. Made a few notes for upcoming Dolphin releases.
6. Figured that we need to get rid of clutter in some (many) places.

All in all, we're good. On to 7.0.2 preparation.

Plussed by

 
 
 
 

Comments

Oldest First
|
Threaded
 
 
Please login to post a comment.
Nathan Paton
I had a feeling this was the culprit of the continued downtime over the last few days. I wonder who'd want to take down the BoonEx web site?
LightWolf
Hmmm..I smell a rat has gotten loose. Wonder who it could be?..Well I have my ideas,but am sorry to see this happening to Boonex.
patrick81
grrrrrr go kill them, boonex. :)
CALTRADE
Who is doing it - and why - does anyone know? I couldn't get on yesterday.
theguypc
It's amazing the trouble some people will go through just to mess up a site.

Good luck guys. Don't let it get you down.
houstonlively
It could be the person that actually said in a blog post about a week ago that they were going to do it
houstonlively
That would be my first guess.
CodeSatori
As for possible motivations --- aside the general DOS in progress --- it's quite possible that this is an attempt to exploit the "database failure leads to compromised DB credentials in the debug output" scenario that has been around for the last few months.

@houston: Someone did mention an umphy botnet at their disposal a while back, yes. Might be a good idea to set up a separate domain/server(s) for redundancy to take over when one server is down. Just set up a script for checking see more current DDOS targeting and rotate servers automatically as necessary.
buckmcgoo
Well no one else has said it so it might as well be me... if you weren't using "Hostforweb" your site's would have been back up MUCH quicker and any other host would have been able to tell you who/what/how this happened... well actually any other host would have been able to stop this as it was happening.
Nathan Paton
@buckmcgoo: What makes you so sure that any other web hosting provider could have done any better? As far as I can tell, they have been stopping it as it is happening (otherwise this web site would still be down). These types of attacks can be difficult to stop, as any web hosting provider, large and small will tell you.
buckmcgoo
This site was down all day yesterday, or at least every time I tried to access it it was down... that is NOT what I call stopping it as it happens. Most providers stop DOS attacks at the hardware level and the users will never know anyone even tried. HFW doesn't stop it at any level. The reason I'm so sure is I tried using them in the past an their tech support didn't know their @ss from their elbow, they couldn't even answer the simplest questions. Kids try this crap every day with "bot nets" see more but it doesn't work if you are using a real host.
houstonlively
CS... I don't think there's any technical motivation. I think it's just that the little voices in their head told them to do it.
annabel
Is this the reason why I can't get into my admin panel ?
gameutopia
Usually it is someone extremely pissed off. You never know though. Plenty of crazy's out there.

I am surprised we haven't seen something like this here before now being dolphin is fairly popular. One of the things any server administrator should look into preventing and might deal with at some point.

Hope you got it tuned up and squared away. You know what they say shit happens!
toasty525
Is this the reason downloads have been disabled ?
tomakali
hmm, real crappy people snooping on boonex beware...
tomakali
i had a chat with HFB and asked them to report this issue to andrew, they asked me to do it myself. as a hosting partner shouldnt they be more supportive on behalf of boonex? something fishy........
marcoart
would this take down access to our own sites admin?
deano92964
Yes. It affects admin access to your site until the licence check times out. After you log into admin, just wait. The timeout can take a while. Give it a couple of minutes it will eventually timeout and finish loading.
 
 
 
PET:0.06655216217041