Stardot hit by an attack over the weekend

Blogs & guides and tales of woo by forum members.
User avatar
exxos
Site Admin
Site Admin
Posts: 28344
Joined: 16 Aug 2017 23:19
Location: UK

Re: Stardot hit by an attack over the weekend

Post by exxos »

rubber_jonnie wrote: 14 Jul 2025 11:55 Not really fun for what probably isn't your full time job...
Yeah..

I didn't mind doing it, it was a lot of work but I learned a lot and was a bit of fun playing whack a mole :lol: Frustrating mostly due to the amount of time things take.. Like everything takes 100x longer than it should. I'm so far behind with everything it's unreal.

The logs end up so big that you can only spot the largest attacks first.. You deal with them, go back the next day and same again.. And again. And again..

It's why I used AI to write scripts to look though the logs for stuff which doesn't match predictable patterns. Like if there's millions of 404s from similar ip ranges then every IP range is checked to see how many other odd things are going on.. Long story short, I have a list of what was blocked and why plus what was flagged as suspect for me to decide manually.

What I mostly see is just a couple small number of ip addresses that only hit the server a couple times a day and just not worth bothering with. I'm blocking like 99℅ of all known attacks. If a attack isn't caught with the current rules then I get a list of suspect IP addresses to either do new rule or ignore them.

The server CPU is pretty much idle all the time now. Before it was maxing out a 4 core CPU trying to deal with all the traffic.

Only time the server may go down is during disk backups or kernel updates. It actually happens about once or twice a week.

I do keep an eye on things but people will have to let me know if the server is running slow constantly... It could mean something has got past my rules... But i haven't had to do any new rules for a while now. It's just a matter of "what's next" in the world of attacks..
User avatar
rubber_jonnie
Site Admin
Site Admin
Posts: 14888
Joined: 17 Aug 2017 19:40
Location: Essex

Re: Stardot hit by an attack over the weekend

Post by rubber_jonnie »

exxos wrote: 15 Jul 2025 11:54 I do keep an eye on things but people will have to let me know if the server is running slow constantly... It could mean something has got past my rules... But i haven't had to do any new rules for a while now. It's just a matter of "what's next" in the world of attacks..
You know me, I'll be messaging you as soon as I see something off :)
Collector of many retro things!
800XL and 65XE both with Ultimate1MB,VBXL/XE & PokeyMax, SIDE3, SDrive Max, 2x 1010 cassette, 2x 1050 one with Happy mod, 3x 2600 Jr, 7800 and Lynx II
Approx 20 STs, including a 520 STM, 520 STFMs, 3x Mega ST, MSTE & 2x 32 Mhz boosted STEs
Plus the rest, totalling around 50 machines including a QL, 3x BBC Model B, Electron, Spectrums, ZX81 etc...
User avatar
exxos
Site Admin
Site Admin
Posts: 28344
Joined: 16 Aug 2017 23:19
Location: UK

Re: Stardot hit by an attack over the weekend

Post by exxos »

rubber_jonnie wrote: 15 Jul 2025 13:19 You know me, I'll be messaging you as soon as I see something off :)
Indeed you do, its most helpful :)
User avatar
rubber_jonnie
Site Admin
Site Admin
Posts: 14888
Joined: 17 Aug 2017 19:40
Location: Essex

Re: Stardot hit by an attack over the weekend

Post by rubber_jonnie »

exxos wrote: 15 Jul 2025 14:07
rubber_jonnie wrote: 15 Jul 2025 13:19 You know me, I'll be messaging you as soon as I see something off :)
Indeed you do, its most helpful :)
Was there anything going on around about an hour ago? I couldn't get on the site.
Collector of many retro things!
800XL and 65XE both with Ultimate1MB,VBXL/XE & PokeyMax, SIDE3, SDrive Max, 2x 1010 cassette, 2x 1050 one with Happy mod, 3x 2600 Jr, 7800 and Lynx II
Approx 20 STs, including a 520 STM, 520 STFMs, 3x Mega ST, MSTE & 2x 32 Mhz boosted STEs
Plus the rest, totalling around 50 machines including a QL, 3x BBC Model B, Electron, Spectrums, ZX81 etc...
User avatar
exxos
Site Admin
Site Admin
Posts: 28344
Joined: 16 Aug 2017 23:19
Location: UK

Re: Stardot hit by an attack over the weekend

Post by exxos »

rubber_jonnie wrote: 15 Jul 2025 14:55 Was there anything going on around about an hour ago? I couldn't get on the site.
Yeah, 12:51 SQL backup. The database will freeze for a few moments during backup :) The backup happens every 3 or 4 hours during the day.
User avatar
rubber_jonnie
Site Admin
Site Admin
Posts: 14888
Joined: 17 Aug 2017 19:40
Location: Essex

Re: Stardot hit by an attack over the weekend

Post by rubber_jonnie »

exxos wrote: 15 Jul 2025 15:01
rubber_jonnie wrote: 15 Jul 2025 14:55 Was there anything going on around about an hour ago? I couldn't get on the site.
Yeah, 12:51 SQL backup. The database will freeze for a few moments during backup :) The backup happens every 3 or 4 hours during the day.
Okey Dokey
Collector of many retro things!
800XL and 65XE both with Ultimate1MB,VBXL/XE & PokeyMax, SIDE3, SDrive Max, 2x 1010 cassette, 2x 1050 one with Happy mod, 3x 2600 Jr, 7800 and Lynx II
Approx 20 STs, including a 520 STM, 520 STFMs, 3x Mega ST, MSTE & 2x 32 Mhz boosted STEs
Plus the rest, totalling around 50 machines including a QL, 3x BBC Model B, Electron, Spectrums, ZX81 etc...
User avatar
exxos
Site Admin
Site Admin
Posts: 28344
Joined: 16 Aug 2017 23:19
Location: UK

Re: Stardot hit by an attack over the weekend

Post by exxos »

I can actually see a "new problem".. These are not in time order, but IP order.. Basically loads beginning with 45.xxx.xxx.xxx , What they are doing is using 1 IP to hit a link once per day by the looks of it. They triggering 404, but only once. So they get around the firewall rules because they are rotating IPs all the time now :roll:

I can add a rule to block those easy enough. They not really bothering anything currently.. just making a mess of my logs :lol: :roll:


Capture.PNG
You do not have the required permissions to view the files attached to this post.
User avatar
exxos
Site Admin
Site Admin
Posts: 28344
Joined: 16 Aug 2017 23:19
Location: UK

Re: Stardot hit by an attack over the weekend

Post by exxos »

Looks like we was hit pretty hard recently as well, almost 68,000 IPs in the reporting queue now...

Capture.PNG


It really paints a picture on how things just get worse as time goes on.


Whats also somehow "worrying" is the IPs I am reporting a lot of the time are not even in the abuseipdb :shrug:
You do not have the required permissions to view the files attached to this post.
User avatar
exxos
Site Admin
Site Admin
Posts: 28344
Joined: 16 Aug 2017 23:19
Location: UK

Re: Stardot hit by an attack over the weekend

Post by exxos »

Something has happened literally just, because the abuse list I download is normally like 300 ips per 3 hours, its just jumped to 41,000 IPs. I only download the worst ones as well.

My own server has found over 70,000 IPs to block so far today (there are no duplicates either!) . Normally its more like around 2,000 -5,000 per day.

A lot of them seem to originate from Brazil, but we are being hammered from all over the world...

Capture.PNG

Incidentally I only report IPs once every two seconds.. I've just changed the script to report every second as there's over 70,000 IPs in the queue so far and its going up faster than they are getting reported !
You do not have the required permissions to view the files attached to this post.
User avatar
exxos
Site Admin
Site Admin
Posts: 28344
Joined: 16 Aug 2017 23:19
Location: UK

Re: Stardot hit by an attack over the weekend

Post by exxos »

Now its signup bots..

Capture.PNG

Oh its back onto other stuff now.. its pretty interesting in a really boring kind way :P

Capture.PNG
You do not have the required permissions to view the files attached to this post.

Return to “MEMBER BLOGS”

Who is online

Users browsing this forum: ClaudeBot, Google [Bot] and 9 guests