Re: Server updates
Posted: 10 Mar 2026 15:56
Our largest DOS attack yet.
Over 167,000 IPs on top of that. Seem to be coming from Asia.
It's bad enough with a mobile IPs because one moment they are good traffic and the next moment they are bad traffic and because of the sheer amount of them I just have no choice but to block them in order to get server online. They are basically infected networks in my book. Similar with all the malware in consumer devices like we have seen before. The actual home user might actually be a legitimate use above their network is infected where again I just have to block it. There's simply nothing I can do about infected networks.Even more evidently clear that pretty much every site I go on now is behind cloudflare. Sign of the times...
In other news, certificates which use GETSSL, stopped working. For some bizarre reason the binary had completely disappeared!! So just had to reinstall it! :crazy:
Also Grok suggested some fixes to make the SQL database queries a bit more efficiently seem to have helped a lot as well.
Well, that's the best part of my day gone again now :roll:
Over 167,000 IPs on top of that. Seem to be coming from Asia.
Started running my botnet scripts every half an hour in order to keep on top of it all.. The amount of IP's is just mind blowing along with the ranges of them..General pattern from your list
Most of the large /16 blocks you’re blocking are consumer ISP address pools — especially:
PLDT / Philippines ISP networks (multiple 112.x and 49.x blocks)
Other APNIC‑allocated Asia blocks (e.g., 223.x, 14.x) likely belonging to regional carriers or ISPs.
This aligns with typical botnet behavior, where malware on consumer devices (home routers, PCs) in large ISP blocks generate traffic.
It's bad enough with a mobile IPs because one moment they are good traffic and the next moment they are bad traffic and because of the sheer amount of them I just have no choice but to block them in order to get server online. They are basically infected networks in my book. Similar with all the malware in consumer devices like we have seen before. The actual home user might actually be a legitimate use above their network is infected where again I just have to block it. There's simply nothing I can do about infected networks.Even more evidently clear that pretty much every site I go on now is behind cloudflare. Sign of the times...
In other news, certificates which use GETSSL, stopped working. For some bizarre reason the binary had completely disappeared!! So just had to reinstall it! :crazy:
Also Grok suggested some fixes to make the SQL database queries a bit more efficiently seem to have helped a lot as well.
Well, that's the best part of my day gone again now :roll: