Discuss What's been going on with the forum then? in the Plumbing Jobs | The Job-board area at PlumbersForums.net

Status
Not open for further replies.

Dan

Administrator
Staff member
Admin
Messages
2,786
I wouldn't want to 'test' the attackers so don't post anything about this anywhere public. If you're found to do so we'll just ban your account. It's not worth it.

Now things appear to have settled I feel comfortable letting you know what's being going on and why we've been up and down like a yoyo.

Keep this out of the public areas of the forum and whatnot. As it risks screwing the forum again.

Sunday morning we noticed a massive amount of traffic coming into the network, a few hours on we noticed it was a DDOS attack. Where too many requests are sent to the websites for the server and network to handle so it crashes the websites. Our hosts were able to manage the traffic to a degree while we traced what was going on. And it became apparent that it was thousands if not near 100,000+ botnets (computers being controlled by attackers without the owners knowledge) sending false requests to the forums to crash the server.

This had a knock-on effect on our hosts other customers, and even my hosts ISP in the London Docklands had to shut down some of their own traffic routing systems to stop the traffic.

Monday the attackers changed tactics and used HTTP requests that were left open, so the websites wouldn't resolve them properly. That crashed the forums too.

Tuesday it changed to DNS reflection where they attack the IP address itself and send traffic directly to that.

And today we've switched to an expensive routing service to send traffic through to filter out any nasty stuff. Done this for the main forums, carted all my customers off to other solutions so they're not affected now, and I have closed down a lot of my own websites and forums and things.

It's cost me thousands in losses and extra services and I wouldn't wish this on any of our competitor forums. Really dodgy situation to be put in.

I was expecting a ransom related message but haven't got anything so far. The attack is classed as industrial sabotage and as dozens of other companies we affected, along with our host, their network provider (and their other customers) and their ISP (and their other customers) we've had to get the old SOCA (Serious and Organised Crimes Agency) which is now called NCA (National Crimes Agency) involved who are investigating the attack in case this is part of some bigger issue (like that dodgy RansomWare thing that's going about). We're not too sure who's doing it or why but we've fought them off for now.

At no point were anything to do with personal details at risk. They we're NOT physically hacking us or anything, just sending massive amounts of traffic to us in the form of what took down PayPal and Amazon and VISA (and even SOCA last year).

So it looks like we're okay now. A few people are having DNS / Cache related issues but that'll all calm down in the next 24 hours or so as networks refresh and whatnot.

I wouldn't want to 'test' the attackers so don't post anything about this anywhere public. If you're found to do so we'll just ban your account. It's not worth it.
 
Last edited:
I must add that at one point they gained access to several servers owned by the same poor sod in the Netherlands and used those for the HTTP attacks. Meanwhile couldn't gain access to our own. So that shows how solid we are. We were literally only open to DDOS attacks, but such things only usually happen to massive firms. So nobody who runs a forum would ever think of protecting against it without needing it as it costs thousands.
 
Well that might as well have been in Japanese :)

Thanks for the hard work in the background :)
 
Thanks for even letting us know and hopefully all will be well, long live the forum,,
 
If anyone who's not in the Arms asks any of you what this is about just tell them it's some technical server schizzle that you don't really understand.

Dan's extremely serious about the banning thing. We've been told there are no exceptions and no second chances.

I don't want to ban any of you, except maybe Leo, and I know the other mods feel the same but if it comes to it, we'll have to.

Not something I really want to have to do. Please help us with this by staying schtum.
 
as croppie says we don't like banning anyone but on this occasion if anything gets out of the arms we won't hesitate to do the deed. it is very important for the security of the forums that this is adhered to. thank you in advance for being understanding.
 
Yeah no second warning from me you've seen it said in the original post here. I wrote it twice. And in bold. That's enough for me. I know you've read it. Mention this in the public domain, on or off the forum, and I'll just remove your account, you're not worth the hassle I'm afraid. This nearly cost us the whole network of forums. If it wasn't for the awesome team I have behind the scenes we could have been vulnerable and lost the lot. Or worse.

I'd rather not set a challenge for anybody who has the sort of resources they appear to have.
 
New posts
Status
Not open for further replies.

Reply to What's been going on with the forum then? in the Plumbing Jobs | The Job-board area at PlumbersForums.net

Similar plumbing topics

J
Hi - I'm not sure if this is the right forum or not, but I'm looking for some advice with regards to a recent (nightmare) new gas boiler install...
Replies
7
Views
4K
Mark Butler
M
    • Like
You can now subscribe to the forum and browse with no sponsors ads (there will still be a list in the main plumbing forum to show you who is a...
Replies
4
Views
1K
Hi all This is only about my third/fourth post, so go easy. Also, I'm only an enthusiastic amateur, not a pro... I'm having issues with the...
Replies
7
Views
2K
I thought explaining why we have the system in place will help you guys get over it. It's to do with our search engine rankings, and how much...
Replies
0
Views
783
    • Like
Just letting you guys and gals know that the advent winnings (including forum hats) will be going out in batches. We did this on all three forums...
Replies
0
Views
651
Back
Top
AdBlock Detected

We get it, advertisements are annoying!

Sure, ad-blocking software does a great job at blocking ads, but it also blocks useful features of our website. For the best site experience please disable your AdBlocker.

I've Disabled AdBlock