shineworld 89 Posted October 8 (edited) Could be the server is below DDoS... Many forums are in same state, also our: In my case, massive guest access to the pages, till 150000 for day, continuously increases the session table and session keys in the server database, which slows down more and more every day, paralyzing the forum. At the moment, the only solution I have is to periodically clean up the two tables, but this also disconnects all connected users... I hope this is not the problem in this forum. Edited October 8 by shineworld Share this post Link to post
Tommi Prami 159 Posted October 9 (edited) Slowness seems to be ralated to time of day. Maybe. Some time ago it was very slow, now just slow... Adn very slow again, atleast posting new message and editing existing is very slow, Edited October 9 by Tommi Prami More info Share this post Link to post
Lars Fosdal 1961 Posted October 9 According to @TBx, the attack appears to be vectored towards DOSing the Apache server, more than it is about the forum software. 1 Share this post Link to post
Angus Robertson 696 Posted October 9 48,000 guests active over the past 24 hours is similar to a long term attack on one of my web sites. A Chinese hacker changed tactics over the months, from two IP addresses in Hong Kong, to VPNs around the world and currently a worldwide botnet that reached over one million IP addresses a week at the peak in July, now down to 30,000 a week, most from South America and the Far East, but over 100 different counties. More detail at This was to an ICS web server, and I contained the problem by adding geographic blocking using IP addresses and ASN checking, so requests are terminated before being connected. Angus Share this post Link to post
FPiette 394 Posted October 9 It is still very slow for me. I'm in Belgium if it matters. Share this post Link to post
DelphiUdIT 271 Posted October 9 It's been slow for me since yesterday morning, with timeout as well. Share this post Link to post
DelphiUdIT 271 Posted Tuesday at 09:32 AM 21 minutes ago, chmichael said: Somebody block those AI IPs We'll have to get used to it... it's the "price" we pay for those who want increasingly efficient and high-performance AI. ... the problem is that we all pay this "price"... Share this post Link to post
chmichael 16 Posted Tuesday at 09:42 AM Do you care about 3rd Party AIs and let the forum be slow as turtle ? Come on ... Block them! 1 Share this post Link to post
Lars Fosdal 1961 Posted Thursday at 07:43 AM The attacks are distributed. It is not as simple as blocking a handful of IP adresses. Share this post Link to post
salvadordf 40 Posted Thursday at 09:11 AM Check the user agents too. Sometimes those bots are so badly written that they identify as outdated browsers. Share this post Link to post
DelphiUdIT 271 Posted Thursday at 10:18 AM Today seems that no lantency is present. Good news. Share this post Link to post
Angus Robertson 696 Posted Thursday at 11:35 AM My experience of monitoring attacks is checking ASNs can be very productive, since attacks often come from multiple countries but the same or similar ASNs, ie the same cloud hosting businesses. ICS now has geo databases that get both country and ASN for IP addresses, which are reported in the server logs. Not all my servers have public domains, but still get scanned by IP address for exploits in popular web management systems like WordPress. The scanning IPs are often consecutive IPs from large hosting companies in multiple countries, like 1,000 Google IPs. So my servers now reject traffic from a small list of mostly Chinese related ASNs, although not Google, yet. Angus Share this post Link to post
FPiette 394 Posted Thursday at 02:10 PM 3 hours ago, DelphiUdIT said: Today seems that no lantency is present. Good news. Same here: normal response time. Share this post Link to post
corneliusdavid 277 Posted Thursday at 02:48 PM It had gotten to the point where I wasn't reading this forum much because there was a 3-5 second delay between each link click. Now, it's back to being fast, so it's usable once again! 2 Share this post Link to post
Anders Melander 2137 Posted Thursday at 07:14 PM 11 hours ago, Lars Fosdal said: It is not as simple as blocking a handful of IP adresses. Has Cloudflare been considered or even tried? Maybe @TBx knows? Share this post Link to post
Vincent Parrett 914 Posted Thursday at 09:03 PM Cloudflare would be good idea, however the forum owner would need to pay for the Pro plan as the free plan doesn't allow enough WAF rules needed to get forums working correctly. It's also not simple to configure for dynamic sites like forums, lots of trial and error unless someone has already documented it. Share this post Link to post
Lars Fosdal 1961 Posted yesterday at 06:11 AM AFAIK, @TBx has been working on setting up for Cloudflare. What is the approximate cost of a pro plan? Share this post Link to post
Vincent Parrett 914 Posted yesterday at 06:19 AM 7 minutes ago, Lars Fosdal said: AFAIK, @TBx has been working on setting up for Cloudflare. What is the approximate cost of a pro plan? https://www.cloudflare.com/en-au/plans/ 1 Share this post Link to post
Lars Fosdal 1961 Posted yesterday at 06:23 AM The question then is who will fund $240/year for the sites. Share this post Link to post
Anders Melander 2137 Posted yesterday at 07:52 AM 10 hours ago, Vincent Parrett said: the free plan doesn't allow enough WAF rules needed to get forums working correctly. I see. I assumed that the free plan would be usable but I guess not. Share this post Link to post
DelphiUdIT 271 Posted yesterday at 08:43 AM 2 hours ago, Lars Fosdal said: The question then is who will fund $240/year for the sites. The community has given me so much and continues to give (and not just to me, I think), and to support it I can easily pay a fee if necessary. Share this post Link to post
Lars Fosdal 1961 Posted yesterday at 09:58 AM 1 hour ago, DelphiUdIT said: I can easily pay a fee if necessary. That is a decision for @Daniel and @TBx to make. Share this post Link to post
Gord P 20 Posted 21 hours ago 7 hours ago, DelphiUdIT said: The community has given me so much and continues to give (and not just to me, I think), and to support it I can easily pay a fee if necessary. I am sure there would be more than a few people willing to chip in (spread the load around). Maybe it is more hassle than it is worth to have a donate button or something though. Share this post Link to post