Forums under DDoS attack

DutchDaemon

Administrator
Staff member
Administrator
Moderator
Developer
As you will have noticed, the Forums are either very hard to reach or very hard to use.

The Forums server in itself is entirely functional, but the 'front door' is being hammered by many thousands of IP addresses opening and closing the Forums website at a large rate (for the interested: nginx throws 499 errors), causing slowness and resource starvation.

I have made the decision to try to thwart these bots by installing the bot-check software called Anubis (go-anubis; you will recognize it from the interstitial screen before a forum page is loaded - your browser gets a little javascript riddle to solve, and you're in) which will redirect most of the attacks to a quick termination.

This has brought the forums back online, but it will be (much) slower than usual, and sometimes connections will stall or time out until this attack dies down.

Also, people not allowing javascript cannot visit. I'm sorry: it's the lesser of two evils.

For the time being, I advise people making posts or opening threads to copy whatever they're writing before actually posting, so they don't lose their work when the process fails.
 
We're back to the pre-Anubis setup. Especially Safari users were negatively impacted, possibly due to the hurried Anubis setup and some related errors in its logging (a not entirely functional ip:port combination in X-Forwarding headers and such). This also caused some broken images and general slowness for users that could otherwise use the forums.
 
Right, considering the options, we are simply going to serve a static single-page website (see image) when a DDoS occurs, and switch back to normal operations when it's over. The Anubis solution has been partially successful, but it still adds load and artifacts that prevent normal usage, so we might as well just drink coffee and watch a movie.

1789389265711.png
 
Back
Top