I've seen a real uptick in the past couple of days in attacks on my IP address space. Not sure if I'm being targeted, or part of a wider campaign. Oh well, fail2ban makes quick work of them
I've seen a real uptick in the past couple of days in attacks on my IP address space. Not sure if I'm being targeted, or part of a wider campaign. Oh well, fail2ban makes quick work of them
I'm having trouble figuring out what kind of botnet has been hammering our web servers over the past week. Requests come in from tens of thousands of addresses, just once or twice each (and not getting blocked by fail2ban), with different browser strings (Chrome versions ranging from 24.0.1292.0 - 108.0.5163.147) and ridiculous cobbled-together paths like /about-us/1-2-3-to-the-zoo/the-tiny-seed/10-little-rubber-ducks/1-2-3-to-the-zoo/the-tiny-seed/the-nonsense-show/slowly-slowly-slowly-said-the-sloth/the-boastful-fisherman/the-boastful-fisherman/brown-bear-brown-bear-what-do-you-see/the-boastful-fisherman/brown-bear-brown-bear-what-do-you-see/brown-bear-brown-bear-what-do-you-see/pancakes-pancakes/pancakes-pancakes/the-tiny-seed/pancakes-pancakes/pancakes-pancakes/slowly-slowly-slowly-said-the-sloth/the-tiny-seed
(I just put together a bunch of Eric Carle titles as an example. The actual paths are pasted together from valid paths on our server but in invalid order, with as many as 32 subdirectories.)
Has anyone else been seeing this and do you have an idea what's behind it?
So apart from the attempt to open a lot of Facebook accounts using my domain, my site has also been under sporadic DDoS attacks. I hope you don't have too much trouble connecting at times.
And no, I have no idea who I ticked off now.
Sales pitch toward the end.
Akamai: DDoS Attack Trends in 2024 Signify That Sophistication Overshadows Size https://www.akamai.com/blog/security/ddos-attack-trends-2024-signify-sophistication-overshadows-size @akamai_research #cybersecurity #infosec #DDoS
Nachdem diverse #ki #ai #crawler besonders respektvoll mit den öffentlichen Ressourcen von Open Source Projekten umgehen, habe ich mich dazu entschlossen eben diese auszusperren. Wir hatten in der Vergangenheit crawls, die im #monitoring als #ddos gewertet wurden.
Diverse AS erfreuen sich nun einem dauerhaften 429, einige wenige die es für alle kaputt machen…
@Prozak @seanfobbe Lets say @Codeberg did suffer some serious #DDoS (which OFC isn't their fault) so I'd rather see #SelfHosting as a better option...
It's just.currently.not.my.priority, but *my.priorities.ain't authoritative...
@seanfobbe personally I'd consider #gitea and #SelfHosting.
Once any of my projects would gain traction I'd move from there away.
I jist move to either SelfHosting or nowhere...
The Dutch web hosting company Argeweb has experienced performance issues for over a week now.
DNS Flood Attack vs. DDoS
A DNS Flood Attack targets DNS servers specifically, whereas a DDoS Attack can target any online service. Understanding the distinction is key to building stronger defenses!
Join our Cyber security training Course -
https://infosectrain.com/cybersecurity-certification-training/
#DDoS Attacks: The New Frontier of Political Cyber Warfare
In recent months, Distributed Denial of Service attacks have emerged as a significant tool in political cyber warfare, with a notable increase in their use during critical sociopolitical events.
DDoS Attacks (HTTP/2, DNS, Hacktivist)
This is Real World Technical Analysis
YouTube video: https://youtu.be/t2jKcA1OyBE
#Sponsored #cybersecurity #ddos #dos #DNS #http #tls #hack #hacker #hacking #cyber #internet Radware
Netscout reports DDoS attacks surged from 13M+ in 2023 to ~17M in 2024, with new tech like #AI supercharging their impact. These attacks are now a staple of #GeopoliticalConflict.
[related]
Article intéressant sur les alliances d’intérêts — ici contre la France — entre groupuscules de mercenaires, avec un petit twist sur ceux qui concentrent leur attention sur les SCADA (infra critiques)
"Hacktivists Increasingly Target France for Its Diplomatic Efforts"
"Pro-Russian and pro-Palestinian hacktivist groups share a common adversary in France, leading to coordinated cyberattacks against the country."
https://cyble.com/blog/hacktivists-france-for-its-diplomatic-efforts/
& concernant z-pentest et les systèmes de contrôle :
https://cyble.com/blog/russian-hacktivists-target-energy-and-water-infrastructure/
Ce phénomène de mise en commun des ressources pour optimiser les attaques est en forte accélération ces derniers mois.
Côté oursons sans nom, la stratégie de coordination s’est clairement déployée depuis l’an dernier — notamment pour muscler les attaques DDOSIA Layer 7 avec des botnets Mirai "propriétaires" en mode amplification réseau
"The Rise of Alliances: NoName057(16)'s Transformation in 2024"
https://www.radware.com/security/threat-advisories-and-attack-reports/the-rise-of-alliances-noname057-16-transformation-in-2024/
(cela dit, derrière ces danses en ligne, restent des visages — et des relations — qui commencent à se dessiner / doxer plus clairement :
https://molfar.com/en/blog/russian-cyber-army )
@LunaDragofelis Consider #blackholing entire #ASN|s like #aws and all the ofther #GAFAMs instead.
«There’s been something of an epidemic of malicious bots on the internet these days. You may have seen a post recently titled “Please stop externalizing your costs directly into my face“, or “FOSS infrastructure is under attack by AI companies“. Those are all happening to us, too. Surprise.»
TCRF has been getting DDoSed – Xkeeper's blog - https://blog.xkeeper.net/uncategorized/tcrf-has-been-getting-ddosed/
I'm getting #DDOS-ed by #AIcrawlers right now, even though I have a strict robots.txt.
Outgoing traffic suddenly increased (more or less 10 times regular traffic).
I have to block their crap using my firewall. That's NOT OK.