Yep, server is/was getting attacked. The outage for the last few hours was us trying to clean up the mess.. I'm not sure if it's still getting attacked or if the current slowness is just a result of me cleaning out a bunch of temp files.
Mine did too. Server started doing weird stuff like it did that morning a couple months ago when the database drive died...I started wibblingThose *****. My heart skipped a beat.
Mine did too. Server started doing weird stuff like it did that morning a couple months ago when the database drive died...I started wibbling
We all know the server crashed because fury was downloading a bootleg copy of Debbie does them All.cant wait to see what @Professur says...
Wish granted. Porn.cant wait to see what @Professur says...
Aunty is not a girl....Anyone else curious how dearest Auntie knew what that film was? She might not know anything about servers, but she knows her adult cinema.
Im interested in learning who you pissed off enough to have them attempt a denial of service attack on a lowly racing forum.Yep, server is/was getting attacked. The outage for the last few hours was us trying to clean up the mess.. I'm not sure if it's still getting attacked or if the current slowness is just a result of me cleaning out a bunch of temp files.
Aunty is not a girl....
You might be unaware but everyone else knows that I am a feminist lesbian.Anyone else curious how dearest Auntie knew what that film was? She might not know anything about servers, but she knows her adult cinema.
Darn shame.Well there goes date night.
you still can if you promise to braid the hair on my back.Darn shame.
I was gonna wear the chaps.
Gee thanks @fury Another word I had to google..I started wibbling
Im interested in learning who you pissed off enough to have them attempt a denial of service attack on a lowly racing forum.
When a few other guys & myself managed some gaming forums where online war was a high possibility, forum trashing & closings were expected. 3rd party attacks were abnormal unless we unknowingly pissed of an ally of an enemy, etc...hackers do DDOS attacks for the fun of it on many sites.
UnfortunateIt's not someone directly attacking Racing Forums, they're attacking one of the other sites on the server and everyone else suffers as well.
The type of threat the server is/was under (I think the threat has subsided for now, but I'm often wrong) does not indicate an attempt to break their way in to get databases and whatnot, they're just mad at being banned from a game and they're expressing their frustration the only way script kiddies know how, "wah, I can't play, so I'm going to try to take the thing down". If they were wanting to break in to get databases and whatnot, then they'd probably be trying to be more sneaky about it.Unfortunate
How secure are your servers? It may be a little concerning for members here if they use a legit email address for a log in or a repetitive password & the site is indirectly under threat of breach.
Correct me if Im wrong
The type of threat the server is/was under (I think the threat has subsided for now, but I'm often wrong) does not indicate an attempt to break their way in to get databases and whatnot, they're just mad at being banned from a game and they're expressing their frustration the only way script kiddies know how, "wah, I can't play, so I'm going to try to take the thing down". If they were wanting to break in to get databases and whatnot, then they'd probably be trying to be more sneaky about it.
The server is regularly auto-updated and rebooted to ensure security vulnerabilities are closed ASAP. Various services on the server are protected by fail2ban, which blocks people that it detects are attempting to brute-force logins (and is great fun when somebody forgets their password to log into the server). There is no access to the database server through the internet. And XenForo uses a salted SHA256 hash for passwords. So, it's about the best we know how to secure it at the moment. If you have any more tips, I'm all ears
However, I would point out that if anyone is using the same password at this site as they are at any other, they should probably change that password, regardless of any security measures in place on this server.
I highly recommend LastPass as a password manager, it helps keep track of all your passwords, generate secure new ones, check to see whether any of your emails are in compromised databases, and remind you to change your passwords if they are the same. Free, or $12/year for premium. Premium gets you syncing across browser and mobile.
Also, any email accounts should be protected by 2-factor authentication where possible. Gmail has pretty good 2-factor authentication. You can have an authenticator app on your phone display a code, or have a code sent to your cell via text message, and you have to have that code when you log in (not just your password, but this random one-time code). That secures your email account much better than just a password.
After having had 2 of my email accounts raped and pillaged all for the sake of stealing my Twitter handle and selling it to someone for like $75, I had to get much better at protecting my stuff than just having good passwords...
Good read, thanksThe type of threat the server is/was under (I think the threat has subsided for now, but I'm often wrong) does not indicate an attempt to break their way in to get databases and whatnot, they're just mad at being banned from a game and they're expressing their frustration the only way script kiddies know how, "wah, I can't play, so I'm going to try to take the thing down". If they were wanting to break in to get databases and whatnot, then they'd probably be trying to be more sneaky about it.
The server is regularly auto-updated and rebooted to ensure security vulnerabilities are closed ASAP. Various services on the server are protected by fail2ban, which blocks people that it detects are attempting to brute-force logins (and is great fun when somebody forgets their password to log into the server). There is no access to the database server through the internet. And XenForo uses a salted SHA256 hash for passwords. So, it's about the best we know how to secure it at the moment. If you have any more tips, I'm all ears
However, I would point out that if anyone is using the same password at this site as they are at any other, they should probably change that password, regardless of any security measures in place on this server.
I highly recommend LastPass as a password manager, it helps keep track of all your passwords, generate secure new ones, check to see whether any of your emails are in compromised databases, and remind you to change your passwords if they are the same. Free, or $12/year for premium. Premium gets you syncing across browser and mobile.
Also, any email accounts should be protected by 2-factor authentication where possible. Gmail has pretty good 2-factor authentication. You can have an authenticator app on your phone display a code, or have a code sent to your cell via text message, and you have to have that code when you log in (not just your password, but this random one-time code). That secures your email account much better than just a password.
After having had 2 of my email accounts raped and pillaged all for the sake of stealing my Twitter handle and selling it to someone for like $75, I had to get much better at protecting my stuff than just having good passwords...
And by that I mean you can't directly access it through the internet--none of the database users have internet permissions, only local permissions. Of course, if you get in via SSH, you can access the database locally (as if you were physically logged into the computer with a keyboard, mouse, and monitor). So, again, fail2ban comes to the rescue there and stops people from trying to brute force. And I can review failed login attempts and stuff to see if anyone in particular is getting targeted. Right now, from the looks of it, it's limited to the usual scattershot attempts to bruteforce the logins for root, and various other random usernames that don't exist. This is stuff that every server on the internet has to deal with and is not something specific to ours. Fun fact: you can't even log in as root directly on this server--you have to get in as one of the admin-type users first and then put on your super suit. So I laugh at their pitiful attempts to brute force their way into root.There is no access to the database server through the internet.
Im interested in learning who you pissed off enough to have them attempt a denial of service attack on a lowly racing forum.
fluff, I think maybe you shouldn't show all your cards. Lack of information is still the greatest security feature.