Admin

Staff member
Admin
Mod
Jun 28, 2007
14,781
3
4,440
65,798
Staffordshire
www.electriciansforums.net
If you're a qualified, trainee, or retired electrician - Which country is it that your work will be / is / was aimed at?
United Kingdom
What type of forum member are you?
Other
If other, please explain
Not an electrician at all.
Business Name
Ekthetikos
I wouldn't want to 'test' the attackers so don't post anything about this anywhere public. If you're found to do so we'll just ban your account. It's not worth it.

Now things appear to have settled I feel comfortable letting you know what's being going on and why we've been up and down like a yoyo.

Keep this out of the public areas of the forum and whatnot. As it risks screwing the forum again.

Sunday morning we noticed a massive amount of traffic coming into the network, a few hours on we noticed it was a DDOS attack. Where too many requests are sent to the websites for the server and network to handle so it crashes the websites. Our hosts were able to manage the traffic to a degree while we traced what was going on. And it became apparent that it was thousands if not near 100,000+ botnets (computers being controlled by attackers without the owners knowledge) sending false requests to the forums to crash the server.

This had a knock-on effect on our hosts other customers, and even my hosts ISP in the London Docklands had to shut down some of their own traffic routing systems to stop the traffic.

Monday the attackers changed tactics and used HTTP requests that were left open, so the websites wouldn't resolve them properly. That crashed the forums too.

Tuesday it changed to DNS reflection where they attack the IP address itself and send traffic directly to that.

And today we've switched to an expensive routing service to send traffic through to filter out any nasty stuff. Done this for the main forums, carted all my customers off to other solutions so they're not affected now, and I have closed down a lot of my own websites and forums and things.

It's cost me thousands in losses and extra services and I wouldn't wish this on any of our competitor forums. Really dodgy situation to be put in.

I was expecting a ransom related message but haven't got anything so far. The attack is classed as industrial sabotage and as dozens of other companies we affected, along with our host, their network provider (and their other customers) and their ISP (and their other customers) we've had to get the old SOCA (Serious and Organised Crimes Agency) which is now called NCA (National Crimes Agency) involved who are investigating the attack in case this is part of some bigger issue (like that dodgy RansomWare thing that's going about). We're not too sure who's doing it or why but we've fought them off for now.

At no point were anything to do with personal details at risk. They we're NOT physically hacking us or anything, just sending massive amounts of traffic to us in the form of what took down PayPal and Amazon and VISA (and even SOCA last year).

So it looks like we're okay now. A few people are having DNS / Cache related issues but that'll all calm down in the next 24 hours or so as networks refresh and whatnot.

I wouldn't want to 'test' the attackers so don't post anything about this anywhere public. If you're found to do so we'll just ban your account. It's not worth it.
 
Last edited:
Was annoying our end but now you've kindly explained Dan I can say that its much appreciated the effort you have put in to resolve the attack... :tank:
 
  • Like
Reactions: 1 person
I must add that at one point they gained access to several servers owned by the same poor sod in the Netherlands and used those for the HTTP attacks. Meanwhile couldn't gain access to our own. So that shows how solid we are. We were literally only open to DDOS attacks, but such things only usually happen to massive firms. So nobody who runs a forum would ever think of protecting against it without needing it as it costs thousands.
 
There isn't a smiley appropriate for the amount of drink I'm having tonight to celebrate.
 
  • Like
Reactions: 4 people
worlds-biggest-beer-pint-glass-drinking.jpg

Is that any good for you
 
  • Like
Reactions: 1 person
Nope, bigger please.
 
That's the one lad. Well done. That much drink I'm having, that much.
 
  • Like
Reactions: 1 person
So an attempt to sink the forum with no apparent gain to the attackers apart from the act itself ? Seems very odd. Maybe some wannabes practicing for bigger targets or just hacking for the hell of it ?

I would suggest that it could be the work of someone, or an organisation, or a group of organisations that had seen something they didn't like in the open forums.... but I wouldn't have the foggiest idea what such topics, views, or potential movements could provoke such a reaction, and I'm also not paranoid..... or should I be ?

Thanks for the update Dan.
 
  • Like
Reactions: 1 person
So an attempt to sink the forum with no apparent gain to the attackers apart from the act itself ? Seems very odd. Maybe some wannabes practicing for bigger targets or just hacking for the hell of it ?

I would suggest that it could be the work of someone, or an organisation, or a group of organisations that had seen something they didn't like in the open forums.... but I wouldn't have the foggiest idea what such topics, views, or potential movements could provoke such a reaction, and I'm also not paranoid..... or should I be ?

Thanks for the update Dan.

I was expecting a ransom threat. Failing that they perhaps wanted to make the forum vulnerable to a SQL injection to place RansomWare software on the server to attack its visitors. Failing that they are testing the network we're on. Failing that it's some form of person or group of people we've annoyed somehow, whether being so popular or have upset them some other way.

But the fact they controlled botnets means they had access to thousands of computers with viruses on. And the fact they gained control of several servers in the Netherlands suggests they know how to hack well.

But for now your guess is as good as mine.

I don't think the NCA will ever reveal anything they find for security reasons. But they're certainly very interested in knowing everything we do so they can investigate.

No need to be paranoid. The attack was certainly aimed at myself / my business (and my customers websites) and not members per se.
 
defleted.
 
Ddos attacks are nasty, if you guys are curious about these kinds of things.

Have a look at defcon on youtube.

Smoocon or blackhat is also interesting
 
Having access to a botnet doesn't narrow it down much, anyone can hire the services of a botnet, you just need money and you need to know where to look. Glad to say speeds are good for me tonight, first night this week I've been able to load pages.
 
  • Like
Reactions: 2 people
Having access to a botnet doesn't narrow it down much, anyone can hire the services of a botnet, you just need money and you need to know where to look. Glad to say speeds are good for me tonight, first night this week I've been able to load pages.
The problem is that it is very difficult to track these people down because they will have infected pc's with a virus.

These computers will then either wait for a command from a certain server or will constantly communicate.

The server will then eventually select a target and then the zombie computers will start the ddos attack.

The problem is it is very hard to trace
 
  • Like
Reactions: 1 person
I am now having trouble with managing attachments/uploading pics but only in the last 30 minutes and everything else is running fine
 
The problem is that it is very difficult to track these people down because they will have infected pc's with a virus.

These computers will then either wait for a command from a certain server or will constantly communicate.

The server will then eventually select a target and then the zombie computers will start the ddos attack.

The problem is it is very hard to trace

Its like walking outside on a hot day seeing thousands of raindrops on the pavement and road after a quick light shower that have only just fallen and been asked to identify which one fell first.
 
  • Like
Reactions: 2 people

Similar threads

OFFICIAL SPONSORS

Electrical Goods - Electrical Tools - Brand Names Electrician Courses Green Electrical Goods PCB Way Electric Underfloor Heating Electrician Courses Heating 2 Go Electrician Workwear Supplier
These Official Forum Sponsors May Provide Discounts to Regular Forum Members - If you would like to sponsor us then CLICK HERE and post a thread with who you are, and we'll send you some stats etc

Advert

Daily, weekly or monthly email

Thread starter

Admin

Staff member
Admin
Mod
Joined
Location
Staffordshire
Website
https://www.electriciansforums.net
If you're a qualified, trainee, or retired electrician - Which country is it that your work will be / is / was aimed at?
United Kingdom
What type of forum member are you?
Other
If other, please explain
Not an electrician at all.
Business Name
Ekthetikos

Thread Information

Title
What's been going on with the forum then? - Arms thread
Prefix
N/A
Forum
Electrician Talk
Start date
Last reply date
Replies
119

Advert

Thread statistics

Created
Admin,
Last reply from
shanky887614,
Replies
119
Views
1,653

Advert