Page 1 of 1

The Forum Server is under attack

Posted: Thu May 08, 2025 5:41 pm
by Dominic
That sounds dramatic. It just means it looks like somebody is doing a DDOS attack on the server, and specifically the forum. There are over 3000 active connections, which is obvious skullduggery.

If there is a downtime, that is why. Normal service will resume as soon as possible etc.

Re: The Forum Server is under attack

Posted: Thu May 08, 2025 5:53 pm
by trevnhil
I had to log in a short while ago. Maybe that was why..

Re: The Forum Server is under attack

Posted: Thu May 08, 2025 6:19 pm
by Dominic
Possibly. According to the Popular Times stats at the bottom of the main page, there were over 4800 active sessions just before 5PM.

Anyway, the webhosts have done their magic and things are back to normal now. Of course, the attacker may try a different route, but more likely it is an automated attack and they will move on to their next target.

Re: The Forum Server is under attack

Posted: Thu May 08, 2025 6:35 pm
by jagwheels
Thanks for the update Dominic & explains my problems earlier

Re: The Forum Server is under attack

Posted: Thu May 08, 2025 6:35 pm
by sueb
Yes would not load the pages for me. Switched off and back on . Made no difference. Even this time to get on to make a reply it was slow to load.
Eastern forum is the same.

Maybe a Cyprus thing. Daily Mail or the Daily Hate as we call loads quick.

Here's hoping it doesn't cause you any problems. As it is a great forum that you manage!

Re: The Forum Server is under attack

Posted: Thu May 08, 2025 7:22 pm
by cyprusmax47
Dominic wrote: Thu May 08, 2025 5:41 pm That sounds dramatic. It just means it looks like somebody is doing a DDOS attack on the server, and specifically the forum. There are over 3000 active connections, which is obvious skullduggery.

"If there is a downtime, that is why. Normal service will resume as soon as possible etc.
I am not clever enough to tell, but today I had from 6 AM until 1 PM no internet connection at all. It was obviously a CYTA problem as my internet provider send me several emails like this one:

I know many of you will not get this until service is resumed, but if you are planning on going out and about in Paphos in the meantime, we are hearing reports from people who can't pay for fuel at garages, having to abandon their shopping at shops because JCC is down (no internet) and I have been told some ATMs are not working for the same reason.

If you are going out, please take some cash with you.

Details from Ctya are still sketchy, they seem to have closed ranks and no matter who we call we get the same line.

We are all still standing by to check our equipment as soon as the fibre network comes back up.

Sorry, yet again.

Nigel."

There was also a post in the local press:

Traders and consumers in Paphos have been outraged for hours. CYTA is carrying out network upgrade work, resulting in many businesses being out of service since this morning.
Such work should be carried out at times and days when trade is not affected.

source: https://pafoslive.com.cy/αναστάτωση-λόγω-αναβάθμισης/

Max

Re: The Forum Server is under attack

Posted: Thu May 08, 2025 7:39 pm
by Dominic
The events on Paphos Life this afternoon were nothing to do with Cyprus. The website is hosted somewhere in central Europe, probably Germany. I can't remember off the top of my head. Anyway, Max will appreciate that when I wanted a reliable server with excellent support I went to a German company.

A DDOS (Distributed Denial Of Service) [distributed means more than one attacker] attack is when somebody tries to bring server down by contacting it from lots of different connections at the same time. The server itself wasn't the target, but the forum.

I don't think it was a competitor or anything like that. More likely it was just a bit of software that searches out phpBB forums and tries to crash the server. The hope is that in its broken state they can access the nuts and bolts of a broken system.

Thankfully, with the help of the webhost's support (they did all the actual work!) we were able to block the attackers.

Re: The Forum Server is under attack

Posted: Fri May 09, 2025 3:58 pm
by jeba
Dominic wrote: Thu May 08, 2025 7:39 pm I don't think it was a competitor or anything like that. More likely it was just a bit of software that searches out phpBB forums and tries to crash the server. The hope is that in its broken state they can access the nuts and bolts of a broken system.
Sorry for asking such a stupid question: What benefit will they have from accessing the nuts and bolts of a broken system? What´s in it for them?

Re: The Forum Server is under attack

Posted: Fri May 09, 2025 5:02 pm
by Dominic
Some sites would have financial information stored on a database somewhere. At the very least, there would be a list of email addresses which can be quite valuable. Not just for spam purposes either, passwords would also be available, and if you knew somebody's email and password, you could try using it on another site.

Here's one scenario:

Somebody hacks Site A, and gets user table complete with passwords.
They take a user email and password, and try logging on to Facebook with it.
Bingo, they are now on Facebook (or whatever). That account is now hacked and can be used to post spam etc.

This is why using one password for everything is a very bad idea.

Re: The Forum Server is under attack

Posted: Sat May 10, 2025 8:27 pm
by Dominic
Looks like they are trying again. Over 10000 users today.

Re: The Forum Server is under attack

Posted: Sat May 10, 2025 8:49 pm
by trevnhil
The forum loading is very slow and sometimes I get the message that I cannot connect to the Forum

Re: The Forum Server is under attack

Posted: Sat May 10, 2025 10:53 pm
by Dominic
I just did a tweak that can take up to 24 hours to be effective, but it seems a lot better already.

Re: The Forum Server is under attack

Posted: Sun May 11, 2025 7:27 am
by trevnhil
It seems just fine at loading this morning

Re: The Forum Server is under attack

Posted: Sun May 11, 2025 2:58 pm
by Dominic
Still not out of the woods yet. On the plus side, I am learning a bit more about security. The attacks are coming from Vietnam, Singapore and the Alibaba Cloud. No idea why though.