BOINC.dk and DoS attacks

Message boards : Number crunching : BOINC.dk and DoS attacks
Message board moderation

To post messages, you must log in.

AuthorMessage
Janus
Volunteer developer

Send message
Joined: 4 Dec 01
Posts: 376
Credit: 967,976
RAC: 0
Denmark
Message 57176 - Posted: 25 Dec 2004, 11:26:51 UTC

Im sorry to announce that BOINC.dk is currently under a heavy DoS (Denial of Service) attack launched from the forums on www.visualcoders.net.

The attack has hit the main MySQL server pretty hard. To avoid further damage to any of the systems most of the BOINC.dk services will be taken down now.

BOINC.dk has been taking care of many things related to BOINC for the past years and many sites (including all BOINC projects) partly rely on services from BOINC.dk (The addons page here on seti@home to mention one). These services will be kept online to as great an extend as possible. Other services such as statistics, standard downloads, forums, XML-exports, news etc. will be offline.

I must say that this news makes me very sad, and I need a little time to calm down and decide what will happen with BOINC.dk

Now you know why
ID: 57176 · Report as offensive
Profile Trane Francks

Send message
Joined: 18 Jun 99
Posts: 221
Credit: 122,319
RAC: 0
Japan
Message 57182 - Posted: 25 Dec 2004, 11:59:30 UTC

I'm really sorry to hear of the trouble, Janus. Hang tough, man. Let the script kiddies' hard drives throw a bearing.
ID: 57182 · Report as offensive
HachPi
Avatar

Send message
Joined: 2 Aug 99
Posts: 481
Credit: 21,807,425
RAC: 21
Belgium
Message 57192 - Posted: 25 Dec 2004, 12:44:59 UTC

Please do let us know if we can be of any support to you!!!

We don't let you down!!!

Greetings from Belgium :-))


ID: 57192 · Report as offensive
.
Volunteer tester

Send message
Joined: 3 Apr 99
Posts: 410
Credit: 16,559
RAC: 0
Message 57198 - Posted: 25 Dec 2004, 13:05:58 UTC - in response to Message 57176.  

> Im sorry to announce that BOINC.dk is currently under a heavy DoS (Denial of
> Service) attack launched from the forums on <a> href="http://www.visualcoders.net/">www.visualcoders.net[/url].
>
> The attack has hit the main MySQL server pretty hard. To avoid further damage
> to any of the systems most of the BOINC.dk services will be taken down now.
>
> BOINC.dk has been taking care of many things related to BOINC for the past
> years and many sites (including all BOINC projects) partly rely on services
> from BOINC.dk (The addons page here on seti@home to mention one). These
> services will be kept online to as great an extend as possible. Other services
> such as statistics, standard downloads, forums, XML-exports, news etc. will be
> offline.
>
> I must say that this news makes me very sad, and I need a little time to calm
> down and decide what will happen with BOINC.dk
>
> Now you know why
>

@Janus: I (and others) have noticed for a while that someone is -1'ing my posts almost instantly, no matter what the content is, and I thought for a while that it had something to do with [url=http://setiweb.ssl.berkeley.edu/forum_thread.php?id=7400#56065]this person!<a> Can this phenomenom have something to do with the above? If it has, you might know where the source of this can be found!
ID: 57198 · Report as offensive
HachPi
Avatar

Send message
Joined: 2 Aug 99
Posts: 481
Credit: 21,807,425
RAC: 21
Belgium
Message 57233 - Posted: 25 Dec 2004, 17:08:18 UTC - in response to Message 57198.  
Last modified: 10 Jan 2005, 21:11:28 UTC


ID: 57233 · Report as offensive
.
Volunteer tester

Send message
Joined: 3 Apr 99
Posts: 410
Credit: 16,559
RAC: 0
Message 57246 - Posted: 25 Dec 2004, 18:07:42 UTC - in response to Message 57233.  
Last modified: 25 Dec 2004, 18:19:56 UTC

> @ Lena,
>
> I'm constantly +1 ing your posts, to keep the balance fair. I really do find
> such personal attacks unfair, everyone has the right to have a personal
> meaning about the world.
> If we can possibly be of any help to Janus he is welcome,
>
> Greetz, Merry Xmas Happy N Y ;-))
>
>

Thanks! I have started to think it's kind of funny that a person really have the time so sit and monitor all my posts! Therefore I started to think that maybe someone hacked in and changed some code, so my posts automatically are -1'ed! I have contacted the abuse@webspeed.dk, TDC's account for hacker alert, about this and attached links to these boards!


ID: 57246 · Report as offensive
HachPi
Avatar

Send message
Joined: 2 Aug 99
Posts: 481
Credit: 21,807,425
RAC: 21
Belgium
Message 57253 - Posted: 25 Dec 2004, 18:43:54 UTC - in response to Message 57246.  
Last modified: 10 Jan 2005, 21:11:12 UTC

ID: 57253 · Report as offensive
ric
Volunteer tester
Avatar

Send message
Joined: 16 Jun 03
Posts: 482
Credit: 666,047
RAC: 0
Switzerland
Message 57316 - Posted: 26 Dec 2004, 0:22:38 UTC - in response to Message 57176.  

Dear Janus

We urge you, to not close the wonderfull pages you are providing and maintaining. It's hard to say, but even over the internet, assholes finds a way to take for a short while our attention.

You don't have to calm. other has to calm.

Right now, perhaps the same people/category are trying to mess up the pirates forum in the same manner as it was done at the seti cafe.

Please, Janus in the name of the more than well done job you did, in the name of the 99,9999% of the more or less "normaly" people supporting a weldon effort, don't let you influence to much from those negative elements.

Stand over!
You are to intelligent for those people.

Friendly and merry chrismas!

ric
ID: 57316 · Report as offensive
N/A
Volunteer tester

Send message
Joined: 18 May 01
Posts: 3718
Credit: 93,649
RAC: 0
Message 57322 - Posted: 26 Dec 2004, 0:40:28 UTC - in response to Message 57176.  

I think everyone here appreciates your effort and situation. If I were in your shoes, I'd sit it until at least Jan/15 before restarting BOINC.dk. But since I'm not, I'm throwing my two cents/grenades in. Script kiddies are the reason why abortion is still legal - Take the fuckers down for all they've got. I demand blood!! >:-O

[Man enters room, hands me legal papers.]

Oh, alright... Install BOINC on their servers, set httpd's priority to zombie and boinc's to real-time...

[Man leaves room shredding papers]
ID: 57322 · Report as offensive
Profile Misfit
Volunteer tester
Avatar

Send message
Joined: 21 Jun 01
Posts: 21804
Credit: 2,815,091
RAC: 0
United States
Message 57353 - Posted: 26 Dec 2004, 2:05:05 UTC - in response to Message 57198.  

> @Janus: I (and others) have noticed for a while that someone is -1'ing my
> posts almost instantly, no matter what the content is,

Hey welcome to the club! It means youre popular. ;)
ID: 57353 · Report as offensive
Profile Jord
Volunteer tester
Avatar

Send message
Joined: 9 Jun 99
Posts: 15184
Credit: 4,362,181
RAC: 3
Netherlands
Message 57359 - Posted: 26 Dec 2004, 2:34:08 UTC - in response to Message 57233.  
Last modified: 26 Dec 2004, 2:37:43 UTC

I really do find such personal attacks unfair, everyone has the right to have a personal meaning about the world.
If we can possibly be of any help to Janus he is welcome.


Maybe it would help if the rating system only worked on those forums where it was needed. Like the Actual tech help forums. What good is a rating system that can be abused this much in this forum and in Cafe Seti?

If it is for moderating purposes, okay. Have a moderator look daily at all those posts that are -25 or worse. But at that same time, if just a small group of people here don't like one other person, s/he'll get minused a lot within a small amount of time. About every next thread or post started by a new person is being glared at with suspicion and hate. What good is that to the outside world?

No, I am not WW or his daughter who can't tell time for dinner. ;)
ID: 57359 · Report as offensive
PerttiR

Send message
Joined: 3 Apr 99
Posts: 2
Credit: 151,643
RAC: 0
China
Message 57445 - Posted: 26 Dec 2004, 6:52:04 UTC

It appeasrs that the site http://www.visualcoders.net/ is hosted by www.godaddy.com.

Godaddy's site says they provide masking free as part of their service.

Quote...

DOMAIN FORWARDING & MASKING
Domain Forwarding and Masking Direct different WWW addresses to an existing site. With masking, users don't see the underlying address; only what they type in.

... unquote

You may want to report the attack problem the service provider of http://www.visualcoders.net/, maybe they can shut the attack down (at least for a while) and reveal the true source of the attacker.
ID: 57445 · Report as offensive
Janus
Volunteer developer

Send message
Joined: 4 Dec 01
Posts: 376
Credit: 967,976
RAC: 0
Denmark
Message 57467 - Posted: 26 Dec 2004, 10:40:11 UTC - in response to Message 57176.  
Last modified: 26 Dec 2004, 10:42:03 UTC

I'm afraid the attack has now evolved to a DDoS (distributed denial of service) attack. Visualcoders.net has now been temporarily shutdown by request to their internet provider, but other (possibly hacked) sites are joining.

The MySQL database has been damaged due to these attacks. Especially the statistics for the large projects (seti@home and climateprediction). I have managed to get climateprediction stats fixed, but seti@home stats will be offline for a while.

I'm very thankful for all the mails with help and support I get at the moment, however I cannot answer them (the webaccess to my mail is swamped by the DDoS attack as well, I can only slowly stream down mails to read using pop).

I will try to write some protection filters today so maybe you will see the site online - maybe not. It will be slow, but online if I succeed.

Thanks for your support - it means a lot in times like these!
ID: 57467 · Report as offensive
Janus
Volunteer developer

Send message
Joined: 4 Dec 01
Posts: 376
Credit: 967,976
RAC: 0
Denmark
Message 57471 - Posted: 26 Dec 2004, 11:47:15 UTC - in response to Message 57467.  

I wrote some filters that seem to do the trick for now. Every time one of the DDoS queries is detected the server simply waits for 25 seconds and does nothing - hence not loading the MySQL or network bandwidth.

The server is still getting hammered with requests so it will seem a bit slow.
ID: 57471 · Report as offensive
Profile Trane Francks

Send message
Joined: 18 Jun 99
Posts: 221
Credit: 122,319
RAC: 0
Japan
Message 57473 - Posted: 26 Dec 2004, 12:35:05 UTC - in response to Message 57471.  

> The server is still getting hammered with requests so it will seem a bit slow.

I just posted an update for BOINCprog. The site was nice and responsive for me. Nice work, man!

ID: 57473 · Report as offensive
Profile Paul D. Buck
Volunteer tester

Send message
Joined: 19 Jul 00
Posts: 3898
Credit: 1,158,042
RAC: 0
United States
Message 57492 - Posted: 26 Dec 2004, 15:31:00 UTC - in response to Message 57471.  

Janus,

> The server is still getting hammered with requests so it will seem a bit slow.

Cool!

Though I don't use your site that much (for some reason it does not read like the FORTRAN I know and that is about as far as my skills with a second language goes ..), but it is sad that there are people that seem to find value in this type of thing.
ID: 57492 · Report as offensive
Profile Misfit
Volunteer tester
Avatar

Send message
Joined: 21 Jun 01
Posts: 21804
Credit: 2,815,091
RAC: 0
United States
Message 57645 - Posted: 27 Dec 2004, 5:36:39 UTC - in response to Message 57467.  

Is that what is happening with this message board?

Warning: mysql_query(): Can't connect to local MySQL server through socket '/tmp/mysql.sock' (2) in /disks/koloth/raid5_b/users/boincadm/projects/sah/html/inc/forum.inc on line 74

Warning: mysql_query(): A link to the server could not be established in /disks/koloth/raid5_b/users/boincadm/projects/sah/html/inc/forum.inc on line 74

Warning: mysql_fetch_object(): supplied argument is not a valid MySQL result resource in /disks/koloth/raid5_b/users/boincadm/projects/sah/html/project/forum_index.php on line 27
ID: 57645 · Report as offensive
N/A
Volunteer tester

Send message
Joined: 18 May 01
Posts: 3718
Credit: 93,649
RAC: 0
Message 57684 - Posted: 27 Dec 2004, 14:06:14 UTC - in response to Message 57467.  

The MySQL database has been damaged due to these attacks.
Yup - looks like we got hit, too.

Damn script kiddie bastards... >:-O
ID: 57684 · Report as offensive
Profile Doris and Jens
Volunteer developer
Volunteer tester
Avatar

Send message
Joined: 21 Nov 99
Posts: 362
Credit: 3,539,386
RAC: 13
Germany
Message 57719 - Posted: 27 Dec 2004, 20:36:02 UTC - in response to Message 57645.  

> Is that what is happening with this message board?
>
> Warning: mysql_query(): Can't connect to local MySQL server through socket
> '/tmp/mysql.sock' (2) in
> /disks/koloth/raid5_b/users/boincadm/projects/sah/html/inc/forum.inc on line

No, that was a missing file update yesterday.

@Janus: I am very sad to hear about this DoS bullshit. As other users wrote before, tell us if wer can help in any way. (And don't worry to much, there is a little light in the dark. It really means your site is very popular and liked by many people, or it wouldn't become a target for this [zensored] kids.)

Keep up, BOINC rulez!
Greetings from Bremen/Germany
Jens Seidler (TheBigJens)

ID: 57719 · Report as offensive
N/A
Volunteer tester

Send message
Joined: 18 May 01
Posts: 3718
Credit: 93,649
RAC: 0
Message 57729 - Posted: 27 Dec 2004, 20:57:30 UTC - in response to Message 57719.  

No, that was a missing file update yesterday.
Can't we blame them anyway? :-)
ID: 57729 · Report as offensive

Message boards : Number crunching : BOINC.dk and DoS attacks


 
©2024 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.