DDR 215 March 31, 2018 Share March 31, 2018 Hello everyone, We apologise for the instability and downtime of the forums that occurred today. A spammer was, probably inadvertently, performing a denial of service attack on us – they were requesting so many forum pages and searches that no legitimate traffic could get through. This also maxed out our database, which led to instability and downtime in some other Poniverse services which shared the DB instance. We've blocked the spammer's IP for now, and added basic rate limiting. Let us know if you encounter any 403 "service temporarily unavailable" errors, please. A long-term solution would be to introduce better rate-limiting (so offenders can't take us down as easily) and fail2ban (automatically block offenders from accessing MLPF at all). We will be investigating this over the coming weeks. 17 Link to comment Share on other sites More sharing options...
The Recherche 29,967 March 31, 2018 Share March 31, 2018 Good to hear! Though, of course, that could also mean that they will try again under a separate IP address... Regardless, it's good to hear that the problem has been resolved for the time being! 3 ❆~ 𝓐𝓵𝔀𝓪𝔂𝓼 𝓪𝓷𝓭 𝓕𝓸𝓻𝓮𝓿𝓮𝓻 𝓟𝓮𝓮𝓻𝓵𝓮𝓼𝓼 ~❆ 𝓕𝓲𝓿𝓮 𝓨𝓮𝓪𝓻𝓼 𝓲𝓷 𝓽𝓱𝓮 𝓜𝓪𝓴𝓲𝓷𝓰: 𝓜𝔂 𝓟𝓮𝓻𝓼𝓸𝓷𝓪𝓵 𝓕𝓻𝓲𝓮𝓷𝓭𝓼𝓱𝓲𝓹 𝓲𝓼 𝓜𝓪𝓰𝓲𝓬 𝓡𝓮𝓿𝓲𝓮𝔀 Link to comment Share on other sites More sharing options...
Nightfall Gloam 18,258 March 31, 2018 Share March 31, 2018 That's good! The downtime was really annoying for me, especially with the notifications never properly loading. 4 Aspiring animator/illustrator, founder of MLPF's Lighthoof and Shimmy Shake fan club! "The magic of friendship grows" Link to comment Share on other sites More sharing options...
King of Canterlot 9,603 March 31, 2018 Share March 31, 2018 Damn spammers and hackers, they only like to be an annoyance to everyone else .................... 5 RA RA RASPUTIN Link to comment Share on other sites More sharing options...
SparklingSquirrels 21,332 April 1, 2018 Share April 1, 2018 @DDR I appreciate all your work on the forums! Thanks to you and the other admins for working to get MLPF fixed as soon as possible. 5 ֍֎֍֎ Link to comment Share on other sites More sharing options...
The Kaeya Simp 13,988 April 1, 2018 Share April 1, 2018 Well, it could've been worse! @DDR you and all of the other admins are the best, there is so much shit you need to deal with! 1 Link to comment Share on other sites More sharing options...
shadowwarp940 1,303 April 1, 2018 Share April 1, 2018 Ugh, spammers! Aren't useful for nothing, I'm telling you, But that aside, I'm glad that the issue is over now 2 Link to comment Share on other sites More sharing options...
Will Guide 21,360 April 1, 2018 Share April 1, 2018 So THAT was what was going on! So it wasn't MY connection particularly. 1 A Dragon as big as his love for Disney and has his head in the clouds literally and figuratively Ask Will Guide | Signature by Wife of Hawks | WiiGuy2014’s OCs Link to comment Share on other sites More sharing options...
Nyactis Mewcis Catlum 672 April 1, 2018 Share April 1, 2018 4 hours ago, DDR said: fail2ban (automatically block offenders from accessing MLPF at all) What will this exactly entail? Will it block people who are loading lots of pages? I tend to reload pages a lot while I'm waiting for replies in threads, and of course i check notifications the instant I notice them. I'm assuming it won't block what could be considered normal user activity? 2 TwiDash, Promptis & Sonadow. RC Enthusiast. OC: Canary Wing. Signature by @KyoshiASK SCOOTALOO! | ASK CANARY WING Link to comment Share on other sites More sharing options...
Prospekt 11,018 April 1, 2018 Share April 1, 2018 Glad things are up and running again and that the issue has been rectified for now. It was indeed frustrating having pages quit loading on the same day as a new episode of the show. @DDR Thank you for all you've done and all you continue to do. It's very much appreciated. 3 Signature by Kyoshi Link to comment Share on other sites More sharing options...
Esom 56 April 1, 2018 Share April 1, 2018 Well glad to hear things were taken care of in time. Imagine edgy signature image here Link to comment Share on other sites More sharing options...
Ganondorf8 11,288 April 1, 2018 Share April 1, 2018 At least you were on top of things before they could get out of hand. Link to comment Share on other sites More sharing options...
Sketchy Tune 964 April 1, 2018 Share April 1, 2018 Thank goodness. At least it's being taken care of ^^ My Character | My Art Shop | My OC Art Request Shop | Ask Sketchy Tune! Link to comment Share on other sites More sharing options...
SDP40F amtrak 2,447 April 1, 2018 Share April 1, 2018 Who is the spammer ?? Link to comment Share on other sites More sharing options...
DDR 215 April 2, 2018 Author Share April 2, 2018 On 31/03/2018 at 9:14 PM, Scootaloved said: What will this exactly entail? Will it block people who are loading lots of pages? I tend to reload pages a lot while I'm waiting for replies in threads, and of course i check notifications the instant I notice them. I'm assuming it won't block what could be considered normal user activity? You are correct; it will probably only block you if you try to load load several hundred pages in a few seconds. It was looking like we were getting a few dozen a second from the spammer, which is fairly easy to filter out. 8 hours ago, Moondancer is best said: Who is the spammer ?? We'll never know. Probably some automated bot that was set upon us and hundreds of other forums. Such is the nature of the internet; every networked computer is effectively constantly under attack. My own home machine sees hundreds of user/pass login attempts every day, for example, despite the fact you can't log in to it with a password. On 31/03/2018 at 4:41 PM, Recherche said: Though, of course, that could also mean that they will try again under a separate IP address... Yep. Happened earlier today while I was out. We should be more resilient to these sorts of attacks anyway, it's kind of shameful that we aren't. 3 Link to comment Share on other sites More sharing options...
Hierok 11,831 April 2, 2018 Share April 2, 2018 So that's the reason mlpforums would not load. I thought it was because mlpforums had updates\upgrades. If I don't understand something or Interpret it wrong, I'm dutch. Sometimes I gamble for meanings of the words. And sometimes I write the wrong words, like week and weak for example. Sorry for it already. Discord, Twilight, Sunset, Fluttershy, Starlight, Rarity, Luna, Celestia, Big MCintosh, Cadence, Shining, Minuette, Lyra, Rara, Sweetie Belle, Cheerilee, Derpy, Spike. !Feel Free To Talk And Walk Where Ever You Like On This Forum! Link to comment Share on other sites More sharing options...
DDR 215 April 2, 2018 Author Share April 2, 2018 Upgrades are always announced at https://twitter.com/Poniverse , if you're ever curious. I wonder if I can make that Twitter feed show up on the actual error page, so it's more useful than just 'forums gone'. I actually should have posted outage updates there too, but I forgot. I've added that step my incident response checklist for next time. 3 Link to comment Share on other sites More sharing options...
BloodDrops 762 April 23, 2018 Share April 23, 2018 On 01/04/2018 at 12:32 AM, DDR said: Hello everyone, We apologise for the instability and downtime of the forums that occurred today. A spammer was, probably inadvertently, performing a denial of service attack on us – they were requesting so many forum pages and searches that no legitimate traffic could get through. This also maxed out our database, which led to instability and downtime in some other Poniverse services which shared the DB instance. We've blocked the spammer's IP for now, and added basic rate limiting. Let us know if you encounter any 403 "service temporarily unavailable" errors, please. A long-term solution would be to introduce better rate-limiting (so offenders can't take us down as easily) and fail2ban (automatically block offenders from accessing MLPF at all). We will be investigating this over the coming weeks. Whats there Ip I shall throttle their port 1 IT DOESN'T MATTER IF YOU'RE ALIVE OR DEAD YOUR MAREFRIEND IS ALWAYS RIGHT Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Join the herd!Sign in
Already have an account? Sign in here.
Sign In Now