Hi,

We had a DDOS attack against old.lemmy.today which overloaded the entire server for about 20 minutes. I had to turn off old.lemmy.today temporarily and will look through logs and probably block more chinese ip ranges, since thats where it came from.

Always something to do. :) Keeping this as sticky for a while to inform everyone.

Edit: I added more ip blocks for Chinese networks and hopefully it will keep future bots away. Bringing up the old.lemmy.today user interface again…

    • mrmanager@lemmy.todayOPM
      link
      fedilink
      arrow-up
      2
      ·
      9 hours ago

      It’s manual at this point since it hasn’t been a huge problem so far, but we will see how it evolves. Perhaps it gets worse as the instance grows bigger.

  • db0@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    4
    ·
    15 hours ago

    Look into pow protection. The Chinese botnets come from a practically infinite range at the moment

      • mehquestion@lemmy.world
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        7 hours ago

        First, thank you for all the hard work you do.

        Second, as someone still struggling to understand lemmy, one of the reasons I’m not a fan of old.lemmy.world is that I have to turn on cloudflare.

        I have noscript running and I have cloudlflare blocked.

        Your response implies otherwise that you don’t have cloudflare running either.

        So why am I always greeted with cloudflare when I visit old.lemmy.world?

        Edit: Oh I misread the title. Its old.lemmy.today that you’re talkinga bout, not old.lemmy.world.

        My goof. Please ignore my post, but do take my gratitude.

        Edit 2: So I went over to old.lemmy.today. It is tempting to switch. I like the default interface and it has content from a lot of places (on quick glance). One of the reasons I’m not a huge fan of old.slrpnk.net is that I can’t figure out how to access content from other instances. I seem tempted to switch.

        • mrmanager@lemmy.todayOPM
          link
          fedilink
          arrow-up
          3
          ·
          5 hours ago

          You are very welcome if you do. Its the same content in old.lemmy.today as lemmy.today, just a different look. :)

          I dont like cloudflare so doing my best to avoid it if I can.

  • freudian_slop@programming.dev
    link
    fedilink
    arrow-up
    12
    ·
    22 hours ago

    I don’t have an account there but I am always happy when fediverse instance admins are transparent about their problems. This will help other instances too.

  • MyOpinion@lemmy.today
    link
    fedilink
    English
    arrow-up
    12
    ·
    23 hours ago

    When I was running a web server this was a common occurrence. Most of the DDOS attacks I experienced came from China.

      • YiddishMcSquidish@lemmy.today
        link
        fedilink
        English
        arrow-up
        7
        ·
        22 hours ago

        This is a genuine question, but why doesn’t this instance? Is it because we would miss out on some content? I mean you are much more in touch with the technicalities, but do we have a mandarin speaking user base you’re not trying to alienate?

        • mrmanager@lemmy.todayOPM
          link
          fedilink
          arrow-up
          8
          ·
          22 hours ago

          I think we are unfortunantly heading in that direction of blocking more and more of them…

          And no, no mandarin user base. :)

      • mrmanager@lemmy.todayOPM
        link
        fedilink
        arrow-up
        6
        ·
        21 hours ago

        Very good, I pulled the latest version.

        Thanks for your work on this, and the code you added to forward ip numbers was super useful today to see where these botnets are coming from. Really appreciate it.

      • CalcProgrammer1@lemmy.today
        link
        fedilink
        English
        arrow-up
        4
        ·
        21 hours ago

        Thanks to both of you for keeping mlmym alive. It’s the best way to use Lemmy and I moved to lemmy.today primarily because they have it as an available interface.

      • somebody_to_love@lemmy.today
        link
        fedilink
        arrow-up
        2
        ·
        20 hours ago

        Thanks to both of you!

        Now that you’re both here, I have a question/request. What I love most from the “old Reddit” interface is using RES to navigate through posts with the keyboard: “h” to hide, j/k as up/down, “l” to open in a new tab, etc. Makes browsing super fast and efficient.

        Is this something you’d consider? I’m not asking for a full RES reimplementation, of course. Just the keyboard navigation.

        • mschae@discuss.mschae23.de
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          19 hours ago

          I know of the lemmy keyboard navigation addon that reimplements this feature for lemmy-ui and mlmym. I haven’t tested it myself though, and it’s been last updated over a year ago, so I don’t know if it still works. I have thought about including the feature directly in mlmym (could actually make use of the keyboard navigation setting that lemmy already has to toggle it), but if I do, that’ll only happen after I’m done with the refactor for the v4 API. So it will probably take a while 😅

          edit: opened an issue for it (#27) so I don’t forget

  • ThunderComplex@lemmy.today
    link
    fedilink
    English
    arrow-up
    5
    ·
    22 hours ago

    Thanks for keeping the instance running. I happened to get a error message smth about the instance being broken and remembering that disk upgrade post from a couple days ago I feared the DB got nuked for a sec hehe.

  • Wren@lemmy.today
    link
    fedilink
    English
    arrow-up
    1
    ·
    21 hours ago

    Thanks for the heads up. I got a brief error message a while ago and figured that’s what happened. Good job keeping the instance going!

    • mrmanager@lemmy.todayOPM
      link
      fedilink
      arrow-up
      3
      ·
      21 hours ago

      Thank you! These ddos attacks are annoying but not so common after all. Last time was like 3 months ago or something.

  • Johnny_Arson [she/her]@hexbear.net
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    2
    ·
    17 hours ago

    more ip blocks for Chinese networks

    Lmao I don’t think China is attacking you and this reeks of main character syndrome and xenophobia.