Elevated Easter attack activity
- =(V)=RocketJedi
- Lieutenant Colonel
- Posts: 11559
- Joined: Fri Oct 11, 2013 8:41 pm
- Location: New York
- Has thanked: 72 times
- Been thanked: 17 times
- Contact:
Elevated Easter attack activity
Elevated Easter attack activity
Apr 21 2019 08:18:00 AM PT We are observing particularly frequent and large attacks today at most locations, including NYC. When an attack is occurring that saturates one of our upstream links, our system instantly null-routes the target to minimize damage, but a small burst of packet loss is seen by a segment of clients (those whose inbound traffic came over a saturated upstream link).
The primary source of these attacks continues to be Amazon, as they still do not have systems in place to effectively mitigate outbound attack traffic. Some other cloud providers that do not proactively notice abuse and do not quickly handle abuse notifications are also involved, including Oracle, Microsoft, and DO.
We will continue to mitigate these attacks as they are seen. We have been in contact with a couple of these other cloud providers in the past about improvements that need to be implemented on their end to help, and we have been assured by some that improvements are on the way. In locations that can receive upgrades, such as Chicago, we are also in the process of those upgrades, to help on our end with attacks that may occur later on.
Attacks activity typically comes in bursts, and holidays are a favorite time for attackers to launch attacks.
Apr 21 2019 08:18:00 AM PT We are observing particularly frequent and large attacks today at most locations, including NYC. When an attack is occurring that saturates one of our upstream links, our system instantly null-routes the target to minimize damage, but a small burst of packet loss is seen by a segment of clients (those whose inbound traffic came over a saturated upstream link).
The primary source of these attacks continues to be Amazon, as they still do not have systems in place to effectively mitigate outbound attack traffic. Some other cloud providers that do not proactively notice abuse and do not quickly handle abuse notifications are also involved, including Oracle, Microsoft, and DO.
We will continue to mitigate these attacks as they are seen. We have been in contact with a couple of these other cloud providers in the past about improvements that need to be implemented on their end to help, and we have been assured by some that improvements are on the way. In locations that can receive upgrades, such as Chicago, we are also in the process of those upgrades, to help on our end with attacks that may occur later on.
Attacks activity typically comes in bursts, and holidays are a favorite time for attackers to launch attacks.
=(V)=BloodyRabbit wrote: ↑Tue Oct 10, 2017 3:13 pm That was EPIC! I just creamed all over my panties!!!
-
- Co-Leader
- Posts: 2242
- Joined: Mon Apr 25, 2016 7:59 pm
- Location: Narnia
- Has thanked: 22 times
- Been thanked: 22 times
Re: Elevated Easter attack activity
=O
=(V)=RocketJedi wrote: ↑Wed Sep 27, 2017 4:44 pm During the Cold War, the U.S. considered airdropping enormous condoms labeled "Medium" on the Soviets
=(V)=RocketJedi wrote: ↑Sun Feb 18, 2018 6:33 pm how about we mute the entire server then all you can do is play or rage quit.
=(V)=RocketJedi wrote: ↑Mon Nov 20, 2017 10:49 pm BloodyRabbit is the sexiest man alive!! (Rubs nipples)
Oh RJ, the things you say. This is worth the super long sig
- =(V)=Mar
- Colonel
- Posts: 2602
- Joined: Fri Oct 11, 2013 7:27 pm
- Has thanked: 9 times
- Been thanked: 20 times
Re: Elevated Easter attack activity
It looks like this seems to have affected the server bot which is hosted on DO (Digital Ocean)
I think they blocked the whole IP range :/
@=(V)=RocketJedi can you ask them to whitelist my server ip, please.
I think they blocked the whole IP range :/
@=(V)=RocketJedi can you ask them to whitelist my server ip, please.
- =(V)=RocketJedi
- Lieutenant Colonel
- Posts: 11559
- Joined: Fri Oct 11, 2013 8:41 pm
- Location: New York
- Has thanked: 72 times
- Been thanked: 17 times
- Contact:
Re: Elevated Easter attack activity
I will take a look tonight. I cant access nfo servers from my work network.
=(V)=BloodyRabbit wrote: ↑Tue Oct 10, 2017 3:13 pm That was EPIC! I just creamed all over my panties!!!
-
- Co-Leader
- Posts: 2242
- Joined: Mon Apr 25, 2016 7:59 pm
- Location: Narnia
- Has thanked: 22 times
- Been thanked: 22 times
Re: Elevated Easter attack activity
Status update? =)
=(V)=RocketJedi wrote: ↑Wed Sep 27, 2017 4:44 pm During the Cold War, the U.S. considered airdropping enormous condoms labeled "Medium" on the Soviets
=(V)=RocketJedi wrote: ↑Sun Feb 18, 2018 6:33 pm how about we mute the entire server then all you can do is play or rage quit.
=(V)=RocketJedi wrote: ↑Mon Nov 20, 2017 10:49 pm BloodyRabbit is the sexiest man alive!! (Rubs nipples)
Oh RJ, the things you say. This is worth the super long sig
- Abigor
- Pilot First Class
- Posts: 314
- Joined: Sat Mar 28, 2015 4:31 pm
- Location: hell
- Contact:
Re: Elevated Easter attack activity
still down lol. dont need to ask for that update, just check discord
- =(V)=CandyMan
- Forums Master
- Posts: 7026
- Joined: Fri Oct 11, 2013 7:19 pm
- Location: The Throne of VM
- Been thanked: 3 times
- Contact:
Re: Elevated Easter attack activity
The last time we spoke to our host, this was their response:
Thanks for contacting us today.
Right now, Digital Ocean is entirely blocking all of our IP address space as part of emergency mitigation as they deal with a serious fraud and abuse problem on their network. We have asked several times for them to improve this system by adding a whitelist or by switching to a simple rate-limiting strategy, but they seem unwilling to do so. We will continue to petition them for these measures from our side. DO seems to have limited experience when it comes to handling abuse and DDoS attacks.
So basically, until Digital Ocean is willing to work on improving their systems and such, the server bot on the Discord will be down until further notice, unless we use another host, like our webhost (RJ suggested that).
Thanks for contacting us today.
Right now, Digital Ocean is entirely blocking all of our IP address space as part of emergency mitigation as they deal with a serious fraud and abuse problem on their network. We have asked several times for them to improve this system by adding a whitelist or by switching to a simple rate-limiting strategy, but they seem unwilling to do so. We will continue to petition them for these measures from our side. DO seems to have limited experience when it comes to handling abuse and DDoS attacks.
So basically, until Digital Ocean is willing to work on improving their systems and such, the server bot on the Discord will be down until further notice, unless we use another host, like our webhost (RJ suggested that).
Co-Leader of the Vulpine Mission branch(es) in War Thunder and Call of Duty.
My tags are: =VM19=Coty2255 and |VM|TH3 J0K3R
More games and divisions are coming soon...
-
- Co-Leader
- Posts: 2242
- Joined: Mon Apr 25, 2016 7:59 pm
- Location: Narnia
- Has thanked: 22 times
- Been thanked: 22 times
Re: Elevated Easter attack activity
Ah, okay
=(V)=RocketJedi wrote: ↑Wed Sep 27, 2017 4:44 pm During the Cold War, the U.S. considered airdropping enormous condoms labeled "Medium" on the Soviets
=(V)=RocketJedi wrote: ↑Sun Feb 18, 2018 6:33 pm how about we mute the entire server then all you can do is play or rage quit.
=(V)=RocketJedi wrote: ↑Mon Nov 20, 2017 10:49 pm BloodyRabbit is the sexiest man alive!! (Rubs nipples)
Oh RJ, the things you say. This is worth the super long sig
- =(V)=Mar
- Colonel
- Posts: 2602
- Joined: Fri Oct 11, 2013 7:27 pm
- Has thanked: 9 times
- Been thanked: 20 times
Re: Elevated Easter attack activity
Damn :/
The DiscordBot is made on Nodejs I dont think we can host that on our webhost.
I don't know why they just don't let us whitelist ips.
The DiscordBot is made on Nodejs I dont think we can host that on our webhost.
I don't know why they just don't let us whitelist ips.
- =(V)=RocketJedi
- Lieutenant Colonel
- Posts: 11559
- Joined: Fri Oct 11, 2013 8:41 pm
- Location: New York
- Has thanked: 72 times
- Been thanked: 17 times
- Contact:
Re: Elevated Easter attack activity
they are blocking us. We (our host) are not blocking them.
=(V)=BloodyRabbit wrote: ↑Tue Oct 10, 2017 3:13 pm That was EPIC! I just creamed all over my panties!!!
- =(V)=CandyMan
- Forums Master
- Posts: 7026
- Joined: Fri Oct 11, 2013 7:19 pm
- Location: The Throne of VM
- Been thanked: 3 times
- Contact:
Re: Elevated Easter attack activity
Well until we come up with a solution I could remove the VMBot from the Discord server until further notice, it's solely up to you folks.
Co-Leader of the Vulpine Mission branch(es) in War Thunder and Call of Duty.
My tags are: =VM19=Coty2255 and |VM|TH3 J0K3R
More games and divisions are coming soon...
- Abigor
- Pilot First Class
- Posts: 314
- Joined: Sat Mar 28, 2015 4:31 pm
- Location: hell
- Contact:
Re: Elevated Easter attack activity
it wouldn't make a difference. people would still type it in then wonder what happened to the bot. then you would have a new question everyday lol=(V)=CandyMan wrote: ↑Tue May 28, 2019 3:34 pm Well until we come up with a solution I could remove the VMBot from the Discord server until further notice, it's solely up to you folks.
- =(V)=Mar
- Colonel
- Posts: 2602
- Joined: Fri Oct 11, 2013 7:27 pm
- Has thanked: 9 times
- Been thanked: 20 times
Re: Elevated Easter attack activity
Oh sorry, didn't read correctly the first time.=(V)=RocketJedi wrote: ↑Tue May 28, 2019 9:23 amthey are blocking us. We (our host) are not blocking them.
I will see what it can be done on their side then.
- =(V)=RocketJedi
- Lieutenant Colonel
- Posts: 11559
- Joined: Fri Oct 11, 2013 8:41 pm
- Location: New York
- Has thanked: 72 times
- Been thanked: 17 times
- Contact:
Re: Elevated Easter attack activity
no worries :) just wanted to make sure everyone understood.=(V)=Mar wrote: ↑Tue May 28, 2019 8:05 pmOh sorry, didn't read correctly the first time.=(V)=RocketJedi wrote: ↑Tue May 28, 2019 9:23 amthey are blocking us. We (our host) are not blocking them.
I will see what it can be done on their side then.
=(V)=BloodyRabbit wrote: ↑Tue Oct 10, 2017 3:13 pm That was EPIC! I just creamed all over my panties!!!
- =(V)=Mar
- Colonel
- Posts: 2602
- Joined: Fri Oct 11, 2013 7:27 pm
- Has thanked: 9 times
- Been thanked: 20 times
Re: Elevated Easter attack activity
Here's what DO support said
:/ so we cant do anything other than wait.Hello,
Thank you for contacting DigitalOcean support !
Thanks for reaching out, and I'm sorry for the trouble there. Due to repeated abuse issues, we are currently blocking all traffic to NuclearFallout IP address ranges. Our own network infrastructure team and the NuclearFallout team are working together to mitigate the issue, which has resulted in some improvement, but for now the blackhole is temporarily in place until the issues subside.
Please let us know if we can be of further assistance!