Bonum Certa Men Certa

DDOS and Migration (Updated)

Summary: Boycott Novell had been under DDOS attacks for almost 4 days. We were struggling to just stay online while hosts investigated where the attacks came from. We moved between hosts (to semi-dedicated) and the same pattern of attack persisted until yesterday.

WE have kept silent about it in order not to encourage the attacker/s, but it's true. We have been under heavy DDOS attacks since Thursday night. What has happened since then? Well, a lot. Our previous host is no more as far as we are concerned. After struggling with the botnet for like 10 hours (filtering to no avail) our Web site got isolated. It did not serve any pages for almost 2 days. A reader of Boycott Novell was kind enough to lend us room on his server (more or less dedicated), on which he fought the botnets for over a day. The attackers kept changing tactics. Some other readers offered filtering advice and we are grateful to all of them. Ultimately, the attacks halted yesterday afternoon.



“Ultimately, the attacks halted yesterday afternoon.”The migration from the old server was not simple because the site was disabled abruptly following the early attacks. But now we have ensured that all data has been migrated. The only 'good' thing which came out of this attack is that, as oiaohm put it, the ordeal sort of made us more robust to future attacks.

Now that we have a new host in place, we also have more features. Data on the site (comments, posts, etc.) was not lost in the migration, just heaps of time and effort affecting several people. We have moved to a bigger, more robust environment that will hopefully facilitate the needs of the Web site as it continues to grow (we served about 200GB of data last month). We apologise for the downtime, which is unprecedented.

The plan is to carry on exposing Comes exhibits next month and also organise the Wiki. There is enough for years of work.

Again: we would like to thank all those who helped during the downtime and especially our generous reader ( Copilotco) who offered to host the Web site, taking us away from shared hosting in the process. Dedicated servers on normal Web hosts are just far too expensive for us to afford and I swear that I never made a single dime from this Web site. The ads merely covered the hosting fees which Shane has been paying since 2006.

One last clarification for lunatics who are now suggesting that we DDOSed ourselves, where to even begin refuting such nonsense (coupled with personal abuse)?

The attacks came from many addresses, for example 88.198.60.8 which is "tor-proxy.va6.de". Multiple such IPs hit us constantly and relentlessly (all tor exit nodes at first). At one stage it seemed like the front page alone received 3 page requests per second. But the IPs were also doing a HEAD on the Web site as many times as possible, bringing the server down to its knees (both the old server and new server, the former running Red Hat and the latter CentOS). ⬆

Update: Here is a report from the administrator.

I took over hosting of boycottnovell.com for Roy in the middle of the DDOS attack. I am looking at the squid log for boycottnovell.com during the DDOS. I have squid caching/proxying/url-rewriting for apache for various reasons.

The attack initially (or at least, at the time the DNS was re-pointed to my server) consisted of lots of HEAD requests. Then I wrote up a script to tail the log finding anyone doing lots of HEAD requests and putting the offending IP into the iptables packet filter while I cooked up a more permanent solution. Eventually they figured this out and switched to a full on GET of the root of the site and then I think they started getting random pages from the site as fast as they could although I'm not sure about that.

The interesting part starts around timestamp 1242543590.804 which is apparently when most of the world's DNS cut over to me including that of the machines in whatever bot net was employed in the attack.

If we run this command on the logfile with the logfile being /tmp/bn.log:




grep " HEAD http://boycottnovell.com/ " /tmp/bn.log | awk '{print $3}' | sort | uniq -c |sort -n | tail -10



we get:

   2716 81.175.61.4
   2960 212.24.147.228
   3056 204.209.56.56
   5637 87.236.199.73
   6645 145.100.100.190
   7261 212.42.236.140
   8487 88.198.14.120
   9640 62.141.58.13
  11008 87.118.104.203
  11269 88.198.60.8


and if we do:




grep " GET http://boycottnovell.com/ " /tmp/bn.log | awk '{print $3}' | sort | uniq -c |sort -n|tail -10



we get:




5801 94.136.16.242 5854 85.25.152.185 5865 212.24.147.228 6367 66.35.1.170 6682 205.209.142.210 6977 87.118.104.203 8102 83.140.125.188 8300 85.25.145.98 8441 212.42.236.140 20065 66.230.230.230



So one IP did a get of the root of the site 20k times before I really effectively got everything blocked off and another did a HEAD around 11k times. You can get a feel for how the attack progressed using:




egrep ' GET http://boycottnovell.com/ | HEAD http://boycottnovell.com/ ' /tmp/bn.log | less



Assuming that everyone who did a GET or a HEAD more than 100 times (a conservative estimate) is involved in the attack:




egrep ' GET http://boycottnovell.com/ | HEAD http://boycottnovell.com/ ' /tmp/bn.log | awk '{print $3}' | sort | uniq -c| sort -n > /tmp/attackers



and then counting only the lines with greater than 100 hits we can see that there were 281 unique IP addresses involved in the attack.

However, it looks like they switched to targeting various different parts of the site later on or maybe just random pages because if we look at all of the accesses to the site which made more than 100 requests we get 863 IPs involved the top 19 being the following:




6193 62.141.53.224 7153 85.25.151.22 7764 145.100.100.190 8524 66.35.1.170 8757 94.136.16.242 9256 85.25.152.185 10369 83.140.125.188 10464 212.24.147.228 10874 205.209.142.210 10935 87.236.199.73 11441 88.198.14.120 12094 62.141.58.13 12208 88.198.60.8 12994 66.249.70.134 13940 85.25.145.98 19119 212.42.236.140 19867 87.118.104.203 26480 216.105.40.113 29854 66.230.230.230



So 66.230.230.230 made 29k requests to the site in total.

Putting some iptables rules in place (which I document here):

http://www.kernel-panic.org/pipermail/kplug-list/2009-May/108075.html

nicely cut the problem down to size and now the effect of the DOS is unnoticeable.

11M of gzipped log are used for this sample.

Comments

Recent Techrights' Posts

Slop is Plagiarism
Plagiarism is not "theft" and copyright infringement is not "piracy"
EPO Union Bemoans Lack of Social Dialogue as Dictator Wishes to Govern Forever (No Elections, No Rivals), Hide the Many Issues
"Exchange of open letters"
IBM Cannot Hide the Layoffs Forever
we welcome whistleblower to tell us more and send us documents related to that
What is a Conditional Fee Agreement (CFA)? When Law Firms Become the Litigants.
And the Solicitors Regulation Authority (SRA) needs to be more serious about tackling this
 
EPO's Local Staff Committee The Hague (LSCTH) Plans Presentation Next Week (Coinciding With Apparent Coronation of 'Cocaine King' Campinos)
They've outsourced this session to the dictator's spying eye
The GNOME Foundation's Code of Conduct Has Been Misused to Hide Corruption
People who value free speech and freedom of expression won't touch social control media with a 10-foot bargepole
Voting for Freedom of the Press
American elections happen every 4 years
What Brett Wilson LLP and Matt Garrett Don't Want People to See/Read
Book-burning is counterproductive
Book-Burning Mindset Does Not Work
It makes the suppressed voices more widely known
Microsoft's XBox in 'Freefall'
XBox is practically finished
IBM is Almost Defunct
IBM is doomed. It just tries to test how much more patience the shareholders have.
Criminalisation of Journalism
"Journalist Derya Okatan arrested in Turkey for allegedly possessing classified material"
Brigading Against Women - Part XXI - Hiding Behind the Veil of "Privacy" After Telling Nazi Things in IRC Channels of Techrights and Physically Threatening People
To merely explain an abuse (or crime) requires naming people; that's a fundamental tenet of reporting
Links 07/10/2026: Quitting Smartphone and "Meta's Muse Is Spying on All Your Friends and Family"
Links for the day
Gemini Links 07/10/2026: Greed, In Praise of Zotero, and The de-Google Path
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, October 06, 2026
IRC logs for Tuesday, October 06, 2026
Microsoft Hiring Only on the Cheap
Much of the same can be said about GAFAM and IBM
Gemini Links 06/10/2026: Nightfall Express, Shorthanding, and Raspberry Pi Desktop Gets a Debian Trixie Refresh
Links for the day
20th Anniversary Next Month
We are currently trying to agree on a plan for next month's celebrations
Taking Photos With Richard Stallman (RMS)
What's the point?
GAFAM Attack on FreeDesktop
Now they push lots of LLM slop into Linux
GNU/Linux Has Risen in France Since the Order to Adopt GNU/Linux (in Public Services)
We can expect the same in countries like Denmark, Switzerland, Germany, and The Netherlands
On Microsoft Hiring Freeze or No Permanent Jobs at Microsoft Anymore (Amid Many Silent Layoffs)
Microsoft has changed what it can offer workers
EPO's Central Staff Committee Asking The Council to Get Rid of Corrupt Campinos
We'll be covering EPO scandals around the time of that meeting
Gemini Links 06/10/2026: EU Kids Act, Practicality of Gemini, and Games
Links for the day
Links 06/10/2026: Data Breaches Epidemic and Turkey Blocking Journalists
Links for the day
The Whole Point of Computing is That Computers Are Deterministic (Speed With Predictable Accuracy)
Unlike stochastic parrots that stochastically utter out lies
It's Not a Linux Back Door If It's an Unpatched Device
"Linux Backdoor" is a glaring misfit, a possibly 'obscene' term
Brigading Against Women - Part XX - Attempts by Lozza to Deplatform Techrights and Tux Machines Only Days After I Sued Garrett and My Wife Also Sued Garrett (Shortly Before the Serial Strangler From Microsoft Joined)
in 2024
Links 06/10/2026: A Year Since "NSA Whistleblower Reality Winner Released From Prison", World Tries to Deal With El Niño
Links for the day
"SIRIUS CORPORATION LIMITED" as Evidence of the Financial Shell Games in the UK
Rianne and I still have some fond memories of the time the ex-wife of the CEO treated us like human beings
Lots of Silent Layoffs at IBM Last Week, Employees Explain Patterns of Those Impacted
It wasn't just gossip, it actually happened even if the media chose to look the other way (as usual)
Gemini Links 06/10/2026: Fighting for Purpose, Gemlogs, and Gemtext
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, October 05, 2026
IRC logs for Monday, October 05, 2026
Red Hat is Phased Out of Existence This Month Onwards
Within a few years we'll probably not see many redhat.com addresses anymore; many became ibm.* last week
Finland's GNU/Linux Share Measured at 12%
Last month GNU/Linux was measured at about 10% in Finland
UK Layoffs and Closures by Microsoft. In Expected Blow, Microsoft Likely Shuts Down Another Studio.
Microsoft's layoffs are never-ending, they just try to keep them all secret.
NVIDIA Buys the Media With Companies It Sponsors to Pretend to be Customers (Circular Funding Scheme)
The media crisis worsens
Discussion About Potential Sale of EPO Buildings and Enshittification of Europe's Largest Patent Office
It's noteworthy that only one hour (or 70 minutes) was devoted to so many topics
Brigading Against Women - Part IXX - Overreaction From Young Female Professional After Invalid Threats Made and Sent From an Incel in Another Continent
Cowards who send threats after committing crimes online
Stonewalling by Bots
We'll now turn our attention back to EPO and other matters
Gemini Links 05/10/2026: "Posthumanism", Cardputer, and More
Links for the day
Links 05/10/2026: “I’m Embarrassed on Behalf of the Tech Industry” and Slop Scammers "Lobbying the Vatican"
Links for the day
SIRIUS OPEN SOURCE LTD Officially Insolvent, Is Reform UK Next?
Sirius no more
Links 05/10/2026: "Congress Must Investigate War Profiteers Once Again" and Update on Thomson Reuters v. Ross Intelligence
Links for the day
libera.chat is an Agenda-Peddling Platform Run by Agenda-Peddling Individuals
The volunteers of libera.chat ("staff") aren't working for free, they work towards an agenda
Nobel Season is Plutocracy Week
Later this week the billionaires will give a fake "Nobel" (in "Economics") to someone who parrots their preferred narrative and those same billionaires will use "Nobel" to bless the promoter of their latest pyramid scheme/buzzword
GNU/Linux Market Share in North America 13% This Past Weekend
It is perhaps not shocking that adoption of GNU/Linux is very high there
When Did Europe Begin to Side With White-Collar Criminals (or Participate in Suppressing People Who Oppose Them)?
How much corruption can we tolerate before the European Union becomes another Russian Federation?
Libera Chat's "Level of Control Might Make Sense for a Corporate Platform"
IRC is not centralised
Brigading Against Women - Part XVIII - Turning Censorship Attempts (Articles About Matthew Garrett) Into Mild Redactions
What Lozza did two years ago
Greenland Needs Digital Sovereignty
the large icy island isn't moving to GNU/Linux as quickly as the rest of Europe
Tracker of Internet Relay Chat Networks Out of Service (But Not Down) Since Thursday
We should note that the number of unique networks they track has grown since we last checked
Gemini Links 05/10/2026: NixOS, Guix, Codeberg Banning Slop, and "Gopher Apps on Android"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, October 04, 2026
IRC logs for Sunday, October 04, 2026