Instagram AmazingRibs Facebook AmazingRibs X - Meathead Pinterest AmazingRibs Youtube AmazingRibs

Welcome!


This is a membership forum. Guests can view 5 pages for free. To participate, please join.

[ Pitmaster Club Information | Join Now | 30 Day Trial | Login | Contact Us ]

Only 4 free page views remaining.

Announcement

Collapse
No announcement yet.

The Forum Is Wonky

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    #61
    All is well as of now.

    Of course, just after I fix the configurations to start login real IP addresses, the bots vanished.

    Red line is where the configuration was fixed...

    Click image for larger version

Name:	image.png
Views:	267
Size:	31.8 KB
ID:	1767872

    Figures.

    I am now certain that this was either a direct DOS/DDOS attack or someone scraping the site (and being a jerk since you can set your scraper/crawler to slowly hit the site, even once a second would not be noticeable). One other bit of info, found via CloudFlare, most of the hits were from Hong Kong.

    I created access log scanner script to pull the offending IPs when (not if) this happens again. I might work on an automated blocker. If more that x hits in x minutes, block for x hours.

    Comment


    • Panhead John
      Panhead John commented
      Editing a comment
      That’s exactly what I was going to recommend! 🙄

      Thanks Ray!

    • jayjordan
      jayjordan commented
      Editing a comment
      raywjohnson - Thanks for the many hours you put into finding and resolving the issues!

    • Duanessmokedmeats
      Duanessmokedmeats commented
      Editing a comment
      I recommend an airstrike on Hong Kong!

    #62
    Updated Graph: I realize that the times were UTC. I set the account Timezone to Central. And my red line was off a bit...

    Click image for larger version

Name:	image.png
Views:	237
Size:	32.0 KB
ID:	1767877

    Comment


      #63
      All this scraping of data, often copyrighted, to produce AI insightful analysis and easy to understand information to educate people. I feel smarter already. 🙄

      Click image for larger version

Name:	IMG_2682.jpg
Views:	236
Size:	191.0 KB
ID:	1767919

      Comment


      • Huskee
        Huskee commented
        Editing a comment
        This pic is hilarious!

      #64
      Ray,

      As I work in infosec, I appreciate you taking the time to share the technical details. I wish I had a useful suggestion to offer. At the risk of suggesting something utterly unpractical, have you considered nginx? It seems to be a little more DDoS resilient in my experience. Granted, that would be a major architecture change and something that would be far down the road, of course.

      Horizontal scaling is also probably out of the picture due to expense, I imagine. And that would just mitigate, but not solve, the problem.

      DDoS attacks are insidious. We certainly get them from time to time at the University. For us, when they occur our procedure is to go get a cup of coffee and take a walk around the datacenter. We have such a huge inbound pipe that there effectively is no defense.

      My favorite DDoS story is when we DDoS'ed ourselves. It was Wednesday, September 19, 2012. Approximate mid-day, we couldn't get to external web sites. Then we "fell off the internet." Rice University soon followed.

      We quickly realized the traffic flood was coming from inside our network, nearly all from our wireless network. We were being attacked from within! A few packet captures later we saw what was happening and couldn't believe it.

      Apple had released its much-anticipated iOS 6 update that day. 20,000+ iPhones were all trying to download it at once. Due to a horrendous misconfiguration with Akamai, it flooded our network and, as at the time, we went through Rice to go to the outside world, we brought them down, too!

      Fun day.

      Comment


      • DaveD
        DaveD commented
        Editing a comment
        The call is coming from INSIDE THE HOUSE....!!

      #65
      Takeaway: even bots and nefarious ne'er-do-wellers can't stay away from us.

      Comment


      • Jerod Broussard
        Jerod Broussard commented
        Editing a comment
        You've pointed out Panhead John what else ya got

      • Panhead John
        Panhead John commented
        Editing a comment
        Hey, I’m no bot! A nefarious ne’er-do-weller? Well, occasionally…..🥸

      • Smoker_Boy
        Smoker_Boy commented
        Editing a comment
        I can't even spell nefarious.

      #66
      Originally posted by Michael_in_TX View Post
      As I work in infosec, I appreciate you taking the time to share the technical details. I wish I had a useful suggestion to offer. At the risk of suggesting something utterly unpractical, have you considered nginx? It seems to be a little more DDoS resilient in my experience. Granted, that would be a major architecture change and something that would be far down the road, of course.
      I am not a fan of nginx (for those that do not know, it is pronounced Engine X). The configuration for anything complex is always difficult. And no .htaccess files. Everything has to be in the config file. It is currently used on the main (free) site. I dread having to make changes to the config.

      Originally posted by Michael_in_TX
      Horizontal scaling is also probably out of the picture due to expense, I imagine. And that would just mitigate, but not solve, the problem.
      Yep. I robust solution would be to have 7 servers, 2 for load balancing, 4 to serve the site, and one for the database. 2 load balancing so that if one goes down, the other will still be operational (they could also be uses as caching proxies for static content using.... nginx! But easy configure and you rarely have to make changes). All this makes the costs x 7. Not to mention the extra complexity and managment.

      Originally posted by Michael_in_TX
      DDoS attacks are insidious. We certainly get them from time to time at the University. For us, when they occur our procedure is to go get a cup of coffee and take a walk around the datacenter. We have such a huge inbound pipe that there effectively is no defense.

      My favorite DDoS story is when we DDoS'ed ourselves. It was Wednesday, September 19, 2012. Approximate mid-day, we couldn't get to external web sites. Then we "fell off the internet." Rice University soon followed.

      We quickly realized the traffic flood was coming from inside our network, nearly all from our wireless network. We were being attacked from within! A few packet captures later we saw what was happening and couldn't believe it.

      Apple had released its much-anticipated iOS 6 update that day. 20,000+ iPhones were all trying to download it at once. Due to a horrendous misconfiguration with Akamai, it flooded our network and, as at the time, we went through Rice to go to the outside world, we brought them down, too!

      Fun day.
      Fun day indeed!​

      Comment


        #67
        Actual unretouched photo taken on the outskirts of Hong Kong of Ray conducting a commando op from his home in Thailand to root out the cyberattackers...

        Click image for larger version

Name:	Ray Johnson IT commando.png
Views:	201
Size:	1.90 MB
ID:	1768245

        Comment


        • STEbbq
          STEbbq commented
          Editing a comment
          Seriously, it Ray doesn’t make this his avatar…it is perfect.

        • SheilaAnn
          SheilaAnn commented
          Editing a comment
          Do it ray!!

          Avatar!
          Avatar!
          Avatar!

        • RAYMBO
          RAYMBO commented
          Editing a comment
          Done!

        #68
        Yes... it is Raymbo: First Blood, part 37. We just need that voice-over dude from back in the day... "In a world where Hong Kong hackers attack a barbecue forum... Only one man can stop them: RAYMBO."

        Click image for larger version

Name:	Raymbo.jpg
Views:	196
Size:	366.0 KB
ID:	1768301
        Last edited by DaveD; September 9, 2025, 06:45 PM.

        Comment


        • Donw
          Donw commented
          Editing a comment
          Okay Ray. New member name!

          RAYMBO
          Code Ninja

        #69
        Yeah!!! Raymbo in da houuuuuuuuse!!!

        Comment


        • STEbbq
          STEbbq commented
          Editing a comment
          Woohoo!!!!!

        #70
        raywjohnson Last night, East coast time, and continuing into this morning I’m getting a lot of “Working” messages and also Error 0 messages. Basically a slowdown.

        Comment


        • Panhead John
          Panhead John commented
          Editing a comment
          It’s starting to mess up for me also. The last few hours have been slow, very slow, to load pages or to post something. @RAYMBO

        • RAYMBO
          RAYMBO commented
          Editing a comment
          I checked the load data. There was a spike for about 2 hours on CPU and DISK, but not network. So something on the server. The daily backup lasts about 6 minutes. Let me know if the site is still slow for you.

        #71
        raywjohnson I have not had the issues reported this time. I must be special.

        Comment


        • RAYMBO
          RAYMBO commented
          Editing a comment
          special special

        #72
        Painfully slow today for some reason. Anyone else seeing this same issue?

        Comment


        • Sid P
          Sid P commented
          Editing a comment
          Yep, a lot of "Working".

        • Panhead John
          Panhead John commented
          Editing a comment
          Same here. It’s off and on sloooow. Been going on for a few days now. Occasionally it’s taken 30 seconds to a minute to load or change pages.

        #73
        20 minutes ago I couldn't do anything.
        Now it's fine.

        Comment


          #74
          I had a couple of burps today.

          Comment


            #75
            When I just now clicked on this page in Notifications, it took about 30-45 seconds to get here. Does it on my iPad and iPhone running the latest update.

            Comment


            • Huskee
              Huskee commented
              Editing a comment
              The blocks I set up to stop you are failing and it's letting you in!! Drat!

            • Panhead John
              Panhead John commented
              Editing a comment
              With all my skills I should put my name in the hat for the next administrators position…..🥸

            • Huskee
              Huskee commented
              Editing a comment
              You just may have more skills than I!

          Announcement

          Collapse
          No announcement yet.
          Working...
          X
          false
          0
          Guest
          Guest
          500
          ["membership","help","nojs","maintenance","shop","reset-password","authaau-alpha","ebooklogin-start","alpha","start"]
          false
          false
          Yes
          ["\/forum\/free-deep-dive-guide-ebook-downloads","\/forum\/free-deep-dive-guide-ebook-downloads\/1157845-paid-members-download-your-6-deep-dive-guide-ebooks-for-free-here","\/forum\/the-pitcast","\/forum\/national-barbecue-news-magazine","\/forum\/national-barbecue-news-magazine\/national-barbecue-news-magazine-aa","\/forum\/national-barbecue-news-magazine\/national-barbecue-news-magazine-aa\/bbq-news-magazine-2019-issues","\/forum\/national-barbecue-news-magazine\/national-barbecue-news-magazine-aa\/bbq-news-magazine-2020-issues","\/forum\/national-barbecue-news-magazine\/national-barbecue-news-magazine-aa\/bbq-news-magazine-2021-issues","\/forum\/national-barbecue-news-magazine\/national-barbecue-news-magazine-aa\/bbq-news-magazine-2022-issues","\/forum\/national-barbecue-news-magazine\/national-barbecue-news-magazine-aa\/current-2023-issues","\/forum\/national-barbecue-news-magazine\/national-barbecue-news-magazine-aa\/current-2024-issues","\/forum\/national-barbecue-news-magazine\/national-barbecue-news-magazine-aa\/current-2025-issues","\/forum\/national-barbecue-news-magazine\/national-barbecue-news-magazine-aa\/current-2026-issues","\/forum\/bbq-stars","\/forum\/bbq-stars\/tuffy-stone","\/forum\/bbq-stars\/meathead","\/forum\/bbq-stars\/harry-soo","\/forum\/bbq-stars\/matt-pittman","\/forum\/bbq-stars\/kent-rollins","\/forum\/bbq-stars\/dean-fearing","\/forum\/bbq-stars\/tim-grandinetti","\/forum\/bbq-stars\/kent-phillips-brett-gallaway","\/forum\/bbq-stars\/david-bouska","\/forum\/bbq-stars\/ariane-daguin","\/forum\/bbq-stars\/jack-arnold","\/forum\/free-deep-dive-guide-ebook-downloads"]
          /forum/free-deep-dive-guide-ebook-downloads