{"id":24938,"date":"2015-02-23T08:54:59","date_gmt":"2015-02-23T14:54:59","guid":{"rendered":"http:\/\/rankexploits.com\/musings\/?p=24938"},"modified":"2015-02-23T08:54:59","modified_gmt":"2015-02-23T14:54:59","slug":"bozer-and-his-bulgarians-ddos","status":"publish","type":"post","link":"https:\/\/rankexploits.com\/musings\/2015\/bozer-and-his-bulgarians-ddos\/","title":{"rendered":"Bozer and his Bulgarians: DDOS?"},"content":{"rendered":"<p>This is an open thread. But I want to tell people what&#8217;s been up on the back end of the blog.<\/p>\n<p>Have some of you seen internal error pages? Been presented the &#8220;scary page&#8221; after commenting? That was my fault. Thanks for emailing me. <\/p>\n<p>A variety of temporary glitches were introduced as I edited both the &#8216;.htaccess&#8217; and the &#8216;zbblock&#8217; files that I use to deal with bots.  I did something of a &#8216;re-organize&#8217;. <\/p>\n<p>Why?I&#8217;ve been dealing with what appears to have been a fairly low-tech, slow, d-semi-dos; that is: it seemed to be &#8216;distributed&#8217; and but seemed to only semi-deny service. So &#8220;distributed-semi-denial-of-service.   The main features were\/are<\/p>\n<ul>\n<li>A specific old post was requested roughly every two minutes. (The request rate is now reduced.)<\/li>\n<li>The overwhelming majority of requests come from thousands of different IPs associated with server farms or some sort. Of the remaining, most requests come from countries with reputations of hosting quite a bit of hacking\/spamming.  A small amount does come from connection providing ISPs in &#8216;mostly clean&#8217; countries. <\/li>\n<li>Some of the same IPs would return and ask for the post after a period of an hour or so. These &#8216;slow&#8217; returns any individual IP makes it difficult for an upstream CDN like Cloudflare to detect its undesired traffic.<\/li>\n<li>There were\/are features that make this seem like it <i>might<\/i> be &#8216;personal&#8217; (in some sense) rather than just &#8220;garden variety script-kiddy bots who just look for low hanging fruit&#8221;. That said, it&#8217;s really hard to say.<\/li>\n<li>During one period, at least made several requests that revealed x-forward headers which included a second IP: 198.50.228.116.  This IP is at AS16276 OVH  and whois tells me it&#8217;s a &#8220;Private Customer&#8221; in &#8220;Sofia, BG&#8221;. So, I&#8217;ve nicknamed the person (or group of person) hitting the blog &#8220;Bozer and his Bulgarians&#8221;. (This is not to say that I actually suspect this originates in Bulgaria, but who knows.)   <\/li>\n<\/ul>\n<p>Although this behavior was not going to <em>take down<\/em> the server, it was pesky.   <\/p>\n<p>But I also decided the pesky behavior could be turned into an episode of using lemons to make lemonade: it gave me a chance to identify all the new &#8216;pesky servers&#8217; and update my list of &#8216;currently active bad servers&#8217;.  I hadn&#8217;t done that in&#8230; oh&#8230;. a year or two.  So, it needed doing.<\/p>\n<p>Because if the features of these connections, I also changed strategy for dealing with these IPs. Previously I dealt with all the proxyIPs in ZBblock and ultimately banned some at Cloudflare.  I now detect a sizable number of pesky IP ranges and do<br \/>\nRewriteRule ^(.*) http:\/\/%{REMOTE_ADDR}\/ [L]<br \/>\nin htaccess. <\/p>\n<p>This rewrite rule sends the request back to its originating IP.  The current rules are likely over inclusive, and I&#8217;ll be backing some off over time. If you or someone you know runs across it, you (or they) will be told you are having trouble connecting to the site and your IP will be displayed to you.  <\/p>\n<p>A few countries are also currently blocked at Cloudflare. Some of these countries will be unblocked by the end of the week, others will not. (China will never be unblocked. Sorry.)<\/p>\n<p>Of course, somethings still only get blocked in ZBblock. (Last night, people who commented were blocked. Sorry!)<\/p>\n<p>If you see any &#8216;block&#8217; page, email me. Or tweet me.  (Of course, I&#8217;m aware if that&#8217;s happening to you, you won&#8217;t read this post. So, it&#8217;s a bit of a catch-22. But if someone else tells you they are encountering the problem, have <em>them<\/em> email me. )<\/p>\n<p>If someone does ask me to let them through, I will ask them their IPs to help me fix the problem for them&#8211; either by opening a wide range or opening up a specific one for individual static IP. If they refuse to provide IP &#8212; as <I>some people do<\/i>, I will be unable to fix the problem.  If&#8211; for some mysterious reason &#8212; they insist on connecting through Tor, a vpn or some server farm, and lecture me on how I should permit them &#8212; and everyone else on Tor, vpns, or serverfarms&#8211; to do so I will tell them to pound sand. I know perfectly well that they have a non-Tor\/VPN\/server-farm IP they use to connect to Tor\/vpn\/serverfarm. If they are too stubborn to use that to read my blog, I&#8217;m too stubborn to let them use Tor\/vpn\/serverfarm.  <\/p>\n<p>Likewise: I am probably blocking most rss feeds. I can&#8211; over time&#8211; open up some of these as I identify which need to be unblocked. However, from my point of view, preventing the D-S-DOS is a higher priority than unblocking feeds. If you the rss feed <i>you<\/i> prefer is currently blocked and you want it unblocked quickly, you will need to email me, ask me, and&#8211; possibly&#8211; provide information to help me identify the IP ranges\/user agents etc. that particular feed uses. Not to sound too snotty: but if you aren&#8217;t willing to do some digging to supply me with information regarding the feed you prefer, it&#8217;s not going to get unblocked quickly. There are <i>tons<\/i> of things hitting the feed, not all are feed readers.   <\/p>\n<p>Obviously, as I am currently blogging lightly, I don&#8217;t expect to be overwhelmed with request for connection clearing feed etc.  But if your university, country, feed etc. has been blocked let me know. If it&#8217;s easy to fix, I&#8217;ll fix it. If it requires info to fix, I&#8217;ll assign you the task of getting the info, and then fix it. <\/p>\n<p>Anyway, for now, the d-semi-dos seems to have slowed down. The effects of its main strategy seem to be neutralized. If it is a person and it is personal, my posting may cause it to change strategies. If it&#8217;s just a script-kiddie, it&#8217;s taken care of.  <\/p>\n<p>Either way, open thread. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is an open thread. But I want to tell people what&#8217;s been up on the back end of the blog. Have some of you seen internal error pages? Been presented the &#8220;scary page&#8221; after commenting? That was my fault. Thanks for emailing me. A variety of temporary glitches were introduced as I edited both &hellip; <a href=\"https:\/\/rankexploits.com\/musings\/2015\/bozer-and-his-bulgarians-ddos\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Bozer and his Bulgarians: DDOS?<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[382],"tags":[],"class_list":["post-24938","post","type-post","status-publish","format-standard","hentry","category-spam"],"_links":{"self":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/posts\/24938","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/comments?post=24938"}],"version-history":[{"count":0,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/posts\/24938\/revisions"}],"wp:attachment":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/media?parent=24938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/categories?post=24938"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/tags?post=24938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}