Australian Ham Radio Discussion Forum ( AHRDF )

Full Version: Hack attempts 13 Sept 2023
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
There have been a number of hacking attempts on this forum, in major proportions in the last day or so but in lower levels over the last couple of weeks.  The obvious indication is that the forum becomes very slow to respond plus the 'users in the last 15 minutes ' count skyrockets.  This morning it was around 4300 where normally it remains well under 200-300.

I took the forum off line so that it was no longer in overload mode while the hackers tried their best. The SQL server was rejecting all requests for service (hence the slow speed) but there has not been any actual successful hack, data access or data loss.  Please recall that only callsigns, a password and email addresses are requested on signup/registration so nothing totally critical is available to hackers anyway. The software that runs the forum is up to date with security patches at this time.

In the event that I see a recurrence, I will re-activate a static HTML page that de-activates the forum until I am ready to make it available again - hopefully the hackers will have given up by then !  The presence of the static page will be obvious as, while it has the logo, it has no menu or login options etc..

Doug, admin
Hello Doug,
thanks for your efforts, certainly some down time is a small price compared to threads full of nonsense Big Grin
Thanks Peter

The majority of the IP addresses trace back to various Russian Federation entities.

They won't do much other than force me to put the static page back up for a few days, certainly won't get much info !
Regardless, the forum will be back up in due course.

Doug

LATE PPS :   
The forum was taken off-line again for a number of hours today (14Sep23) due to rapidly rising accesses, at least some of which were from the Russian Federation (again !).

I am going to take a different approach for the near future : I will IP-ban whole ranges of V4 addresses where the visitor count is rising quickly due to similtaneous multi-IP accesses and those bans will be permanent.  A single user only causes a single log entry, bots and hackers can generate large numbers of logged entries in a short time from different IPs. 

I know ithe banning won't solve it all but will put in place reduced access from some geographic areas, and this will be extended as more hack attempts appear.  At least I should be able to leave the actual forum active.  

Symptom :  If your IP range gets banned then you simply will not get browser access to the forum...

This may also affect undocumented search engine bots that traverse the forum : it won't be able to access or update into the future. The main ones like Google, Bing etc are well documented and will not face exclusion.

Posted at 5:30PM EAST 14Sep23
Hi Doug,
shame the forum could not be hosted from my work, we have some very expensive firewalls that have lots of tricks with banning via geo location to name just one.