We got DDoSed. #153
Replies: 6 comments 1 reply
-
Mirror of this on Medium: https://medium.com/@ProdigyPNP/we-got-ddosed-1a71a9810577 |
Beta Was this translation helpful? Give feedback.
-
Update: Why can't I get even fucking 6 hours of sleep without getting DDoSed again? I'm trying to well... actually keep the servers alive. Screw you hostedposted for being a DDoSer. |
Beta Was this translation helpful? Give feedback.
-
Atleast you get to learn some web security |
Beta Was this translation helpful? Give feedback.
-
All I have to say abut this is that this battle is going too far. |
Beta Was this translation helpful? Give feedback.
-
Wednesday, September 7, 2022.
After school, I had noticed that people were experiencing unusual errors with hacks. I checked the
#zero-status
channel in the Discord Server, and surely enough, Infinite Zero was down. AsPHEx v>2.1.9
relies on Infinite Zero, and most users were on 3.0.1, this was really a large-scale problem for the hacks. I of course, opened the DigitalOcean droplet dashboard of Infinite Zero, and when I saw the graphs, holy shit. Someone had loaded the (now no-longer-existing) infinitezero.net/analytics.json an incredible amount of times, and caused the server to crash from overloading of disk reading and data output.My quickest fix to this was to just remove /analytics.json and /uniques, as those were the most vulnerable pages. However, shortly after this hotfix, Zero was still getting DDoSed. I decided to finally move my DNS to Cloudflare, and set up protections there, such as IP-banning the DDosers. That worked, except there were way too many IPs to manually ban, so I'd need a solution on Infinite Zero itself. Luckily, Rate Limiters exist, and it's now set to allow only 4 requests per 20 seconds.
Who is responsible for this? My guess is hostedposted. First of all, he was bragging about "ProdigyPNP has weak servers y'all take a look Infinite Zero is down" in our Discord, almost exactly as soon as it went down. Later, after some forbidden promotion of the "other prodigy hack", hosted was muted. Not too far after, the ProdigyPNP Discord server was being hardraided with tons of bots targeting... me (gemsvidø), with a funny picture of a face reveal I did on a livestream over a year ago.
I wasn't really expecting all this to go down, but whatever, I guess I'll finally learn some web security.
Beta Was this translation helpful? Give feedback.
All reactions