CEO and Khmer440 BLACKOUT!

This is where our community discusses almost anything! While we're mainly a Cambodia expat discussion forum and talk about expat life here, we debate about almost everything. Even if you're a tourist passing through Southeast Asia and want to connect with expatriates living and working in Cambodia, this is the first section of our site that you should check out. Our members start their own discussions or post links to other blogs and/or news articles they find interesting and want to chat about. So join in the fun and start new topics, or feel free to comment on anything our community members have already started! We also have some Khmer members here as well, but English is the main language used on CEO. You're welcome to have a look around, and if you decide you want to participate, you can become a part our international expat community by signing up for a free account.
johnnyj
Expatriate
Posts: 22
Joined: Mon Aug 11, 2014 1:32 am
Reputation: 1
Location: floating about

Re: CEO and Khmer440 BLACKOUT!

Post by johnnyj »

OrangeDragon wrote:TO protect us from hacking/DDoS attempts our ISP shut us down for 3 hours. And then again. I have put in some countermeasures that will hopefully stop the attack from reaching us again... we will see.

Did they confirm it was a combined attack (hack/DDOS)?
there are some pretty clever anti-DDOS measures that can be taken at a layer 2 level, however sometimes shutting the site down is the only resort... which sort of achieves the goal of a DDOS anyway...

Any ideas on where the traffic was coming from?
User avatar
General Mackevili
The General
Posts: 18418
Joined: Tue May 06, 2014 5:24 pm
Reputation: 3408
Location: The Kingdom
Contact:
United States of America

Re: CEO and Khmer440 BLACKOUT!

Post by General Mackevili »

That ssd scary! I'm still shook up, LoL.
"Life is too important to take seriously."

"Life does not cease to be funny when people die any more than it ceases to be serious when people laugh."

Have a story or an anonymous news tip for CEO? Need advertising? CONTACT ME

Cambodia Expats Online is the most popular community in the country. JOIN TODAY

Follow CEO on social media:

Facebook
Twitter
YouTube
Google+
Instagram
User avatar
General Mackevili
The General
Posts: 18418
Joined: Tue May 06, 2014 5:24 pm
Reputation: 3408
Location: The Kingdom
Contact:
United States of America

Re: CEO and Khmer440 BLACKOUT!

Post by General Mackevili »

johnnyj wrote:
Any ideas on where the traffic was coming from?
Please don't be from Saudi, please don't be from Saudi......
"Life is too important to take seriously."

"Life does not cease to be funny when people die any more than it ceases to be serious when people laugh."

Have a story or an anonymous news tip for CEO? Need advertising? CONTACT ME

Cambodia Expats Online is the most popular community in the country. JOIN TODAY

Follow CEO on social media:

Facebook
Twitter
YouTube
Google+
Instagram
User avatar
General Mackevili
The General
Posts: 18418
Joined: Tue May 06, 2014 5:24 pm
Reputation: 3408
Location: The Kingdom
Contact:
United States of America

Re: CEO and Khmer440 BLACKOUT!

Post by General Mackevili »

And very well done, OD!

"Life is too important to take seriously."

"Life does not cease to be funny when people die any more than it ceases to be serious when people laugh."

Have a story or an anonymous news tip for CEO? Need advertising? CONTACT ME

Cambodia Expats Online is the most popular community in the country. JOIN TODAY

Follow CEO on social media:

Facebook
Twitter
YouTube
Google+
Instagram
EdinWigan
Expatriate
Posts: 910
Joined: Sat May 17, 2014 6:13 am
Reputation: 1
Great Britain

Re: CEO and Khmer440 BLACKOUT!

Post by EdinWigan »

I am also wondering if this event and the vicious and deliberate attack on my avatar are connected.

The attack on Cambodia's two top forums and my avatar, could be seen as attacking three of the four cornerstones of ex-pat culture in the region.

Can we expect an imminent attack on Vlads - Pun-store next? This would complete the most callous assault on our way of life.

Is there any hope for the walls of Babylon ?

I tremble with anticipation


:no:
Remember your Karma helps a Wet Child In Wigan !
User avatar
General Mackevili
The General
Posts: 18418
Joined: Tue May 06, 2014 5:24 pm
Reputation: 3408
Location: The Kingdom
Contact:
United States of America

Re: CEO and Khmer440 BLACKOUT!

Post by General Mackevili »

EdinWigan wrote:
The attack on Cambodia's two top forums and my avatar, could be seen as attacking three of the four cornerstones of ex-pat culture in the region.
Haha! Now this is even ten times more worrying! Ed, I think you need to post a list of anyone you've had disagreements with over the past 2 years. Potty will weed them out, one by one.

This is bigger than I had originally thought.

I think your avatar was the main target, and the sites going down were just collateral damage.

Image
"Life is too important to take seriously."

"Life does not cease to be funny when people die any more than it ceases to be serious when people laugh."

Have a story or an anonymous news tip for CEO? Need advertising? CONTACT ME

Cambodia Expats Online is the most popular community in the country. JOIN TODAY

Follow CEO on social media:

Facebook
Twitter
YouTube
Google+
Instagram
OrangeDragon
Site Admin
Posts: 4193
Joined: Fri May 02, 2014 8:05 pm
Reputation: 17
United States of America

Re: CEO and Khmer440 BLACKOUT!

Post by OrangeDragon »

johnnyj wrote:
OrangeDragon wrote:TO protect us from hacking/DDoS attempts our ISP shut us down for 3 hours. And then again. I have put in some countermeasures that will hopefully stop the attack from reaching us again... we will see.

Did they confirm it was a combined attack (hack/DDOS)?
there are some pretty clever anti-DDOS measures that can be taken at a layer 2 level, however sometimes shutting the site down is the only resort... which sort of achieves the goal of a DDOS anyway...

Any ideas on where the traffic was coming from?
not positive it was aimed at us both.. but that would be a shaky coincidence if it weren't. it was for sure a DDoS attack on our side, and I've now added another layer of protection at the DNS level, and will be continuing to tune my countermeasures through the day. Biggest hit was timing... they hit while i was asleep and couldn't react quickly.

and a site shutdown is only one minor impact/goal of a DDoS. They can also be used to launch man in the middle attacks, which are much much worse and can cause a server security breach. i'd rather the site shut down than some hackers gain access to it for sure.

downloading all of my logs now, and i'm going to toss them all into Splunk to review and search for patterns on. With any luck Scoby will send me the ones from 440 as well so I can do a full analysis. Depends on how cooperative they're feeling.
johnnyj
Expatriate
Posts: 22
Joined: Mon Aug 11, 2014 1:32 am
Reputation: 1
Location: floating about

Re: CEO and Khmer440 BLACKOUT!

Post by johnnyj »

OrangeDragon wrote:
johnnyj wrote:
OrangeDragon wrote:TO protect us from hacking/DDoS attempts our ISP shut us down for 3 hours. And then again. I have put in some countermeasures that will hopefully stop the attack from reaching us again... we will see.

Did they confirm it was a combined attack (hack/DDOS)?
there are some pretty clever anti-DDOS measures that can be taken at a layer 2 level, however sometimes shutting the site down is the only resort... which sort of achieves the goal of a DDOS anyway...

Any ideas on where the traffic was coming from?
not positive it was aimed at us both.. but that would be a shaky coincidence if it weren't. it was for sure a DDoS attack on our side, and I've now added another layer of protection at the DNS level, and will be continuing to tune my countermeasures through the day. Biggest hit was timing... they hit while i was asleep and couldn't react quickly.

and a site shutdown is only one minor impact/goal of a DDoS. They can also be used to launch man in the middle attacks, which are much much worse and can cause a server security breach. i'd rather the site shut down than some hackers gain access to it for sure.

downloading all of my logs now, and i'm going to toss them all into Splunk to review and search for patterns on. With any luck Scoby will send me the ones from 440 as well so I can do a full analysis. Depends on how cooperative they're feeling.
I've done quite a bit of work on tracking this sort of thing down, let me know if you want a hand reviewing any logs, I'll be offering the same to Scobienz as well.
EdinWigan
Expatriate
Posts: 910
Joined: Sat May 17, 2014 6:13 am
Reputation: 1
Great Britain

Re: CEO and Khmer440 BLACKOUT!

Post by EdinWigan »

johnnyj wrote:
OrangeDragon wrote:
johnnyj wrote:
OrangeDragon wrote:TO protect us from hacking/DDoS attempts our ISP shut us down for 3 hours. And then again. I have put in some countermeasures that will hopefully stop the attack from reaching us again... we will see.

Did they confirm it was a combined attack (hack/DDOS)?
there are some pretty clever anti-DDOS measures that can be taken at a layer 2 level, however sometimes shutting the site down is the only resort... which sort of achieves the goal of a DDOS anyway...

Any ideas on where the traffic was coming from?
not positive it was aimed at us both.. but that would be a shaky coincidence if it weren't. it was for sure a DDoS attack on our side, and I've now added another layer of protection at the DNS level, and will be continuing to tune my countermeasures through the day. Biggest hit was timing... they hit while i was asleep and couldn't react quickly.

and a site shutdown is only one minor impact/goal of a DDoS. They can also be used to launch man in the middle attacks, which are much much worse and can cause a server security breach. i'd rather the site shut down than some hackers gain access to it for sure.

downloading all of my logs now, and i'm going to toss them all into Splunk to review and search for patterns on. With any luck Scoby will send me the ones from 440 as well so I can do a full analysis. Depends on how cooperative they're feeling.
I've done quite a bit of work on tracking this sort of thing down, let me know if you want a hand reviewing any logs, I'll be offering the same to Scobienz as well.
Great to see the brains of both sites working together for the common benefit of us all.

Thank you
Remember your Karma helps a Wet Child In Wigan !
OrangeDragon
Site Admin
Posts: 4193
Joined: Fri May 02, 2014 8:05 pm
Reputation: 17
United States of America

Re: CEO and Khmer440 BLACKOUT!

Post by OrangeDragon »

Worst part is, i'd JUST downloaded the distro of Splunk last night to put on the server for monitoring this stuff live... and ended up going to bed without finishing.

*sigh*
Post Reply Previous topicNext topic
  • Similar Topics
    Replies
    Views
    Last post