• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Continuing Attempts to Thwart FluTrackers

Re: Continuing Attempts to Thwart FluTrackers

We went down this morning for some period of time. The server company told me that ONE ip, alone, had 100 connections to the site. It was another DOS attack.

And this afternoon:

From: support
To: flutrackers
Subject: Re: High load on dedicated server
Date: Apr 18, 2013 3:35 PM
Note: Replying more than once may delay our response time, because your ticket will be placed at the bottom of our ticket queue.

Dear FluTrackers,

Request supervisor
A technician responded to your ticket with:

Hello,

Recently your server become unresponsive due to huge load. I've rebooted it but the server remain inaccessible. I've contacted my colleague from our datacenter and soon we'll update you regarding your server status. Meanwhile, if you need information or have some questions, please don't hesitate to contact us. Our team will be glad to assist you in this matter!

Thank you!

Kind Regards,
 
Re: Continuing Attempts to Thwart FluTrackers

From: support
To: flutrackers
Subject:High load on dedicated server
Date: Apr 18, 2013 4:03 PM
Note: Replying more than once may delay our response time, because your ticket will be placed at the bottom of our ticket queue.

Dear FluTrackers,

Request supervisor
A technician responded to your ticket with:

Hello,

fsck has checked the file system and now your server is up and fully functional.

Your serer was unresponsive due to huge load (load average: 177.57, 89.14, 36.91 ). I've checked and I noticed that your server have high traffic.
 
Re: Continuing Attempts to Thwart FluTrackers

Yesterday we were down for about an hour due to a huge DOS attack.

From: support
To: flutrackers@earthlink.net
Subject: Re: Online HelpDesk
Date: May 14, 2013 4:56 PM

Note: Replying more than once may delay our response time, because your ticket will be placed at the bottom of our ticket queue.

Dear FluTrackers,

Request supervisor
A technician responded to your ticket with:

Hello,


Again your server become unresponsive due to huge load.

CPU % 233.83.......


:(
 
Re: Continuing Attempts to Thwart FluTrackers

We went down today due to a DOS attack. We have noticed over the last 3 weeks an increase of spam attempts against the site.

From:lunarpages
To: flutrackers
Subject:
Date: Sep 16, 2013 5:57 AM


Dear FluTrackers,

Request supervisor
A technician responded to your ticket with:

Hello,

Once again your server is alerted for very high load due to Apache processes, please check the details given below.

snip


=================

1 199.30.16.13
1 199.30.16.48
1 208.115.111.69
1 27.153.161.40
1 5.10.83.105
1 5.10.83.22
1 5.10.83.26
1 5.10.83.59
1 5.10.83.95
1 66.249.73.122
2 157.55.33.88
5 108.60.141.199
5 198.27.126.80
6 208.177.76.10
6 66.117.9.107
6 94.228.34.212
12 222.77.246.250
13 36.248.161.216
31 82.65.251.97
339 175.44.59.62

=============

I have blocked the IP : 175.44.59.62 , please let us know if its a legitimate IP so that we can white list the IP in the servers firewall.

Please feel free to contact us if you need any further assistance.

....
 
Re: Continuing Attempts to Thwart FluTrackers

We are also sustaining many phishing attempts to our email account per day. Of course, I do not open any of these:


service@earthlink.net
ACCOUNT CONFIRMATION
Sep 20 2 KB

service@earthlink.net
ACCOUNT CONFIRMATION
Sep 20 2 KB

service@earthlink.net
ACCOUNT CONFIRMATION
Sep 20 2 KB

service@earthlink.net
ACCOUNT CONFIRMATION
Sep 20 2 KB

service@earthlink.net
ACCOUNT CONFIRMATION
Sep 20 2 KB

service@earthlink.net
ACCOUNT CONFIRMATION
Sep 20 2 KB

service@earthlink.net
ACCOUNT CONFIRMATION
Sep 20 2 KB

service@earthlink.net
ACCOUNT CONFIRMATION
Sep 20 2 KB

service@earthlink.net
ACCOUNT CONFIRMATION
Sep 20 2 KB
 
Re: Continuing Attempts to Thwart FluTrackers

From CybernetQuest query:

175.44.59.62 - Whois Information
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

#
# Query terms are ambiguous. The query is assumed to be:
# "n 175.44.59.117"
#
# Use "?" to get help.
#
#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=175.44.59.117?showDetails=true&showARIN=false&ext=netref2
#
NetRange: 175.0.0.0 - 175.255.255.255
CIDR: 175.0.0.0/8
OriginAS:
NetName: APNIC-175
NetHandle: NET-175-0-0-0-0
Parent:
NetType: Allocated to APNIC
RegDate: 2009-08-03
Updated: 2010-07-30
Ref: http://whois.arin.net/rest/net/NET-175-0-0-0-0
OrgName: Asia Pacific Network Information Centre
OrgId: APNIC
Address: PO Box 3646
City: South Brisbane
StateProv: QLD
PostalCode: 4101
Country: AU
RegDate:
Updated: 2012-01-24
Ref: http://whois.arin.net/rest/org/APNIC
ReferralServer: whois://whois.apnic.net
OrgAbuseHandle: AWC12-ARIN
OrgAbuseName: APNIC Whois Contact
OrgAbusePhone: +61 7 3858 3188
OrgAbuseEmail: search-apnic-not-arin@apnic.net
OrgAbuseRef: http://whois.arin.net/rest/poc/AWC12-ARIN
OrgTechHandle: AWC12-ARIN
OrgTechName: APNIC Whois Contact
OrgTechPhone: +61 7 3858 3188
OrgTechEmail: search-apnic-not-arin@apnic.net
OrgTechRef: http://whois.arin.net/rest/poc/AWC12-ARIN

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Found a referral to whois.apnic.net.
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html
% Information related to '175.44.32.0 - 175.44.63.255'
inetnum: 175.44.32.0 - 175.44.63.255
netname: UNICOM-FJ-PUTIAN-MAN
country: CN
descr: Putian city, fujian provincial network of UNICOM
admin-c: PT239-AP
tech-c: PT239-AP
status: ALLOCATED NON-PORTABLE
changed: chenmin_deletethispart_@chinaunicom.cn 20111111
mnt-by: MAINT-CNCGROUP-FJ
mnt-lower: MAINT-CN-PT28
mnt-irt: IRT-CU-CN
source: APNIC
irt: IRT-CU-CN
address: No.21,Jin-Rong Street
address: Beijing,100140
address: P.R.China
e-mail: zhouxm@chinaunicom.cn
abuse-mailbox: zhouxm@chinaunicom.cn
admin-c: CH1302-AP
tech-c: CH1302-AP
mnt-by: MAINT-CNCGROUP
changed: zhouxm@chinaunicom.cn 20101110
changed: hm-changed@apnic.net 20101116
source: APNIC
person: PU TIAN
nic-hdl: PT239-AP
e-mail: wengqingwu@chinaunicom.cn
address: Putian city, Fujian province, China
phone: +86-594-6284431
fax-no: +86-594-6284433
country: cn
changed: chenmin_deletethispart_@chinaunicom.cn 20091106
mnt-by: MAINT-CNCGROUP-FJ
source: APNIC
% Information related to '175.44.0.0/16AS4837'
route: 175.44.0.0/16
descr: China Unicom Fujian Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20091215
source: APNIC
% This query was served by the APNIC Whois Service version 1.68 (UNDEFINED)
 
Re: Continuing Attempts to Thwart FluTrackers

From CybernetQuest:

175.44.59.62 - Geo Information
IP Address 175.44.59.62
Host 175.44.59.62
Location CN CN, China
City Fuzhou, 07 -
Organization China Unicom Fujian
ISP China Unicom Fujian
AS Number AS4837 CNCGROUP China169 Backbone
Latitude 26?06'14" North
Longitude 119?30'61" East
Distance 8535.51 km (5303.72 miles)
 
Re: Continuing Attempts to Thwart FluTrackers

From: lunarpages
To: flutrackers
Subject:
Date: Sep 22, 2013 6:35 AM
Note: Replying more than once may delay our response time, because your ticket will be placed at the bottom of our ticket queue.

Dear FluTrackers,

Request supervisor
A technician responded to your ticket with:


Hello,

I am writing to inform you that during routine monitoring your server was again alerted for very high load in our monitoring system.

.....


1 108.203.180.123
1 108.60.141.199
1 108.76.104.29
1 109.105.91.19
1 109.172.59.243
1 109.248.182.27
1 109.251.56.149
1 109.73.120.132
1 109.75.140.11
1 112.198.77.88
1 128.68.165.54
1 141.105.141.2
1 144.76.22.78
1 144.76.22.83
1 176.241.108.186
1 176.36.82.225
1 176.51.4.51
1 178.124.112.52
1 178.150.233.93
1 178.217.108.57
1 182.178.75.215
1 188.168.153.33
1 188.242.41.4
1 192.151.156.66
1 195.158.75.132
1 195.19.63.215
1 199.16.186.114
1 212.152.53.32
1 217.23.12.71
1 2.95.223.139
1 37.110.149.177
1 37.54.81.251
1 37.57.223.82
1 37.78.60.11
1 46.146.166.139
1 5.9.113.104
1 78.154.174.102
1 78.85.4.210
1 78.85.5.175
1 85.114.99.73
1 86.182.81.209
1 88.147.239.180
1 89.178.131.204
1 89.185.21.138
1 90.197.84.198
1 91.229.54.16
1 91.79.179.42
1 93.115.86.194
1 93.72.117.201
1 94.19.238.140
1 95.130.216.25
1 95.131.9.242
1 95.132.95.180
1 95.26.175.140
1 95.52.52.147
2 109.104.168.43
2 109.195.152.182
2 109.95.221.13
2 112.123.168.76
2 120.139.124.237
2 120.40.150.154
2 125.165.91.119
2 176.196.117.17
2 176.96.186.96
2 178.126.22.25
2 178.35.221.87
2 178.93.220.97
2 188.19.24.135
2 188.244.195.85
2 208.79.212.99
2 213.88.125.138
2 220.245.17.44
2 31.31.125.34
2 31.43.112.226
2 37.232.167.81
2 37.53.212.135
2 37.54.69.220
2 37.54.99.76
2 37.55.233.134
2 46.50.141.121
2 46.72.200.86
2 63.141.233.146
2 78.108.79.231
2 79.134.15.123
2 79.141.57.130
2 81.1.189.110
2 85.192.168.209
2 91.204.60.14
2 93.124.120.165
2 94.179.42.189
2 94.228.34.212
2 94.241.7.221
2 94.72.63.31
3 121.54.48.41
3 128.74.192.250
3 147.30.96.177
3 176.195.113.143
3 178.67.108.247
3 178.74.79.250
3 188.162.166.5
3 192.162.155.165
3 199.15.233.137
3 213.135.136.103
3 217.199.236.44
3 36.69.178.106
3 37.25.115.49
3 41.222.255.173
3 77.122.46.143
3 78.111.25.52
3 83.149.35.171
3 89.189.191.24
3 93.120.213.204
3 95.55.69.20
4 111.95.158.71
4 125.161.67.79
4 157.56.93.83
4 176.124.15.178
4 178.165.78.172
4 178.236.140.18
4 178.74.225.168
4 178.94.6.238
4 188.233.136.135
4 24.203.117.135
4 37.237.147.26
4 46.165.60.253
4 46.53.195.31
4 5.200.32.250
4 79.172.100.139
4 91.209.51.245
4 95.165.164.76
4 95.179.22.126
5 109.162.3.144
5 109.172.98.242
5 109.188.127.133
5 109.191.2.189
5 109.87.151.236
5 178.94.7.17
5 188.230.40.110
5 31.162.86.211
5 46.191.219.217
5 89.23.168.99
5 94.253.123.213
5 95.132.188.161
5 95.190.110.213
5 95.79.170.124
6 178.218.36.134
6 178.65.47.236
6 213.88.17.138
6 5.248.254.200
6 79.133.142.146
7 178.95.17.116
7 213.187.113.5
7 85.21.163.18
8 109.254.162.57
8 188.123.253.97
8 212.109.6.117
8 93.116.205.239
9 109.194.231.120
9 159.224.8.111
9 188.190.84.115
9 46.165.61.242
9 46.200.19.221
9 95.153.170.156
12
12 94.136.198.117
13 62.122.64.55
19 5.100.192.20


=============

Please check the above detailed traffic and block the IPs....
 
Re: Continuing Attempts to Thwart FluTrackers

This ip just launched a DOS attack against this site and I banned it from the server:

91.207.7.238

registed in the Ukraine
 
Re: Continuing Attempts to Thwart FluTrackers

From: lunarpages
To: flutrackers
Subject: Re: [Lunarpages Online HelpDesk] [YA78KH83EVH0] Apache stopped
Date: Feb 12, 2014 5:26 AM
Note: Replying more than once may delay our response time, because your ticket will be placed at the bottom of our ticket queue.

Dear FluTrackers,

Request supervisor
A technician responded to your ticket with:

Hello,

I'm contacting you today to inform you that I have noticed that your server is alerting of Load

......
 
Re: Continuing Attempts to Thwart FluTrackers

As some of you know we were down for about 3 hours yesterday due to tow "targeted disseminated" denial of service attacks.

One partial email from our server company:

Date: Apr 17, 2014 2:06 PM
Note: Replying more than once may delay our response time, because your ticket will be placed at the bottom of our ticket queue.

Dear FluTrackers,

Request supervisor
A technician responded to your ticket with:

Hello,

We have checked your server in detail and can see that vbulletin forum consuming high memory and cpu usage on server. Please see the results pasted below:

-----
redacted
------

Also from the domlogs I can see that lot of hits are coming to register.php?do=addmember just seconds after register.php?do=register. While humans take a minute or more to fill out the registration form, bots do it instantly. Here's some evidence from my logs:

----------
46.119.122.102 - - [17/Apr/2014:10:46:29 -0700] "POST /forum/register.php?do=addmember HTTP/1.0" 200 34931 "http://www.flutrackers.com/forum/register.php" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.146 Safari/537.36"
46.119.122.102 - - [17/Apr/2014:10:46:33 -0700] "POST /forum/register.php?do=addmember HTTP/1.0" 200 34931 "http://www.flutrackers.com/forum/register.php" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.146 Safari/537.36"
46.119.122.102 - - [17/Apr/2014:10:46:35 -0700] "POST /forum/register.php?do=addmember HTTP/1.0" 200 34931 "http://www.flutrackers.com/forum/register.php" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.146 Safari/537.36"
46.119.122.102 - - [17/Apr/2014:10:46:38 -0700] "POST /forum/register.php?do=addmember HTTP/1.0" 200 34931 "http://www.flutrackers.com/forum/register.php" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.146 Safari/537.36"
46.119.122.102 - - [17/Apr/2014:10:46:41 -0700] "POST /forum/register.php?do=addmember HTTP/1.0" 200 34931 "http://www.flutrackers.com/forum/register.php" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.146 Safari/537.36"

more redacted...


---------------------------------------------

In the 2nd attack yesterday thousands of ips from all over the world tried to: register, log in, post to threads, view the index, view random attachments, and view the tags - all at the same time.

The robbers of our resources and time are using a computer program to synchronize the requests to our server for page views to a guarantee maximum hit against us.

In the 1st attack a similar program asked thousands of computers to guess the user name and password combination to our server. Our firewall stopped all attempted intrusions into the server. In addition, obviously none of their guesses were correct. We have employed a strategy for many years that is very effective in dealing with this problem.

The robbers are continuing today - generating thousands of requests to our server to join etc. We are maintaining.

Also, we are receiving emails containing viruses to the FluTrackers email account.

Thank you to everyone who views us. Our team is committed to providing the most accurate and timely information possible.

We are all volunteers and we do this because we want to.

It is our will power that propels this site.
 
Re: Continuing Attempts to Thwart FluTrackers

to me it sounds pretty easy to defend against these attacks.
E.g. detect suspicious logins/registrations (time between attempts, match of passwords,)
detect hightraffic from one site, bot-like-behaviour

if the defenders were only as creative as the hackers ...


but then, when I check the views of my attached pictures, it's _very_ low.
Maybe some bot can be programmed to look at my charts ;-)
 
Re: Continuing Attempts to Thwart FluTrackers

And we are not the only ones. Crof blog has been several times this week from DOS attacks. And now - again today:

FluTrackers.com ‏@FluTrackers 11m
@Crof So your blog is down again? :(

Crawford Kilian ‏@Crof 8m
@FluTrackers Yup. Discovering powers & limits of FluTweeting!

FluTrackers.com ‏@FluTrackers 5m
@Crof We would be honored to post anything you write. Please send to our email & we will post and tweet w/hat tip to you. :)

Retweeted by FluTrackers.com
Crawford Kilian ‏@Crof 3m
@FluTrackers Very kind offer! May take you up on it if DOS attack persists. In meantime, will tweet you folks. :-)
 
Re: Continuing Attempts to Thwart FluTrackers

And now we are having a large influx of ips trying to repeatedly register etc.. A sample:

46.119.112.63 flutrackers.com POST /forum/register.php?do=addmember HTTP/1.0

134.249.141.83 flutrackers.com POST /forum/register.php?do=addmember HTTP/1.0

183.60.214.59 flutrackers.com GET /forum/misc.php?do=whoposted&t=218671 HTTP/1.1

134.249.141.83 flutrackers.com POST /forum/register.php?do=addmember HTTP/1.0

46.119.112.63 flutrackers.com POST /forum/register.php?do=addmember HTTP/1.0

134.249.141.83 flutrackers.com POST /forum/register.php?do=addmember HTTP/1.0

134.249.141.83 flutrackers.com POST /forum/register.php?do=addmember HTTP/1.0

-------------------

Our techs are dealing with this.
 
Re: Continuing Attempts to Thwart FluTrackers

I haven't been able to access Flutrackers.com for about a week from my personal computer. The screen comes up with "Forbidden" in bold letters (quotes mine)

Then below that "You don't have permission to access/forum/search.php on this server. Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request."

I can access Flutrackers.org, but it won't accept my i.d. or password. I am sending this post via another computer in our household that uses the same network connection. I can access Flutrackers.com from this other computer.

We have Windows8 with the firewall on, and the security scans have not found any problems. I am having zero problems accessing any other sites including another VBulletin forum. I was online and on Flutrackers.com when it was attacked.
 
Re: Continuing Attempts to Thwart FluTrackers

I suspect you are experiencing a DNS issue. Try to switch to a public DNS service instead to our provider.
 
Re: Continuing Attempts to Thwart FluTrackers

I would also suggest running a virus scan. AVG has some good free software, and as a secondary (free) system run malwarebytes.

Both have paid versions, but the free ones should suffice. I would suggest you run these in addition to whatever software you may currently run for virus and similar protection.
 
Re: Continuing Attempts to Thwart FluTrackers

I haven't been able to access Flutrackers.com for about a week from my personal computer. The screen comes up with "Forbidden" in bold letters (quotes mine)

Then below that "You don't have permission to access/forum/search.php on this server. Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request."

I can access Flutrackers.org, but it won't accept my i.d. or password. I am sending this post via another computer in our household that uses the same network connection. I can access Flutrackers.com from this other computer.

We have Windows8 with the firewall on, and the security scans have not found any problems. I am having zero problems accessing any other sites including another VBulletin forum. I was online and on Flutrackers.com when it was attacked.

Our server has never been accessed. We are on lock down mode.

The attacks on us are a bunch of computers all programmed at the same time to ask to view a page on FT. With thousands of requests coming in at the same time, the server gets overloaded and slows down to barely operating. These are not attacks were someone has been able to get inside of the server to embed anything.

There is a new scam online. Some sites have a pop-up that suggests that you upgrade your video player or reader. If you mistakenly click on one of these fake solicitations you may get a virus.

Also, try clearing your cache.
 
Re: Continuing Attempts to Thwart FluTrackers

And...you might want to send me a message with your ip so I can check if I accidentally banned it.

As I said we are sitting very tight on the server right now. Maybe too tight!

Today I "banned" 3 people. :oops:
 
Re: Continuing Attempts to Thwart FluTrackers

As of yesterday, apparently, all links to FluTrackers from the browser Internet Explorer do not work. An error message is displayed. Firefox, Safari, Opera, and Google Chrome are working. It appears someone hacked into Internet Explorer and changed the linking directions to FluTrackers to invalid ones.

Way to go Microsoft! :(
 
Last edited:
Back
Top