Kuribo64
Views: 25,841,459 Home | Forums | Uploader | Wiki | Object databases | IRC
Rules/FAQ | Memberlist | Calendar | Stats | Online users | Last posts | Search
06-22-25 08:32 PM
Guest:

0 users reading so we're getting attacked... | 1 bot

Main - General Chat - so we're getting attacked... Hide post layouts | New reply


Arisotura
Posted on 06-09-25 12:30 PM Link | #102246
2a0d:bbc7:0:1::3cc - - [09/Jun/2025:03:00:37 +0000] "GET /board/search.php?q=e%2Ar%2A HTTP/1.1" 499 0 "-" "Still broken, dumbass!" "-"

someone needs to get a life

I saw that after this, that script kiddie tried to run another wave while I was attending an appointment. it amounted to a little spike in server CPU usage, but that's about it.

tee hee.

____________________
NSMBHD - Kafuka - Jul
melonDS the most fruity DS emulator there is

zafkflzdasd

Staryu Trek
Posted on 06-09-25 12:53 PM Link | #102247
Posted by Staryu Trek
×
_


That "still" in the message disturbs me. Is it someone who's hacked the board before?



 "To boldly glitch where no one has glitched before" - Staryu Trek

 
Hover!
Posted by kikilxve
he's rly nice
  
SM64DS body horror (hacking fail)fail
  
Weird quote
Posted by me to someone I know, joking
Flareon shoarma doesn't need to be baked anymore, it's pre-baked.

Layout background by alpha rats_1 on Open Game Art
Sig background from dreamstime.com
Avatar Staryu model from Retromesh (edited)
Avatar background from space.com

Arisotura
Posted on 06-09-25 01:01 PM Link | #102248
oh yeah a bit more context

the first iteration of the attack consisted into spamming a huge amount of "*e* *e* *e* *e*" into the search query, which caused it to take forever to be processed, and, if repeated quickly enough, caused the MySQL server to give up on life alltogether.

it turns out nothing was enforcing a length limit on the search query, so I fixed that.

100 characters ought to be enough for everyone? yeah, our friend was still doing the same shit, even with 100 characters it was enough. because the abuse of *'s meant the queries were returning basically every post on the board.

so I changed it to reject any query that had more than 3 *'s.

then the little moron just decided to keep spamming queries like "a*b*c" over and over again, which is what was quoted above. it was several bursts of those requests, but one of them had the useragent changed to that (instead of having some generic useragent), so I found that amusing.

in any case, now it limits how many searches you can run within a 5-minute period, so that will defeat his little attack entirely. I doubt he has the means to evolve this into an actual DDoS.

____________________
NSMBHD - Kafuka - Jul
melonDS the most fruity DS emulator there is

zafkflzdasd

rommoisseur
Posted on 06-14-25 07:50 PM Link | #102251
Anything of value is always sought after heavily.

Staryu Trek
Posted on 06-15-25 07:05 AM Link | #102254
Posted by Staryu Trek
×
_


Posted by rommoisseur
Anything of value is always sought after heavily.
But as Thierry once said, a message board isn't a bank. There's not much of value here. And they didn't even legit hack the board.



 "To boldly glitch where no one has glitched before" - Staryu Trek

 
Hover!
Posted by kikilxve
he's rly nice
  
SM64DS body horror (hacking fail)fail
  
Weird quote
Posted by me to someone I know, joking
Flareon shoarma doesn't need to be baked anymore, it's pre-baked.

Layout background by alpha rats_1 on Open Game Art
Sig background from dreamstime.com
Avatar Staryu model from Retromesh (edited)
Avatar background from space.com


Main - General Chat - so we're getting attacked... Hide post layouts | New reply

Page rendered in 0.048 seconds. (2048KB of memory used)
MySQL - queries: 30, rows: 210/210, time: 0.012 seconds.
[powered by Acmlm] Acmlmboard 2.064 (2018-07-20)
© 2005-2008 Acmlm, Xkeeper, blackhole89 et al.