Not entirely clear to me what is going on, but we’ve seen a large influx in traffic from oversea today. This has lead to high CPU and performance issues.

I’ve put in place a block to what seems to be the source of the traffic, but its not perfect and may cause other issues. If you see/hear of any please let me know here.

  • Lodion 🇦🇺OPMA
    link
    fedilink
    arrow-up
    12
    ·
    22 days ago

    For some context, CPU usage jumped when the traffic started… and dropped after the block was applied:

    • ikt
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      22 days ago

      What sort of block if I can ask? blocking AI bots or blocking Russian bots?

      • Lodion 🇦🇺OPMA
        link
        fedilink
        arrow-up
        15
        ·
        22 days ago

        The unusual traffic all appeared to be coming from one location on the internet, with the same user agent string. Any traffic from that network will now receive a captcha from Cloudflare. I’m not aware of any lemmy instances hosted there, but will keep an eye on things.

        • dumblederp
          link
          fedilink
          arrow-up
          8
          ·
          22 days ago

          I’m all for captcha use to limit bots and this kind of stuff, which effectively became a DDoS.

  • imoldgreeeg
    link
    fedilink
    arrow-up
    6
    ·
    21 days ago

    Definitely noticed someyuwas up today. Not just here but lags across a few different websites - my speeds were fine so I wondered if it was a broader DNS or DDoS attacks

  • Lodion 🇦🇺OPMA
    link
    fedilink
    arrow-up
    6
    ·
    21 days ago

    And for anyone curious… blue line is traffic from a country we don’t normally see much traffic from. The unusual spike, then drop when I blocked the specific sources:

    • NathA
      link
      fedilink
      arrow-up
      2
      ·
      20 days ago

      It’s probably Nicole. She’s mad that she can’t spam us any longer.

  • Lodion 🇦🇺OPMA
    link
    fedilink
    arrow-up
    5
    ·
    21 days ago

    The traffic stopped a few hours back, from all IPs at once. Definitely seems to have been some sort of deliberate action.

  • Aussiemandeus
    link
    fedilink
    arrow-up
    5
    ·
    21 days ago

    An odd place to attack or try spam, but I guess if you have unlimited resources you would hit anywhere

  • hitmyspot
    link
    fedilink
    arrow-up
    4
    ·
    21 days ago

    I noticed something was up. I’d seen some meta posts about other instances updating so I wondered if it was a bug or federation issue but obviously not.