• Tired of adverts on RWI? - Subscribe by clicking HERE and PMing Trailboss for instructions and they will magically go away!

RWG Official Latest Outage Thread - July 2012

greg_r

Departed Friend
Patron
8/7/08
985
5
0
Okay folks,

I'll update this post with info on what's happening, but here's the deal as of:

9.22AM GMT

We're under attack yet again. Somebody REALLY doesn't like us - we've been hit every two months this year and I'll admit I'm getting mighty tired of it.

This attack started as an attempt to get into our database - it failed miserably and I blocked the IP range of the attacker, thinking that would solve it. Unfortunately, they've decided to DoS us again as well. I'm not currently certain where the DDoS is coming from, but I'm assuming it's the same source as the hack attempt - it could just be co-incidence, however (edit: it's increasingly looking like it was indeed a co-incidence - the hacking attempt was highly inept). This DoS attack follows the exact same pattern as the one we suffered back in March.

Working on it, but as of right now, I have no idea how long this is going to take... The traffic is sufficiently high that the protection we had in place is just using all the available system RAM to fight it off - hence it's hard to get onto the board atm.

More when I know it.

UPDATE: 09:44

Just to let you know that you'll get a 404 (or some other random error) when you try to visit RWG. That's expected, so don't panic! ;) I've firewalled off public access so that I can get in and work on this uninterrupted without some *insert very rude name here* banging on the door. We may end up switching IP addresses and domain names again - too early to be sure right now.

UPDATE: 14:15

Realistically, we're going to be down for a while. I don't expect to be able to announce any progress today, sorry.

UPDATE: Tuesday 08:20

Nothing much to report. We have some options, but for now our best move is to sit and wait. FWIW there's no data loss, no 'rebuilding' to be done - the server is working well and we've got 100% current backups of everything. Currently, I've just closed the door so that the attacker is banging on a black hole and getting no response - I'm hoping he'll get bored with that. I would like to stay at our current URL if possible, but that may prove unrealistic. Time will tell...

UPDATE: Tuesday 13:50

Okay - this guy is still banging on the door pretty hard. I have a plan to get the board back up, but it's going to take a few days as there are some DNS changes involved. Not going to give any details on this, but please bear with me.

UPDATE: Thursday 11:50

Hi all - ignoring all the threadcrapping for a minute, this is still the official RWG update thread, honest ;)

Sorry I haven't updated this post for a while. Much of this process is a waiting game. Most of those trying to get to the board will, at least, now see a message about the downtime rather than just get an error - it might be tomorrow before that's the case for everyone, though. Alterations to DNS always take a few days to actually work - on top of which I'm taking the opportunity to implement some changes that were planned for next month. Might as well avoid a second spell of downtime if we can.

At the moment I have a support ticket in with our web hosts as there's a problem (not related to the attack) that I haven't been able to resolve. They're usually pretty quick and once that's sorted we should be able to move forward.

I'd like to say that we'll be back up tomorrow - it's possible, but equally it's possible it might not be until next week. Ultimately it depends on how fast our hosts resolve the issue I've run into - and how nuts work is (as I'm trying to fit this stuff in around a rather hectic day job! ;) )

Sorry for the time this is taking, but ultimately there's no practicable way to speed things up at this stage. All I can say is that RWG WILL be back and it'll be as soon as I can possibly make it happen.

UPDATE: Thursday 14:30
Okay, our hosts have finally discovered the cause of this new issue we've been having and are working on a fix right now. Once done, I will have some basic setup work to do and some re-configuration of the board due to the changes, but we should then be that bit closer to getting the board back up.

UPDATE: Friday 08:30
Don't want to count any chickens quite yet - especially given the date (!) , but progress is being made. Watch this space.

RWG IS BACK UP!!!

The old links should work, or you can go straight to: http://www.rwg.bz/board/

Welcome home, folks... :)

Greg_R: Admin - RWG
 

trailboss99

Head Honcho - Cat Herder
Staff member
Administrator
Certified
30/3/08
42,540
12,961
113
Fecking hackzors :lolcina:
 

Del

I'm Pretty Popular
Supporter
15/7/10
2,233
7
38
Jeez, not again. :frusty:

Thanks for the update G, and good luck sorting this out. Much appreciated.
 

redrising

I'm Pretty Popular
23/4/12
2,943
11
38
hmmm. In these kind of instances, is it possible to trace the hacker(s)? Can you hack the hacker(s)? Spank them. Teach them a lesson.
 

trailboss99

Head Honcho - Cat Herder
Staff member
Administrator
Certified
30/3/08
42,540
12,961
113
Regrettably not rr, it's not so simple and hacking hackers is usually more trounie than it's worth.
 

5up3rman

Renowned Member
4/12/10
964
2
0
Man this getting ridiculous.
Thanks as always Greg for your hard work and time.
 

greg_r

Departed Friend
Patron
8/7/08
985
5
0
hmmm. In these kind of instances, is it possible to trace the hacker(s)? Can you hack the hacker(s)? Spank them. Teach them a lesson.

The DDoS isn't of a conventional type - on this type attack the sending IP is spoofed and isn't resolved by our server as the connection never completes. We've got protections in place against this kinda thing and have fought off a few of these before, but this time - like back in March - there's SO much traffic being thrown our way that it's saturating our connecting to the Internet.
 

Ron76

You're Saying I Can Sell?
22/1/12
26
0
1
This is getting old, frecking twats.
Good luck Greg.
 

co-axial

Legendary Member
Advisor
16/9/10
23,226
10
0
well, all we can wish is good luck then RWG.

For the meantime we welcome our fellow watch nutters back here ;)

You´re welcome @RWI as always :)
 

Bonesey

Mythical Poster
Advisor
15/1/11
8,926
63
0
Wow, you guys vacation here more and more, which sucks, but is of course welcome :D Hope you guys get this sorted sometime soon.
 

Graman

Active Member
27/8/06
219
0
0
Thanks Greg...You're blood's well worth bottling ;)
:notworthy:
 

gtwc

You're Saying I Can Sell?
16/7/10
43
0
0
Thanks Greg for the info.
What a way to start a Monday morning !!
THis is getting to be an all-too familiar occurence.
Is it the same people?
 

greg_r

Departed Friend
Patron
8/7/08
985
5
0
Good question. This attack follows the same pattern as we had in March, which suggests there could be a connection.

The attack in May, however, was very different and we managed to trace the culprit - don't think there's a connection there...