Well, the attacks seem to have stopped, so the wiki is back up... for the time being, at least. If the attacks start up again, well, then we'll post a notice here.
For those of you not in the know, it's at http://badgeometry.com/wiki.
Enjoy!
These forums are CLOSED. Please visit the new forums HERE
The wiki is back! |
|
Catherine Omega
Geometry Ninja
![]() Join date: 10 Jan 2003
Posts: 2,053
|
11-01-2004 17:33
Well, the attacks seem to have stopped, so the wiki is back up... for the time being, at least. If the attacks start up again, well, then we'll post a notice here.
For those of you not in the know, it's at http://badgeometry.com/wiki. Enjoy! _____________________
|
Djiket Nyak
![]() Join date: 30 Sep 2004
Posts: 116
|
11-01-2004 18:33
I've missed it so. *sheds a tear*
_____________________
|
Goshua Lament
Registered User
![]() Join date: 25 Dec 2003
Posts: 703
|
11-01-2004 18:34
woot!
_____________________
Flickr Second Life Photo Gallery
I no longer regularly login to SecondLife, but please contact me if an issue arises that needs my attention. |
Jillian Callahan
Rotary-winged Neko Girl
![]() Join date: 24 Jun 2004
Posts: 3,766
|
11-01-2004 18:35
{{{Wiki}}}
{{{Catherine Omega}}} |
Morgaine Dinova
Active Carbon Unit
![]() Join date: 25 Aug 2004
Posts: 968
|
11-01-2004 21:05
{{{Wiki}}} {{{Catherine Omega}}} ![]() _____________________
-- General Mousebutton API, proposal for interactive gaming
-- Mouselook camera continuity, basic UI camera improvements |
Moleculor Satyr
Fireflies!
![]() Join date: 5 Jan 2004
Posts: 2,650
|
11-01-2004 21:57
And it's down again! Same errors as last time:
Warning: mysql_pconnect(): User badgeo has already more than 'max_user_connections' active connections in /home/badgeo/public_html/wiki/wakka.php on line 25 Warning: mysql_select_db(): supplied argument is not a valid MySQL-Link resource in /home/badgeo/public_html/wiki/wakka.php on line 26 Warning: mysql_query(): supplied argument is not a valid MySQL-Link resource in /home/badgeo/public_html/wiki/wakka.php on line 34 Query failed: delete from wakka_referrers where time < date_sub(now(), interval '1' day) (User badgeo has already more than 'max_user_connections' active connections) |
Karizon Hatfield
Second Life Mentor
Join date: 22 Oct 2004
Posts: 18
|
looks down again
11-01-2004 22:00
mysql connections overloaded.
dunno if this is the same problem as before. |
Cashmere Falcone
Prim Manipulator
Join date: 21 Apr 2004
Posts: 185
|
11-02-2004 06:50
Yep, been fighting this for about 2 hours this morning, on and off.
![]() _____________________
Jebus Linden for President!
![]() |
Catherine Omega
Geometry Ninja
![]() Join date: 10 Jan 2003
Posts: 2,053
|
11-02-2004 07:02
Well, guess I spoke too soon. I'm actually having trouble even getting into our backend right now. Whoops. In any event, I'm told that our long-term hosting plan is almost ready, so this downtime shouldn't be much longer.
Please continue to bear with us over the next few days, and thanks for all the offers to host a mirror. It's not necessary though. _____________________
|
blaze Spinnaker
1/2 Serious
Join date: 12 Aug 2004
Posts: 5,898
|
11-02-2004 08:34
Any backups out there?
_____________________
Taken from The last paragraph on pg. 16 of Cory Ondrejka's paper "Changing Realities: User Creation, Communication, and Innovation in Digital Worlds :
"User-created content takes the idea of leveraging player opinions a step further by allowing them to effectively prototype new ideas and features. Developers can then measure which new concepts most improve the products and incorporate them into the game in future patches." |
Nada Epoch
The Librarian
![]() Join date: 4 Nov 2002
Posts: 1,423
|
11-02-2004 08:56
ok so my host suspended the account, amusingly enough, after i got it under control. go figure. Anyways, once they unsuspend it(since i can;t override the root user), it will be back in the disabled directory.
if they haven;t gotten back to me in 30 minutes, i will set up the most recent backup at a temporary location. sorry about this. _____________________
i've got nothing.
![]() |
Zuzi Martinez
goth dachshund
![]() Join date: 4 Sep 2004
Posts: 1,860
|
11-02-2004 09:15
thank you wiki people.
|
Barbarra Blair
Short Person
![]() Join date: 18 Apr 2004
Posts: 588
|
11-02-2004 09:24
Thanks for your efforts--
Next time it's up I'm burning the whole dang thing to a CD, if y'all don't mind. |
Ulrika Zugzwang
Magnanimous in Victory
![]() Join date: 10 Jun 2004
Posts: 6,382
|
Dang!
11-02-2004 09:36
It's down again after another round of attacks. Here's the message you get when you try to go to badgeometry.com:
This Account Has Been Suspended I have suspended this account until further notice. *This is some sort of malicious attack, since it is querying pages that do not exist, is doing so 150,000 times in the last 2 hours, has the referrer showing up as a porn site with a rotating ip address, and is doing 750mb of traffic from this entirely text based site, again in under two hours. *I apologize for the inconvience, I am working with with the host right now to get this fixed. If worse comes to worse, I just made a back-up so we can move the site to a new domain if necessary. To compensate, I'm using: http://www.sluniverse.com/lsl.html I supplement this with Google searches for '"lsl wiki" keyword'. I then look at pages of the LSL Wiki in the Google cache. (Edit: I just noticed that this was mentioned above. Oopsie! ![]() ~Ulrika~ Edited for clue. _____________________
Chik-chik-chika-ahh
|
Moleculor Satyr
Fireflies!
![]() Join date: 5 Jan 2004
Posts: 2,650
|
11-02-2004 10:01
Can't you ban by domain name? If it's showing up as one porn site with a rotating IP, banning by the domain name would get rid of all of it, right?
Also, is it just one of the four octets in the IP address that is changing? (i.e. 145.64.55.*, where * is any number from 1 to 255?) If so, just ban the entire range. It's just 255 IP address, and they probably all belong to the robot. (Dunno for sure, I've not worked with website stuff before.) |
Nada Epoch
The Librarian
![]() Join date: 4 Nov 2002
Posts: 1,423
|
11-02-2004 10:08
you can ban by ip, however, it isn;t just a single field, it is all four fields. and i haven;t found a way to ban by domain yet.
_____________________
i've got nothing.
![]() |
Moleculor Satyr
Fireflies!
![]() Join date: 5 Jan 2004
Posts: 2,650
|
11-02-2004 10:36
If it is the kind of IP range I described (with only the last octet changing) have you tried either not filling in the fourth box, or putting an * in it instead of a number?
I find it hard to believe your hosting software would not provide the ability to ban IP ranges. |
Nada Epoch
The Librarian
![]() Join date: 4 Nov 2002
Posts: 1,423
|
11-02-2004 10:47
it isn't the kind of range that you are talking about.
_____________________
i've got nothing.
![]() |
Nada Epoch
The Librarian
![]() Join date: 4 Nov 2002
Posts: 1,423
|
11-02-2004 11:27
ok, so i set it up temporarily here.
_____________________
i've got nothing.
![]() |
Morgaine Dinova
Active Carbon Unit
![]() Join date: 25 Aug 2004
Posts: 968
|
11-02-2004 12:36
I just queried the webserver on the commandline:
CODE HEAD / HTTP/1.0So it's running Apache (as one would expect bright people to do!), and Apache has no trouble at all barring any number of IP addresses, without or without proper reverse domain names. It might be simpler though to just temporarily disallow access from any IP address not having a valid reverse DNS entry. I'm not sure if mod_bwlimited allows you to do that though, ie. by restricting certain accesses to zero bandwidth. If you had mod_access installed then you could require all reverse names to pass a double-reverse test too --- this would almost certainly block the abuse, although a lot of folks with dynamic IP might suffer as well since some ISPs don't provide proper reverse names. It's been a while since I last played with this stuff to block DDoS attacks at a major ISP, but I can look it up again if help is needed. _____________________
-- General Mousebutton API, proposal for interactive gaming
-- Mouselook camera continuity, basic UI camera improvements |
Catherine Omega
Geometry Ninja
![]() Join date: 10 Jan 2003
Posts: 2,053
|
11-02-2004 12:55
Yes, of course there are things that could be done, but we don't have direct access to the server. It's a shared server, which we have access to through a horrible CGI backend.
_____________________
|
Morgaine Dinova
Active Carbon Unit
![]() Join date: 25 Aug 2004
Posts: 968
|
11-02-2004 13:05
From klomp.org, this seems to be the best Apache module to use as it lets the O/S handle it:
CODE mod_hosts_access 1.0.0The TCP Wrapper blockfile hosts.deny can be changed on the fly without even needing to send Apache a SIGHUP, and it accepts both domain names and IP addresses using a variety of range specifiers. That's all the flexibility you need I think. You could use the kernel's packet filtering as well, but then you wouldn't have the flexibility of blocking by domain name. _____________________
-- General Mousebutton API, proposal for interactive gaming
-- Mouselook camera continuity, basic UI camera improvements |
Morgaine Dinova
Active Carbon Unit
![]() Join date: 25 Aug 2004
Posts: 968
|
11-02-2004 13:06
Yes, of course there are things that could be done, but we don't have direct access to the server. It's a shared server, which we have access to through a horrible CGI backend. ![]() _____________________
-- General Mousebutton API, proposal for interactive gaming
-- Mouselook camera continuity, basic UI camera improvements |
Moleculor Satyr
Fireflies!
![]() Join date: 5 Jan 2004
Posts: 2,650
|
11-02-2004 17:40
Is there any place where the Wiki is "guaranteed" to be up at for the next few days or so? I'm going off site trying to find some math help, and I'm using the current "backup" of the site to link to explanations of various portions of LSL, but I'm not sure if I can depend on those links, and need to know if I should provide alternate URLs as well.
|
Nada Epoch
The Librarian
![]() Join date: 4 Nov 2002
Posts: 1,423
|
11-02-2004 18:57
I will leave the temporary site up for as long as we need it. I can even leave it up after we get badgeometry back up and running if you need, just let me know.
_____________________
i've got nothing.
![]() |