Yet Another DDoS Attack

Soul Calibre

༒тнє тєямιηαтσя༒
Contributor
I woke up 2 hours ago only to find out that my internet is down.. or so I thought. Akala ko talaga may problema na naman ang converge so I decided to check. Nakalagay naman ay "normal" ang status, and may connection din. I restarted the modem, still no internet. I turned it off, unplugged it and plugged it back in after 2 minutes, still "normal" status but no internet. My PC says "connected" but I cannot browse the internet. Iniisip ko na lang na may problema talaga ang converge. I am about to just wait pero nag-notify ang phone ko. Ang sabi "cannot connect to DNS". Eh I am using my own AdGuard Home DNS. I changed the DNS settings to "automatic" and boom.. MAY INTERNET! So, hindi converge ang may problema kundi yung DNS ko. I tried logging in to the AdGuard Home DNS portal pero ayaw nyang mag-load. Aside sa DNS, I am also using the same VPS to host my website. My DNS is running inside a docker so kung may problema sa DNS, sana hindi affected yung website, tama? But then even my website isn't working. I tried to connect to the VPS but it's not working. I then found out that my VPS is down. Buti na lang very handy ang Google Cloud. I restarted the VPS from GCP and waited until it's working again. Akala ko noong una baka nagka-error lang kaya nag-stop bigla yung VPS. But then, this showed up in my AdGuard Home DNS Portal...
1757248236599.webp

DNS 2.webp

2M DNS queries?? At bakit may russian websites diyan? Suspicious, right? Buti na lang nag-try akong mag-login kanina sa DNS Portal kaya noong nag-reboot ako ng VPS ay nag-load yang DNS portal. And After checking the logs, I can see na tuloy-tuloy pa rin ang queries. I disconnected my devices sa DNS and cleared the logs para makasiguro na wala sa phone or laptop ko ang problema. Luckily, hindi naman na-häçk ang PC ko or what not kasi even after disconnecting my phone and laptop sa DNS ay may mga queries pa din. As you can see, I kept refreshing and tuloy-tuloy pa rin ang queries kahit hindi na connected and devices ko sa DNS.

I am already thinking na something is wrong so I logged back in to my VPS and checked the log. And yeah, I found this...
1757249556578.webp

Confirmed! My VPS is under attack. I set PermitRootLogin to "no" naman na as a safety precaution. Shutdown the VPS for 5 minutes but still, when I check it again, tuloy pa rin ang bruteforce.
1757250032439.webp

And just now, my DNS stopped working again. Well, it seems like hindi nila titigilan. I shut the VPS down and I am planning to build a new one. Ang hassle lang kasi ang mag-migrate.

May suggestion ba kayo? What if I change the VPS IP? Naka-static IP kasi eh. Ano sa tingin nyo?
 
wag muna i try ya baka matuwa kapa gawin mo sa kalokohan hahaha joke
Baka kamo mabaliw din. Hahahahahaha

me na may server, always may ddos attack.. install lang fail2ban ikaw na bahala sa config.
naubos ko na mga yan.
Yung DDoS prevention ng Google Cloud security ang naka-enable eh. Mahina naman palang mang-detect yun. Hahahahahaha


lakas naman nyan. ano bang meron nyan boss bat sila nagka interest sila dyan?
Ewan ba at anong satisfaction ang napapala nila sa kaka-DDoS.
 
Baka kamo mabaliw din. Hahahahahaha


Yung DDoS prevention ng Google Cloud security ang naka-enable eh. Mahina naman palang mang-detect yun. Hahahahahaha


Ewan ba at anong satisfaction ang napapala nila sa kaka-DDoS.
hindi yan ddos attack eh.. bruteforce attack yun nasa image..
may ganyan din sakin, inubos ko na sa fail2ban config.
 
Naka f2b ka? Madami din logs sakin ng error wala pang 1 days almost 3k attempts sa brute force. OVH gamit ko wala din ata mga protection mga ito haha
 
[Hidden content]
Mahihirapan PC ko kung gawin kong physical server. Hehehehehe

Change ka login port na ikaw lang nakakaalam. ganyan tlga mga vps lalo na pag OVH
Isa ito sa mga gagawin ko.

Naka f2b ka? Madami din logs sakin ng error wala pang 1 days almost 3k attempts sa brute force. OVH gamit ko wala din ata mga protection mga ito haha
Hindi pa. Nagre-rebuild pa ako ng new server then lagyan ko nito.
 
Mahihirapan PC ko kung gawin kong physical server. Hehehehehe


Isa ito sa mga gagawin ko.


Hindi pa. Nagre-rebuild pa ako ng new server then lagyan ko nito.
Ito din additional ko, tutal si GCP mandatory atang may sshkey

PermitRootLogin no
PubkeyAuthentication yes
PasswordAuthentication no
 
Boss ano mas maganda yang gamit mo or pihole?
Not sure.. hindi ko pa na-try yang PiHole.

hindi yan ddos attack eh.. bruteforce attack yun nasa image..
may ganyan din sakin, inubos ko na sa fail2ban config.
Gumawa ako ng bagong VPS, new static IP din, tapos nilagyan ko ng fail2ban, changed SSH port, changed PermitRootLogin to "no", same sa PasswordAuthentication. I updated my domain's target IP while migrating my website. Kakatapos lang at pagka-check ko ito agad bumungad.

Aaayy.. May nag-i-scan yata sa domain ko mismo.
1757288385697.webp
 

Similar threads

About this Thread

  • 50
    Replies
  • 3K
    Views
  • 28
    Participants
Last reply from:
Jieeem27

Trending Topics

Online now

Members online
1,073
Guests online
2,174
Total visitors
3,247

Forum statistics

Threads
2,269,698
Posts
28,930,664
Members
1,241,536
Latest member
buleconer123
Back
Top