About this bulletin board and the Pale Moon website
Moderators: FranklinDM, Lootyhoof
-
Moonchild
- Pale Moon guru

- Posts: 38428
- Joined: 2011-08-28, 17:27
- Location: Motala, SE
Post
by Moonchild » 2025-07-17, 22:42
We get such curious traffic on the forum these days.
I'm not sure if whomever is causing this is thinking they are keeping the forum downed or what not, because they don't get a response... but just some statistics on the bogus traffic, just for today (about 20 hours worth analysed of bad traffic):
Total bad requests: 841,788 (of about 900k total)
Unique IPs: 673,936 (can't get much more distributed than that...)
Unique countries/territories: 192
All following an easy to recognise pattern (which has made it fairly easy for me to block, no "AI" needed)
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
-
Gemmaugr
- Lunatic

- Posts: 295
- Joined: 2025-02-03, 07:55
Post
by Gemmaugr » 2025-07-17, 23:35
That country number is intriguing, and curious, indeed. That's almost as many as there are countries in the world..
Bot-scrapers for AI LLM's perhaps? It is all the rage currently.
AI written text is also following a very easy to spot pattern that seems hard for them to shake.
-
suzyne
- Keeps coming back

- Posts: 782
- Joined: 2023-06-28, 22:43
- Location: Australia
Post
by suzyne » 2025-07-18, 02:49
The number of different IPs and countries make me think it is some malware installed on regular users computers that is being controlled to do it? That's my theory, but the question is why forum.palemoon.org?
Could being the target of such traffic, be a sign of being singled out and special in some way!
Laptop 1: Windows 11 64-bit, i7 @ 2.80GHz, 16GB, NVIDIA GeForce MX450.
Laptop 2: Windows 10 32-bit, Atom Z3735F @ 1.33GHz, 2GB, Intel HD Graphics.
Laptop 3: Linux Mint 20.3 64-bit, i5 @ 2.5GHz, 8GB, Intel HD Graphics 620.
-
Kris_88
- Board Warrior

- Posts: 1165
- Joined: 2021-01-26, 11:18
Post
by Kris_88 » 2025-07-18, 08:14
I had to deal with this phenomenon on my website. In my case it was a DDOS attack. The sources of requests were mobile phones, probably with some vulnerable application. Each source generated a request only once a minute, but the total traffic was staggering. I simply blocked entire subnets by IP and that solved the problem. As I found out later, attackers can also use some vulnerable IP cameras as sources of requests.
And no, I don't think in your case it has anything to do with AI. Most likely, it is an attack on the site.
-
Moonchild
- Pale Moon guru

- Posts: 38428
- Joined: 2011-08-28, 17:27
- Location: Motala, SE
Post
by Moonchild » 2025-07-18, 09:01
Kris_88 wrote: ↑2025-07-18, 08:14
Most likely, it is an attack on the site.
I tend to agree - but if it is, then
I wonder what the point is. Clearly I've been able to mitigate the attack (without blocking whole swathes of subnets denying service for legitimate users) so the most it does right now is give my server a bit of a workout to filter all this out, but it isn't even hitting the php processor so load is minimal. The overall volume is a nuisance at most and not causing issues otherwise.
suzyne wrote: ↑2025-07-18, 02:49
The number of different IPs and countries make me think it is some malware installed on regular users computers that is being controlled to do it?
Probably. But indeed the question then becomes who is controlling that botnet and why target our community forum?
Gemmaugr wrote: ↑2025-07-17, 23:35
Bot-scrapers for AI LLM's perhaps? It is all the rage currently.
AI written text is also following a very easy to spot pattern that seems hard for them to shake.
I don't think they are bot scrapers - the request pattern is wrong for it and the number of IPs is going against that.
Bot scrapers will be from a few dozen IPs at most and all in data centres; this isn't the case here.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
-
ron_1
- Knows the dark side

- Posts: 3025
- Joined: 2012-06-28, 01:20
Post
by ron_1 » 2025-07-18, 20:54
PCLinuxOS forums were down a few days ago due to attacks. I wonder if it's the same people.
-
Moonchild
- Pale Moon guru

- Posts: 38428
- Joined: 2011-08-28, 17:27
- Location: Motala, SE
Post
by Moonchild » 2025-07-18, 21:42
Since they are also running phpbb, it's quite possible. If unmitigated, the attack will cause extremely heavy server load that will bring the forum down.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
-
Moonchild
- Pale Moon guru

- Posts: 38428
- Joined: 2011-08-28, 17:27
- Location: Motala, SE
Post
by Moonchild » 2025-07-19, 10:05
oh.him again. luckily i have a nuke button for that kind of account.
Possible it's the same one as the traffic DoS attack, but without more information it could just be unrelated and timing. The repo political/religious/gay/etc. spammer just seems to be someone with a chip on his shoulder with too much time on his (assuming based on context) hands. Just wasting his time, really, it takes a few clicks to clean it up. Just get a life already
EDIT: Curiously, the repo spammer went through:
If I really cared, I could home in on it much more, but I really don't feel like spending more than 5 minutes on it at the moment. Maybe if this person is so obsessed with Pale Moon, he'll read this and consider the risk taken by causing abuse. Can't even be bothered to report it right now.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
-
Kris_88
- Board Warrior

- Posts: 1165
- Joined: 2021-01-26, 11:18
Post
by Kris_88 » 2025-07-19, 15:09
Moonchild wrote: ↑2025-07-19, 10:05
EDIT: Curiously, the repo spammer went through:
Most likely, it was just someone's hacked computer or server...
-
Moonchild
- Pale Moon guru

- Posts: 38428
- Joined: 2011-08-28, 17:27
- Location: Motala, SE
Post
by Moonchild » 2025-07-19, 15:29
Kris_88 wrote: ↑2025-07-19, 15:09
Most likely, it was just someone's hacked computer or server...
Unlikely. This kind of behaviour isn't what someone with much wits would do XD
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
-
Thad E G
- Apollo supporter

- Posts: 30
- Joined: 2022-10-23, 10:38
Post
by Thad E G » 2025-07-22, 14:18
Moonchild wrote: ↑2025-07-18, 09:01
I tend to agree - but if it is, then
I wonder what the point is. Clearly I've been able to mitigate the attack (without blocking whole swathes of subnets denying service for legitimate users)
Thank you! My country is definitely on the internet-hates-you list, although probably nowhere near as high as some. But there must be a billion people here who never do any harm out there.
But I'm so glad I retired before these things became so big. All I had to worry about was a fairly simple firewall, and an external services filtering email.
Keep up the good work. I'm sorry it gets harder everyday.
-
Moonchild
- Pale Moon guru

- Posts: 38428
- Joined: 2011-08-28, 17:27
- Location: Motala, SE
Post
by Moonchild » 2025-07-28, 19:17
Thad E G wrote: ↑2025-07-22, 14:18
My country is definitely on the internet-hates-you list, although probably nowhere near as high as some.
I'm afraid it's definitely in the top 3 due to its persistently lax attitude towards large scale scam centers.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite
-
Pelican
- Lunatic

- Posts: 276
- Joined: 2018-02-23, 06:51
Post
by Pelican » 2025-07-28, 23:55
A lot of sites have been reporting 5 times the normal traffic. A lot of it is coming from bots for AI research rush. If running phpBB you will be affected more because their crawling is a runaway train.
Apparently phpBB version 4.0 is coming soon.
-
Moonchild
- Pale Moon guru

- Posts: 38428
- Joined: 2011-08-28, 17:27
- Location: Motala, SE
Post
by Moonchild » 2025-07-29, 00:30
Pelican wrote: ↑2025-07-28, 23:55
A lot of it is coming from bots for AI research rush.
This isn't. It's obviously been a DoS attack of some sort.
Considering the repo and xref servers are being hit with regular bouts of it also (e.g. a SYN flood attack earlier today - reported to Hetzner), it's clearly a directed attempt at disrupting operations. Unfortunately for them I know how to make a fairly robust setup after a few decades of admin experience.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite