Page 7 of 7

Re: DDoS Round 10

Posted: Mon Sep 07, 2026 10:53 am
by Spring
Are the server migrations currently going on? This doesn't seem like a ddos.

Re: DDoS Round 10

Posted: Mon Sep 07, 2026 10:59 am
by Swiftus
DDoS attack again?

Re: DDoS Round 10

Posted: Mon Sep 07, 2026 11:05 am
by Momohomo
well during the attacks on the login screen it was more like

Connecting - Authenticating - Handshaking - Success! -Connected -Disconnected from server

when I couldn't make it in atall, now it's

Connecting (which takes some seconds this time) - Disconnected from server

so something changed probably

Re: DDoS Round 10

Posted: Mon Sep 07, 2026 11:09 am
by Graywisp1
Kestrel wrote: Sun Sep 06, 2026 8:18 pm I am shocked to see our community not just survive, but continue to grow despite these DDoS attacks coming in so persistently. <3 I cannot express how grateful myself and the team are for all of you sticking with us during this time.

We are doing everything that we can to mitigate them for now, and hope this will be the final weekend were these attacks are able to affect us in this way. Find the timeline for the attacks from yesterday and the attacks (thus far) from today below.

2026-09-05 16:02 - 2026-09-05 17:15
2026-09-05 17:21 - 2026-09-05 17:31
2026-09-05 17:45 - 2026-09-05 18:05
2026-09-05 18:37 - 2026-09-05 19:08
2026-09-05 19:13 - 2026-09-05 19:37
2026-09-05 19:52 - 2026-09-05 20:20
2026-09-05 20:44 - 2026-09-05 21:04
2026-09-05 21:45 - 2026-09-05 22:15
2026-09-05 22:26 - 2026-09-05 22:52
2026-09-05 22:55 - 2026-09-05 23:14
2026-09-05 23:34 - 2026-09-06 00:00
2026-09-06 10:12 - 2026-09-06 10:18
2026-09-06 16:07 - 2026-09-06 16:13
Hi guys, are we down right now? Not sure if its my internet connection? I dont remember DDOS starting this early before, thats why I am confused.

Re: DDoS Round 10

Posted: Mon Sep 07, 2026 11:15 am
by Deviouss1
Kestrel has posted a new announcement about this.

"The TCP proxy that we have been using for temporary DDoS protection has stopped allowing all traffic through. We are working to re-route traffic around the proxy temporarily while we wait for our proxy provider to inform us of what is causing this disruption. We will update with more information when we know more."
Sincerely,
Kestrel
Your Temporary Part Time Community Manager - Full Time Developer

Re: DDoS Round 10

Posted: Mon Sep 07, 2026 11:23 am
by Wowgab
Maybe we can help you think the defence process?

As it was said, blocking individual IP addresses does not scale. An attacker can rotate source IPs, use botnets, or spin up more virtual machines.

I guess you already identified which resource is being overflood/exhausted.

We need to solve "Where can I drop the malicious traffic before it consumes my limited resources?"

We need to clean the traffic before it arrives to the firewall, otherwise it is going to flood the server anyways.

I guess you already solved this.

1. Is bandwidth exhausted first?
2. Is the SYN backlog filling up?
3. Is conntrack filling up?
4. Is CPU being exhausted processing packets?

These are basic TS provided by AI's and sites.


I was also thinking about a privbate server to which users could access via VPN. Have a public registration server which provides VPN tokens that allow users login to the backend server on a private network accesible by VPN?