Last night I uploaded some updates to the site theme. A little while later, the site went down. On the control panel I could see my CPU and process usage were both pegged at 100%. I naturally assumed the outage was related to the changes I’d just made. I spent hours fussing with things, trying to figure out what I’d done wrong. I finally reverted everything and discovered that the problem persisted.
I reached out to support and they determined I was experiencing a DDOS attack, and the site update was unrelated. Lots of unrelated IP addresses from around the world were all hammering away at the WordPress login script, probably trying to brute-force using common passwords. It’s a hopeless effort on their part. My blog password is in excess of 128 bits, which means the sun will burn out before this botnet cracks it. Still, they managed to overwhelm the site and take it down. So I guess technically this wasn’t really a DDOS. It was a hack attempt that accidentally became a DDOS due to my site being a little undermatched for this particular botnet.
I’m reasonably sure this DDOS isn’t the first. You might remember my adventures with 1 & 1 Hosting. What I think was happening is I was getting slammed with this same botnet. Instead of notifying me or investigating, 1 & 1 just took my site down until the bots gave up and left.
I’m experimenting with a cloud service to distribute the load. This is supposedly a really good defense against these sorts of things. I don’t know. I guess we’ll see if / when this happens again.
The Best of 2014
My picks for what was important, awesome, or worth talking about in 2014.
Shamus Plays WOW
Ever wondered what's in all those quest boxes you've never bothered to read? Get ready: They're more insane than you might expect.
MMO Population Problems
Computers keep getting more powerful. So why do the population caps for massively multiplayer games stay about the same?
Trashing the Heap
What does it mean when a program crashes, and why does it happen?
Internet News is All Wrong
Why is internet news so bad, why do people prefer celebrity fluff, and how could it be made better?