Oh boy...

Maybe it's time for a donation maraton, Scott.
You know I don't like doing that.

I love running this place for you guys. This is my hobby I guess. Some people bowl, some people smoke or drink, some people paint... Me my hobby is I run SatelliteGuys. :)
 
Am able to log on using Google but haven't been able to log on with Edge all morning. Am getting this message with Edge..."Forbidden. You don't have permission to access this resource."
 
  • Like
Reactions: charlesrshell
I had a hiccup at 9:07PM PDT last night. I was reading posts and at that time when I went to a different post it hung up like there wasn't a website to connect to. I tried again at 9:09 and it was the same. I tried again at 9:29 and all was well.
 
  • Like
Reactions: charlesrshell
I had a hiccup at 9:07PM PDT last night. I was reading posts and at that time when I went to a different post it hung up like there wasn't a website to connect to. I tried again at 9:09 and it was the same. I tried again at 9:29 and all was well.
I did also, forgot what time, but definitely after 9pm but before 10PM.

On my ipad pro.
 
  • Like
Reactions: charlesrshell
I did also, forgot what time, but definitely after 9pm but before 10PM.

On my ipad pro.
Bruce you are on Eastern Time, and Bobby is on Pacific time. I was online and active here at that time (Eastern Time) and had no issues no see no log file of any issues.

With this said there DID seem to be some kind of outside internet issues that started at approximately 2:28 am Eastern Time where people from outside the USA could not get to the server and those out of the country could not get in for 4 hours and 22 minutes (6:47am ET). This issue was outside our server as most of our remote monitoring were able to get to the server, but in places like Australia and New Zealand couldn't get here during those times.

bb6056583efde379740c1c1d4d14d463.jpg



I just paid for extra monitoring so our server is tested every 60 seconds from 30 different locations across the globe.

Bobby, I think the issue you may have seen was because of the backups, looks like 3 different backups of the SatelliteGuys database were happening at the same time. Cpanel does one... Xenforo does one and Jetbackup does one.

I just changed the Jetbackup one to 3am. Working on changing the Xenforo one to start at a different time (not midnight) depending on the backup being done it is a resource heavy thing as not only is it dumping a huge database, but then it also gzip's it up for sending it offsite. gzip is a hog. I need to change gzip for pigz which is much better and handles more CPU cores, so you don't even notice when its running. I am adding that to my todo list now. :)

 
Last edited:
Maybe fail2ban could be used to swat the DOS attacks on the main server at least.
Fail2ban is mainly good for remote login failures.

We use ModSecurity to actually examine all the packets and we are subsribed to a database so it checks everything against the database.


Its funny to watch, we get a lot of hack attempts but most attacks only try a few times and when they fail they give up. The one from Hong Kong was doing hundreds of them a minute.

Also funny to see attempted hack attempts on files which are no longer here... more specifically attacks on old vBulletin files which are all gone. vBulletin was the software we use to use 10 or more years ago, surprising to see them still trying to attack those files which were gone so long ago.

We can install another firewall (CSF) that works with ModSecurity to tighten things up more, but I am worries that it will block things since this system uses a bunch of non standard strange ports for some things.
 
  • Like
Reactions: charlesrshell
Bruce you are on Eastern Time, and Bobby is on Pacific time.
I know that, Bobby have posted each other many times about the price of homes there, when I was offered a job in California.
I was online and active here at that time (Eastern Time) and had no issues no see no log file of any issues.
To be fair, you have posted that you do not see anything after others have said they have had issues.

Just had another one about 10 minutes ago, I was trying to reply to a post, totally locked up and my post I was writing disappeared and had to start over.
 
  • Like
Reactions: charlesrshell
Fail2ban is mainly good for remote login failures.
fail2ban can parse all manner of text from a log. It isn't limited to failed logins. If there's a pattern (such as a "[security2:error]") and an IP address, that's all you need to get the address blocked at the operating system level (extremely efficient).

Getting the database involved extends the DOS attack to the database.
 
  • Like
Reactions: charlesrshell
Top