Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 
freitasm

BDFL - Memuneh
81043 posts

Uber Geek
+1 received by user: 41942

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3505691 24-Jun-2026 08:50
Send private message quote this post

Tinkerisk:

 

@freitasm What surprises me is why they started up so suddenly. Can you tell if this is happening in a coordinated way?

 

 

I first noticed this behaviour about six months ago. Initially, as a wave of requests from Asia, mainly Hong Kong, Vietnam and Singapore. When I put in captchas for Asia only, the traffic moved from there to South America, including Chile, Brazil and Argentina. And when I put barriers to these accesses, it moved to New Zealand. I put some captchas back then, and when the traffic disappeared, I removed them.

 

This happened twice since then, with the last wave coming last week.

 

The requests are mainly for specific pages, repeatedly, from hundreds or thousands of different IP addresses, but concentrated in a few residential ISPs. The pages are always the same, about ten different ones, so it's not like a bot crawling the site to scrape content. It's purely an attempt to overload, like a DDoS. 

 

The initial volume did not cause problems until that big spike in the chart. 

 

It looks orchestrated in nature, and it could well be trying to hide smaller malicious traffic in the middle of the thousands of requests. 

 

Because it happens from consumer ISPs and with such a variety of IPs, I think this is using a botnet made of devices, as described before. The cost per compromised IP in Asia is a lot cheaper than in South America, and many times cheaper than in New Zealand, so it follows the logic of moving the source region when I put barriers.

 

I won't disclose what other measures we have in place, but I'm well aware that while our site is not high value, having user accounts means bad actors can always try to use our login to validate leaked authentication data from other sites, or try to exfiltrate data, hoping some people use the same password in other places.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 




rb99
3540 posts

Uber Geek
+1 received by user: 1868

Lifetime subscriber

  #3505785 24-Jun-2026 12:13
Send private message quote this post

Would this issue thing be causing this at all -

 

 

seems to be just on the Home page, logged in or not, just for Geekzone.





“The modern conservative is engaged in one of man's oldest exercises in moral philosophy; that is, the search for a superior moral justification for selfishness.” -John Kenneth Galbraith

 

rb99


gzt

gzt
19162 posts

Uber Geek
+1 received by user: 8286

Lifetime subscriber

  #3505791 24-Jun-2026 12:30
Send private message quote this post

Just for the record - no captchas seen since this thread started, chrome mobile and desktop 2deg and Spark.



freitasm

BDFL - Memuneh
81043 posts

Uber Geek
+1 received by user: 41942

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3505792 24-Jun-2026 12:30
Send private message quote this post

rb99:

 

Would this issue thing be causing this at all -

 

 

seems to be just on the Home page, logged in or not, just for Geekzone.

 

 

Interesting. I use Firefox as my main browser and I didn't come across this. Have you tried with add-ons disabled?





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


rb99
3540 posts

Uber Geek
+1 received by user: 1868

Lifetime subscriber

  #3505795 24-Jun-2026 12:36
Send private message quote this post

Not yet. I'll give it a go.





“The modern conservative is engaged in one of man's oldest exercises in moral philosophy; that is, the search for a superior moral justification for selfishness.” -John Kenneth Galbraith

 

rb99


rb99
3540 posts

Uber Geek
+1 received by user: 1868

Lifetime subscriber

  #3505801 24-Jun-2026 12:54
Send private message quote this post

I disabled all extensions, closed Firefox, ran CCleaner (if that helps), Restarted Firefox, went to GZ and it was the same, with that message.

 

Closed Firefox, re-enabled Extensions, ran CCleaner again, restarted Firefox, went to GZ and it did the captcha thing, logged in and now it seems to be OK, touch wood, etc etc.

 

Maybe it was the capcha thing, which it hasn't asked for a while.

 

Re the above, can't guarantee thats the exact order I did stuff, but hopefully its correct.

 

 





“The modern conservative is engaged in one of man's oldest exercises in moral philosophy; that is, the search for a superior moral justification for selfishness.” -John Kenneth Galbraith

 

rb99


HP

 
 
 
 

Shop now for HP laptops and other devices (affiliate link).
geek3001
349 posts

Ultimate Geek
+1 received by user: 530

ID Verified
Subscriber

  #3505802 24-Jun-2026 12:57
Send private message quote this post

freitasm:

 

rb99:

 

Would this issue thing be causing this at all -

 

 

seems to be just on the Home page, logged in or not, just for Geekzone.

 

 

Interesting. I use Firefox as my main browser and I didn't come across this. Have you tried with add-ons disabled?

 

 

I have been seeing this on and off over the last few days.

 

The prompt appears when I press F5 to manually refresh the home page, is still present after I log on to geekzone and press F5 but goes away once the home page has had a chance to auto-refresh itself.

 

I am seeing this behaviour on three different FF versions, across three different machines, all running different FF profiles.

 

On all three, starting FF in troubleshooting mode and pressing F5 sees this prompt not show up at all, and the home page manually refreshes OK.

 

Weird.


richms
29311 posts

Uber Geek
+1 received by user: 10396

Trusted
Lifetime subscriber

  #3505804 24-Jun-2026 13:16
Send private message quote this post

freitasm:

 

rb99:

 

Would this issue thing be causing this at all -

 

 

seems to be just on the Home page, logged in or not, just for Geekzone.

 

 

Interesting. I use Firefox as my main browser and I didn't come across this. Have you tried with add-ons disabled?

 

 

This is the normal thing that you get after completing a captcha and seeing a page, and then reloading on the page that comes up.

 

If you navigate to another page there is no POST on the next request to cause this.





Richard rich.ms

Behodar
11244 posts

Uber Geek
+1 received by user: 6274

Trusted
Lifetime subscriber

  #3505814 24-Jun-2026 13:49
Send private message quote this post

I just tried to open this topic and got a "security check" page that automatically redirected to this page on completion, but with all the images (both avatars and in-post screenshots) and the text editor missing. I had to refresh the page twice to get the images and editor to show up, which triggered the check each time.

 

Firefox 152.0.1 on Windows, at work (which I think is Spark).


freitasm

BDFL - Memuneh
81043 posts

Uber Geek
+1 received by user: 41942

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3505820 24-Jun-2026 13:57
Send private message quote this post

Possible. I have adjusted the rule and added a filter. 

 

Have updated it again so you shouldn't see this.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Tinkerisk
4963 posts

Uber Geek
+1 received by user: 3910


  #3505899 24-Jun-2026 16:02
Send private message quote this post

freitasm:

 

It's purely an attempt to overload, like a DDoS.

 

 

I see it exactly the same way. We once had a case where a simple, static homepage was attacked repeatedly and with increasing intensity (it was just a honeypot to see what would happen).

 

Sleeper devices. They have already been compromised and are activated for attacks only when needed. This usually happens at times when their unsuspecting owners won't notice any disruption. In your case, during the (NZ-)nighttime.

 

It is clearly a botnet. And—to add to its stupidity—it is the kind rented out as a service by shady companies (DDoS-as-a-Service). The costs involved are a secondary consideration; the activity will always shift toward the path of least resistance—or to a time when the infected devices' actions are least likely to be noticed. Your sites appear to be serving as a testing ground for a growing botnet, which explains the repeat attack after six months (once more junk had been added to the global botnet).





     

  • Qui nihil scit, omnia credere debet. - He who knows nothing must believe everything.
  • Firewalls do NOT stop dragons. Really not!
  • I avoid Big Tech. They try hard to dictate technology and „culture“ across borders.
  • In effect we have everything to hide from someone, and no idea who „someone“ is.

1 | 2 
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.