← Back to team overview

torios team mailing list archive

Why the domain went down

 

I was able to trace back to the IP address that caused the evil-script activity on the ToriOS.org domain resulting in Turnkey's firewall blocking it. It came from, wait for it... wait for it... me.

Here's what happened:

I woke up early that morning so I decided to take the time to learn phpBB inside and out. I decided I would commit to a break-neck speed comb over of the whole systems administrative capabilities. This resulted in the following activity on my part: logging in as admin, making changes, logging out, logging back in as a regular user, observing changes, logging out as regular user, logging back in as admin, make more changes... you can see where this is going and it was all coming from a single IP address. There was enough to explore that I must have kept at it for a couple of hours, and I was moving fast. This caused Turnkey's firewall to (rightfully) flag me as a malicious script due the unusual activity and the fact that it was all coming from a single IP, and block the domains IP. I really should have known better - live and learn I guess. Why there was first a throttling down of bandwidth with a slightly delayed blocking I do not know, perhaps a network guru here does but it's not really important.

Do not expect our domain to be blocked in the future:

It is perfectly safe to administrate the forum or any part of the web site. Again: it was the bizarre activity on my part that caused this. If anything we should be grateful that Turnkey's systems are smart enough to hit the kill switch. This was also not an issue of bandwidth, we have more than we could ever use. Normal administration and end user activity will not cause this to happen. We can handle hundreds if not thousands of simultaneous logged on users all doing there thing.

Sorry about all that.

BTW - We are on a shared server so please do not ever attempt an SSH session, that is the only other that could get us blocked.

Going back to chilling now, I promise Ali : )