Turning off Anonymous User Access to BlueNC

Now that I'm home I need to address the denial of service attack we suffered last week. I will be turning off access to BlueNC by anonymous users until we have addressed this issue. Please log in if you wish to access BlueNC. Anonymous users should be able to see the front page and this message. Sorry for the inconvenience.

Comments

Thanks, Betsy

I've determined that I don't much like anonymous anyway. Interesting experiment.

Welcome home.
_____________________________________

Jesus Swept, so you can come clean.

Anonymous users can't post anything as it is

but on the 25th anonymous user(s) using a series of IP addresses traced to the Asia Pacific Network either embedded code or tried to. There are over a hundred entries in a span of a few hours. I'm going to clean what needs to be cleaned and then Jerimee and I are going to upgrade to a newer version of Drupal to get us current on security updates.



***************************
Vote Democratic! The ass you save may be your own.

I don't like Anonymous either

Do what you need to do. This let us know that somebody has a problem with this wonderful site.

Thank you for all that you and the others do providing us a meeting place on the web.

The Political Agitator

"I swore never to be silent whenever human beings endure suffering and humiliation. We must always take sides. Neutrality helps the oppressor, never the victim. Silence encourages the tormentor, never the tormented." - Elie Weisel

"I swore never to be silent whenever human beings endure suffering and humiliation. We must always take sides. Neutrality helps the oppressor, never the victim. Silence encourages the tormentor, never the tormented." - Elie Weisel

Thank you, Mr. Dancy!

We'll get it taken care of. I've been able to ban the main IP address sending requests to our server. Funny, it leads straight to Google.com.



***************************
Vote Democratic! The ass you save may be your own.

Good Move Betsy!

The closer you come to the election, the more crap will comes out of the woodwork with the Republicans thugs. This is not your usual presidental election and things have change greatly. In short, all dirty tricks will apply and since BlueNC is consider a high profile target on their enemy list that must be stop at all cost.........

fwiw, as a lurker

"Anonymous users should be able to see the front page and this message."

I surfed over tonight after exhausting myself on dailykos & orangepolitics and couldn't see anything - not even this thread. Saw the "log in" and thought I'd give it a shot... and then I could see this thread.

Thanks for letting me know

Hopefully we can go back to letting folks who aren't logged in access the site. I haven't checked the logs this morning. We'll lose some traffic for a few days, but hopefully we can get the upgrades taken care of and get back to normal.



***************************
Vote Democratic! The ass you save may be your own.

yep

Thanks. We have basically no idea what the world of lurking at BlueNC really looks like. This kind of feedback is always welcome.

_____________________________________

Jesus Swept, so you can come clean.

fyi

Before I logged in, I could see the left and right frames, but the only thing in the middle of the page was, "Access denied. You are not authorized to access this page." (In the right frame, I could see comments but not blog posts.)

DDOS and anonymous access...

I don't mind having to log on. However, when you go to the homepage, it's not at all clear that one is required to log on just to read.

Your webmaster should be able to change the "access denied" page to be more informative. It might help others... Took me a while to think of logging on.

Btw, unfortunately, requiring a logon offers absolutely no protection from a DDOS attack. The attackers simply see the logon page.

That wasn't the point of clearing out anonymous users, though

It clears up the logs, so I am not looking at hundreds/thousands of entries from anonymous users and I can more easily trace the mischief.



***************************
Vote Democratic! The ass you save may be your own.

Not clear

It's not clear to anonymous users when you go to the BlueNC home page why nothing is accessible. Perhaps you ought to make it more clear?

It's temporary

We'll be going back to allowing anons to read content.



***************************
Vote Democratic! The ass you save may be your own.

Thanks, Betsy

Sorry for all the pestering.

Reminds me of one of my favorite lyrics from Joni Mitchell's Court and Spark album: "You don't know what you got till it's gone."
_____________________________________

Jesus Swept, so you can come clean.

Need to unlock BlueNC

I've had to deal with a few DDOS issues on my site so FWIW I think cutting read access off is not a good tactic. I happen to have a login to BlueNC but if I didn't I would bypass it and move on probably never to return. Maybe there's enough readership on BlueNC that you can reject new "eyeballs" possibly forever but.....

Just my $0.04.5 ($0.02 adjusted to match our current madministration's klepto-economy).

CitizenWill
there comes a time when one must take a position that is neither safe, nor politic, nor popular, but he must do it because Conscience tells him it is right. MLK,Jr. to SCLC Leadership Class

CitizenWill
there comes a time when one must take a position that is neither safe, nor politic, nor popular, but he must do it because Conscience tells him it is right. MLK,Jr. to SCLC Leadership Class

Will....for heaven's sake it is temporary!

Please read the comments above before criticizing. I was trying to keep the important data from scrolling off of the logs and limiting access by anonymous users helps reduce the number of log entries. If you don't have anons clicking on every link/page/node/comment on the site, then you don't have all those log entries. IF they can't see it, they can't click on it.



***************************
Vote Democratic! The ass you save may be your own.