this post was submitted on 28 Jul 2026
47 points (100.0% liked)

LemmyToday

322 readers
7 users here now

If you experience issues or problems with this instance (lemmy.today), this is the place to discuss them. Or if you just want to ask questions about how something works. Anything related to the instance or lemmy itself.

founded 2 years ago
MODERATORS
 

Hi,

We had a DDOS attack against old.lemmy.today which overloaded the entire server for about 20 minutes. I had to turn off old.lemmy.today temporarily and will look through logs and probably block more chinese ip ranges, since thats where it came from.

Always something to do. :) Keeping this as sticky for a while to inform everyone.

Edit: I added more ip blocks for Chinese networks and hopefully it will keep future bots away. Bringing up the old.lemmy.today user interface again...

Edit 2: Had to take it down again due to massive bot scraping. Currently down.

top 50 comments
sorted by: hot top controversial new old
[–] MyOpinion@lemmy.today 10 points 6 days ago (1 children)

When I was running a web server this was a common occurrence. Most of the DDOS attacks I experienced came from China.

[–] mrmanager@lemmy.today 8 points 6 days ago (1 children)

Yeah its very common. Some instances block the entire Chinese internet for this reason...

[–] YiddishMcSquidish@lemmy.today 5 points 6 days ago (1 children)

This is a genuine question, but why doesn't this instance? Is it because we would miss out on some content? I mean you are much more in touch with the technicalities, but do we have a mandarin speaking user base you're not trying to alienate?

[–] mrmanager@lemmy.today 7 points 6 days ago

I think we are unfortunantly heading in that direction of blocking more and more of them...

And no, no mandarin user base. :)

[–] freudian_slop@programming.dev 9 points 6 days ago (1 children)

I don't have an account there but I am always happy when fediverse instance admins are transparent about their problems. This will help other instances too.

[–] mrmanager@lemmy.today 6 points 6 days ago

Absolutely!

[–] hexagonwin@lemmy.today 6 points 6 days ago (1 children)

thanks a lot for keeping this instance running without cloudflare stuff, really appreciate it..

[–] mrmanager@lemmy.today 9 points 6 days ago (1 children)

Thank you!

I dont want cloudflare either. :)

[–] mehquestion@lemmy.world 2 points 6 days ago* (last edited 6 days ago) (2 children)

First, thank you for all the hard work you do.

Second, as someone still struggling to understand lemmy, one of the reasons I'm not a fan of old.lemmy.world is that I have to turn on cloudflare.

I have noscript running and I have cloudlflare blocked.

Your response implies otherwise that you don't have cloudflare running either.

So why am I always greeted with cloudflare when I visit old.lemmy.world?

Edit: Oh I misread the title. Its old.lemmy.today that you're talkinga bout, not old.lemmy.world.

My goof. Please ignore my post, but do take my gratitude.

Edit 2: So I went over to old.lemmy.today. It is tempting to switch. I like the default interface and it has content from a lot of places (on quick glance). One of the reasons I'm not a huge fan of old.slrpnk.net is that I can't figure out how to access content from other instances. I seem tempted to switch.

[–] mschae@discuss.mschae23.de 2 points 5 days ago (1 children)

One of the reasons I'm not a huge fan of old.slrpnk.net is that I can't figure out how to access content from other instances.

old.slrpnk.net should still have posts from other instances, as far as I can tell. They only show local stuff by default, so you have to set “listing” to “all” to see them (the small toggle under the yellow tagline). If you want to primarily interact with posts from other instances, lemmy.today is probably the better choice though either way. slrpnk.net looks like it mostly focuses on local communities.

I have noscript running and I have cloudlflare blocked.

The good thing about mlmym (the software behind old.lemmy.today, old.lemmy.world, and so on) is that it's entirely usable without JavaScript :)

So as long as there isn't something like cloudflare in the way that does require JS, it should work fine to use it that way.

Looking at it right now though, @mrmanager@lemmy.today it looks like old.lemmy.today is erroring with 502?

[–] mrmanager@lemmy.today 3 points 5 days ago

Yeah, I had to take it down overnight and currently experimenting with anubis for it... will be a bit unstable today.. :)

[–] mrmanager@lemmy.today 2 points 6 days ago (2 children)

You are very welcome if you do. Its the same content in old.lemmy.today as lemmy.today, just a different look. :)

I dont like cloudflare so doing my best to avoid it if I can.

[–] hexagonwin@lemmy.today 2 points 5 days ago* (last edited 5 days ago) (2 children)

seems like it's working again but with anubis.. maybe can we just have something like http basic auth with a public password? (like have the password prompt as "type lemmy")

i don't think anubis is a good solution. it's very trivially bypassed though maybe good enough to block stupid generic bots..

see also https://lock.cmpxchg8b.com/anubis.html

[–] mrmanager@lemmy.today 2 points 5 days ago

Ok now its working and seemingly blocking bots, but we will see over time how well this works. Like you said, im sure its possible to bypass but maybe it improves the situation somewhat still.

[–] mrmanager@lemmy.today 2 points 5 days ago

Its not really working yet, it keeps popping up the "seeing if you are a bot" message all the time.

But yeah, working on it. If it can prevent dumb bots, its a win for sure.

[–] mehquestion@lemmy.world 2 points 5 days ago (2 children)

Hi I just wanted to follow up on something

Since last evening, I can't access old.lemmy.today (I can still access lemmy.today but that's not an interface I like).

Are you having bot issues again or is there something I messed up on my end?

[–] mrmanager@lemmy.today 3 points 5 days ago

It was down overnight and today im working on trying to get anubus to work with it, so it will be unstable... :)

[–] mrmanager@lemmy.today 2 points 5 days ago (2 children)

Now it should work well again. I put it behind anubis and we will see if it improves the situation with the bots.

[–] mehquestion@lemmy.world 1 points 4 days ago (1 children)

I'm so sorry to constantly pester you, but I have another question.

I've been enjoying old.lemmy.today for the past few days. The biggest praise I can give it: I haven't missed reddit at all, and the smaller community actually makes it feel like an upgrade. Like the reddit of old.

But I wanted to make an account on Lemmy.today to make a post, however to register it seems I need an email address.

I don't want to give an email address. I could give a disposable one from one of those sites, but that would be obvious (to what it sounds like is a human curation process).

I know you said its to ward off bots, I'm wondering if its a temporary pause, or if its a permanent policy?

[–] mrmanager@lemmy.today 1 points 4 days ago (2 children)

It's fine to not give an email address. It's just for the email to let you know that you were approved or denied. So if you put something random there and check if you can login later, it's all good.

I think it's even optional to give it... You can try registering without. :)

[–] mehquestion@lemmy.world 2 points 3 days ago (1 children)

So just as an update, I checked both old.lemmy.today and lemmy.today; both seem to require an email address.

On lemmy.today is explicitly says email is required. On old.lemmy.today I tried fiddling around with various entries in the email field such as na, not_applicable, etc, but that didn't seem to work either.

Is there something obvious I'm missing?

[–] mrmanager@lemmy.today 1 points 3 days ago

No, I checked and we do require email. I wasnt sure what was set there but yep, its required. But just put any email address there if you dont want to use a real one. You just wont get an email with approval or denyal after account creation, so you have to come back later and try to log in at some point.

[–] mehquestion@lemmy.world 1 points 4 days ago

Cool thank you so much!

[–] mehquestion@lemmy.world 2 points 4 days ago

Thanks, and again, keep up the good work!

[–] db0@lemmy.dbzer0.com 5 points 6 days ago (1 children)

Look into pow protection. The Chinese botnets come from a practically infinite range at the moment

[–] mrmanager@lemmy.today 3 points 6 days ago (1 children)

Thank you, I was reading about pow protection and finding out more about it. Is there some local software you could recommend? I'm not too hot on cloudflare or other big tech services unless absolutely needed.

[–] db0@lemmy.dbzer0.com 3 points 6 days ago (1 children)

What is your reverse proxy software?

[–] mrmanager@lemmy.today 2 points 6 days ago (1 children)
[–] db0@lemmy.dbzer0.com 3 points 6 days ago (2 children)

You can look into Anubis then.

[–] mrmanager@lemmy.today 2 points 5 days ago* (last edited 5 days ago) (2 children)

I added Anubis for https://old.lemmy.today/ and will see if it helps the situation. Bots are hammering it pretty hard but not getting any lemmy content at least. Thank you for your advice. :)

load more comments (2 replies)
[–] mrmanager@lemmy.today 2 points 6 days ago

Much appreciated sir. :)

[–] mrmanager@lemmy.today 6 points 6 days ago (1 children)

Alright, https://old.lemmy.today/ is back up, as well as the other alternative user interfaces mentioned in the sidebar.

I have blocked more chinese ip ranges found in the log files, so hopefully it helps.

[–] mschae@discuss.mschae23.de 5 points 6 days ago (5 children)

While you're here, I published a small update yesterday (26.3.4) that fixes a few more bugs I've found :)

[–] CalcProgrammer1@lemmy.today 4 points 6 days ago

Thanks to both of you for keeping mlmym alive. It's the best way to use Lemmy and I moved to lemmy.today primarily because they have it as an available interface.

[–] mrmanager@lemmy.today 3 points 6 days ago

Very good, I pulled the latest version.

Thanks for your work on this, and the code you added to forward ip numbers was super useful today to see where these botnets are coming from. Really appreciate it.

load more comments (3 replies)
[–] PapaSkwat@lemmy.today 2 points 5 days ago

Thanks for the heads up!

[–] ThunderComplex@lemmy.today 4 points 6 days ago (1 children)

Thanks for keeping the instance running. I happened to get a error message smth about the instance being broken and remembering that disk upgrade post from a couple days ago I feared the DB got nuked for a sec hehe.

[–] mrmanager@lemmy.today 4 points 6 days ago (2 children)

The db is like the holy grail for a lemmy instance. Heavily backed up and fortified. :)

load more comments (2 replies)
[–] breadsmasher@lemmy.world 3 points 6 days ago (1 children)

are you sure it wasnt the tesseract dev slipping in some javascript to DDOS your instance?

[–] mrmanager@lemmy.today 4 points 6 days ago

I dont think so since the traffic came from China and came from 951,466 unique ips. :)

[–] sanitation@lemmy.today 3 points 6 days ago* (last edited 6 days ago) (1 children)

dang it . interesting.
I wonder if this is shady reddit operation

[–] victorz@lemmy.world 6 points 6 days ago (1 children)

Maybe someone hid some JavaScript on some page somewhere.

[–] Rivalarrival@lemmy.today 4 points 6 days ago (1 children)

I understood that reference.

load more comments (1 replies)
load more comments
view more: next ›