Polish users cut off from TalkChess

Discussion of anything and everything relating to chess playing software and machines.

Moderators: hgm, Rebel, chrisw

Modern Times
Posts: 3546
Joined: Thu Jun 07, 2012 11:02 pm

Re: Polish users cut off from TalkChess

Post by Modern Times »

There are issues from the UK as well, but intermittently. When I strike that, I connect to a U.S. VPN and then it is fine. Crazy.
User avatar
Rebel
Posts: 6991
Joined: Thu Aug 18, 2011 12:04 pm

Re: Polish users cut off from TalkChess

Post by Rebel »

Modern Times wrote: Mon Aug 16, 2021 11:18 am There are issues from the UK as well, but intermittently. When I strike that, I connect to a U.S. VPN and then it is fine. Crazy.
It's a pattern, it looks like the US is free from attacks and the target is Europe.
90% of coding is debugging, the other 10% is writing bugs.
User avatar
mclane
Posts: 18748
Joined: Thu Mar 09, 2006 6:40 pm
Location: US of Europe, germany
Full name: Thorsten Czub

Re: Polish users cut off from TalkChess

Post by mclane »

Thats why we have to go.
What seems like a fairy tale today may be reality tomorrow.
Here we have a fairy tale of the day after tomorrow....
User avatar
Scally
Posts: 232
Joined: Thu Sep 28, 2017 9:34 pm
Location: Bermondsey, London
Full name: Alan Cooper

Re: Polish users cut off from TalkChess

Post by Scally »

I’m in the UK and am getting this daily:

Forbidden

You don't have permission to access /forum3/search.php on this server.


Al.
User avatar
mclane
Posts: 18748
Joined: Thu Mar 09, 2006 6:40 pm
Location: US of Europe, germany
Full name: Thorsten Czub

Re: Polish users cut off from TalkChess

Post by mclane »

Thats a shame
What seems like a fairy tale today may be reality tomorrow.
Here we have a fairy tale of the day after tomorrow....
User avatar
Eelco de Groot
Posts: 4561
Joined: Sun Mar 12, 2006 2:40 am
Full name:   

Re: Polish users cut off from TalkChess

Post by Eelco de Groot »

Scally wrote: Tue Aug 17, 2021 12:14 pm I’m in the UK and am getting this daily:

Forbidden

You don't have permission to access /forum3/search.php on this server.


Al.
I wasn't blocked this year, unlike the previous episode. If I don't try to log in can read everything. The forum was just terribly slow a few weeks back, so I just left bcause I had the idea it has to do with the number of users that are active. I could even restore an Avatar. Just posting is difficult because then you are thrown off when you want to submit a message, or for any number of other reasons it seems. Why I don't know, but it is not blocking known IPs I think, just when you log in. But today posting this message I did not get thrown off, could submit without hassle and edit , hurray (you lower your expectations after a while)
Debugging is twice as hard as writing the code in the first
place. Therefore, if you write the code as cleverly as possible, you
are, by definition, not smart enough to debug it.
-- Brian W. Kernighan
User avatar
flok
Posts: 481
Joined: Tue Jul 03, 2018 10:19 am
Full name: Folkert van Heusden

Re: Polish users cut off from TalkChess

Post by flok »

I'm a bit sceptical about this hacker.
Why on earth would someone try to hack a website selling chess-stuff?
Ras
Posts: 2487
Joined: Tue Aug 30, 2016 8:19 pm
Full name: Rasmus Althoff

Re: Polish users cut off from TalkChess

Post by Ras »

flok wrote: Wed Aug 18, 2021 10:22 pmWhy on earth would someone try to hack a website selling chess-stuff?
Hacking attempts go automated via bots these days. Even I see a lot of attempts to get access to my Wordpress installation - which fails of course because I don't use Wordpress in the first place.

Some possible benefits of hacking a small chess shop:
- Gaining access to customer data for all kinds of fraud
- Blackmailing the owner (ransomware, threatening to publish data and destroy the website reputation)
- Injecting malicious scripts to attack website visitors
- Adding the server to a botnet for DDOS attacks
- Abusing the associated mailserver for spam
- Abusing the storage for illegal content.
Rasmus Althoff
https://www.ct800.net
User avatar
flok
Posts: 481
Joined: Tue Jul 03, 2018 10:19 am
Full name: Folkert van Heusden

Re: Polish users cut off from TalkChess

Post by flok »

Ras wrote: Wed Aug 18, 2021 10:33 pm
flok wrote: Wed Aug 18, 2021 10:22 pmWhy on earth would someone try to hack a website selling chess-stuff?
Hacking attempts go automated via bots these days. Even I see a lot of attempts to get access to my Wordpress installation - which fails of course because I don't use Wordpress in the first place.

Some possible benefits of hacking a small chess shop:
- Gaining access to customer data for all kinds of fraud
- Blackmailing the owner (ransomware, threatening to publish data and destroy the website reputation)
- Injecting malicious scripts to attack website visitors
- Adding the server to a botnet for DDOS attacks
- Abusing the associated mailserver for spam
- Abusing the storage for illegal content.
After I wrote that post, I got a 403 (writing this via a proxy).
Ok so I'm a hacker apparently.
I wonder then why I still have access to chessusa.com (just checked).
smatovic
Posts: 2639
Joined: Wed Mar 10, 2010 10:18 pm
Location: Hamburg, Germany
Full name: Srdja Matovic

Re: Polish users cut off from TalkChess

Post by smatovic »

I am not aware what happens behind the scene, but I guess our sponsor performs a site migration to the CDN and DOS protection provider
Cloudflare. If you do an traceroute you will see that talkchess.com is hosted meanwhile behind Cloudflare at your local provider's CDN server and chessusa.com in the US via Amazon. The actual hosting of both sites might still happen on the same machine or not, with Cloudflare as proxy in front of it for TC. Maybe talkchess.com is currently under DDOS, dunno, according to netcraft TC is on rank 89620 of all websites, so it might be a site of interest for hackers. Since the shift to Cloudflare I get frequently logged out, and TC moved to https, hence I guess the site migration is yet not comlete/perfect. I don't get quite why there is still IP blocking or 403 Errors going on with Cloudflare as front-hoster, in my understanding this should not happen. Again, this is all just my speculation, I am not involved in this.

--
Srdja