4 ms·
Ask HN: Our app has been attacked – How do you handle?
Our App** has been recently attacked in the last 24 hours.
Someone is testing and doing security checking on our platform** without our consent. Even though, this has not made any single dent on our performance, Since our architecture is rock solid, but we failed on throttling user's request.
We have received massive entries in our database from multiple attackers.
We have temporarily disabled few things while we add throttling, but wanted to ask, how do you guys handle such attacks, when you receive them on your end?
*Our internal chat screenshot - https://i.imgur.com/VPuBdnA.jpg
**our app that is under attack by spammers - qocial.com, we launched a week ago and we shared our URL on reddit ( this is where I believe attackers are coming from )
Looking for some valuable feedback, if you report them at some places or just move on and add or improve throttling to requests, feel free to share your feedback please.
Thanks
- qocial 4y agoThose spammers have also targeted our Email account. We got the first possible name of the attackers as "Junaid Raza."
- cinntaile 4y agoPlease don't do this, if you're wrong you're accusing the wrong person and this can have a negative impact on their lives.
- qocial 4y agoWe have proof of our investigation, and we are only sharing while being 100% sure of what data we have received from Attackers on our end while they were attempting to find the available mail by sending email contents to multiple email addresses.
- ksaj 4y agoThat doesn't mean the name is a real name, or that it doesn't belong to a compromised account. Either way, searching the name on Google suggests it is like "John Smith" in how very common it is. So nobody should wrongly get the blame this time around.
- ksaj 4y agoMaybe it is a lack of info or differentiation between the different attack vectors, but it sounds like you actually have it under control if the business is not being impacted. Are they "testing" your security, or spamming from your service, or spamming to your service?
- qocial 4y agoThey are spamming our services; we do see a couple of security testing codes made to our infrastructure by those spammers, but they are all invalid, so we are not impacted by them. But our concern is: we missed throttling, so they are DDOSing to our services; it has not impacted us on performance, but user experience. We are currently working on adding throttling now. We are monitoring our Logs to find out attacks we been receiving and mitigating them. Beyond this, we are still determining what other actions can be taken and looking for feedbacks.
- qocial 4y agoThe SPAMMER is from Thailand Bangkok - https://whatismyipaddress.com/ip/49.49.248.205 https://whatismyipaddress.com/ip/49.49.248.205 and is spamming to all our networks in the last 24 hours.
- yellow_lead 4y agoCollect as much data as possible on them and use it to shadow ban them, or outright ban them. Blacklist their IPs, devices, etc. You can even blacklist their country temporarily if possible. For DDOS, etc you could look at putting Cloudflare in front of your services. And make sure you rate limit everything. >We have received massive entries in our database from multiple attackers. Review all your validation code. If this shouldn't be possible, but your code let it through, it's something you should be validating but are not.
- qocial 4y agoOur validations are not the issue, they are correctly working for forms. We had no limit set per user. We have just started throttling user's request based on their activity. We are still working on it and performing all app related updates. Outside app, we are not sure, what else can be done. We are already using PRO membership of cloudflare, but I don't think cloudflare are working correctly. requests in cloudflare is not matching with the request in nginx reverse proxy log.
- saluki 4y agoCloudflare business level plan has upgraded DDOS protection that's a good first step to upgrade to even temporarily. Block Thailand IPs. https://www.alphr.com/block-country-cloudflare/ https://www.alphr.com/block-country-cloudflare/ Add honeypot form fields if it's a bot you can show success message but disregard the data and blacklist their ip.
- qocial 4y agoWe have PRO plan in our Frontend serving requests and are running on Enterprise plan on few of our backend endpoint. We have not yet fully implemented Enterprise plan for our backend due to CORS issue, we will be resolving them today and getting that applied too. Thanks
- gardenhedge 4y ago> our architecture is rock solid > We have received massive entries in our database from multiple attackers. Really?
- qocial 4y agoYes ( except what we missed was throttling requests )