DDoS attacks

dude basedflare is ran by Stephen Lynch who was the guy that designed the algo that Kiwi Flare (and now that anime tranny shit Anubis) use. He's just some guy with a few servers and upstream DDoS mitigation that already banned us.

do people REALLY THINK i have NEVER searched "BASED DDOS MITIGATION" in Google in the last 6 fucking years???
Maybe then some big mitigation service on the eastern side of the world that wouldn't submit to media pressure, then? What do big companies in China use? Surely there's one big enough that will see you as a customer and not like some boogieman like Cloudflare does
 
dude basedflare is ran by Stephen Lynch who was the guy that designed the algo that Kiwi Flare (and now that anime tranny shit Anubis) use. He's just some guy with a few servers and upstream DDoS mitigation that already banned us.

do people REALLY THINK i have NEVER searched "BASED DDOS MITIGATION" in Google in the last 6 fucking years???
maybe if you searched "opsec demon ddos mitigation" you would have found the solution already
 
TOR is a lot faster than I remember it being last time we were exiled from Egypt clearnet.
 
I'm sorry if this topic has been discussed here before (I can't read through 73 pages of posts right now), but would it be possible to create some kind of community-driven cloud botnet, with volunteers contributing their own IPv4 addresses / IPv6 addresses, and bandwidth? Couldn't we protect ourselves from a botnet using some kind of community-built DDoS protection?

How many A/AAAA records can you store on DNSPod's nameservers? Would something like that work? Or perhaps a different approach, where DNSPod would return, say, 4–10 healthy IP addresses at a time, potentially selected based on geographic location, while a much larger pool of servers exists behind the DNS system. You could rotate the returned set as individual nodes come under attack or become unavailable via DNSPod APIs.

I don't think troons could DDoS DNSPod itself, and even if they tried, I imagine Tencent has a large enough network to protect itself against them. The question is whether DNSPod would eventually drop the site the way Crimeflare (fuck Cloudflare) did.

I'm sorry if my reasoning is completely wrong. I'm not very experienced with how DNS works.

Edit: Forget about that, for something like this to work Null would have to expose IP addresses of back end servers to volunteers in some way and I don't think that's a wise decision.
 
Thanks for the onion link, mister Moon. I can't believe I actually have to use tor for a site I use rather than a niche curiosity, it's bizarre. I'll go purchase drugs and 3D printed guns with my Monero wallet now.
 
From Null's tg:
Good morning. The Tor is down because our physical datacenter for the Tor backend is being DDoS attacked by unrelated extortion efforts. Since the new botnet is so large, a lot of resellers are selling it, and people are going crazy with the bandwidth. This is indirectly impacting us on other small hosts that are targets. It's very unfortunate.
And that is exactly the shit that scares me. KF getting botted nonstop is bad enough. Retarded monkeys realizing they too can buttfuck the website they got kicked off from for just the low fee of $80/month? Insanity.
 
I'm sorry if this topic has been discussed here before (I can't read through 73 pages of posts right now), but would it be possible to create some kind of community-driven cloud botnet, with volunteers contributing their own IPv4 addresses / IPv6 addresses, and bandwidth? Couldn't we protect ourselves from a botnet using some kind of community-built DDoS protection?

How many A/AAAA records can you store on DNSPod's nameservers? Would something like that work? Or perhaps a different approach, where DNSPod would return, say, 4–10 healthy IP addresses at a time, potentially selected based on geographic location, while a much larger pool of servers exists behind the DNS system. You could rotate the returned set as individual nodes come under attack or become unavailable via DNSPod APIs.

I don't think troons could DDoS DNSPod itself, and even if they tried, I imagine Tencent has a large enough network to protect itself against them. The question is whether DNSPod would eventually drop the site the way Crimeflare (fuck Cloudflare) did.

I'm sorry if my reasoning is completely wrong. I'm not very experienced with how DNS works.

Edit: Forget about that, for something like this to work Null would have to expose IP addresses of back end servers to volunteers in some way and I don't think that's a wise decision.
shit id contribute
 
Maybe then some big mitigation service on the eastern side of the world that wouldn't submit to media pressure, then? What do big companies in China use? Surely there's one big enough that will see you as a customer and not like some boogieman like Cloudflare does
you mean like how ddos-guard (ru) folded in under 12 hours?
 
JUST HURRY THE FUCK UP AND DO IT, YOU FUCKERS--WHIP OUT YOUR DICK AND SLAP JOSH ACROSS THE FACE WITH IT. BLACK-BAG HIM, CRASH A DRONE INTO HIS HOUSE, ORDER A MILLION PIZZAS TO HIS ADDRESS EACH LACED WITH A DIFFERENT TYPE OF POISON--JUST SHIT OR GET OFF THE FUCKING POT ALREADY!!!

sorry, I'm a little stressed out by all this right now.
 
I'm sorry if this topic has been discussed here before (I can't read through 73 pages of posts right now), but would it be possible to create some kind of community-driven cloud botnet, with volunteers contributing their own IPv4 addresses / IPv6 addresses, and bandwidth? Couldn't we protect ourselves from a botnet using some kind of community-built DDoS protection?
yes it's called the Tor Network you're free to set up a Tor relay.
 
I've never had any luck with the Tor Browser for Android. Always slow and often needs several attempts to even connect to the network. Using Orbot on the phone has been much better, and I can keep using Brave browser for Android. On PC Brave's built in Tor Browser has always been fine and easy to use.

Maybe things are burning down around us, but this is fine.
 
dude basedflare is ran by Stephen Lynch who was the guy that designed the algo that Kiwi Flare (and now that anime tranny shit Anubis) use. He's just some guy with a few servers and upstream DDoS mitigation that already banned us.

do people REALLY THINK i have NEVER searched "BASED DDOS MITIGATION" in Google in the last 6 fucking years???

There are some others I think I saw people @ to you on Twitter. But if the forum ends up just on Tor for a while, I still see activity here when it's like that. I'm on Tor right now. So it won't just be dead as an onion so long as people can find the link easily.

(Speaking of dark web, I know Darkmatter (drug market) gets absolutely hammered by DDoS attacks 24/7/365. Not sure what method they use to mitigate it).

I don't know anything about this stuff personally lthough my own online business I got SiteGuarding for, and that completely stopped the attacks I did face.
 
With my approach, you wouldn't need a Tor client to browse the forums and it would be dedicated to Kiwifarms, with no criminal, drug dealing or pedo backstory. I'm sorry if my idea sounds stupid or overly idealistic, hoping that the community has enough nerds willing to help. I just thought I'd throw in my two cents.
 
Última edición:
With my approach, you wouldn't need a Tor client to browse the forums and it would be dedicated to Kiwifarms, with no criminal, drug dealing or pedo backstory. I'm sorry if my idea sounds stupid or overly idealistic, hoping that the community has enough nerds willing to help. I just thought I'd throw in my two cents.
There are no "dumb" ideas, only ideas that don't lead anywhere productive (i.e. most of them).

you tried.jpg
 
With my approach, you wouldn't need a Tor client to browse the forums and it would be dedicated to Kiwifarms, with no criminal, drug dealing or pedo backstory. I'm sorry if my idea sounds stupid or overly idealistic, hoping that the community has enough nerds willing to help. I just thought I'd throw in my two cents.

No need to apologise — it's a good-faith idea, and some version of it gets proposed in every thread like this one. It's worth writing out properly why a volunteer-run frontend doesn't work, because the reasons aren't obvious and they're precisely why the current setup looks the way it does.

You actually spotted the fatal problem yourself in your edit, so I'll start there.

1. It invites the attacker inside the perimeter

The threat model here isn't random internet noise. It's a small number of dedicated people who actively want to harm this site and the people who read it. An open volunteer programme is an open invitation to those exact people to sign up.

A frontend node has to do one of two things:

  • Terminate TLS — which means handing the certificate's private key to strangers. Anyone holding it can transparently decrypt and rewrite traffic: harvest logins, steal session cookies, read DMs, impersonate staff, inject anything they like into pages. A single hostile volunteer compromises every user routed to them.
  • Pass TLS through (SNI-based TCP proxying) — safer, no key exposure, but the node still sees the source IP of every connection, can log it, can selectively drop or delay traffic, and can correlate who is reading what and when.

There is no way to vet volunteers at scale, and DNS hands each visitor a node at random, so users can't choose a trustworthy one. You'd be asking people to route their traffic through a stranger who may well be the person attacking them.

2. Residential connections mostly can't accept inbound 443 anyway

Setting the trust problem aside entirely, the plumbing doesn't cooperate:

  • A large share of home IPv4 sits behind CGNAT — the subscriber has no public IPv4 of their own and cannot port forward at all, regardless of what they do to their router.
  • Most consumer ISP terms of service prohibit running public servers, and plenty block inbound 80/443 outright.
  • Residential IPs are dynamic. They change on lease renewal, reboots and outages, so records go stale constantly.
  • It assumes every volunteer can correctly configure port forwarding and then keep a box patched and online 24/7. Most can't, and a neglected node is a liability rather than an asset.
  • Plenty of corporate, school and mobile networks blocklist residential ranges outright, so a chunk of users simply could not reach whichever node they were handed.

3. The bandwidth maths runs the wrong way

DDoS mitigation works when you have more capacity than the attacker. Residential lines have dramatically less.

Home connections are asymmetric — a typical upload is a few tens of megabits against a gigabit download. This is an image and video heavy forum; a handful of users pulling attachments would saturate a domestic uplink on its own, before a single packet of attack traffic arrives.

More importantly, pointing DNS at someone's house means pointing the attack at their house. When their node gets hit it doesn't degrade gracefully — it takes out that person's home internet, their family's connection, and quite possibly their ISP account once the abuse complaints land. Volunteers would also burn through monthly data caps in short order. You would be asking civilians to absorb attack traffic on domestic lines, and the people throwing that traffic would enjoy it enormously.

4. It's a privacy disaster in both directions

  • Volunteers' home IP addresses would be published in DNS, permanently associating their household with this site. That's a doxing, harassment and swatting vector, plus abuse complaints and potential legal exposure depending on where they live.
  • Users would be handing their real IP addresses to unvetted strangers. For a site whose readers often have genuine reasons not to want that logged, this is materially worse than the commercial provider everyone was glad to see the back of.

5. DNS rotation doesn't hide the pool

Rotating a subset of records conceals nothing. An attacker simply queries repeatedly from many resolvers and enumerates the entire pool within hours — it is public data by design. Meanwhile resolvers and browsers cache aggressively and routinely ignore short TTLs, so you cannot actually pull a node out of rotation quickly; users keep landing on dead or actively attacked nodes for as long as the cache holds. It also makes the DNS provider a single point of failure for takedown pressure, which is the same dependency that caused the last problem — as you rightly noted yourself.

6. On Tor specifically

The onion service is the one option that exposes nobody's address — not the servers', not the users', not a volunteer's. That is a real technical property rather than a compromise. The "backstory" objection is about perception rather than function, and it's worth noting that relaying traffic for one specific named site from your home connection carries far more personal legal and social risk than running a Tor relay does.

Finally, the professional version of your idea already exists. The site sits behind a network of dedicated reverse-proxy nodes, run by people who understand and have knowingly accepted the risk, on connections built for it, without handing private keys or user traffic to strangers. Same concept — implemented the only way that is actually safe.

Genuinely, thanks for thinking about the problem rather than just complaining about it. The instinct is sound; it's the volunteer part specifically that turns it from a mitigation into a new attack surface.
 
I saw some talk about https://i2p.net/en/ on here earlier. That's one I can't really wrap my head around still, never got into it but apparently it's TOR-esque? Don't know if that would help in this situation or not in any way.
Tor and I2P are just different flavors of similar ideas. With Tor you get some weird courting dance being the circuit you construct on connection, then the opposite party is doing basically the same dance with its circuit, then you talk over these to avoid directly interacting with eachother and gives other plausible deniability benefits that would only interest glowies.

I2P, instead of doing some weird circuit dance you get in a giant message passing circle, messages are passed and 99% of them you cant read, only traffic intended for you is readable, and your neighbors cant see if you passed the message to the next party or not, so effectively you get a similar effect as TOR doing glowie shit.


The concepts behind Tor or I2P is mostly privacy focused, it just happens to be that both of these protocols fix the intentionally left defects in the clearnet's setup.
 
Atrás
Top Abajo