Postmortem DDoS Attack of May 28th, 2026

  • 🔧 Site instability resolved. You can report double-posts and broken attachments. For bigger issues, use the Technical Grievances thread.
    🇵🇦 Nuestro primer dominio localizado está en español en kiwifarms.pa. Our first localized domain is on Spanish on kiwifarms.pa.
  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
The year is 2043. Nanomachine viruses are deployed to take down the kiwi data centers on the moon. As the swarm approaches, an aged tired man strokes a cat and watches the tartarus shields engage, encaging the moon and the Moon in impervious energy barriers as the cybertroons of old Earth throw wave after endless wave at their most hated foe, the truth enabler.
AI slop, but:
shields.png
 
Thank you Null, it's all good for me now. I did have a nice burst of nostalgia a couple of hours ago, things were going at 1996 dail up speed and it made me pleasantly reminiscent.
 

'File => New Tor Circuit for this Site' generally fixes extant problems related to this issue if you're using the Tor Browser on the user end. If you get an error about being rate-limited do this and it'll probably resolve on the next attempt to load a page. Some exit nodes are better / less populated than others so try a few times before giving up.
>onion
>exit node

Negro intellect detected, there is no exit node :story: Although yes, a new circuit sometimes helps for onion sites too.
 
Basically, of our 8 frontend servers, 7 were to small to deal with 1/8th of the attack's traffic that survived DDoS filtering. The big one could handle the entire attack, but the provider null routed it, so now I have to upgrade the smaller servers and try again. I've also reached out to the last DDoS provider I can possibly think of that might facilitate us. If they can't, and I can't sort this out otherwise, I might literally have to start my own. I'm sort of running out of options.
 
Yeah 28 US Marines pulling up in black Ford Raptor Trucks
Helicopters landed
Kiwi Farms is under siege under lock down
 
still very fucked
true, but thats why we have tor

Basically, of our 8 frontend servers, 7 were to small to deal with 1/8th of the attack's traffic that survived DDoS filtering. The big one could handle the entire attack, but the provider null routed it, so now I have to upgrade the smaller servers and try again. I've also reached out to the last DDoS provider I can possibly think of that might facilitate us. If they can't, and I can't sort this out otherwise, I might literally have to start my own. I'm sort of running out of options.
My kiwi tax dollars at work, keep it up Nool
 
We have 5 different providers in 8 different locations. One of them reported that he was eating 800Gbps of attack traffic. If that's an even split across published IPs, this could have topped more than 6Tbps of attack traffic.

Symptoms of the attack:
  • Automatically followed DNS changes. Due to how I advertise IPs for Tartarus, I suspect that the volumetric attack could have totaled 10Tbps.

I never thought I'd hear about an attack that size against KF. That is insane.

Also, a handcrafted attack. Well, we know who that must be then.

Good to know about the IPv6, I wondered what was going on. I usually run exclusively on IPv4 because my provider's IPv6 support is dog shit, but I have reversed that.
 
Bah. Keffals and his troon army took this site down from the clearnet for a time. And here we are still. Somehow i don't think that (insert current enemy of KF, or some randoms) will kill the site. Thank you for your service null. It is good that i have a place to post my retarded lukewarm takes on happenings around the capital I internet.
 
Samsung internet is still not able to get past tartarus with 'invalid response'.
Tor will connect me on mobile (praise be unto Null)
but will not allow me to log in.
Tor on desktop will allow both connection and log
in. (eternal praise be unto Null(
 
The technical stuff is above my pay grade, but something that fancy sounds fluorescently unusual. It's absolutely insane the amount of time, effort and money people put into trying to stop idiots shitposting on the internet. Imagine all the good things that could be done with that time and effort instead?

Also I'm salty because I can't eat my dinner properly if I don't have the Farms to read. Bastards.

Semper Fi, Null. You do serious internet wrangling stuff and have the patience of a saint. There should be an international prize named after you.
 
Basically, of our 8 frontend servers, 7 were to small to deal with 1/8th of the attack's traffic that survived DDoS filtering. The big one could handle the entire attack, but the provider null routed it, so now I have to upgrade the smaller servers and try again. I've also reached out to the last DDoS provider I can possibly think of that might facilitate us. If they can't, and I can't sort this out otherwise, I might literally have to start my own. I'm sort of running out of options.

Sounds like upgrading the smaller servers will make the site far more resilient, which will be good. Too bad parts are at such a premium at the moment (AI cocksuckers!).

Also, a small suggestion, mention on Twitter that if people are having trouble, to make sure they have IPv6 enabled, I know many people that keep it off by default.
 
Wouldn't 10 Tbps make this one of the largest DDoS attacks ever? Or do they only record them if Cuckflare, Azure, or Google write a blog post about it?

Ask your friendly AI for the top 10 DDoS attacks. It ranges from 2.3 to 31.4 Tbps.
 
Based on my back of the envelope math, I'd ballpark this attack is costing high five to low six figures per day (USD) to run, but access to existing botnets could lower this. This should definitely be raising the eyebrows of state cybersecurity actors.
 
Based on my back of the envelope math, I'd ballpark this attack is costing high five to low six figures per day (USD) to run, but access to existing botnets could lower this. This should definitely be raising the eyebrows of state cybersecurity actors.
If it lasts longer then three days we are definitely looking at either a State Actor, or someone with enough spare cash to put them in the top .1% of the global population. That or someone in the top 1% who is a fucking retard.
 
Atrás
Top Abajo