Folks,
Sending this to your personal email addresses because the VATSIM server’s (including the mail server) remain under attack. Just got off the phone with Richard and this is an update on what happened and where we sit right now.
- At some point Friday night a very, very sophisticated Denial of Service (DOS) attack was started against VATSIM. It initially took the form of flooding UK-1 and USA-1 servers…in some cases as much as 7 gigabytes per second of bandwidth. As a result, both those servers are down, which poses a major impact on the network because so many things run off them (including the website).
- There we two additional servers that had been brought up for Cross the Pond and presently those are still being used. As a server is brought up, the attacker starts flooding it with the result that Luca ends up having to take it down, reload everything and bring it back up. The attacker is doing this through multiple falsified IP’s to make it hard to locate him. Result is that different servers on the network are coming up and going down quite frequently, which would be apparent to users as either server splits or them being kicked off the network.
- The attacker also initiated a flood attack against the mail servers. At one point my VATSIM address was receiving over 2 emails per second and built up several thousand emails. As a result, I had to take down the address that pointed to. The vatsim and vatsim-bog mailing lists cannot be relied on for communications right now.
- Yesterday afternoon he started attacking the forums and membership accounts. Multiple accounts being created in a flood and multiple posts to the forums with code embedded in them. At present the forum server is operational, but the forums have been deactivated until we can ensure the attacks can be prevented.
- Last night he attacked Liveatc.net with a major UDP flood attack. As a result, Liveatc.net is down.
- Last night he also attacked the server CERT and some VATSIM backbone functions reside on, so it is also down.
- The dataserver is pushing the data feed (which is necessary for VRC and Squawkbox to get updated server lists and connect to the network. At present it is feeding the vatsim, fsproshop and klain.net servers and accurate data can be pulled by servinfo and the various clients…issue is that the feed is only updated every 2 minutes but in some cases servers are going down and being brought up more quickly than that, so what the feed indicates for servers may or may not be accurate.
- VATSIM leadership is in touch with various data center managers as well as the Metropolitan police (UK) and FBI (US).
So where do we sit?
- The FSD servers are working, albeit being attacked and going offline periodically, so the network can be used by both pilots and controllers, but with none of the reliability we have come to expect from VATSIM.
- Forums will remain down until we have some resolution or the attack stops.
Hopefully this will all be over soon, but that is truly wishful thinking with no basis in fact at this point…
Regretfully,
Dave