Live data from Hacker News

Arxiv.org is experiencing a DDoS attack

blog.arxiv.org

1–10 of 49 posts

Re: Arxiv.org is experiencing a DDoS attack

#2
These requests originated from over 200 IP addresses – almost all owned by an ISP for a particular province in China. The confirmation emails for this volume of requests overwhelmed our email service. As a result, many arXiv users may not have received their daily emails. And other users may not have received their confirmation emails for registering accounts, or legitimate email change requests.

this should be easy to block, no? just 200 out of millions

Re: Arxiv.org is experiencing a DDoS attack

#5

These requests originated from over 200 IP addresses – almost all owned by an ISP for a particular province in China. The confirmation emails for this volume of requests overwhelmed our email service. As a result, many arXiv users may not have received their daily emails. And other users may not have received their confirmation emails for registering accounts, or legitimate email change requests. this should be easy…

[deleted]

Re: Arxiv.org is experiencing a DDoS attack

#6
A million password resets is shockingly low for a DDOS, could this have been an university assignment gone wrong? I can imagine some clueless dean ordering all their engineering grads to submit research to arXiv. If they have 100-200K students, a single poorly written script to link the institution's SSO with automatically created arXiv accounts could easily overwhelm the system.

Re: Arxiv.org is experiencing a DDoS attack

#8

A million password resets is shockingly low for a DDOS, could this have been an university assignment gone wrong? I can imagine some clueless dean ordering all their engineering grads to submit research to arXiv. If they have 100-200K students, a single poorly written script to link the institution's SSO with automatically created arXiv accounts could easily overwhelm the system.

What school has 200k engineering students?

Re: Arxiv.org is experiencing a DDoS attack

#10
post #8

A million password resets is shockingly low for a DDOS, could this have been an university assignment gone wrong? I can imagine some clueless dean ordering all their engineering grads to submit research to arXiv. If they have 100-200K students, a single poorly written script to link the institution's SSO with automatically created arXiv accounts could easily overwhelm the system.

What school has 200k engineering students?

"poorly written" could easily remove the "engineering" qualifier.
Post reply on HN