Earlier quoted context omitted.
I'm the author of the blog. I don't know. Internally, we were half joking that we were going to get ransom notice, but we never did. The only thing that sort of correlates with this attack is that before it started, we began rolling out some slightly more aggressive rate limits one by one. This was mostly because anytime any new "company" thinks they're going to catchup with Claude/OpenAI, they scrape us very aggress…
Good to know. I use your site (with a manual transmission user-agent) often, and it's fantastic. Thanks for your work and the writeup!
Understanding the recent DDoS attack against Read the Docs
11–20 of 73 posts
Re: Understanding the recent DDoS attack against Read the Docs
#12I'm curious if anybody could speculate who would be attacking a documentation silo, and to what end?
Re: Understanding the recent DDoS attack against Read the Docs
#13I am thinking it's probably an AI lab that misconfigured their data scraper (made it too agentic) and it ended up looking like a DDoS.
The new generation of scrapers are all agentic and self healing. (As an example see YC's https://parse.bot)
Re: Understanding the recent DDoS attack against Read the Docs
#14A more interesting question is, what exactly do the attackers gain from hitting read the docs? Most of their docs hosting is static/easily CDN cached. Unlike database bound sites, you would need a lot more traffic to overload pure/mostly static hosting. Maybe it's a malicious AI lab looking to deny their competitors training data? As far as infosec profiling goes, this is probably the oddest case I have heard of. I a…
[1] https://about.readthedocs.com/blog/2024/07/ai-crawlers-abuse...
Re: Understanding the recent DDoS attack against Read the Docs
#15A more interesting question is, what exactly do the attackers gain from hitting read the docs? Most of their docs hosting is static/easily CDN cached. Unlike database bound sites, you would need a lot more traffic to overload pure/mostly static hosting. Maybe it's a malicious AI lab looking to deny their competitors training data? As far as infosec profiling goes, this is probably the oddest case I have heard of. I a…
The article says
> and it purposefully attacked areas that bypassed caching
So that doesn't work. Also, it seems that they were trying to cause financial harm, not to take down the infrastructure but to make it costly for the org itself. That's smart.
Re: Understanding the recent DDoS attack against Read the Docs
#16I'm curious if anybody could speculate who would be attacking a documentation silo, and to what end?
Edit: why the down vote? That is literally in the realm of possibility!
Re: Understanding the recent DDoS attack against Read the Docs
#17Re: Understanding the recent DDoS attack against Read the Docs
#18Given how adaptive the rest of the attack was, I would be very curious to find out how it would approach that obstacle.
Re: Understanding the recent DDoS attack against Read the Docs
#19I'm curious if anybody could speculate who would be attacking a documentation silo, and to what end?
I can't speak for RTD, but I think it's less "documentation site" and more just that we sit on the domains of high-profile products and the tools are just looking for any hole they can find?
Often it's even the company themselves, for whatever reason (security research, etc).
Re: Understanding the recent DDoS attack against Read the Docs
#20There’s an assumption that turning on Cloudflare’s “under attack” mode would mitigate the attack. Given how adaptive the rest of the attack was, I would be very curious to find out how it would approach that obstacle.
We're currently on the "Business" plan, but I'm coming to the conclusion that we need to upgrade to the "Enterprise Advantage" plan for the JA3/4 fingerprinting and detection ID features.
I get put off by "Contact Sales" pricing.