Theme editor

ATF not shutting down now

I wonder if they're working on that, or if Vistarrr just moved on.
 
I wonder if they're working on that, or if Vistarrr just moved on.
Vistarr gets more stubborn every time ATF is attacked. Being DDOS'd is paradoxically great for the site's survival since it survives on pure spite.

But with a DDOS like this you kinda have to wait it out until the attackers get bored.

BTW, I send Vistarr a message about a proposal to have a very small Xenforo extension that enables users that are older than 3 months to create a private key + random deviceid + public key locally and register the random deviceid + public key to their account.

Then in normal operation, nothing changes. But if Vistarr uploads a ddos_mode_active.txt to his server, a PHP script would intercept calls before it reaches Xenforo. If the requester has registered a key and therefore can prove they had access to the forum in the past, they get a 24h cookie that enables them to access Xenforo to log in to their actual account (with their actual credentials). This cookie keeps tracks of how often they access the forum per few seconds, if they spam requests the device key gets revoked.

Note: The device key is purely a DDOS protection, you won't be able to login to anything with it. If somebody steals the key, worst case is that they can DDOS the server with it with a few requests, which would invalidate the key and mean the user unfortunately needs to wait out the DDOS attack, but nothing worse than that.

In this way, if an anti with too much time on their hands tries to attack ATF again, you have a pretty cheap way to filter out requests before they even hit Xenforo and it would probably allow forum access for legitimate users even during a DDOS attack. Of course, it's shit for new users they won't be able to use the forum, but currently no one can.

If someone spots a flaw in this mechanism or already knows it won't work the way I think it works I'm all ears lol. I'm not experienced with DDOS, I figured that if you could reject malicious requests with as little calculation as possible you can mitigate them, but it might very well be the case that it's the amount of requests that's the problem, not even the compute spend per request.
 
Games+


If it had Animations/Lewd Sounds would be the greatest game ever.
Hope its ok I linked the thread to it, if not please let me know.
 
Thanks, I know this game, but the image has slipped my mind...
 
Vistarr gets more stubborn every time ATF is attacked. Being DDOS'd is paradoxically great for the site's survival since it survives on pure spite.

But with a DDOS like this you kinda have to wait it out until the attackers get bored.

BTW, I send Vistarr a message about a proposal to have a very small Xenforo extension that enables users that are older than 3 months to create a private key + random deviceid + public key locally and register the random deviceid + public key to their account.

Then in normal operation, nothing changes. But if Vistarr uploads a ddos_mode_active.txt to his server, a PHP script would intercept calls before it reaches Xenforo. If the requester has registered a key and therefore can prove they had access to the forum in the past, they get a 24h cookie that enables them to access Xenforo to log in to their actual account (with their actual credentials). This cookie keeps tracks of how often they access the forum per few seconds, if they spam requests the device key gets revoked.

Note: The device key is purely a DDOS protection, you won't be able to login to anything with it. If somebody steals the key, worst case is that they can DDOS the server with it with a few requests, which would invalidate the key and mean the user unfortunately needs to wait out the DDOS attack, but nothing worse than that.

In this way, if an anti with too much time on their hands tries to attack ATF again, you have a pretty cheap way to filter out requests before they even hit Xenforo and it would probably allow forum access for legitimate users even during a DDOS attack. Of course, it's shit for new users they won't be able to use the forum, but currently no one can.

If someone spots a flaw in this mechanism or already knows it won't work the way I think it works I'm all ears lol. I'm not experienced with DDOS, I figured that if you could reject malicious requests with as little calculation as possible you can mitigate them, but it might very well be the case that it's the amount of requests that's the problem, not even the compute spend per request.
smart.
 
I saw a note on ATF about looking into alternative protocols. I haven't seen the site go down this long before, though I'm also not super active. Is it typical for it to be down for days at a time?
 
Vistarr gets more stubborn every time ATF is attacked. Being DDOS'd is paradoxically great for the site's survival since it survives on pure spite.

But with a DDOS like this you kinda have to wait it out until the attackers get bored.

BTW, I send Vistarr a message about a proposal to have a very small Xenforo extension that enables users that are older than 3 months to create a private key + random deviceid + public key locally and register the random deviceid + public key to their account.

Then in normal operation, nothing changes. But if Vistarr uploads a ddos_mode_active.txt to his server, a PHP script would intercept calls before it reaches Xenforo. If the requester has registered a key and therefore can prove they had access to the forum in the past, they get a 24h cookie that enables them to access Xenforo to log in to their actual account (with their actual credentials). This cookie keeps tracks of how often they access the forum per few seconds, if they spam requests the device key gets revoked.

Note: The device key is purely a DDOS protection, you won't be able to login to anything with it. If somebody steals the key, worst case is that they can DDOS the server with it with a few requests, which would invalidate the key and mean the user unfortunately needs to wait out the DDOS attack, but nothing worse than that.

In this way, if an anti with too much time on their hands tries to attack ATF again, you have a pretty cheap way to filter out requests before they even hit Xenforo and it would probably allow forum access for legitimate users even during a DDOS attack. Of course, it's shit for new users they won't be able to use the forum, but currently no one can.

If someone spots a flaw in this mechanism or already knows it won't work the way I think it works I'm all ears lol. I'm not experienced with DDOS, I figured that if you could reject malicious requests with as little calculation as possible you can mitigate them, but it might very well be the case that it's the amount of requests that's the problem, not even the compute spend per request.
i don't think that will work; if you hit it with a booter, the site gets flooded with so many packets that the key becomes useless. You'd have to stop the attack before it reaches the IP address, f95 uses Cloudflare for that...

But I could be mistaken, maybe your method work, however, I think it would be better to switch to a different host.

What is ATF?
google allthefallen
 
Do we even know why it's under attack? Is it a supposed internet white knight or just someone who wants to be a pain?

The guy few months back that threatened the police after stealing the database which caused the first shutdown notice is rumored to be back with DDOS attacks the one last month and this one.

Like i said the host content this world hates with a passion while also doing nothing IRL hell we got targeted censorship now.

You must be registered to see attachments



I assume they got there DIGITAL ID cards and censored the one USA said is underage also yes we are censoring fucking boobs that in many countries its legal for women to be topless.




I'm getting the same and based on these other posts it's a hit or miss situation at the moment .


I would not log into the site until there is a officail post as that database was stolen and who knows the domain could be shutdown next and rehosted by the thief.



Damn, I didn' think it was THAT cheap...

Dox/ddos is also against the law but no one fucking cares about that anymore sense you must dox your self to AI too see medical information.

I wonder if they're working on that, or if Vistarrr just moved on.


That person still has there support pages up and stated there working on it on AUG 1rst as a supporter i have not heard of another shutdown yet.


I saw a note on ATF about looking into alternative protocols. I haven't seen the site go down this long before, though I'm also not super active. Is it typical for it to be down for days at a time?

Back in 2024? it was down for 3 weeks during a winter attack and then you got the last 2 shutdowns from DDOS and that asshole.
 

Attachments

You must be registered for see attachments list
i don't think that will work; if you hit it with a booter, the site gets flooded with so many packets that the key becomes useless. You'd have to stop the attack before it reaches the IP address, f95 uses Cloudflare for that...

But I could be mistaken, maybe your method work, however, I think it would be better to switch to a different host.
Yeah, I've been looking into a bit more, and apparently you multiple avenues of attacks (application layer attacks vs just packet spam).

Against packet spam there doesn't seem to be anything you can do except use cloudflare-esque services as you said, but they wouldn't like to protect ATF. Packet spam is more expensive than application layer attack though, so that's at least something.

We'll see if Vistarr responds.
The guy few months back that threatened the police after stealing the database which caused the first shutdown notice is rumored to be back with DDOS attacks the one last month and this one.
Doesn't sound logical to me tbh.

He threatened to release the database to get restored as a mod, and when Vistarr was like "I'll pull the plug then", he backed off so Vistarr wouldn't pull the plug.

When Vistarr still wanted to pull the plug after he backed off, he said something like "I already deleted the DB but if I didn't I would release it when ATF shuts down" to pressure Vistarr in keeping the site online.

So he's clearly invested in ATF remaining online (probably has a sock puppet), doesn't make too much sense of he tried to take it down with DDOS.
 
Yeah, I've been looking into a bit more, and apparently you multiple avenues of attacks (application layer attacks vs just packet spam).

Against packet spam there doesn't seem to be anything you can do except use cloudflare-esque services as you said, but they wouldn't like to protect ATF. Packet spam is more expensive than application layer attack though, so that's at least something.

We'll see if Vistarr responds.

Doesn't sound logical to me tbh.

He threatened to release the database to get restored as a mod, and when Vistarr was like "I'll pull the plug then", he backed off so Vistarr wouldn't pull the plug.

When Vistarr still wanted to pull the plug after he backed off, he said something like "I already deleted the DB but if I didn't I would release it when ATF shuts down" to pressure Vistarr in keeping the site online.

So he's clearly invested in ATF remaining online (probably has a sock puppet), doesn't make too much sense of he tried to take it down with DDOS.
Vistarr can use alternatives




If Cloudflare isn't an option, there are alternatives, well, it's all in Vistarr's hands; in any case, the site seems to still be offline right now.
 
I been saying for months saving everything you like on that site


Right now its under attack so visstar could walk away i mean who would blame them.
Yeah that’s true, but it still sucks… Feels like the internet’s just getting more and more locked‑down. Places like these forums are getting harder and harder to stay alive......:cry:
 
Games+


If it had Animations/Lewd Sounds would be the greatest game ever.
Hope its ok I linked the thread to it, if not please let me know.
Hell, I didn't recognize them with their clothes on!!! ;)
 
Wouldn't the website be under DDoS attacks too...I don't think it's just about loli content...

My point is that it's also about the fact that ATF, this site, and AC are competitors. Websites like LZ or f95 mirror sites are also being hit by DDoS attacks...

I think some people just don't like the existence of alternative pirate sites, and there's a constant hate war going on.

Whenever I try to share the site on ulfa now, I get this:

You must be registered to see attachments


I believe ULFA started adding this site to their word filter after June 27th. And later on, they moved to banning private messages altogether.

We can see here that sites like F95 and ULFA definitely don't like the fact that sites like this one exist...

I think they are looking for reasons to shut these sites down.
What is ULFA? Google tells me this is United Liberation Front of Assam😁
 
DDoS attacks are not a new tactic for sites like these. Always a few idiots with a grudge trying to take them down.

If not them it's some white knight organization with an agenda. I'm not kidding they have websites that celebrate this shit.

Owners of such sites wont do a damn thing because the law wont help them, but put a target on them instead.
 
ATF - Forum is back online now, no promises for how long or how consistently 💕
 
Back
Top Bottom