Starting 2022-04-27 22:18:22, this site came under hostile traffic from a China Telecom residential broadband line in Jinjiang District, Chengdu, Sichuan, China. Here’s the post-incident breakdown. Please browse this site normally and politely.
Visitor information
- IPv4: 110.185.89.62
- IPv6: 240e:398:94:78b0:c2b4:7dff:fe5c:806c
- Location: Jinjiang District, Chengdu, Sichuan, China
- Line: China Telecom residential broadband
Location estimate
- 143 Beishun Street, Jinjiang District, Chengdu, Sichuan
- 376 Jinshi Road, Jinjiang District, Chengdu, Sichuan
- Huangjinglou West Road, Jinjiang District, Chengdu, Sichuan
- 964 Shuishan Street, Jinjiang District, Chengdu, Sichuan
- Jingyi Road, Jinjiang District, Chengdu, Sichuan
- Jinfeng 3rd Road, Jinjiang District, Chengdu, Sichuan
Timeline
- 2022-04-27 22:15:02 Arrived at my DNS QPS stress test tool via a Baidu search for the keyword “qps testing tool”, browsing on Chrome on Apple macOS.
- 2022-04-27 22:16:38 Switched to Firefox on Apple macOS and visited the homepage.
- 2022-04-27 22:18:22 Started hitting my blog pages continuously with a Python script.
- 2022-04-28 16:44:09 Banned the IPv4 address.
- 2022-04-28 22:26:34 Switched to IPv6 and resumed continuous traffic against my blog pages.
- 2022-04-28 22:28:49 Traffic stopped.
Impact
This hostile traffic ran about 24 hours from a single IP address. It wasn’t a DDoS, so the impact on my site was limited, but it burned through my traffic and bandwidth. Utterly disgraceful behavior that hurt others without benefiting anyone.
- Total requests: 41.2222 million
- Peak bandwidth: 12.24 Mbps
- Peak QPS: 2028
- Traffic consumed: 103 GB
In Closing
This behavior is disgraceful — no technical skill shown, no gain for anyone. Please keep technical exchange civil. Finally: if the hostile traffic continues, I will report it to the cyber police. Residential broadband requires real-name registration these days. Don’t test the law.
