Openstreetmap.org DDoS attack 11 July 2024

There is little point in reporting errors. Apparently the admins are now aware of the problem and are trying to transfer osm.org under the wing of CloudFlare. It’s not easy to do this right away.

Follow Uplink Traffic: Grafana

And Requests by Authentication Method Grafana

When they return to normal, you can report problems

4 Likes

The disruption is not related to the maintenance from yesterday in any way. The maintenance was successfully completed.

We are under a large traffic flood DDOS attack. Ops team working as best we can to mitigate it, but it is a large tsunami.

20 Likes

Personal note: I’ve moved all posts related to the DDoS attacks to this topic. The original maintenance topic is here: Openstreetmap.org database is read-only ... maintenance work is carried out

Also at this point: Many thanks for all those who work for the operation of OSM!

14 Likes

A big Thank You to the Ops team for their hard work!

20 Likes

@mcliquid could we remove the ad for slack if possible?

9 Likes

Ow, that’s why it showed me the Cloudflare verification page and the iD delayed to show the data (just now). Thanks for the heads up. I guess the yesterday’s maintenance annoyed the vandalists.

You probably just didn’t hit the timeout yet (which is fairly long), it is the nature of such things (load/bandwidth induced errors) that you will get different responses based on what just happened to fail for your specific API request.

3 Likes

Where is this announced? I mean, it should be announced i think. I checked the mastodon (OpenStreetMap (@openstreetmap@en.osm.town) - OSM Town | Mapstodon for OpenStreetMap) and Twitter/X (x.com) and the blog (https://blog.openstreetmap.org/) in the forum this is the only thread where a hint can be found.

Slack US is not a proper channel for anything to be announced in the first stage.

2 Likes

Perhaps you could have a chat with the scrote responsible for the DDOS attack and get them to announce their future plans somewhere? :slight_smile:

11 Likes

I think it is more the long standing problem that the maintenance/issue alerts on social media from OSM ops are individually manually posted, so are literally the first thing to be a victim of a work/stress overload situation than any intent to favour a specific platform.

14 Likes

Do you have any information about who is attacking us or is it irrelevant?

A cute cheeky response like that does not help a discussion at all. Its quite possible to announce something while its happening or after something has happend (to explain what happened).

I know, a situation like this is stressfull for all people involved, thats why there should be some kind of plan, what and where something should happen.
My post should probably have been worded differently so it does not sound that accusing - i’m really sorry for that. It was not meant to accuse anyone of anything.

Thanks for your answer SimonPoole. Its simply - OSM.org is down and i’m sure quite a lot of people would like to know what is happening :slight_smile:

4 Likes

@TrickyFoxy Thanks for your update in your post!

2 Likes

funny. there’s someone on the international telegram group claiming they can “end this right now” having written an email to the foundation using jamsboh@gmail.com

4 Likes

As you mentioned Mastodon, just to note for anyone who missed it in the earlier post by @whb, there is a thread started by the Ops Team account (not the main OpenStreetMap account). The earlier server maintenance was also announced on that account.

@osm_tech@en.osm.town

3 Likes

This is unbelievable. I don’t know why cyberattackers would target OpenStreetMap.

5 Likes

Regular criminal extortion. They claim to stop DDoS when they will be paid ransom.

Policy of OSMF is to not pay such ransom.

20 Likes

US$5000 in BTC of extortion to be exact.

22 Likes

Unfortunately, it’s extremely easy and cheap to launch DDoS attacks these days. Any website with at least a bit of notoriety will be hit eventually.

6 Likes