Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WHMCS hanging during Maintenance Activity (-> DDoS Attack) #209

Closed
Remitur opened this issue Sep 1, 2021 · 8 comments
Closed

WHMCS hanging during Maintenance Activity (-> DDoS Attack) #209

Remitur opened this issue Sep 1, 2021 · 8 comments
Assignees
Labels
Backend System Issue with our Backend System / API. improvement Something that we could improve. released

Comments

@Remitur
Copy link

Remitur commented Sep 1, 2021

My own WHMCS install get hanging without any reason (even impossible to login in admin or client area)

Thinking at this communication from Hexonet:
`SERVICE NOTICE: Scheduled Production Maintenance HEXONET [STARTED]

ID: 3398
Type: Scheduled Production Maintenance
Origin: HEXONET
Planned Start Date: 2021-09-01 13:28:00 UTC
Planned End Date: 2021-09-01 20:00:00 UTC
Implications: Restricted Functionality
Affected Environments: Production Environment`
I disabled ISPAPI module by FTP, and my WHMCS woke up again...

@nezzy-the-first
Copy link

nezzy-the-first commented Sep 1, 2021 via email

@KaiSchwarz-cnic
Copy link
Contributor

Hey Remitur & Paul,

thanks for addressing, but no idea how this could get improved. The solution is basically to disable the registrar module in such a case.

We cannot introduce a http request timeout as some api requests may take minutes to complete (3 minutes is our timeout for backend system requests). if our API isn't available, we immediately return with an error message. But as long the api is accepting connections, but is not able to respond as of an ongoing ddos attack, not sure how that could be covered.

Paul is at least right that disabling widgets that are communicating with our api, is worth it to get at least the whmcs admin area accessible.

@Remitur
Copy link
Author

Remitur commented Sep 1, 2021

@Papakai
I just realized you're under DDOS (the message was about some kind of "scheduled maintenance")
I am sympathetic to you (DDOS authors need to die. Slowly and painfully.)

BTW: your collegues in a communication wrote

Since one of the counter measures is to use an additional IP filtering we would like to provide us with your connecting IP address for whitelisting purposes to make API access available again for you.

But not specified HOW to provide the IP...

@KaiSchwarz-cnic
Copy link
Contributor

yes, I guess they noticed that issue already - things that happen in urgency.
mail the ip address(es) to "help at hexonet dot support"

@nezzy-the-first
Copy link

nezzy-the-first commented Sep 1, 2021 via email

@rocketdomains
Copy link

rocketdomains commented Sep 1, 2021 via email

@KaiSchwarz-cnic
Copy link
Contributor

KaiSchwarz-cnic commented Sep 1, 2021

I am curious where ***@***.*** goes to.

Again for clarification (further people checking this thread):

mail your WHMCS System's >>outgoing<< ip address(es) to "help at hexonet dot support"

@centralnicgroup-opensource centralnicgroup-opensource locked and limited conversation to collaborators Sep 1, 2021
@KaiSchwarz-cnic KaiSchwarz-cnic changed the title WHMCS hanging during hexonet maintenance activity WHMCS hanging during hexonet maintenance activity / DDoS Attack Sep 1, 2021
@KaiSchwarz-cnic KaiSchwarz-cnic pinned this issue Sep 1, 2021
@KaiSchwarz-cnic KaiSchwarz-cnic unpinned this issue Sep 3, 2021
@KaiSchwarz-cnic
Copy link
Contributor

KaiSchwarz-cnic commented Oct 12, 2021

fyi, I've been revamping our widgets to be more performant and reliable. Caching data in Session, possibility for deactivation.
Just the domain monitoring widget can't benefit of a caching mechanism otherwise we eventually deal with false positives/wrong data in the analysis part. Suggestion: Use the new icon to keep that widget turned off in general and turn it on once a quarter or so to see if everything is fine and then turn it off again after.

Account Overview Widget
Modules Overview Widget
Domain Monitoring Widget

HTH

@KaiSchwarz-cnic KaiSchwarz-cnic self-assigned this Oct 12, 2021
@KaiSchwarz-cnic KaiSchwarz-cnic added Backend System Issue with our Backend System / API. improvement Something that we could improve. released labels Oct 12, 2021
@KaiSchwarz-cnic KaiSchwarz-cnic changed the title WHMCS hanging during hexonet maintenance activity / DDoS Attack WHMCS hanging during Maintenance Activity (-> DDoS Attack) Oct 12, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Backend System Issue with our Backend System / API. improvement Something that we could improve. released
Projects
None yet
Development

No branches or pull requests

4 participants