Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
API Calls During DoS Attack
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  19 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Dewald Pretorius  
View profile  
 More options Aug 6 2009, 3:35 pm
From: Dewald Pretorius <dpr...@gmail.com>
Date: Thu, 6 Aug 2009 12:35:46 -0700 (PDT)
Local: Thurs, Aug 6 2009 3:35 pm
Subject: API Calls During DoS Attack
Chad,

I know it's a little late in asking, but should we switch off cron
jobs that make a lot of API calls while this DoS is going on, or while
you are recovering from it?

I don't want my IP addresses to be blocked because they are making a
lot of calls! I've seen in the past that Ops lay down carpet bombing
with cluster munitions when under attack.

Will it help you to recover if we switched off the cron jobs?

Right now most of my connections are just being refused.

Do you guys at least check against the list of white listed IP
addresses before you block an IP address in times like these?

Will there be innocent bystanders caught in the cross-fire again?

This is the kind of info that we developers need...

Dewald


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jonathan  
View profile  
 More options Aug 6 2009, 3:52 pm
From: Jonathan <twitcaps.develo...@gmail.com>
Date: Thu, 6 Aug 2009 12:52:12 -0700 (PDT)
Local: Thurs, Aug 6 2009 3:52 pm
Subject: Re: API Calls During DoS Attack
I would also appreciate an answer to this question. My calls to the
Search API are failing because of circular redirection, and

     curl http://twitter.com

returns nothing at all from my production server, which seems like a
sign that its IP has been blocked.

My app works fine from my dev box.

-jonathan

On Aug 6, 1:35 pm, Dewald Pretorius <dpr...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Account Support  
View profile  
 More options Aug 6 2009, 4:30 pm
From: Account Support <useraccountsandsupp...@gmail.com>
Date: Thu, 6 Aug 2009 13:30:37 -0700 (PDT)
Local: Thurs, Aug 6 2009 4:30 pm
Subject: Re: API Calls During DoS Attack
I turned our crons off, just to be safe.  Plus there isn't much of a
point of running them when the majority of the api calls still aren't
getting through.

On Aug 6, 1:35 pm, Dewald Pretorius <dpr...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alex Payne  
View profile  
 More options Aug 6 2009, 4:40 pm
From: Alex Payne <a...@twitter.com>
Date: Thu, 6 Aug 2009 13:40:07 -0700
Local: Thurs, Aug 6 2009 4:40 pm
Subject: Re: [twitter-dev] Re: API Calls During DoS Attack
We're talking to our operations team about it, who in turn is talking
to our hosting provider. It seems that some aggressive IP filtering
may have been catching some web-based third-party Twitter
applications, as well as data centers used by mobile providers.

--
Alex Payne - Platform Lead, Twitter, Inc.
http://twitter.com/al3x

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mario Menti  
View profile  
 More options Aug 6 2009, 4:56 pm
From: Mario Menti <mme...@gmail.com>
Date: Thu, 6 Aug 2009 21:56:40 +0100
Local: Thurs, Aug 6 2009 4:56 pm
Subject: Re: [twitter-dev] Re: API Calls During DoS Attack

Thanks Alex - just to confirm, no requests from twitterfeed have been
getting though ever since the DOS attack. It does appear to be IP based, as
requests from non-production machines (ironically the non-whitelisted IPs)
get through, but all production IPs appear to be blocked.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
twitscoop  
View profile  
 More options Aug 6 2009, 4:54 pm
From: twitscoop <lollic...@gmail.com>
Date: Thu, 6 Aug 2009 13:54:45 -0700 (PDT)
Local: Thurs, Aug 6 2009 4:54 pm
Subject: Re: API Calls During DoS Attack
Hi Alex,

Same thing happening to twitscoop. Our production IP is being blocked
for all streaming apis, oAuth api etc.

Do we need to send an email to the usual api address or have you
identified the third-parties being affected ?

Please let us know if there is anything we can do to help.

Many thanks in advance.

Regards,

Pierre
co-founder twitscoop.com

On Aug 6, 10:40 pm, Alex Payne <a...@twitter.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Hayes Davis  
View profile  
 More options Aug 6 2009, 5:30 pm
From: Hayes Davis <ha...@appozite.com>
Date: Thu, 6 Aug 2009 16:30:09 -0500
Local: Thurs, Aug 6 2009 5:30 pm
Subject: Re: [twitter-dev] Re: API Calls During DoS Attack

 I'm also seeing this same behavior for my whitelisted production IPs for
CheapTweet.com and TweetReach.com. (Those were whitelisted under the
@CheapTweet and @appozite accounts, respectively.) It works in development,
but no requests are getting through to twitter.com on our production
servers.

I know you all have a lot on your plate right now but let us know what we
can do to get un-blocked.

Hayes
--
Hayes Davis
Founder, Appozite
http://cheaptweet.com
http://tweetreach.com


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
stephane  
View profile  
 More options Aug 6 2009, 5:35 pm
From: stephane <stephane.philipa...@gmail.com>
Date: Thu, 6 Aug 2009 14:35:00 -0700 (PDT)
Subject: Re: API Calls During DoS Attack
Same thing here on google appengine side for www.twazzup.com

Stephane
@sphilipakis
www.twazzup.com

On Aug 6, 2:30 pm, Hayes Davis <ha...@appozite.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Paul Kinlan  
View profile  
 More options Aug 7 2009, 4:46 am
From: Paul Kinlan <paul.kin...@gmail.com>
Date: Fri, 7 Aug 2009 09:46:21 +0100
Local: Fri, Aug 7 2009 4:46 am
Subject: Re: [twitter-dev] Re: API Calls During DoS Attack

I concur with stephane, all request from the app engine fail for twollo too.
Paul

2009/8/6 stephane <stephane.philipa...@gmail.com>


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Dewald Pretorius  
View profile  
 More options Aug 7 2009, 6:42 am
From: Dewald Pretorius <dpr...@gmail.com>
Date: Fri, 7 Aug 2009 03:42:18 -0700 (PDT)
Local: Fri, Aug 7 2009 6:42 am
Subject: Re: API Calls During DoS Attack
They are definitely still actively blocking all volume requests.

I noticed this morning that my website was working. Checked, and my
rate limit was back to 20,000.

So, I switched on one of my cron jobs, and within less than 5 minutes
all requests from my IP were being completely blocked again.

Wonder just how big are these woods that Twitter has to come out of.

Dewald


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Hedley Robertson  
View profile  
 More options Aug 7 2009, 9:48 am
From: Hedley Robertson <hedley.robert...@gmail.com>
Date: Fri, 7 Aug 2009 06:48:17 -0700
Local: Fri, Aug 7 2009 9:48 am
Subject: Re: [twitter-dev] Re: API Calls During DoS Attack

Yes seems like this is some sort of IP based blocking that they introduced,
since one of my production servers started failing yesterday, then the other
server, on a different IP, which was consistantly working, started failing
later in the evening.

Any suggestions on who can I contact directly to get this resolved?  I
filled out the 'whitelisting form' just now, but never had to worry about it
in the past as my application is not abusive with rate limits, and not sure
if this is the best channel anyway, since its more of an incorrect /
misapplied blacklisting issue, it would seem?

Hedley


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Zaudio  
View profile  
 More options Aug 7 2009, 10:47 am
From: Zaudio <si...@z-audio.co.uk>
Date: Fri, 7 Aug 2009 07:47:31 -0700 (PDT)
Local: Fri, Aug 7 2009 10:47 am
Subject: Re: API Calls During DoS Attack
I'm getting the ame problem with bullsonwallstreet.com - previous
whitelisted rates of 20000 now down to 150... not recovered yet.

And I throttle all requests to a pretty low level for the REST API...
but still down at 150!

Let's hope that this attack ends soon, and honest users can have the
performance needed back again soon!

Simon

On Aug 7, 7:48 am, Hedley Robertson <hedley.robert...@gmail.com>
wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Vignesh  
View profile  
 More options Aug 7 2009, 11:45 am
From: Vignesh <vignesh.isqu...@gmail.com>
Date: Fri, 7 Aug 2009 08:45:41 -0700 (PDT)
Local: Fri, Aug 7 2009 11:45 am
Subject: Re: API Calls During DoS Attack
I have a site on app engine twivert.com, api calls are failing and my
requests are less than 2 every hour at this stage

On Aug 7, 7:47 am, Zaudio <si...@z-audio.co.uk> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Jonathan Joyce  
View profile  
 More options Aug 7 2009, 12:15 pm
From: Jonathan Joyce <jonathan.jo...@gmail.com>
Date: Fri, 7 Aug 2009 17:15:46 +0100
Local: Fri, Aug 7 2009 12:15 pm
Subject: Re: [twitter-dev] Re: API Calls During DoS Attack

We have seen the rates for our app go from 20,000 to 150 and back to 20,000
over a short interval. It is causing complete havoc to our traffic as 150
requests are used up in a matter of minutes and we have no notice about the
change happening.

This is not affecting an optional cron job, this is for normal usage to make
requests on behalf of our users. If we are limited then the user feels it
immediately.

Can you ring fence those white-listed addresses that you recognise as
totally legitimate - even if it requires an intensive manual exercise - and
then just stabilise things for these sites? Is that being attempted at all?
The IP addresses of every app for users of this thread would be a great
start!

The IP address I am most concerned about is for Twibbon.com: 174.129.249.253

I appreciate these are difficult times.

Anything you can do would be much appreciated.

Jonathan

Founder - Twibbon.com


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
vp  
View profile  
 More options Aug 7 2009, 6:20 am
From: vp <vivpu...@gmail.com>
Date: Fri, 7 Aug 2009 03:20:53 -0700 (PDT)
Local: Fri, Aug 7 2009 6:20 am
Subject: Re: API Calls During DoS Attack
All API calls from LinksAlpha.com are also failing. Please let us know
if there is a way to get IP address whitelisted.

Thanks


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
AdamHertz  
View profile  
 More options Aug 7 2009, 11:54 am
From: AdamHertz <adamdhe...@gmail.com>
Date: Fri, 7 Aug 2009 08:54:14 -0700 (PDT)
Local: Fri, Aug 7 2009 11:54 am
Subject: Re: API Calls During DoS Attack
Our site (tunein.com) is getting 408s from the OAuth API; also, our
daemons that do friend timeline calls have been getting empty results
since 11 PM last night.

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
kabayan  
View profile  
 More options Aug 7 2009, 12:53 pm
From: kabayan <tkab...@gmail.com>
Date: Fri, 7 Aug 2009 09:53:23 -0700 (PDT)
Local: Fri, Aug 7 2009 12:53 pm
Subject: Re: API Calls During DoS Attack
Failed IP 206.225.19.45
Japan
Docomo

On 8月8日, 午前1:15, Jonathan Joyce <jonathan.jo...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Josh Roesslein  
View profile  
 More options Aug 7 2009, 5:18 pm
From: Josh Roesslein <jroessl...@gmail.com>
Date: Fri, 7 Aug 2009 16:18:01 -0500
Local: Fri, Aug 7 2009 5:18 pm
Subject: Re: [twitter-dev] Re: API Calls During DoS Attack

I've noticed that friends_timeline when supplied a count parameter will
return nothing.
Other parameters seem to work okay.

On Fri, Aug 7, 2009 at 10:54 AM, AdamHertz <adamdhe...@gmail.com> wrote:

> Our site (tunein.com) is getting 408s from the OAuth API; also, our
> daemons that do friend timeline calls have been getting empty results
> since 11 PM last night.

--
Josh

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
kabayan  
View profile  
 More options Aug 8 2009, 11:30 am
From: kabayan <tkab...@gmail.com>
Date: Sat, 8 Aug 2009 08:30:24 -0700 (PDT)
Local: Sat, Aug 8 2009 11:30 am
Subject: Re: API Calls During DoS Attack
Now I tested again, works well via docomo.

On 8月8日, 午前1:53, kabayan <tkab...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »