BiggerPockets Founder · HI · Member since 2008 · 16k+ posts · 5k+ votes
Hey BP Family -
This morning BiggerPockets was attacked by what appears to be some kind of network of spammers, including folks from Korea, Hong Kong, Southern California and elsewhere. This may have been a simple spam attack or a DDoS. We're not sure of the intent, but obviously it wasn't positive.
We've been working to ensure something like this can't happen again, but this is the first attack of this kind we've faced in the 10+ years the site has been around, so we're in the middle of working on countermeasures. We've had many DDoS attacks over the years, but none quite like this.
Meanwhile, I want to apologize to those of you who saw this, and I especially want to apologize to those who got email notifications for these posts.
Please bear with us as we deal with this and if you see something, say something. Seriously -- just report any accounts that are spamming and we'll nail them.
This morning BiggerPockets was attacked by what appears to be some kind of network of spammers, including folks from Korea, Hong Kong, Southern California and elsewhere. This may have been a simple spam attack or a DDoS. We're not sure of the intent, but obviously it wasn't positive.
We've been working to ensure something like this can't happen again, but this is the first attack of this kind we've faced in the 10+ years the site has been around, so we're in the middle of working on countermeasures. We've had many DDoS attacks over the years, but none quite like this.
Meanwhile, I want to apologize to those of you who saw this, and I especially want to apologize to those who got email notifications for these posts.
Please bear with us as we deal with this and if you see something, say something. Seriously -- just report any accounts that are spamming and we'll nail them.
Thanks for the patience.
Josh
Hey Josh,
Don't give it a second thought when it comes to the user's here. We're all adults and are completely understanding when it comes to things like this. It happens. :)
That being said, if your server runs Linux, and your attacks followed a pattern, you may want to check out Fail2Ban. It's an awesome program (free and open source), that you can custom tailor to automatically ban people at the firewall level (iptables), if certain criteria is met.
Feel free to pm me if that's the case and you want some more info. Happy to help! Thanks again for an awesome site!
Flipper/Rehabber · Rochester, NY · Member since 2014 · 1k+ posts · 1k+ votes
11y
Look what the team at BP did with this problem! They dealt with it! Kudos!
In any business, including real estate, we will have hurdles commensurate with the size of our business. If you are a newbie, you may be your own hurdle. Find a way to get over. If you are a small fish investor like me, you'll run into bad contractors and bad tenants. I'm in the midst of getting over that hurdle now. If you are bigger you may have trouble getting enough deals, enough money, enough marketing, trouble with employees, etc. And even bigger and you may get sued, you may get scrutinized by government and so on.
You make it to the next level by getting over those hurdles.
Investor · Thermopolis, WY · Member since 2012 · 4k+ posts · 4k+ votes
11y
Good job on handling the attack. Hopefully they were not able to get to billing information like what happened to Target. It is nice to know you have systems in place. I was unable to access the site so I didn't see anything unusual. Thanks for the heads up. We all need to report the spammers when we see them, and any other real strange activity.
BiggerPockets Founder · HI · Member since 2008 · 16k+ posts · 5k+ votes
11y
Don't worry, @Jerry W. - we don't store billing information on BiggerPockets' servers; we use a 3rd party provider called Stripe which I have full faith in.
Investor · Bay Shore, NY · Member since 2014 · 1k+ posts · 688 votes
11y
DDoS attacks are here to stay. This will not be the last, as you know, but, as the network is hardened it will be better prepared to readily fend off future attacks.
You have credible support staff and vendors to help resolve this issue, so we are not worried, it's only annoying.
These hackers/pests will not go away unfortunately and have nothing significant to add to the betterment of mankind other than misery.
Real Estate Broker · Indianapolis, IN · Member since 2014 · 3k+ posts · 2k+ votes
11y
This thread right here is one of the things I love about Josh and Brandon. They are upfront, honest, and open. If this had happened on other forums Admins would pretend nothing happened and sweep it under the rug. Keep up the great work.
No one, I mean no one messes with my mijos Josh and Brandon. The North Koreans will pay for this.
On the bright side, this is like a rite of passage for any major website, consider yourselves "Made Men" because the North Koreans are now targeting you. Here's your members only jacket, you've guys have made it. No more top ramen dinners or Safeway Select Diet Cola, it's caviar and filet mignon from here on out.
BiggerPockets Founder · HI · Member since 2008 · 16k+ posts · 5k+ votes
11y
@Amy Hayek - Sorry to hear about the spam you received, but our site wasn't compromised -- as such, the only way someone might have your email would be if they got it from another source or if you made it available to that person. We take our members' privacy extremely serious and would never give away someone's email.
@Jordan Thibodeau - You made my day as you tend to do! Thanks for the smile!
Investor · Houston, TX · Member since 2015 · 6 posts · 1 vote
11y
it occurs to me, this is the same day our entire office at a specific location received a spam email. That's over 3000 employees and the company is listed among the Fortune 100 Globals,
BiggerPockets Founder · HI · Member since 2008 · 16k+ posts · 5k+ votes
11y
@Daniel Ryu - Unfortunately, since SK was the source, we're playing this thing as carefully as we can. Hopefully we can tone it down at some point. Thanks for the understanding.
@Daniel Ryu - Unfortunately, since SK was the source, we're playing this thing as carefully as we can. Hopefully we can tone it down at some point. Thanks for the understanding.
Sorry to hear it came from SK. if you find out who, let me know and we'll go kick their ***(es) on behalf of all the BP members. ^^
Today .. no Captcha to fill out. If you ever need anything tested from out here, feel free to reach out.