OpenStreetMap logo OpenStreetMap

OpenClipArt suffered DDOS in early May, Still Offline today

Posted by alexkemp on 18 July 2019 in English. Last updated on 19 July 2019.

OpenClipArt Twitter Statement

6:53 am - 3 May 2019 — UPDATE: Our plan is to get the site back online early next week. Under DDOS attack from some unknown forces, the simplest thing to protect our beloved Openclipart is to keep offline at present. Your CLIPART is SAFE.

I was trying to obtain an EPS pair of scissors this evening using File | Import Clip Art… under Inkscape (which is setup to use openclipart.org by default) but got zero result, not even an error message. The OCA index page showed a most peculiar message (“Openclipart is PROTECTED.”) which did not help someone in my position that was unaware of the cause. Then finally DuckDuckGo got me there to twitter.

You will see that these OSM Diaries also suffered constant bot attack starting late April which caused the site admin to take them offline from Search-Engines on 24 May (and again on 23 Jun) as to stop the attacks. It surely cannot be a coincidence that two non-commercial sites run by volunteers both suffered DDOS attacks within a few days of each other, causing both admin to hide their sites from public view as to mitigate the attacks. Of course, the reason for those attacks is still currently unknown.

The nature of these DDOS attacks is also uncertain. OSM used the site-wide robots.txt (see also diary/390115) to stop the bot-flood (OCA does not appear to have a robots.txt). That was physically enacted by two Disallow lines in the text-file:

Disallow: /user/*/diary
Disallow: /diary

If you understand that the Robots exclusion standard is advisory, a little bit of thought will make it obvious that the fact that the bots stopped when the above was placed into robots.txt means that they were spam-bots. However, there were zero links or spam within (most of) their posts. Further, DDOS actions are almost always as to extract large amounts of money from the victims (it is effectively a technological mugging). What is the point in mugging non-commercial sites?

Email icon Bluesky Icon Facebook Icon LinkedIn Icon Mastodon Icon Telegram Icon X Icon

Discussion

Log in to leave a comment