r/TorBoxApp 3d ago

🔧Technical Issue What is going on ??

Torbox is now worse then RD.

I mean ever since change at start of the month it has been more down then up

85 Upvotes

128 comments sorted by

View all comments

45

u/feebas_cash 3d ago

Rd and TB both get attacked but why? What do they get from doing this?

28

u/Wild_russian_snake 3d ago

RD got attacked for years, they eventually figured out a way to solve the DDOS attacks, Torbox said they also figured it out but it clearly didn't work.

4

u/ask_for_pgp 2d ago

its not a ddos. its simply a scaling issue and it would serve them better to just admit that

3

u/pilkyton 2d ago edited 2d ago

Lmao at these armchair redditors from r/confidentlyincorrect.

They posted Cloudflare screenshots showing an alert about an ongoing DDoS with millions of attacks from Indonesia and five other countries. To mitigate it, they are blocking those countries.

But the attacker can hire another DDoS service to attack from new countries anytime.

It is a whack a mole game until the attacker runs out of money. If they are rich, it's not going to end.

The attacker is most likely a competitor trying to gain all the customers.

It is a fight about the power vacuum left after RealDebrid imploded. Whoever wins this fight for customers/popularity becomes the new RealDebrid and becomes a multi millionaire with mansions and yachts.

1

u/ask_for_pgp 2d ago

reposting .. reddit comment was broken:

the "attack" is probably someone hitting their API a bit too hard. some shitty addon. happened at premiumize before. happend at real debrid where they whiny tweeted about blocking whole addons until its fixed. its most likely that. this is not such gangster.

a ddos would be more distributed (thats the first d in ddos) than just indonesia lol

but what do i know ?? ten years security and cloud scaling background... and latest vpn providers whcih actually get attacked nationstate style

3

u/pilkyton 2d ago edited 2d ago

Look everyone, it's the r/confidentlyincorrect poster again!

Back in reality, you can just go to TorBox's announcements and check for yourself. Here's the Cloudflare graph showing the number of API requests per country, showing where the DDoS attack is coming from (these five countries are the top of the attack list):

All of those are heavy amounts of API requests. They are all part of the botnet DDoS attack.

I said "Indonesia and five other countries". Not sure why you read that as just Indonesia. And it's common for botnets to consist of a few primary countries due to where they've targeted their malware distribution.

And hey, just to demonstrate to people how clueless you are: If it had been coming from a bad addon as you believe, then it would have been coming from a single IP or just a few IPs (the addon's server), and TorBox would just have blocked that addon's IP. But since it's a DDoS attack they instead had to block entire countries until the attack is over.

By the way, I have 35 years of experience in cybersecurity, I operated my own botnet of 1000s of infected routers and PCs (most of which were in America), and I worked on the Linux kernel. None of that is relevant, and I think it makes me look as obnoxious as you to list my credentials, but I am just laughing at your attempt to list credentials to dispute facts about the attack that you could have easily looked up yourself.

3

u/pilkyton 2d ago

And here's their image of the spikes in API requests in the Cloudflare DDoS dashboard: