\
  The most prestigious law school admissions discussion board in the world.
BackRefresh Options Favorite

I think I know exactly what's happening to the xo server (TSINAH)

Very, very high chance that it's been compromised by chinks ...
Pink box office
  04/25/24
a cpu server isn't worth it to mine crypto probably a mem...
180 chapel legal warrant
  04/25/24
uhhh isn't worth it? if you have a botnet of tens of thousan...
Pink box office
  04/25/24
running a miner 24/7 on a server would skyrocket costs and R...
180 chapel legal warrant
  04/25/24
He's renting a VPS and wtf are you talking about? running a ...
Pink box office
  04/25/24
(it is 2015)
deranged library electric furnace
  04/26/24
Databases are smart enough to index automatically on primary...
Pink box office
  04/25/24
Tell us more about how the database is automatically indexin...
vigorous selfie
  04/26/24
because the db mysql and it autoindexes primary keys
Pink box office
  04/26/24
Looks like rach is using cpanel, and probably an outdated ve...
Pink box office
  04/25/24
...
Pink box office
  04/25/24
How can we get him to fix this. I'm sure we're all willing t...
cowardly bisexual crackhouse
  04/25/24
if the server is rooted, there's next to nothing that can be...
Pink box office
  04/25/24
Huh, I thought it was confirmed that Rach is logging everyon...
Beady-eyed Blathering Office Jap
  04/25/24
180 if true fuck kikes btw gas every single one
Startling Hot Milk Really Tough Guy
  04/25/24
it'd make sense that the spooks are watching this place
Pink box office
  04/25/24
No it doesn't. That doesn't mean it's unlikely, because they...
abusive athletic conference
  04/27/24
...
Soul-stirring Puce Reading Party Kitchen
  04/26/24
pretty sure this theory is more plausible http://www.xoxo...
Exciting windowlicker
  04/25/24
The periods when the board is fine seem too long and unpredi...
bat-shit-crazy magenta codepig site
  04/26/24
It's obviously caused by twitter links
irate roast beef
  04/26/24
lol ur dumb as fuck its very obviously a simple python ddos...
Disturbing Principal's Office Stock Car
  04/26/24
wow, someone shld email rach immediately at jewNOTgiveaFUCK@...
white resort volcanic crater
  04/26/24
you really think rach is sitting there 24/7 monitoring the s...
Pink box office
  04/26/24
There is no indexing and the DB is too big for query jobs to...
vigorous selfie
  04/26/24
...
Soul-stirring Puce Reading Party Kitchen
  04/26/24
That's fake news. Otherwise, the index page would consistent...
Pink box office
  04/26/24
There are increasing reports of shitty companies scraping fo...
Lilac school marketing idea
  04/27/24
that's definitely possible
Pink box office
  04/27/24
YEah any database full of text generated by real people that...
abusive athletic conference
  04/27/24
imagine how 180 an AI trained on XO would be
pussy-eating rapist
  05/01/24


Poast new message in this thread



Reply Favorite

Date: April 25th, 2024 12:16 PM
Author: Pink box office

Very, very high chance that it's been compromised by chinks to mine bitcoin. That would explain the weird behavior of connections seeming like they're timing out. The reality is the web server is just fine, it's just that it's fighting for CPU cycles against some crypto miner, which it will never win.

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47608806)



Reply Favorite

Date: April 25th, 2024 12:27 PM
Author: 180 chapel legal warrant

a cpu server isn't worth it to mine crypto

probably a memory issue with the server or an issue with the db being slow as shit b/c Rach never indexed anything. look how slow search is, which is only limited to thread titles. searching only thread titles should be instantaneous.

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47608813)



Reply Favorite

Date: April 25th, 2024 12:28 PM
Author: Pink box office

uhhh isn't worth it? if you have a botnet of tens of thousands of compromised machines (completely free!) you can make a lot of money.

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47608820)



Reply Favorite

Date: April 25th, 2024 6:41 PM
Author: 180 chapel legal warrant

running a miner 24/7 on a server would skyrocket costs and Rach would notice...otherwise this bort costs a couple of bucks per month

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47609983)



Reply Favorite

Date: April 25th, 2024 10:51 PM
Author: Pink box office

He's renting a VPS and wtf are you talking about? running a miner 24/7 wouldn't skyrocket costs whatsoever. You know how miners work, right? It'll probably be around 1-2MB/hr, which is far less than xo uses. Some of the threads here are literally like 10MB.

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610407)



Reply Favorite

Date: April 26th, 2024 3:13 AM
Author: deranged library electric furnace

(it is 2015)

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610571)



Reply Favorite

Date: April 25th, 2024 12:32 PM
Author: Pink box office

Databases are smart enough to index automatically on primary keys and that kind of thing. There just isn't enough data on xo to completely bog down a dedicated web server, which is probably running at least 4 cores/vcpus and at least 8gb ram. Could the db have ballooned to the point where it no longer fits in ram & the OS resorts to swapping? Sure, but the much more realistic interpretation is that the system is compromised. Cpanel is essentially a rootkit (and a virus) and should never, ever be used.

Also, swapping doesn't explain why the site intermittently works fine for a few minutes at a time. Much more likely conclusion is that some process that's hogging all the cpu is being killed by the OS, but because the process is malicious, it restarts itself automatically. Hell, if it's actually a chink hacker, it's probably just a cronjob that runs every minute.

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47608824)



Reply Favorite

Date: April 26th, 2024 4:10 AM
Author: vigorous selfie

Tell us more about how the database is automatically indexing on a primary key of 5,521,376 for this thread

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610583)



Reply Favorite

Date: April 26th, 2024 2:06 PM
Author: Pink box office

because the db mysql and it autoindexes primary keys

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47611462)



Reply Favorite

Date: April 25th, 2024 12:27 PM
Author: Pink box office

Looks like rach is using cpanel, and probably an outdated version. Just take a look at these CVEs: https://www.cvedetails.com/vulnerability-list/vendor_id-1766/Cpanel.html?page=1&order=3&trc=424&sha=242cb99ceada8a39ecba543bf138dd933b646268

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47608816)



Reply Favorite

Date: April 25th, 2024 3:09 PM
Author: Pink box office



(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47609383)



Reply Favorite

Date: April 25th, 2024 3:40 PM
Author: cowardly bisexual crackhouse

How can we get him to fix this. I'm sure we're all willing to pay whatever it might cost

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47609442)



Reply Favorite

Date: April 25th, 2024 3:43 PM
Author: Pink box office

if the server is rooted, there's next to nothing that can be done besides blocking all IPs except your own via the host's interface & then going to town trying to undo the damage done (plus fix the vulnerabilities)

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47609454)



Reply Favorite

Date: April 25th, 2024 9:33 PM
Author: Beady-eyed Blathering Office Jap

Huh, I thought it was confirmed that Rach is logging everyone's IP addresses and email accounts to comply with recent amendments to the PATRIOT Act. I am pretty sure EPAH represented him in some secret criminal subpoena thing regarding that.

That disclosure seemed to coincide with the site becoming unusable.

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610275)



Reply Favorite

Date: April 25th, 2024 9:38 PM
Author: Startling Hot Milk Really Tough Guy

180 if true

fuck kikes btw gas every single one

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610280)



Reply Favorite

Date: April 25th, 2024 10:58 PM
Author: Pink box office

it'd make sense that the spooks are watching this place

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610413)



Reply Favorite

Date: April 27th, 2024 6:45 PM
Author: abusive athletic conference

No it doesn't. That doesn't mean it's unlikely, because they really are stupid enough to do something like that, but it's really fuckin stupid because what are you going to do with any information you gather?

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47614132)



Reply Favorite

Date: April 26th, 2024 3:17 PM
Author: Soul-stirring Puce Reading Party Kitchen



(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47611621)



Reply Favorite

Date: April 25th, 2024 11:18 PM
Author: Exciting windowlicker

pretty sure this theory is more plausible

http://www.xoxohth.com/thread.php?thread_id=5460539&mc=9&forum_id=2

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610434)



Reply Favorite

Date: April 26th, 2024 12:27 AM
Author: bat-shit-crazy magenta codepig site

The periods when the board is fine seem too long and unpredictable for bitcoin mining. If they had the server under control it's hard to see why they would take their foot off the gas for hours at a time.

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610501)



Reply Favorite

Date: April 26th, 2024 1:30 AM
Author: irate roast beef

It's obviously caused by twitter links

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610534)



Reply Favorite

Date: April 26th, 2024 3:55 AM
Author: Disturbing Principal's Office Stock Car

lol ur dumb as fuck

its very obviously a simple python ddos script that some gook has running on a cron job (idiot closes his laptop or it goes to sleep which is why it stops intermittently)

when you see xo reset thats rach resetting the server

it would be TRIVIAL for rach to ip block this guy and it would only take like a month for him to be blocked enough that alts/vpns are no longer an issue

rach could also add cloudflare which would stop it instantly and im 100% sure poasters would help w the costs myself included

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610578)



Reply Favorite

Date: April 26th, 2024 4:13 AM
Author: white resort volcanic crater

wow, someone shld email rach immediately at jewNOTgiveaFUCK@gmail.com

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610584)



Reply Favorite

Date: April 26th, 2024 2:08 PM
Author: Pink box office

you really think rach is sitting there 24/7 monitoring the server? he's not.

the MUCH more likely response is that there's a nefarious process that's consuming tons of cpu cycles that eventually gets killed and then restarted after a while

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47611468)



Reply Favorite

Date: April 26th, 2024 4:20 AM
Author: vigorous selfie

There is no indexing and the DB is too big for query jobs to finish timely. It runs a query for "last posted in" to populate your main page

Here is the thread from when rach last wiped the boart when this same issue was happening.

https://www.xoxohth.com/thread.php?thread_id=1&mc=43&forum_id=2

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47610588)



Reply Favorite

Date: April 26th, 2024 3:16 PM
Author: Soul-stirring Puce Reading Party Kitchen



(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47611618)



Reply Favorite

Date: April 26th, 2024 5:01 PM
Author: Pink box office

That's fake news. Otherwise, the index page would consistently take a long time to load, but it doesn't. There is indexing being done. Another possibility is that the site bogs down when too many searches are being run, to the point where nothing loads, because of the concurrent db operations on unindexed columns in tables, e.g., text search

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47611824)



Reply Favorite

Date: April 27th, 2024 11:46 AM
Author: Lilac school marketing idea

There are increasing reports of shitty companies scraping forums and accidentally DDOSing them

https://old.reddit.com/r/linux/comments/1ceco4f/claude_ai_name_and_shame/

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47613087)



Reply Favorite

Date: April 27th, 2024 6:36 PM
Author: Pink box office

that's definitely possible

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47614121)



Reply Favorite

Date: April 27th, 2024 6:51 PM
Author: abusive athletic conference

YEah any database full of text generated by real people that isn't paywalled is subject to scraping right now. These AI companies are all datapigs trying to steal free content.

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47614149)



Reply Favorite

Date: May 1st, 2024 3:10 AM
Author: pussy-eating rapist (ELIMINATE TWO THIRDS OF THE SCHOOL DAY)

imagine how 180 an AI trained on XO would be

(http://www.autoadmit.com/thread.php?thread_id=5521376&forum_id=2#47623991)