MyBB Community Forums

Full Version: Spike in users online...seems fishy
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Hello 

The usual number of users in my forum is about 500-700, but for the past 2 days the total users online shows as 5000-7000. But my google analytics shows only the usual number and no spikes. Also most of the users are either 'searching the forum' or 'viewing no permissions page'

Did a little research on the ip addresses.. almost all ips of the questionable users belong to Russia or China.

How can I prevent them from accessing the forum ?
You can set your site up to use Cloudflare, which involves changing your DNS settings to be hosted with them, but it'll route traffic though their servers and protect you from traffic like this (although ideally it also involves moving to a new server so you get a new IP address).
Hi Matt

Thank you very much for your timely response... Looking for cloudflare now
(2021-11-12, 06:00 PM)bijumk1 Wrote: [ -> ]Hi Matt

Thank you very much for your timely response... Looking for cloudflare now

That's a lot of traffic. Are you certain 🤔 it's 5000-7000? I would rebuild your templates. Maybe there's a glitch some where. Clear cache...
It wouldn’t be a template issue unless a specific number had been hard coded. It’s fairly reasonable for several thousand bots to hit a site at once.
If your forum membership does not include those foreign countries, you could consider using AdminCP / Configuration / Banning menu to select Banned IPs. System uses wildcards for address ranges.
(2021-11-14, 12:36 PM)HLFadmin Wrote: [ -> ]If your forum membership does not include those foreign countries, you could consider using AdminCP / Configuration / Banning menu to select Banned IPs. System uses wildcards for address ranges.

Not really an ideal solution for this sort of scale, as handling them at application level means they’ll still be hitting the forum, just getting a banned message instead of the forum index. This level of traffic needs to be handled at server or network level.
Use CF to ban countries, or (if you can) fail2ban.
ALWAYS route your website through Cloudflare's DNS.
It's free and offers so much protection to your website.

Are the users that are being logged bots? or actual registered accounts? Smile