Another massive distributed HTTP flood is currently hitting git.friendi.ca and causing slow responses. Operationally, this has to be treated as an application-layer DDoS attack, although we cannot determine from the logs whether disruption or aggressive scraping is the original intent.

In a fresh five-minute sample, Anubis saw 56,457 requests carrying client IPs from 50,470 different addresses:


  • 48,519 requests via IPv4
  • 7,938 requests via IPv6
  • 43,621 unique IPv4 addresses
  • 7,407 unique IPv6 addresses


We compared all addresses against the Tor Project’s official, target-specific exit list for our server on port 443. There were zero Tor exit nodes in the sample.

The traffic is spread across many networks and regions and appears more consistent with a large residential-proxy or compromised-device network than with Tor. We are investigating additional capacity protection that does not lock out legitimate users.