# ⚠ DDoS Attack Makes Blender.org Servers Unreachable

**URL:** <https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687>\
**Category:** Latest News\
**Created:** [November 20, 2023, 12:14pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687 "2023-11-20T12:14:49Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![bartv](https://blenderartists.org/user_avatar/blenderartists.org/bartv/32/1477233_2.png) [@bartv](https://blenderartists.org/u/bartv)\
**Post date:** [November 20, 2023, 12:14pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/1 "2023-11-20T12:14:49Z")

</div>

![blender-broken](https://blenderartists.org/uploads/default/original/4X/a/8/0/a80b0f49fa1befd82b96542b60ead4f0506d65ec.jpeg)

The [Blender.org](http://Blender.org) infrastructure is currently under a Denial of Service attack. As a result, all official Blender sites are currently down. The team is aware and is working on a solution.

Be careful when downloading from alternative locations, [the Blender Foundation provided](https://mastodon.social/@Blender/111442195348581546) the following list of official mirrors:

- 🇪🇺 [https://ftp.nluug.nl/pub/graphics/blender/release/](https://ftp.nluug.nl/pub/graphics/blender/release/)
- 🇺🇸 [https://mirrors.ocf.berkeley.edu/blender/release/](https://mirrors.ocf.berkeley.edu/blender/release/)
- 🇨🇳 [https://mirrors.aliyun.com/blender/release/](https://mirrors.aliyun.com/blender/release/)
- Steam: [https://store.steampowered.com/app/365670/Blender/](https://store.steampowered.com/app/365670/Blender/)
- Microsoft Store: [https://microsoft.com/store/apps/9PP3C07GTVRH](https://microsoft.com/store/apps/9PP3C07GTVRH)
- Source code: [https://github.com/blender](https://github.com/blender)

## Update Nov 22:

- Most, but not all [Blender.org](http://Blender.org) sites are back
- To access the main site, use [www.blender.org](http://www.blender.org), not [blender.org](http://blender.org) for now.

---

<div class="post-metadata">

**Author:** ![bartv](https://blenderartists.org/user_avatar/blenderartists.org/bartv/32/1477233_2.png) [@bartv](https://blenderartists.org/u/bartv)\
**Post date:** [November 20, 2023, 12:15pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/2 "2023-11-20T12:15:02Z")

</div>



---

<div class="post-metadata">

**Author:** ![bartv](https://blenderartists.org/user_avatar/blenderartists.org/bartv/32/1477233_2.png) [@bartv](https://blenderartists.org/u/bartv)\
**Post date:** [November 20, 2023, 3:39pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/3 "2023-11-20T15:39:12Z")

</div>

I talked to Ton and apparently this is the largest and longest DDoS attack they experienced so far. Like every large site, this just happens now and then (it’s almost a sign you made it into the big league 😉 ).

Two people are working on this problem, but it’s a whackamole game - simply blocking IP addresses won’t solve this issue as new ones keep popping up.

---

<div class="post-metadata">

**Author:** ![jeremypajot.art](https://blenderartists.org/user_avatar/blenderartists.org/jeremypajot.art/32/1042054_2.png) [@jeremypajot.art](https://blenderartists.org/u/jeremypajot.art)\
**Post date:** [November 20, 2023, 3:52pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/4 "2023-11-20T15:52:22Z")

</div>

I thought my internet was broken

---

<div class="post-metadata">

**Author:** ![Unluccy](https://blenderartists.org/letter_avatar_proxy/v4/letter/u/71c47a/32.png) [@Unluccy](https://blenderartists.org/u/Unluccy)\
**Post date:** [November 20, 2023, 4:11pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/5 "2023-11-20T16:11:10Z")

</div>

I do understand the “big leagues” idea but what I don’t really get is what benefit anyone has from this. Blender is free and you can download it elsewhere.

I would have thought a DDoS attack has some criminal purpose, like blackmailing or getting rid of competition during Black Friday sales. Is this just for the lolz? Someone with a grudge? It’s puzzling to me.

---

<div class="post-metadata">

**Author:** ![bartv](https://blenderartists.org/user_avatar/blenderartists.org/bartv/32/1477233_2.png) [@bartv](https://blenderartists.org/u/bartv)\
**Post date:** [November 20, 2023, 4:13pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/6 "2023-11-20T16:13:42Z")

</div>

What I was referring to is that big sites just become more visible/interesting targets for such attacks.

---

<div class="post-metadata">

**Author:** ![rawalanche](https://blenderartists.org/user_avatar/blenderartists.org/rawalanche/32/538671_2.png) [@rawalanche](https://blenderartists.org/u/rawalanche)\
**Post date:** [November 20, 2023, 4:14pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/7 "2023-11-20T16:14:47Z")

</div>

I struggle to understand what anyone would have to gain from DDOSing Blender.

It’s not anything politics/ideology related so the motivation can’t be suppression of information.

People being unable to download Blender for a day or so won’t really cause any disruption/damage either. Especially since it’s not a release day anymore. The only reason would be competition in 3D software space, but it’s very hard to imagine Blender’s commercial competitors would take a risk initiating something like this. A simple DDOS attack won’t take Blender out of the game, it will just be a nuisance for a day or two. It would not be worth the risk.

Only reason that remains is someone does it for fun, but using such a massive infrastructure just for fun would probably not be worth it.

Really, I am trying to figure out what the incentive to DDOS Blender could be.

---

<div class="post-metadata">

**Author:** ![bartv](https://blenderartists.org/user_avatar/blenderartists.org/bartv/32/1477233_2.png) [@bartv](https://blenderartists.org/u/bartv)\
**Post date:** [November 20, 2023, 4:16pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/8 "2023-11-20T16:16:56Z")

</div>

My bet is script kiddies. DDoS attacks are cheap - you can just order them online and have them run for several days. No technical knowledge is required - just being a bored teenager is enough.

---

<div class="post-metadata">

**Author:** ![tomjejojose](https://blenderartists.org/user_avatar/blenderartists.org/tomjejojose/32/1296648_2.png) [@tomjejojose](https://blenderartists.org/u/tomjejojose)\
**Post date:** [November 20, 2023, 4:57pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/9 "2023-11-20T16:57:25Z")

</div>

> [@bartv](#):
>
> DDoS

Blender 4.0 installation was initially blocked by Windows smartscreen, does that have anything to do with this?

---

<div class="post-metadata">

**Author:** ![rawalanche](https://blenderartists.org/user_avatar/blenderartists.org/rawalanche/32/538671_2.png) [@rawalanche](https://blenderartists.org/u/rawalanche)\
**Post date:** [November 20, 2023, 4:58pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/10 "2023-11-20T16:58:53Z")

</div>

Most likely not: [https://projects.blender.org/blender/blender/issues/114832](https://projects.blender.org/blender/blender/issues/114832)

But still they should be more careful about the signatures I think.

---

<div class="post-metadata">

**Author:** ![BlenderMaster15](https://blenderartists.org/user_avatar/blenderartists.org/blendermaster15/32/1119134_2.png) [@BlenderMaster15](https://blenderartists.org/u/BlenderMaster15)\
**Post date:** [November 20, 2023, 5:50pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/11 "2023-11-20T17:50:42Z")

</div>

Thanks for the update! I was wondering what was wrong…

---

<div class="post-metadata">

**Author:** ![ogonek](https://blenderartists.org/user_avatar/blenderartists.org/ogonek/32/519370_2.png) [@ogonek](https://blenderartists.org/u/ogonek)\
**Post date:** [November 20, 2023, 6:15pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/12 "2023-11-20T18:15:42Z")

</div>

seems to work again

---

<div class="post-metadata">

**Author:** ![FLEB](https://blenderartists.org/user_avatar/blenderartists.org/fleb/32/770151_2.png) [@FLEB](https://blenderartists.org/u/FLEB)\
**Post date:** [November 20, 2023, 6:31pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/13 "2023-11-20T18:31:08Z")

</div>

My off-the-cuff guesses would be ransom or maybe a way to funnel people to the malware-ridden AdWords-advertised versions. (Though, that second one is a bit too involved for Occam’s Razor, so I’d wager against it.)

---

<div class="post-metadata">

**Author:** ![TerraSkilll](https://blenderartists.org/user_avatar/blenderartists.org/terraskilll/32/920716_2.png) [@TerraSkilll](https://blenderartists.org/u/TerraSkilll)\
**Post date:** [November 20, 2023, 6:44pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/14 "2023-11-20T18:44:05Z")

</div>

With the 4.0 release, traffic might have increased significantly, enough to get some scammers attentions, because blender dot org has a ton of traffic and a lot of downloads. It makes for a more interesting target, especially if they can redirect people to scam links, or infect the binaries and downloads with with malware.

I seem to recall a similar scenario, tough I can’t remember if it was blender or another big software release.

---

<div class="post-metadata">

**Author:** ![Kologe](https://blenderartists.org/user_avatar/blenderartists.org/kologe/32/1395643_2.png) [@Kologe](https://blenderartists.org/u/Kologe)\
**Post date:** [November 20, 2023, 10:03pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/15 "2023-11-20T22:03:27Z")

</div>

> [@rawalanche](#):
>
> Really, I am trying to figure out what the incentive to DDOS Blender could be.

Could also be someone’s testrun of their bot-network.

---

<div class="post-metadata">

**Author:** ![SterlingRoth](https://blenderartists.org/user_avatar/blenderartists.org/sterlingroth/32/3107_2.png) [@SterlingRoth](https://blenderartists.org/u/SterlingRoth)\
**Post date:** [November 20, 2023, 10:41pm UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/16 "2023-11-20T22:41:07Z")

</div>

it’s not currently working for me…

---

<div class="post-metadata">

**Author:** ![jonofdevon](https://blenderartists.org/letter_avatar_proxy/v4/letter/j/7ea924/32.png) [@jonofdevon](https://blenderartists.org/u/jonofdevon)\
**Post date:** [November 21, 2023, 8:38am UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/17 "2023-11-21T08:38:58Z")

</div>

I think there tend to be three main reasons for a DDOS attack:

1. For a random, directly from the target of the attack - unlikely in this case, since there’s been no public announcement of such a demand, and I’m not sure the Blender Foundation would make a particularly lucrative target;

2. Scam redirects - malware-infected versions of Blender that feed information back to the hackers, which they can then either sell on, or use for their own ends. While there are undoubtedly some of these around, I’m not sure that they would be downloaded enough for the DDOS to prove a lucrative proposition - Blender is free, so we don’t need a cracked version from a nefarious site, and most users know to get their copy from an approved mirror site;

3. For the “lulz” - I think, sadly, this is the most.likely option. Bored people with too much time and too few scruples, who either decide to build their own script, or buy one off the shelf, and run it for fun or bragging rights.

---

<div class="post-metadata">

**Author:** ![jonofdevon](https://blenderartists.org/letter_avatar_proxy/v4/letter/j/7ea924/32.png) [@jonofdevon](https://blenderartists.org/u/jonofdevon)\
**Post date:** [November 21, 2023, 8:43am UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/18 "2023-11-21T08:43:58Z")

</div>

There is a fourth option as well, now that I think on it - a political attack. But I cannot for the life of me think of anything politically sensitive or controversial that the Blender Foundation might be linked with, so this seems even less likely to me than the random demand.

---

<div class="post-metadata">

**Author:** ![thetony20](https://blenderartists.org/user_avatar/blenderartists.org/thetony20/32/1121876_2.png) [@thetony20](https://blenderartists.org/u/thetony20)\
**Post date:** [November 21, 2023, 9:29am UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/19 "2023-11-21T09:29:45Z")

</div>

> [@jonofdevon](#):
>
> Scam redirects - malware-infected versions of Blender

I’m not so sure that’s as far fetched as one may think. A major release has just happened, chances are plenty went/tried to download/update over the weekend (a more common time to do it for the very likely large number of home/personal uses of Blender, as their weekday job keeps them from finding time till the weekend to do so).

As bart said, DDoS attacks are cheap, and ppl tend to ‘trust’ Blender more then most other stuff, so even if it does throw up a warning during install (which on Windows it can/does at times), many just go ahead and install anyway.

So even if out of a million downloads, you only get 100 that install the malware version you want and only a hand full use internet banking, etc that the key logger picks up and reports back. You still have a good chance of being able to empty a couple of bank accounts and walk away with 1000’s or even 10,000’s of dollars.

---

<div class="post-metadata">

**Author:** ![nickberckley](https://blenderartists.org/user_avatar/blenderartists.org/nickberckley/32/967154_2.png) [@nickberckley](https://blenderartists.org/u/nickberckley)\
**Post date:** [November 21, 2023, 9:56am UTC](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687/20 "2023-11-21T09:56:59Z")

</div>

Is there gonna be punishment for that? Is that possible?

[Next page](https://blenderartists.org/t/ddos-attack-makes-blender-org-servers-unreachable/1493687.md?page=2)
