Those spammers created like 600 accounts with 600 different IP addresses, and were spamming using only 10 of those, and I still see them as logged on, so they are spamming the website with requests as we speak (and probably taking tons of bandwidth)
I simply locked everybody after the spam began, so if you had a legit account and can't post, feel free to let me know so I can unlock your account.
That is a legit spam attack, never seen something like that. This will force me to either open the code to add a "delay" between posts, a captcha when registering and most useful more tools for moderator.. or I might just give up and take something that already exists and use the suggestion of making current forums read only for reference only.
Except I'm not sure an out of the box system would easily make me do database requests like I had to do for this to fix it easy, but oh well.
Needless to say I didn't sleep much last night.