Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Page 1 of 3 123 LastLast
Results 1 to 15 of 32

This is a discussion on DDOS, sigh! in the VPS & Dedicated forum
My site has been down for almost 24 hours, cant even do anything (well, I did 1 thing: install the DOS-Deflate script, doesnt help much ...

  1. #1
    spr
    spr is offline
    Loyal Client
    Join Date
    Jun 2006
    Posts
    71

    DDOS, sigh!

    My site has been down for almost 24 hours, cant even do anything (well, I did 1 thing: install the DOS-Deflate script, doesnt help much tho). This is the biggest and longest DDOS attack on the site so far..... Some people need to get a life.

    (Im not here to complain, I understand Jpc cant do much to help. Just feel bored.)
    Last edited by spr; 10-13-2006 at 06:15 PM.

  2. #2
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Um...

    I assume this is in Atlanta...

    What server are you on, and at what time of day does this take place... or is it a sustained attack?

    I've recently been moved to Atlanta, and I swear... at certain times of day, I could swear a DDOS is taking place, based on apriori knowledge. That is, the server is mad slow, but loads are like .03 or whatever, e.g. it's sitting idle. This is the hallmark of DDOS -- getting tied up with HTTP requests that do nothing but deny service.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  3. #3
    spr
    spr is offline
    Loyal Client
    Join Date
    Jun 2006
    Posts
    71
    Call me a noob but I dont know how JaguarPC name their server, venus and whatsoever *_*. They never told me the name of the server Im on, and erm I didnt really care enough to try to find out.

    Anyway, the Apache server has around 150 - 200 connections since yesterday, and the site just simply...gone. I can even guess who has been doing that, but that doesnt help much, does it? This guy or group of people( or kids?) have been going hacking/attacking quite a lots of sites, and my site suffer at least 2 attacks/month from them (Oct up time: 93.174%). But this is by far the longest down time.

    Actually, they got my admin password (using trojan) a few days ago, I realized that quite fast so nothing so bad happened. Then they got 1 of my forum's supermod pass, they deleted everything, I have JaguarPC restored the database for me. And right after the site goes back up we suffer this attack till now. They seem to really want to bring us down this time.

    BTW, anyone knows if JaguarPC's Managed dedicated server plans have any affordable DDOS monitor service or something like that? (not the 999/month I saw on some sites, just cant afford that)
    Last edited by spr; 10-13-2006 at 01:50 PM.

  4. #4
    Loyal Client
    Join Date
    Sep 2001
    Location
    Wichita, KS
    Posts
    1,647
    Who did you piss off?

  5. #5
    spr
    spr is offline
    Loyal Client
    Join Date
    Jun 2006
    Posts
    71
    I would feel better if I did piss them off, in fact I dont know them in real life, I have never had any conversation on the net or real life with them.

  6. #6
    Loyal Client
    Join Date
    Sep 2001
    Location
    Wichita, KS
    Posts
    1,647
    that sucks, do you know who's doing it by any chance?

  7. #7
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by mattsiegman View Post
    that sucks, do you know who's doing it by any chance?
    Doesn't really matter...

    If it keeps up, 'spr' will get the boot!

    This is SOP at most web hosts!
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  8. #8
    spr
    spr is offline
    Loyal Client
    Join Date
    Jun 2006
    Posts
    71
    Whoever it is, this is really irritating to me (and probably the host too).
    Just a moment ago:
    "The remote system 211.21.9.90 was found to have exceeded acceptable
    login failures on vps.***.***; there was 125 events to the
    service sshd. As such the attacking host has been banned from further
    accessing this system. For the integrity of your host you should investigate
    this event as soon as possible."

    Err, well...Im taking the server down for a while.
    Last edited by spr; 10-14-2006 at 03:27 AM.

  9. #9
    Loyal Client
    Join Date
    Sep 2001
    Location
    Wichita, KS
    Posts
    1,647
    maybe you could just block that IP completely from accessing your server with the firewall?

    I don't exactly know how, but I'm sure it can be done.

  10. #10
    spr
    spr is offline
    Loyal Client
    Join Date
    Jun 2006
    Posts
    71
    I have the firewall and brute-force detector installed, and have received like 10 warnings today. But the guys in the support team said that's okie and normal so I may just leave it that way...

  11. #11
    spr
    spr is offline
    Loyal Client
    Join Date
    Jun 2006
    Posts
    71
    BTW, does anyone know how they attack a site?
    I am assuming they send requests to a specific file on the site such as index.php?

  12. #12
    Ron
    Ron is offline
    Loyal Client
    Join Date
    Aug 2002
    Posts
    7,312
    I wrote this earlier and decided against posting it, but now....

    I not sure we're talking about a DDoS or any kind of DoS attack; that would have tens/hundreds/thousands of millions of attacks.

    Sounds like someone is trying to hack into your root account using, at best, a brute force approach. This happens all the time.

    Is this what you mean? That someone keeps trying to get into your root account?

  13. #13
    spr
    spr is offline
    Loyal Client
    Join Date
    Jun 2006
    Posts
    71
    Both, someone is trying to brute-force the root account + sending a huge amount of requests to the site to kill the server. It cant be normal when you have 500+ guests users on the forum board just continously request the index page.

  14. #14
    Ron
    Ron is offline
    Loyal Client
    Join Date
    Aug 2002
    Posts
    7,312
    That's painful.

    Have you checked your logs to see if you've been slash-dotted or something? See where the referrals are coming from?

    How about changing index.php to index2.php, and setting up a fake index.php file in the forum's root directory, with just a link to index2.php. The fake index.php will also have code in it to check the referrer string and if it (partially) matches your forum's URL will automatically redirect to index2.php.

    When your human visitors to anything that brings them back to the (fake) index.php it will first check the referrer string. If it's a match it will send them there. If not it will give the manual link to index2.php.

    When the bots come-a-callin', they won't be smart enough to click the link (especially if it is someone just using spoofed IPs- they NEVER see the page you present).

    Another approach would be to substitute every occurrence of "index." in phpBB with "index2.", but only when it was referring to the URL, kinda tricky to do that quickly.

    Unfortunately, if there's really someone out to get you and they come back to your site to see what damage they're causing, they'll know to change their attack to index2.php.

    But at least you'll know if someone's after you, of if you've just been slash-dotted or something something else.

    Good luck...

  15. #15
    spr
    spr is offline
    Loyal Client
    Join Date
    Jun 2006
    Posts
    71
    I even changed the folder, and hence dodged the attacks for several hours, then the guy got me again. Im pretty sure that's someone out there is going all out just to kill off the site. Im working on the script that will automatically rename the folde + let the real users know when being attacked.

Page 1 of 3 123 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •