ok something is hitting my server hard dont know what it is how can i find out how can i findout if im under a ddos attack or any other attack? thanks
SSH to your server and su to root. Type this: netstat -an It will show list of active connections to your server. Also, try this as well: netstat -nlp It will show the same thing with more info.
haent tried that yet will now but i think its releated to the db the site will load without the correct db info inthe config.php file but when its all correct the server just goes dead wuld sql injection do this?
when i run netstat -n|p i get the folowing Active UNIX domain sockets (only servers) Proto RefCnt Flags Type State I-Node PID/Program name Path unix 2 [ ACC ] STREAM LISTENING 5435 2723/spamd_full.soc /tmp/spamd_full.sock unix 2 [ ACC ] STREAM LISTENING 4952 2430/lpd /dev/printer unix 2 [ ACC ] STREAM LISTENING 5004 2486/mysqld /var/run/mysqld/mysqld.sock unix 2 [ ACC ] STREAM LISTENING 5185 2585/postmaster /var/run/postgresql/.s.PGSQL.5432 unix 2 [ ACC ] STREAM LISTENING 5683 2802/drwebd /var/drweb/run/.daemon and when i run netstat -n i get tghis tcp6 481 0 ::ffff:85.17.170.205:80 ::ffff:81.241.47.2:2120 ESTABLISHED tcp6 1 0 ::ffff:85.17.170.205:80 ::ffff:82.32.111.5:1302 CLOSE_WAIT tcp6 481 0 ::ffff:85.17.170.205:80 ::ffff:81.241.47.2:2122 ESTABLISHED tcp6 508 0 ::ffff:85.17.170.205:80 ::ffff:208.111.220:4268 CLOSE_WAIT tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:42851 CLOSE_WAIT tcp6 425 0 ::ffff:85.17.170.205:80 ::ffff:82.32.111.5:1304 CLOSE_WAIT tcp6 425 0 ::ffff:85.17.170.205:80 ::ffff:82.32.111.5:1308 CLOSE_WAIT tcp6 0 13888 ::ffff:85.17.170.205:22 ::ffff:81.96.122.1:4161 ESTABLISHED tcp6 0 1253 ::ffff:85.17.170.205:80 ::ffff:85.210.47.5:3731 LAST_ACK tcp6 457 0 ::ffff:85.17.170.205:80 ::ffff:62.31.78.1:60042 ESTABLISHED tcp6 409 0 ::ffff:85.17.170.205:80 ::ffff:24.252.253:14272 CLOSE_WAIT tcp6 409 0 ::ffff:85.17.170.205:80 ::ffff:24.252.253:14278 CLOSE_WAIT tcp6 414 0 ::ffff:85.17.170.205:80 ::ffff:88.90.75.2:26778 CLOSE_WAIT tcp6 450 0 ::ffff:85.17.170.205:80 ::ffff:195.93.102:39771 CLOSE_WAIT tcp6 380 0 ::ffff:85.17.170.205:80 ::ffff:74.101.103.:3092 ESTABLISHED tcp6 500 0 ::ffff:85.17.170.205:80 ::ffff:86.147.204:60441 CLOSE_WAIT tcp6 440 0 ::ffff:85.17.170.205:80 ::ffff:67.91.243.:25472 ESTABLISHED tcp6 313 0 ::ffff:85.17.170.205:80 ::ffff:82.131.223.:1733 ESTABLISHED tcp6 313 0 ::ffff:85.17.170.205:80 ::ffff:82.131.223.:1740 ESTABLISHED tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:80.43.2.22:63997 ESTABLISHED tcp6 665 0 ::ffff:85.17.170.205:80 ::ffff:63.88.109.1:9160 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:42807 ESTABLISHED tcp6 0 1710 ::ffff:85.17.170.205:80 ::ffff:67.55.16.24:2801 LAST_ACK tcp6 665 0 ::ffff:85.17.170.205:80 ::ffff:63.88.109.1:9173 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:217.41.217:56009 CLOSE_WAIT tcp6 413 0 ::ffff:85.17.170.205:80 ::ffff:99.244.148.:1540 CLOSE_WAIT tcp6 0 1260 ::ffff:85.17.170.205:80 ::ffff:195.150.22:61980 LAST_ACK tcp6 527 0 ::ffff:85.17.170.205:80 ::ffff:62.30.203.1:2202 CLOSE_WAIT tcp6 441 0 ::ffff:85.17.170.205:80 ::ffff:80.229.156.:2737 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:85.145.4.1:32827 CLOSE_WAIT tcp6 665 0 ::ffff:85.17.170.205:80 ::ffff:63.88.109.1:9195 CLOSE_WAIT tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:43025 CLOSE_WAIT tcp6 464 0 ::ffff:85.17.170.205:80 ::ffff:87.78.54.21:4458 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:43023 CLOSE_WAIT tcp6 331 0 ::ffff:85.17.170.205:80 ::ffff:84.65.19.2:49799 CLOSE_WAIT tcp6 643 0 ::ffff:85.17.170.205:80 ::ffff:83.70.171.:13560 ESTABLISHED tcp6 0 1258 ::ffff:85.17.170.205:80 ::ffff:85.200.51.1:3711 LAST_ACK tcp6 471 0 ::ffff:85.17.170.205:80 ::ffff:24.175.122.:2633 CLOSE_WAIT tcp6 459 0 ::ffff:85.17.170.205:80 ::ffff:24.175.122.:2635 CLOSE_WAIT tcp6 453 0 ::ffff:85.17.170.205:80 ::ffff:24.175.122.:2637 CLOSE_WAIT tcp6 450 0 ::ffff:85.17.170.205:80 ::ffff:195.93.102:55317 CLOSE_WAIT tcp6 344 0 ::ffff:85.17.170.205:80 ::ffff:89.241.35.:49647 ESTABLISHED tcp6 497 0 ::ffff:85.17.170.205:80 ::ffff:158.143.165:4213 CLOSE_WAIT tcp6 506 0 ::ffff:85.17.170.205:80 ::ffff:67.162.168:61358 CLOSE_WAIT tcp6 506 0 ::ffff:85.17.170.205:80 ::ffff:67.162.168:61357 CLOSE_WAIT tcp6 256 0 ::ffff:85.17.170.205:80 ::ffff:81.152.15.6:2850 ESTABLISHED tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56969 CLOSE_WAIT tcp6 586 0 ::ffff:85.17.170.205:80 ::ffff:195.93.21.:41264 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:99.243.218.:1789 CLOSE_WAIT tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56972 CLOSE_WAIT tcp6 429 0 ::ffff:85.17.170.205:80 ::ffff:87.232.1.4:38946 ESTABLISHED tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56975 CLOSE_WAIT tcp6 353 0 ::ffff:85.17.170.205:80 ::ffff:66.249.70.:51956 CLOSE_WAIT tcp6 508 0 ::ffff:85.17.170.205:80 ::ffff:81.173.238:13031 ESTABLISHED tcp6 519 0 ::ffff:85.17.170.205:80 ::ffff:86.76.109.1:1626 ESTABLISHED tcp6 390 0 ::ffff:85.17.170.205:80 ::ffff:216.220.21:26235 CLOSE_WAIT tcp6 465 0 ::ffff:85.17.170.205:80 ::ffff:84.74.66.2:61941 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56983 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56984 ESTABLISHED tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56985 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56986 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56987 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56988 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56989 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56990 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:90.193.90.:53346 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56993 CLOSE_WAIT tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56994 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:42969 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56995 CLOSE_WAIT tcp6 71 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56996 CLOSE_WAIT tcp6 493 0 ::ffff:85.17.170.205:80 ::ffff:82.29.145.6:1311 ESTABLISHED tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56997 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56998 CLOSE_WAIT tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:56999 CLOSE_WAIT tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:57000 CLOSE_WAIT tcp6 439 0 ::ffff:85.17.170.205:80 ::ffff:204.126.24:47190 CLOSE_WAIT tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:57001 CLOSE_WAIT tcp6 419 0 ::ffff:85.17.170.205:80 ::ffff:62.30.74.70:4301 CLOSE_WAIT tcp6 71 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:57002 CLOSE_WAIT tcp6 65 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:57005 ESTABLISHED tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:32944 ESTABLISHED tcp6 0 1 ::ffff:85.17.170.205:80 ::ffff:86.154.98.1:4493 LAST_ACK tcp6 65 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:32947 ESTABLISHED tcp6 645 0 ::ffff:85.17.170.205:80 ::ffff:71.220.89.:55100 ESTABLISHED tcp6 493 0 ::ffff:85.17.170.205:80 ::ffff:86.12.217.7:1361 ESTABLISHED tcp6 65 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:32953 ESTABLISHED tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:43207 CLOSE_WAIT tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:85.17.170.:32958 ESTABLISHED tcp6 339 0 ::ffff:85.17.170.205:80 ::ffff:81.151.225:50857 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:81.109.239.:3090 CLOSE_WAIT tcp6 339 0 ::ffff:85.17.170.205:80 ::ffff:81.151.225:50859 CLOSE_WAIT tcp6 339 0 ::ffff:85.17.170.205:80 ::ffff:81.151.225:50858 CLOSE_WAIT tcp6 497 0 ::ffff:85.17.170.205:80 ::ffff:81.101.29.1:2896 CLOSE_WAIT tcp6 339 0 ::ffff:85.17.170.205:80 ::ffff:81.151.225:50860 CLOSE_WAIT tcp6 413 0 ::ffff:85.17.170.205:80 ::ffff:61.18.41.16:1432 CLOSE_WAIT tcp6 339 0 ::ffff:85.17.170.205:80 ::ffff:74.70.156.:50081 CLOSE_WAIT tcp6 1 0 ::ffff:85.17.170.205:80 ::ffff:86.3.129.2:63451 CLOSE_WAIT tcp6 1 0 ::ffff:85.17.170.205:80 ::ffff:82.11.32.20:2652 CLOSE_WAIT tcp6 506 0 ::ffff:85.17.170.205:80 ::ffff:61.18.41.16:1428 CLOSE_WAIT tcp6 66 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:42929 CLOSE_WAIT tcp6 344 0 ::ffff:85.17.170.205:80 ::ffff:86.3.129.2:63452 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:138.162.0.:10286 CLOSE_WAIT tcp6 71 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:43177 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:42920 CLOSE_WAIT tcp6 327 0 ::ffff:85.17.170.205:80 ::ffff:86.140.12.:50494 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:195.93.60.:50830 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:85.2.35.21:26459 CLOSE_WAIT tcp6 133 0 ::ffff:85.17.170.205:80 ::ffff:99.243.187.:2293 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:87.194.188.:2262 ESTABLISHED tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:71.205.66.:62733 CLOSE_WAIT tcp6 467 0 ::ffff:85.17.170.205:80 ::ffff:71.77.136.:61256 CLOSE_WAIT tcp6 514 0 ::ffff:85.17.170.205:80 ::ffff:82.41.12.16:1583 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:86.154.98.1:4574 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:43167 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:43157 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:43156 CLOSE_WAIT tcp6 494 0 ::ffff:85.17.170.205:80 ::ffff:85.232.194.:4592 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:204.244.15:56360 ESTABLISHED tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:43151 CLOSE_WAIT tcp6 450 0 ::ffff:85.17.170.205:80 ::ffff:75.65.201.:29200 CLOSE_WAIT tcp6 67 0 ::ffff:85.17.170.205:80 ::ffff:70.47.36.6:43150 CLOSE_WAIT tcp6 0 0 ::ffff:85.17.170.205:80 ::ffff:172.216.245:2634 ESTABLISHED tcp6 493 0 ::ffff:85.17.170.205:80 ::ffff:195.93.102:38037 CLOSE_WAIT udp 0 0 0.0.0.0:32768 0.0.0.0:* udp 0 0 127.0.0.1:32770 127.0.0.1:32770 ESTABLISHED udp 0 0 85.17.170.205:137 0.0.0.0:* udp 0 0 85.17.170.208:137 0.0.0.0:* udp 0 0 0.0.0.0:137 0.0.0.0:* udp 0 0 85.17.170.205:138 0.0.0.0:* udp 0 0 85.17.170.208:138 0.0.0.0:* udp 0 0 0.0.0.0:138 0.0.0.0:* udp 0 0 0.0.0.0:919 0.0.0.0:* udp 0 0 0.0.0.0:922 0.0.0.0:* udp 0 0 85.17.170.208:53 0.0.0.0:* udp 0 0 85.17.170.205:53 0.0.0.0:* udp 0 0 127.0.0.1:53 0.0.0.0:* udp 0 0 0.0.0.0:111 0.0.0.0:* udp6 0 0 :::32769 :::* Active UNIX domain sockets (servers and established) Proto RefCnt Flags Type State I-Node Path unix 2 [ ACC ] STREAM LISTENING 5435 /tmp/spamd_full.sock unix 2 [ ACC ] STREAM LISTENING 4952 /dev/printer unix 2 [ ] DGRAM 2995 @/org/kernel/udev/udevd unix 13 [ ] DGRAM 4753 /dev/log unix 2 [ ACC ] STREAM LISTENING 5004 /var/run/mysqld/mysqld.sock unix 2 [ ACC ] STREAM LISTENING 5185 /var/run/postgresql/.s.PGSQL.5432 unix 2 [ ACC ] STREAM LISTENING 5683 /var/drweb/run/.daemon unix 3 [ ] STREAM CONNECTED 255661 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 255660 unix 3 [ ] STREAM CONNECTED 255636 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 255635 unix 3 [ ] STREAM CONNECTED 255597 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 255596 unix 3 [ ] STREAM CONNECTED 255577 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 255576 unix 3 [ ] STREAM CONNECTED 254907 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254906 unix 3 [ ] STREAM CONNECTED 254889 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254888 unix 3 [ ] STREAM CONNECTED 254881 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254880 unix 3 [ ] STREAM CONNECTED 254866 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254865 unix 3 [ ] STREAM CONNECTED 254834 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254833 unix 3 [ ] STREAM CONNECTED 254802 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254801 unix 3 [ ] STREAM CONNECTED 254792 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254791 unix 3 [ ] STREAM CONNECTED 254779 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254778 unix 3 [ ] STREAM CONNECTED 254756 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254755 unix 3 [ ] STREAM CONNECTED 254737 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254736 unix 3 [ ] STREAM CONNECTED 254720 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254719 unix 3 [ ] STREAM CONNECTED 254703 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254702 unix 3 [ ] STREAM CONNECTED 254692 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254691 unix 3 [ ] STREAM CONNECTED 254668 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254667 unix 3 [ ] STREAM CONNECTED 254656 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254655 unix 3 [ ] STREAM CONNECTED 254638 /var/run/mysqld/mysqld.sock unix 3 [ ] STREAM CONNECTED 254637 unix 2 [ ] DGRAM 242116 unix 2 [ ] DGRAM 5931 unix 2 [ ] DGRAM 5433 unix 2 [ ] DGRAM 5010 unix 2 [ ] DGRAM 4945 unix 2 [ ] DGRAM 4879 unix 2 [ ] DGRAM 4863 unix 2 [ ] DGRAM 4844 unix 2 [ ] DGRAM 4827 unix 2 [ ] DGRAM 4776 unix 2 [ ] DGRAM 4765
run this command if you have APF by any chance to get post 80 connections netstat -an |grep :80 |wc -l
ran it a few times this is what i get paulm@PUY001:~$ netstat -an |grep :80 |wc -l 160 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 165 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 166 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 168 paulm@PUY001:~$ netstat -an |grep :80 |wc -l ran it again just for the fun of it heres what i get paulm@PUY001:~$ netstat -an |grep :80 |wc -l 190 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 193 paulm@PUY001:~$ paulm@PUY001:~$ netstat -an |grep :80 |wc -l 201 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 202 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 202 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 202 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 202 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 204 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 205 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 205 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 205 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 206 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 207 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 207 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 207 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 207 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 206 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 206 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 207 paulm@PUY001:~$ netstat -an |grep :80 |wc -l 207 sorry dont know what APF is lol