IS this a ddos attack?

Discussion in 'Security' started by Renegadez, Jan 29, 2008.

  1. #1
    28 Jan 2008 1444 1412063 1460202 44.01 GB

    Is that 1,444 uniques, over 1 million pageviews/visitors and use of 44GB?

    My average is 500MB with like 2k uniques, but for some reason I'm getting MORE pageviews and MORE bw is being used.

    That's daily, 44GB.

    Also, the IP that AwStats says is sending the Bandwidth is the Server IP i'm on...

    How is that possible? :eek:

    My site is currently down due to too much BW.

    =/

    Can anyone help?
     
    Renegadez, Jan 29, 2008 IP
  2. Ladadadada

    Ladadadada Peon

    Messages:
    382
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    0
    #2
    If the IP address is the server you are on it sounds like there is a script on your site that attempts to download itself, possibly several times per real request.

    This can happen in PHP with file_get_contents("http://www.domain.com/whatever.php"); or include("http://www.domain.com/whatever.php"); or one of several other functions.

    Can you get shell access to your server ? Can you get to your raw log files ? If so, we can help you analyse them further to figure out what's happening.

    If not, AWStats still may help. Try looking at what the most frequently requested file is. Also look at 404 errors (right down the bottom...) and tell us how many of those there are.
     
    Ladadadada, Jan 31, 2008 IP
  3. HurryHost.com

    HurryHost.com Banned

    Messages:
    125
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #3
    DDoS is IP specific, so it targets the server, sounds like DoS
    basically some bots are loading pages over and over again, simple fix will cost you a little but PM me
    if you want me to implement protection
     
    HurryHost.com, Jan 31, 2008 IP
  4. Kaizoku

    Kaizoku Well-Known Member

    Messages:
    1,261
    Likes Received:
    20
    Best Answers:
    1
    Trophy Points:
    105
    #4
    Just apply some iptables rule, search around the forum, you will find plenty.
     
    Kaizoku, Feb 2, 2008 IP
  5. NICKY Nitro

    NICKY Nitro Well-Known Member

    Messages:
    958
    Likes Received:
    59
    Best Answers:
    0
    Trophy Points:
    138
    #5
    Do you think that this would be enough to prevent the whole thing from happening again?
     
    NICKY Nitro, Feb 11, 2008 IP
  6. Kaizoku

    Kaizoku Well-Known Member

    Messages:
    1,261
    Likes Received:
    20
    Best Answers:
    1
    Trophy Points:
    105
    #6
    Not completely prevent, there is no such thing unless you monitor 24/7. But, it will greatly reduce.
     
    Kaizoku, Feb 11, 2008 IP
  7. D'Godown

    D'Godown Well-Known Member

    Messages:
    1,093
    Likes Received:
    25
    Best Answers:
    0
    Trophy Points:
    140
    #7
    Its a botnet for sure, u r compromised if you are running proxy websites.
    Just block whole range and china.
     
    D'Godown, Apr 3, 2008 IP