My sites are under heavy DDOS attack

Discussion in 'Site & Server Administration' started by DomainMagnate, Jan 22, 2010.

  1. #1
    My sites are under ddos attacks for a couple weeks now.
    I upgraded the vps account to a dedicated server, still doesn't help that much. Sites are loading very slow, server is frequently offline.

    The attack seems to be targeted at port 25, email related. That's what the hosting support says (it's on wiretree.com). However they don't provide any ddos attack protection services, so all they can do is turn off the monitoring for that port, so I won't get constant emails notifying of failures of exim and other functions.

    Any ideas what can be done? How can I know if it really is a targeted attack and not just too much traffic on the server? The sites on the server get some 100k pageviews per day.
     
    DomainMagnate, Jan 22, 2010 IP
  2. FavouritesBlog

    FavouritesBlog Peon

    Messages:
    846
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Are you sure they are attacking port 25? If they are attacking port 25 why not close the port and tell your iptables to drop packets coming into port 25?

    Also, how many IP's are apparently attacking?

    What OS server and cp are you running? What spec is the server?
     
    FavouritesBlog, Jan 22, 2010 IP
  3. DomainMagnate

    DomainMagnate Illustrious Member

    Messages:
    10,932
    Likes Received:
    1,022
    Best Answers:
    0
    Trophy Points:
    455
    #3
    Hey, it's on the first dedi plan here
    Hm not sure about ips.. does that matter though?

    I think if the 25 port is closed it won't be able to send/receive email.
     
    DomainMagnate, Jan 22, 2010 IP
  4. alex288288

    alex288288 Well-Known Member

    Messages:
    737
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    130
    #4
    Well if you can ban the IP's that are spamming you, that should help. also if you close port 25 even for awhile.

    i would request new IP's if thats the problem, but look in your logs and see if you can find the IP attack and block it, even block the whole range?

    hope that helps a little!
     
    alex288288, Jan 23, 2010 IP
  5. SecureCP

    SecureCP Guest

    Messages:
    226
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #5
    You can install a quick firewall, CSF. I'm assuming you're running linux. If it's so bad that you can see the sites or receive mail anyways, have your host turn off the server at the switch for a half hour or so. I know, it sounds dumb but hear me out. If the packets have nowhere to go they're going to turn around on the ISP where they're coming from and the ISP should turn the person off who's performing it. That should only be done in extreme cases. Try the firewall first. If you need help on installation check here
     
    SecureCP, Jan 23, 2010 IP
  6. DomainMagnate

    DomainMagnate Illustrious Member

    Messages:
    10,932
    Likes Received:
    1,022
    Best Answers:
    0
    Trophy Points:
    455
    #6
    thanks for your input!
    Attack is focused on one ip on my server, the main one which hosts most of the sites.
    Attacks are coming from all kinds of differents ips, cant block them effectively.
    I guess I could close port 25 for a while, what would this help? I still need it for email etc.

    thanks for the tip, the server already has CSF installed, but my hosting support say it's not meant for DDOS attacks and won't help prevent the issue
     
    DomainMagnate, Jan 23, 2010 IP
  7. DomainMagnate

    DomainMagnate Illustrious Member

    Messages:
    10,932
    Likes Received:
    1,022
    Best Answers:
    0
    Trophy Points:
    455
    #7
    I think I'll try that. Can it do any good if it's for just 12 hours or so?
     
    DomainMagnate, Jan 23, 2010 IP
  8. rahuldas14

    rahuldas14 Well-Known Member

    Messages:
    679
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    130
    #8
    change the mail port from 25 to something else. i am not sure how it is done but i had heard this is possible.
     
    rahuldas14, Jan 23, 2010 IP
  9. FavouritesBlog

    FavouritesBlog Peon

    Messages:
    846
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Ok

    1. How many IP's are attacking you?
    2. What iptables management script are you using currently?
    3. If your using cPanel you can change port 25 to port 26. I suggest you close port 25 for half a day, and set your iptables to DROP packets instead of rejecting them.


    Trust me, I've worked on more servers than the amount of times you have gone to the toilet in your lifetime.
     
    FavouritesBlog, Jan 23, 2010 IP
  10. arunns

    arunns Peon

    Messages:
    7
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Check the mail logs, make sure that your mail server configurations are not allowing open relay. Might be a good idea to scan the server with some security scanners like Nessus.
     
    arunns, Jan 24, 2010 IP
  11. CarbonLife

    CarbonLife Guest

    Messages:
    14
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    I'm surprised that WiredTree didn't help you more.
     
    CarbonLife, Jan 24, 2010 IP
  12. DomainMagnate

    DomainMagnate Illustrious Member

    Messages:
    10,932
    Likes Received:
    1,022
    Best Answers:
    0
    Trophy Points:
    455
    #12
    thanks, did that for now. Dropping packets. Looks like it's quiet for now, but will see after opening port 25 again soon.
     
    DomainMagnate, Jan 25, 2010 IP
  13. HRG-Tina

    HRG-Tina Peon

    Messages:
    24
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #13
    - Is your mail queue normal? (i.e. the queue is not filled with tens of thousand emails)

    - Check the default boxes. Sometimes a wrongly configured default email account can cause this huge server load problem. Example: instead of ":fail:", only "fail:" was entered

    Just a couple of checks I could come up with (maybe you already checked :)). I hope things will return to normal for you soon!
     
    HRG-Tina, Jan 25, 2010 IP