Sudden Huge bandwidth usage

Discussion in 'Site & Server Administration' started by invisible, Apr 8, 2007.

  1. #1
    I own Dedicated server amd athlon 2800+ with directadmin

    and my site gets average 20 - 30 user per 15 minutes .. i.e. aroung 60GB per month bandwidth .. the bandwidth usage has been going correct from the past 3 months.

    This month from april 1st to april 6th .. the bandwidth usage reported 500GB which is i think is impossible for my site.

    I have to no idea which could have caused ddos or apache error ?

    How do i proceed ? i have seen apache access and error logs .. but i dont find any suspicious activity.

    Directamin says site has received more hits than previous month in just 5 days
     
    invisible, Apr 8, 2007 IP
  2. agnivo007

    agnivo007 Peon

    Messages:
    4,290
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Maybe a case of DDoS...is your directadmin updated to latest version?
     
    agnivo007, Apr 9, 2007 IP
  3. stugs

    stugs Peon

    Messages:
    157
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Either someone is sending a ton of traffic to you, or your server is sending a ton of traffic out. Quickiest way if you aren't familiar with linux is to ask your datacenter for a bandwidth graph. If it's all incoming BW have them look into your traffic for a possible DDOS attack.

    It is probably more likely someone is exploiting something on your server to setup a FTP/BNC/whatever server and piggyback on your bandwidth.
     
    stugs, Apr 9, 2007 IP
  4. agnivo007

    agnivo007 Peon

    Messages:
    4,290
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    0
    #4
    agnivo007, Apr 9, 2007 IP
  5. login

    login Notable Member

    Messages:
    8,849
    Likes Received:
    349
    Best Answers:
    0
    Trophy Points:
    280
    #5
    Someone is most likely attacking your server, it happened to me some time ago. Talk to support and get them to trace the traffic and block the IP where its coming from. That should take care of it.
    Then find the domain the traffic is coming from and report that domain to the host so that account will be banned.
     
    login, Apr 9, 2007 IP
  6. invisible

    invisible Banned

    Messages:
    2,031
    Likes Received:
    95
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Thanks for that link

    I guess its Directadmin problem.

    I havent updated my Directadmin .. will try that.
     
    invisible, Apr 9, 2007 IP