Web Hosting Talk







View Full Version : Anyone with ColoPriority?


sHosts
07-07-2003, 08:29 PM
Hey guys,

I was wondering if anyone else has servers with colopriority. I had a few questions. (Important/Urgent).

TotalChoice
07-07-2003, 08:36 PM
We have several boxes there. Whats up?

sHosts
07-07-2003, 08:36 PM
Is their website working for you?

sHosts
07-07-2003, 08:38 PM
Nevermind. For some reason, everything was down for a little bit.

Everything is good:)

Thanks for the reply.

hllMedia
07-07-2003, 09:31 PM
Still down here. Also their site is down as well. Something must be going on at DC. Anyone else noticing this.

TotalChoice
07-07-2003, 10:17 PM
I have been in contact with Myles at PC. There is a ddos attack in progress. They have filtered most of it.

Keep the faith, he is the best in the business! Things will be back soon.

porcupine
07-07-2003, 10:24 PM
We're just riding out the after effects now.

Basically there was a massive DDoS attack hitting the network... A small chunk of it went off and hit a few of our servers, and was neutralized almost instantly. The traffic going through TorIX was also neutralized fairly quickly (as our admin Jon owns TorIX). The NAC link, Torix, and Ottix links have been up throughout most of this, but most of the traffic coming in from the states over the Yipes! link has been completely disrupted in this attack.

Stuff is just starting to come back up now, if there was a particular user on our network attracting this, he'd be packing by now, but unfortunatly, the majority of this attack was focused upstream from us, basically right at our front door.

hllMedia
07-08-2003, 12:06 AM
Good Job As Usual....

wmac
07-08-2003, 12:40 AM
I am down yet.

porcupine
07-08-2003, 12:48 AM
Unfortunatly the DDoS flapped back again just as it started to settle down and the link has begun to hiccup (up, down, up down, you know the drill). We've done everything within our means at this point, filtered out every stray bit of data hitting our network segment, and basically can't do anything now but wait for Istop to continue to combat the situation and repair their flatlined routers, etc.

Unfortunatly at this point, unless further attacks go into our segment, we've done all we can, and can't even get out to push.

Number6
07-08-2003, 01:04 AM
Well Myles, I'm glad in a way because I just had several registrar changes go through today and I originally thought I must have done something wrong.

Personally, I've been with PriColo for almost a year and everything has been tip-top. Highly recommended.

Damn script kiddies though, they should be beaten with sticks.

porcupine
07-08-2003, 01:05 AM
Originally posted by Number6
Well Myles, I'm glad in a way because I just had several registrar changes go through today and I originally thought I must have done something wrong.

Personally, I've been with PriColo for almost a year and everything has been tip-top. Highly recommended.

Damn script kiddies though, they should be beaten with sticks.

My vote is on lead pipes, but I agree 100%.

wmac
07-08-2003, 02:52 AM
Any news?

NZCueBall
07-08-2003, 03:55 AM
Hey porcupine, any update would be most appreciated, especially for your customers in NZ! :)

TotalChoice
07-08-2003, 03:57 AM
Myles is at the DC. I just spoke with him. The attack has not stopped.

Sorry I cant give more updates, I just know Myles is at the DC working on things.

NZCueBall
07-08-2003, 04:00 AM
thanks for the update TotalChoice. Even bad news (that it hasn't stopped yet) is better than no news.

TotalChoice
07-08-2003, 04:26 AM
Yep its ok... Myles is a good person, he will take care of business.

porcupine
07-08-2003, 05:21 AM
Ok well i'm pretty much camped out in our cage right now, but here's the lowdown:

Basically www5 was being attacked on it's main ip address (which mind you we don't even use for hosting really, they're all resellers with private shared ip's) for reasons unknown. Whichever script kiddie was doing this, was using more then one attack type at a time, and was basically syn flooding the server (connection floods) and doing a udp style broadcast attack at the same time (or so it appears), providing enough packets per second to crash routers and even a switch upstream. Unfortunatly apparently Yipes failed to properly filter the attack further upstream on the first few attempts, letting it get back into the link and simply halt the switch and routers in question. After a few attempts Yipes simply blackholed the IP address, and all was fine for about half an hour until the attacker choose another IP address to attack on the same server (reseller servers are easy targets for this). We took the server in question down, but by that point, it didn't seem to matter (they continued the attacks).

After a bit the attacks subsided, combined with filters on the router and filtering upstream by Yipes it's finally got to a level where it's no longer affecting service. Thankfully during the majority of this time the links to most of Canada (Torix and Ottix) remained unaffected (as they're on a different router/switch), as well as the NAC link passing to certain parts of europe.

I sincerely appologise for the inconvinience this has caused anyone/everyone, and can assure you we've done everything in our power to take care of this. We are implamenting other solutiosn as well to try to reduce the vulnerability of any given segment of the network, but it really comes down to how determined an attacker is. Much like a gun and a bullet proof vest, if you can't penetrate the vest, what do you do? Get a bigger gun. Unfortunatly the same holds true to script kiddies, if your attack can't interfere with a network, get a bigger attack.

porcupine
07-08-2003, 05:23 AM
Notably I'd also like to direct any of our current customers attention to the news section of our forum where i'll be posting more on this issue (but as for the usefullness of WHT, it's served its purpose for this incident, until the next [and hopefully a long time, we need sleep too ya know!]) :).

Regards,

Rui
07-08-2003, 06:35 AM
still down :( damm damm damm :(

porcupine
07-08-2003, 06:50 AM
Originally posted by Rui
still down :( damm damm damm :(

Thats because you're on the server that was attacked, that ones main ip and a few sub ip addresses are currently being blocked. We're re-routing anyone whose on the main ip to their respective private shared ip addresses, not much else we can do, if we unblock the filtering, the attacks are still going and hit the network again.

vito
07-08-2003, 07:31 AM
I think this is all my fault. :eek:

The one night I decide to kick off early for the evening (9 PM), the one night I don't work until 12-1 AM, is the night our server is attacked.

I think the Internet Gods are trying to tell me I shouldn't even think about having a life... :bawling:

On the serious side, these attacks are going to happen, script kiddies make everyone's lives miserable. But it is certainly reassuring to know that Myles is on our side. As usual, he jumps to action and does whatever it takes to get it under control.

3 cheers for PriorityColo. Good work, Myles... :beer:

Vito

Rui
07-08-2003, 07:48 AM
Well after a short chat we managed to get it up to work!

thumbs up for Myles and the way we took care of me and my sites ;)

DarktidesNET
07-08-2003, 08:02 AM
First major downtime in 5 months. Not too shabby, but all DDoS is bound to happen. ;-)

sHosts
07-08-2003, 08:39 AM
Everything is ok now.

grahamb
07-09-2003, 12:25 AM
Originally posted by porcupine
Notably I'd also like to direct any of our current customers attention to the news section of our forum where i'll be posting more on this issue

Hi Myles - I think I've got the basics from the posts here and in the demodemo thread, but for the clients not reading WHT (or should those that do fail to miss a thread they didn't know was related) you might want to post an update.

I hope your world is returning to normal, and that you'll get some well deserved rest.

porcupine
07-09-2003, 02:55 AM
I'll be posting the updates in our own forums once i get some sleep, i *still* haven't goten any sleep yet. Sleep first, then updates, as we need to get Vito setup on emergency provisions tomorrow, nasty work.

alapo
07-09-2003, 06:48 PM
Originally posted by vito
I think this is all my fault. :eek:

The one night I decide to kick off early for the evening (9 PM), the one night I don't work until 12-1 AM, is the night our server is attacked.


It has happened to the best of us. :stickout:

choon
07-10-2003, 05:34 PM
Originally posted by DarktidesNET
First major downtime in 5 months. Not too shabby, but all DDoS is bound to happen. ;-)

Ya... and anyone who want to get a server or more from Myles... my comments... GO FOR IT YOU WON'T REGRET :D

Thanks Myles and his company for their support ;)

Kindest regards,
Choon

vito
07-10-2003, 05:37 PM
Myles :beer:
PriorityColo :beer:
PC :beer:
PriorityColocation :beer:

Take your pick... :D

Vito

wateringcan
07-10-2003, 06:31 PM
Originally posted by vito
Myles :beer:
PriorityColo :beer:
PC :beer:
PriorityColocation :beer:

Take your pick... :D

Vito

What about ColoPriority? :)

AKavanaugh
07-10-2003, 08:26 PM
Can I opt for the beer instead?