hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : what is this ATTACK TYPE?
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

what is this ATTACK TYPE?

View Poll Results: what is this ATTACK TYPE?
dos 0 0%
ddos 1 50.00%
software issue 1 50.00%
hardware issue 0 0%
Voters: 2. You may not vote on this poll

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 01-16-2011, 12:32 PM
Bahram0110 Bahram0110 is offline
Newbie
 
Join Date: Mar 2010
Posts: 24

what is this ATTACK TYPE?


Hello all,
I have a dell server about 9 month:
xeon x3220
cpanel
mysql
centos
apache
php 5.2.16
csf
all these softs are updated.
About 500 accounts are located on it and about 6 to 10 accounts are active. I can say other accounts have no visit really.
Csf connection limit is 80 and 10 to 20 IPs are blocking per day for 15 mins for "to many connections".80% of IPs are from foreign countries (that there is no visit from them) and they are from different locations.

Recently my server is going down once at 24 to 72 hrs.

At that time:
my sql has more than 150 queries in the queue.
Server load is going up to 200 or even more.
Csf send many emails at same time. (Excessive processes running under user..)
all mails are at same time and alert for different users.
I also installed PRM (process resource monitor) to limit cpu and ram usage.
Prm also send many emails at that time with content like this:
EVENT: HARD FAIL MAX_PROC
use:135/max:30
ACTION: KILL_PARENT SET; KILLED
PARENT/CHILDREN PROCS WITH 'kill
-9 27192 '
PPID: 27192
PID: 3065
USER: ...
CPU: 0% (max 15)
MEM: 0% (max 8)
ETIME: 0108 (max )
PROCS: 138 (max 30)
CMD: /usr/bin/php /home/
.../public_html/
filename.php

PRM mails are also for different users at same time and all accounts have approximately equal PROCS value (about 130 to 200).



Is this a DDOS Attack?

Thank you.

Reply With Quote


Sponsored Links
  #2  
Old 01-16-2011, 01:00 PM
sitekeeper sitekeeper is offline
Quick, poke it with a stick!
 
Join Date: Jul 2001
Location: Troy, Missouri USA
Posts: 1,299
Reminds me of the old Smurf attacks, can't be that though.

__________________
Sitekeeper
32 Mbps broadband

Reply With Quote
  #3  
Old 01-16-2011, 03:55 PM
valledus valledus is offline
New Member
 
Join Date: Dec 2010
Posts: 2
What's in filename.php? Have you optimized the server? How many queries/sec are you getting?

Reply With Quote
Sponsored Links
  #4  
Old 01-16-2011, 04:03 PM
Bahram0110 Bahram0110 is offline
Newbie
 
Join Date: Mar 2010
Posts: 24
filename.php is an example and is different files. Like default index.php
Normaly there are 4 queries at time.
I optimized mysql based on default mysql generated file, my-huge.cnf

Reply With Quote
  #5  
Old 01-18-2011, 01:37 PM
nonmal nonmal is offline
Newbie
 
Join Date: Dec 2010
Posts: 17
Could you post any sample IPs that are trying to connect in when you see load spiking. It would help in searching for the "reputation" of the connecting IPs.

Reply With Quote
  #6  
Old 01-18-2011, 02:31 PM
Bahram0110 Bahram0110 is offline
Newbie
 
Join Date: Mar 2010
Posts: 24
Unfortunately i can not find any suspicious ip during that time.
I found that during that time mysql connections will increase and they make a big queue. Nobody can connect to mysql,
All things go back to OK when i restart mysql service.

Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
How to stop this type of Dos attack userkiller Hosting Security and Technology 1 10-01-2010 08:07 PM
Need advice on type of attack kamal_s Hosting Security and Technology 8 08-04-2009 07:31 PM
looking for: DDo's attack (Syn type) specialized hosting? thestep1 Web Hosting 16 06-29-2009 09:59 PM
Help. New Type of Server Attack Collaziano Hosting Security and Technology 15 01-31-2008 02:52 PM
type of attack bigzur Dedicated Server 2 11-08-2004 03:11 AM

Related posts from TheWhir.com
Title Type Date Posted
Prolexic Quarterly DDoS Report Finds 11 Percent Increase in Average Attack Bandwidth Over Q2 Web Hosting News 2012-10-17 12:29:18
Web Hosting Talk Message Board Back Online Following DDoS Attack Web Hosting News 2012-09-12 11:59:42
Hackers Target European Web Host 123-reg in DDoS Attack Web Hosting News 2012-05-24 16:43:10
Blogging Site LiveJournal Hit by Ongoing DDoS Attack Web Hosting News 2011-12-08 16:35:38
Web Host Netregistry Hit by DDoS Attack Web Hosting News 2011-09-26 14:11:33


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?