hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Dedicated Server : Help! My server is being attacked!
Reply

Dedicated Server Current and past experiences with dedicated server providers, bandwidth, and server performance. Review managed and unmanaged dedicated web servers, discuss both Windows and Unix dedicated server solutions, and discuss dedicated hosting providers. If your service is unavailable, please click here.
Forum Jump

Help! My server is being attacked!

Reply Post New Thread In Dedicated Server Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 08-04-2001, 02:34 AM
arrty arrty is offline
WHT Addict
 
Join Date: Jun 2001
Posts: 124
*

Help! My server is being attacked! Please Help!


Hi guys,
I would really appreciate it if someone helps me solve a mystery. I have a Cobalt Raq3 and have noticed that in the pas one hour i have recieved 10 hits per second from this IP address 24.4.254.195. I don't know what this person is trying to do but he is visiting the same webpage (on my server) a thousand times and counting. Could you please tell me what to do about it and if it is a big danger.

Thanks in advance.

----------
added:
----------
This guy has been loading a webpage from my server for more than an hour now. Please help me block and secure my server from such attacks. I still have no clue as to why he is doing this and what he intends to do.


Last edited by arrty; 08-04-2001 at 04:21 AM.
Reply With Quote


Sponsored Links
  #2  
Old 08-04-2001, 02:45 AM
webbcite webbcite is offline
WHT Addict
 
Join Date: May 2001
Location: North Bend, WA
Posts: 118
Open a telnet session and do the following:

1. /sbin/route add -host 24.4.254.195 reject

This will block the ip from your route table.

2. add the following line to your /etc/hosts.deny file:

ALL: 24.4.254.195

Using these two commands will block the IP from services...unfortunately I don't believe it will block port 80 webserver.

Maybe someone else might have some ideas?

Reply With Quote
  #3  
Old 08-04-2001, 02:51 AM
arrty arrty is offline
WHT Addict
 
Join Date: Jun 2001
Posts: 124
I'll try that.


thanks

Reply With Quote
Sponsored Links
  #4  
Old 08-04-2001, 02:59 AM
arrty arrty is offline
WHT Addict
 
Join Date: Jun 2001
Posts: 124
webbcite,
I followed your instructions but the http requests are still coming in.

Thanks

Please does any one else have a solution to this. And it is serious?

Reply With Quote
  #5  
Old 08-04-2001, 04:19 AM
Steve33 Steve33 is offline
Junior Guru Wannabe
 
Join Date: Dec 2000
Posts: 69
That IP resolves to proxy2-external.alntn1.tx.home.com
I would say it is a definite attack.

For now until you get better advice I would simply deny them by adding the following line to the htaccess file in the directory of the page they are requesting:
Deny from 24.4.254.195
It wont stop requests being made to the server but at least it wont hog the bandwidth because they will get a permission denied error instead of the page.

Then I would take a sample of the requests from the log file and send them to your hosting company and abuse@home.com

Reply With Quote
  #6  
Old 08-04-2001, 04:29 AM
Palm Palm is offline
Web Hosting Master
 
Join Date: Jul 2001
Location: New York
Posts: 578
Check this out and also check the abuse e-mail:

http://www1.dshield.org/ipinfo.php?i...&Submit=Submit

__________________
PalmVersa Communications
PalmVersa.com
ICQ# 120775841

Reply With Quote
  #7  
Old 08-04-2001, 04:29 AM
arrty arrty is offline
WHT Addict
 
Join Date: Jun 2001
Posts: 124
I added this line to .htacces but does'nt block it
Deny from 24.4.254.195

is it supposed to be exactly like this?

Reply With Quote
  #8  
Old 08-04-2001, 05:02 AM
Steve33 Steve33 is offline
Junior Guru Wannabe
 
Join Date: Dec 2000
Posts: 69
Quote:
Originally posted by arrty
I added this line to .htacces but does'nt block it
Deny from 24.4.254.195

is it supposed to be exactly like this?


How do you know its not getting blocked? If its working you should get something like "client denied by server configuration"
in your logs.

If its not working did you just create the .htaccess file or was one already there? If you just created it make sure its named .htaccess not htaccess

You should have something like this:

<Limit GET POST>
order allow,deny
deny from 24.4.254.195
allow from all
</Limit>

Reply With Quote
  #9  
Old 08-04-2001, 05:10 AM
arrty arrty is offline
WHT Addict
 
Join Date: Jun 2001
Posts: 124
Quote:
<Limit GET POST>
order allow,deny
deny from 24.4.254.195
allow from all
</Limit>
This does'nt work either

I have HumanClick monitor installed on each page so I can see in realtime who is at my website and which page.

Reply With Quote
  #10  
Old 08-04-2001, 05:26 AM
davidb davidb is offline
A#* Duke Of New York
 
Join Date: Jun 2001
Location: Chicago, IL
Posts: 1,953
check pm,

Reply With Quote
  #11  
Old 08-04-2001, 05:30 AM
arrty arrty is offline
WHT Addict
 
Join Date: Jun 2001
Posts: 124
This guy is getting on my nerve now. He is going to use up all my bandwith. I need to block him asap.

please can someone tell me how to block the IP
24.4.254.195
Host: proxy2-external.alntn1.tx.home.com

Reply With Quote
  #12  
Old 08-04-2001, 09:29 AM
RackMy.com RackMy.com is offline
Web Hosting Master
 
Join Date: Apr 2001
Location: St. Louis, MO
Posts: 2,508
You should use ipfwadm. I am not sure the exact command, but that should do it for you and allow you to block that IP.

Hope that helps!

__________________
Mike @ Xiolink.com
http://www.xiolink.com 1-877-4-XIOLINK
Advanced Managed Microsoft Hosting
"Your data... always within reach"

Reply With Quote
  #13  
Old 08-04-2001, 12:03 PM
bert bert is offline
Web Hosting Master
 
Join Date: Apr 2001
Location: Orlando, Florida
Posts: 671
arrty,

If you have not yet been able to block it, create your htaccess file like this:

# Access file
order allow,deny
Deny from XX.XX.XX.XX <<<<<<<<<<<<<<<< HIS IP HERE
allow from all

Make sure you save it as ".htaccess"

Also, if you entered the ip in the /etc/hosts.deny file, I think you will have to reboot the server for the changes to take effect. I am not sure though, but it might be worth rebooting.

Good luck

__________________
Bert Kammerer
ProNIC Solutions - pronicsolutions.com
The Smart Internet of the Future (SM)
Hosting on enterprise grade Dell servers with fast & redundant InterNAP bandwidth

Reply With Quote
  #14  
Old 08-04-2001, 12:53 PM
NyteOwl NyteOwl is offline
ThirtySx Bits Forever!
 
Join Date: Jul 2001
Location: Canada
Posts: 1,284
Cool Another step to take

A call to HOME.COM's support/service/abuse number would be a good idea too. They get hurt by people like this too and if s/he is doing it to you chances are they're doing it to others. HOME.COM can likely check their logs and close the user account.

__________________
"Obsolesence is just a lack of imagination."

Reply With Quote
  #15  
Old 08-04-2001, 02:15 PM
arrty arrty is offline
WHT Addict
 
Join Date: Jun 2001
Posts: 124
Problem Solved

Thanks All,
You guys have been of great help. The problem is solved now and the requests stopped coming from this IP by itself. But the knowledge I have gained here will definately help me the next time such a problem occurs.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Web Host 1&1 Enhances Dedicated Server Line with 32 Core, 64 GB RAM Server Web Hosting News 2011-12-20 15:30:05
Akamai Report Names Taiwan Number-One Source of Attack Traffic Web Hosting News 2011-10-28 18:33:23
Security Firm GlobalSign to Start Issuing Certificates Tuesday After System Breach Detected Web Hosting News 2011-09-12 14:50:47
Spanish Authorities Arrest Three for Sony Playstation Network Hack, Get Hacked Web Hosting News 2011-06-13 17:40:27
APWG Survey Finds One Third of Web Hosts Are Repeat Victims of Phishing Web Hosting News 2011-06-09 20:21:23


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?