hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Dedicated Server : EV1: ongoing ddos attack
Reply

Dedicated Server Current and past experiences with dedicated server providers, bandwidth, and server performance. Review managed and unmanaged dedicated web servers, discuss both Windows and Unix dedicated server solutions, and discuss dedicated hosting providers. If your service is unavailable, please click here.
Forum Jump

EV1: ongoing ddos attack

Reply Post New Thread In Dedicated Server Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 03-13-2004, 01:38 AM
rusko rusko is offline
Web Hosting Master
 
Join Date: Sep 2002
Posts: 3,892

EV1: ongoing ddos attack


several machines at ev1 are currently generating inbound ddos traffic to a machine we help manage. this is a commercial ddos attack - in other words, an e-commerce competitor is ddosing the client in order to hurt his business.

numerous emails have been sent to abuse@ev1 - got one auto-reply, the rest were ignored. noc says to email abuse@.

same goes for managed.com.

as a network operator, such behaviour is irresponsible and inexcusable. time to nullroute their netblocks at the edge?

paul

__________________
* Rusko Enterprises LLC - Upgrade to 100% uptime today!
* Premium NYC collocation and custom dedicated servers
call 1-877-MY-RUSKO or paul [at] rusko.us

dedicated servers, collocation, load balanced and high availability clusters

Reply With Quote


Sponsored Links
  #2  
Old 03-13-2004, 01:53 AM
Steven Steven is online now
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,784
now that just sucks

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #3  
Old 03-13-2004, 01:55 AM
Nessun Nessun is offline
Web Hosting Evangelist
 
Join Date: Dec 2002
Location: US
Posts: 517
I have to agree that would really suck. Maybe try calling?

Reply With Quote
Sponsored Links
  #4  
Old 03-13-2004, 02:05 AM
eBoundary eBoundary is offline
Web Hosting Master
 
Join Date: May 2003
Location: Philadelphia
Posts: 968
Null route then do the abuse@ thing, then you can provide all the info you need to in an email that isnt being rushed.

__________________
http://www.eBoundary.com - Let us help you expand your eBoundaries!
Fast, Secure and reliable FreeBSD shared, reseller and dedicated hosting.
FREE Peace of mind with every account!

Reply With Quote
  #5  
Old 03-13-2004, 02:15 AM
rusko rusko is offline
Web Hosting Master
 
Join Date: Sep 2002
Posts: 3,892
Quote:
Originally posted by Nessun
I have to agree that would really suck. Maybe try calling?
if you read my post, the calls have already been made. we were instructed to email abuse@, so they can proceed to ignore the email.

paul

__________________
* Rusko Enterprises LLC - Upgrade to 100% uptime today!
* Premium NYC collocation and custom dedicated servers
call 1-877-MY-RUSKO or paul [at] rusko.us

dedicated servers, collocation, load balanced and high availability clusters

Reply With Quote
  #6  
Old 03-13-2004, 02:18 AM
rusko rusko is offline
Web Hosting Master
 
Join Date: Sep 2002
Posts: 3,892
Quote:
Originally posted by eBoundary
Null route then do the abuse@ thing, then you can provide all the info you need to in an email that isnt being rushed.
the ddos has already been handled; all the necessary info was provided, they just chose to ignore it. i am not asking for assistance at this point, since everything is under control and service is not affected. this is more of a 'name and shame' deal.

on several occasions in the past some higher-ups from ev1 read threads similar to this one, became clued in to some internal problems and moved to resolve them. i am (somewhat) hoping the same will happen this time, though their whole operation has taken a huge nosedive lately what with all the monkeys they've hired, so im not too optimistic.

paul

__________________
* Rusko Enterprises LLC - Upgrade to 100% uptime today!
* Premium NYC collocation and custom dedicated servers
call 1-877-MY-RUSKO or paul [at] rusko.us

dedicated servers, collocation, load balanced and high availability clusters

Reply With Quote
  #7  
Old 03-13-2004, 02:26 AM
BizB BizB is offline
Web Hosting Evangelist
 
Join Date: Jul 2003
Posts: 526
another reason for me to love SM
i would expect more dos attacks from people as long there getting free setup + no punishment from EV1 staff
spcialy from kids

Reply With Quote
  #8  
Old 03-13-2004, 02:37 AM
rusko rusko is offline
Web Hosting Master
 
Join Date: Sep 2002
Posts: 3,892
no attacks from SM/TP space (yet). the thing that amuses me the most is that the attacker is going to spend the whole night trying to ddos the box, while it took me all of 5-10 minutes to write a script to block the attack so i could move on to {bigger,better} things =]

paul

__________________
* Rusko Enterprises LLC - Upgrade to 100% uptime today!
* Premium NYC collocation and custom dedicated servers
call 1-877-MY-RUSKO or paul [at] rusko.us

dedicated servers, collocation, load balanced and high availability clusters

Reply With Quote
  #9  
Old 03-13-2004, 04:50 AM
amusive.com amusive.com is offline
Web Hosting Master
 
Join Date: Sep 2001
Location: Seattle, WA
Posts: 3,082
Optonline did this to me too. A guy was doing an amateuer DOS on my server, I just firewalled him out but contacted his ISP's abuse desk anyway. He was doing it for 8 days straight. I emailed them day #2, and they didn't care. He was still doing it -- I could see the firewall logs 10-50 rejected connections a second -- but they didn't see anything wrong with that, apparently.

Ugh.

Things like this should be top priority, especially if they're something you can take 5 seconds and SEE is still actively happening.

__________________
Jim Reardon - jim/amusive.com
SiteSurvival Professional, Expensive Hosting -=- Shrink URLs Down For Posting!

Reply With Quote
  #10  
Old 03-13-2004, 05:19 AM
ndctech ndctech is offline
Disabled
 
Join Date: Oct 2003
Location: New Bedford, MA
Posts: 79
Rusko.....

It was funny to see this thread. We are dealing with the exact same thing right now (attacks from EV1 servers). Same thing for us, no response from EV1.

I am very appalled at what an irresponsable company they are.

Reply With Quote
  #11  
Old 03-13-2004, 11:21 AM
Knogle Knogle is offline
Web Hosting Master
 
Join Date: Feb 2002
Posts: 3,727
rusko's case in an inbound DDoS attack to a machine at EV1

__________________
Have you Floble'd today?

Reply With Quote
  #12  
Old 03-13-2004, 12:04 PM
UH-Matt UH-Matt is offline
Corporate Member
 
Join Date: Aug 2002
Location: London, UK
Posts: 9,029
Rusko, ive sent you some contacts in a PM who can help you.

__________________
Matt Wallis
United Communications Limited
High Performance Shared & Reseller | Managed VPS Cloud | Managed Dedicated
UK www.unitedhosting.co.uk | US www.unitedhosting.com | Since 1998.

Reply With Quote
  #13  
Old 03-13-2004, 03:25 PM
rusko rusko is offline
Web Hosting Master
 
Join Date: Sep 2002
Posts: 3,892
Quote:
Originally posted by Knogle
rusko's case in an inbound DDoS attack to a machine at EV1
seems you cant read. it is an inbound attack that is *coming from* ev1.

paul

__________________
* Rusko Enterprises LLC - Upgrade to 100% uptime today!
* Premium NYC collocation and custom dedicated servers
call 1-877-MY-RUSKO or paul [at] rusko.us

dedicated servers, collocation, load balanced and high availability clusters

Reply With Quote
  #14  
Old 03-13-2004, 03:33 PM
rusko rusko is offline
Web Hosting Master
 
Join Date: Sep 2002
Posts: 3,892
Quote:
Originally posted by UH-Matt
Rusko, ive sent you some contacts in a PM who can help you.
matt,

thanks. techiesurfer made contact.

paul

__________________
* Rusko Enterprises LLC - Upgrade to 100% uptime today!
* Premium NYC collocation and custom dedicated servers
call 1-877-MY-RUSKO or paul [at] rusko.us

dedicated servers, collocation, load balanced and high availability clusters

Reply With Quote
  #15  
Old 03-13-2004, 06:02 PM
rusko rusko is offline
Web Hosting Master
 
Join Date: Sep 2002
Posts: 3,892
techiesurfer helped out with the situation, thank you techie =]

with that said, i think you should look into your abuse team operations. most providers whose security people dont know about wht would have been SOL in this situation.

paul

__________________
* Rusko Enterprises LLC - Upgrade to 100% uptime today!
* Premium NYC collocation and custom dedicated servers
call 1-877-MY-RUSKO or paul [at] rusko.us

dedicated servers, collocation, load balanced and high availability clusters

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Three DNS Hosting Providers Report Possibly Linked DDoS Attacks Web Hosting News 2013-06-05 16:50:15
Spamhaus Blames Cyberbunker for the Largest Public DDoS Attack Ever Web Hosting News 2013-03-27 14:11:35
Blogging Site LiveJournal Hit by Ongoing DDoS Attack Web Hosting News 2011-12-08 16:35:38
Web Host Netregistry Hit by DDoS Attack Web Hosting News 2011-09-26 14:11:33
WHIR TV - Rick from Neustar Discusses DDOS Threats and Defense Blog 2011-09-23 13:52:45


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?