hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Attempt of hack
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

Attempt of hack

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 05-20-2005, 11:29 AM
ninteen83 ninteen83 is offline
New Member
 
Join Date: May 2005
Posts: 4

Attempt of hack


Hi all

I'm not able to access my website. I've recieved an email from the webhosting team with the following message

----------------------------

Our server was heavily DoSed through your hosting account. Please see below:

tcp 0 0 66.116.228.238:80 217.197.156.197:29857 SYN_RECV -
tcp 0 0 66.116.228.238:80 201.135.134.33:2517 SYN_RECV -
tcp 0 0 66.116.228.238:80 218.94.61.136:3230 SYN_RECV -
tcp 0 0 66.116.228.238:80 61.220.150.2:2877 SYN_RECV -
tcp 0 0 66.116.228.238:80 203.169.250.29:3108 SYN_RECV -
tcp 0 0 66.116.228.238:80 194.63.225.1:54486 SYN_RECV -
tcp 0 0 66.116.228.238:80 219.93.174.108:39672 SYN_RECV -

and so on...

At the moment your IP address was filtered on the firewall to prevent the server from crashing. Please, check your scripts, applications, anything which might cause this. You need to close all the security holes.
----------------------------

I'm sure this is an attempt of hack.

What should i do now ?? Website is running on a Linux server

any help will be appreciated

Thanks

Reply With Quote


Sponsored Links
  #2  
Old 05-20-2005, 12:23 PM
eth00 eth00 is offline
Web Hosting Master
 
Join Date: Apr 2003
Location: NC
Posts: 2,911
umm...you are getting DOS'ed which is not hacking. There is nothing you can do about your webpage, it is probably some script kiddie you pissed off. The server admin should be able to do some stuff to help with the DOS but you have to wait it out. Enabling syncookies will help if he has not.

__________________
John W
www.eth0.us

Reply With Quote
  #3  
Old 05-20-2005, 12:58 PM
dkitchen dkitchen is offline
Managed Hosting Expert
 
Join Date: Jan 2004
Location: North Yorkshire, UK
Posts: 4,163
Probably nothing wrong with your scripts, someone is just syn flooding the IP you are hosted upon.

Dan

__________________
█ Dan Kitchen | Technical Director | Razorblue
█ ddi: (+44) (0)1748 900 680 | e: dkitchen@razorblue.com
█ UK Intensive Managed Hosting, Clusters and Colocation.
█ HP Servers, Cisco/Juniper Powered BGP Network (AS15692).


Reply With Quote
Sponsored Links
  #4  
Old 05-21-2005, 12:41 AM
ninteen83 ninteen83 is offline
New Member
 
Join Date: May 2005
Posts: 4
thanks eth00 and Dan

this is what I recieved from webhosting team

-----------------
Unfortunately, it was not a security hole. What has happened is your site was a victim of a DOS attack. We had to block access to your site to make sure it did not overload our servers. You will need to find out who would want your site down because they hit your site over and over again from the same location in a very short time.
-----------------

Experts ! what I have to do to get my site back working? Any way to stop these DOS attack OR make my website secure from these attacks ?

I'll be much thankful

Reply With Quote
  #5  
Old 05-21-2005, 12:43 AM
eth00 eth00 is offline
Web Hosting Master
 
Join Date: Apr 2003
Location: NC
Posts: 2,911
Nope there is nothing you can do. Any script kiddie with a botnet can randomly start attacking you. There is some stuff at a server and ISP level that can be done but they usually do little and only mitigate not prevent.

__________________
John W
www.eth0.us

Reply With Quote
  #6  
Old 05-21-2005, 04:59 AM
albatross.smart albatross.smart is offline
Junior Guru
 
Join Date: Feb 2005
Location: I am air u breathe
Posts: 229
*

Did you check up the files on your server this includes all the temperoary files that your clients uploaded. Check if there is any hidden trigger for the bots.

You can watch the logs to identify and target any particular client.

So be assured.

__________________

Al
It is reliability that counts...
Few tips

Reply With Quote
  #7  
Old 05-21-2005, 07:09 AM
ninteen83 ninteen83 is offline
New Member
 
Join Date: May 2005
Posts: 4
Quote:
Originally posted by eth00
Nope there is nothing you can do. Any script kiddie with a botnet can randomly start attacking you. There is some stuff at a server and ISP level that can be done but they usually do little and only mitigate not prevent.
They said that they will remove filter once dos wave will go down

thanks eth00

Reply With Quote
  #8  
Old 05-21-2005, 07:12 AM
ninteen83 ninteen83 is offline
New Member
 
Join Date: May 2005
Posts: 4
Quote:
Originally posted by albatross.smart
Did you check up the files on your server this includes all the temperoary files that your clients uploaded. Check if there is any hidden trigger for the bots.

You can watch the logs to identify and target any particular client.

So be assured.
hi albatross .. thanks for the reply

I'm running a phpBB2 based forum on the site. let me see if there is any such kind of files

Reply With Quote
  #9  
Old 05-21-2005, 11:56 AM
debrown3rd debrown3rd is offline
Junior Guru Wannabe
 
Join Date: May 2005
Posts: 67
Quote:
Originally posted by ninteen83
thanks eth00 and Dan

this is what I recieved from webhosting team

-----------------
Unfortunately, it was not a security hole. What has happened is your site was a victim of a DOS attack. We had to block access to your site to make sure it did not overload our servers. You will need to find out who would want your site down because they hit your site over and over again from the same location in a very short time.
-----------------

Experts ! what I have to do to get my site back working? Any way to stop these DOS attack OR make my website secure from these attacks ?

I'll be much thankful
If it is truly coming from the same location then they should be able to drop just that IP at the router and not effect your machine otherwise. Equally, I would be asking them to respond to the DOS attack since it is their network. Whoever you are hosted through isn't stepping up to the plate.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Name.com Resets Customer Passwords After Security Breach Web Hosting News 2013-05-13 14:43:19
GoGrid Partners with Boston Big Data Research Group hack/reduce With Free Cloud Hosting Web Hosting News 2012-11-08 17:42:48
Dutch Security Firm Gemnet and Certificate Authority Division Gemnet CSP Offline Following Hack Web Hosting News 2011-12-09 15:33:53
Sony Temporarily Locks Accounts After Hack Attempt Detected Web Hosting News 2011-10-12 16:21:46
Citi Says 200,000 Customers Credit Card Data Stolen in Hack Web Hosting News 2011-06-09 17:04:24


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?