    help troubleshooting? possible dos attack

    I'm having problems on one of my servers.

    Every now and then apache will fail to serve pages. Yet the service itself is not actually failing.

    A simple restart in shell corrects the problem for awhile. It's not failing around any certain intervals though.

    I've cheked the apache access and error logs - nothing seems abnormal. Also took a look at /var/log/messages - seems ok.

    The server load is always normal around 0.5.


    Are there any memory hogging apache processes (possibly php/perl)? You usually see CPU try to hit 100% usage when these flake out, but not always. Try a short rlimit in apache and see what happens if this is the case.

    Re: help troubleshooting? possible dos attack


    Do you use any control panel?, if yes tell me the details

    With regards,

    Monitor your server for a day....and see the number of connections which your machine is getting

    command to use bash# netstat -lpn |awk {'print $5'} | sort

    If there are large number of connections from single ip or if there are large connections from different ip then there is a chance of your server being DOSed or DDOSoed

    I would suggest you to install a good APF firewall and enable the DOS protection mode in it. Please read my article on Security to know more about Server Security
    Yeah - forgot to mention that it's a cPanel box.

    I am running APF and have configured the anti-dos protection.

    There is one account with a large number of processes running - all are safe/legit, however. Mostly php processes (web traffic) and some other processes/scripts which provide online stats for a gameing server and such.

    It's a Dual Xeon 2.4GhZ RHEL 3 box
    2GB RAM
    php_suexec configuration.

    I'll try your suggestions and see if I can dig up anything additonal.

    The reason I thought DOS attack was because we had an account that was under attack previously (numerous time)
    We had stopped that by adding a static .html file as the entry page - rather than the php file they were hitting.

    I was thinking maybe they realized that and better directed the attack. But traffic seems normal for this account.

    Yeah - this turned out to be a bad network card...


