Web Hosting Talk


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Track down attack target
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)

 
Thread Tools Search this Thread Display Modes
  #1  
Old 03-23-2009, 01:17 PM
papaja papaja is offline
View Beta Profile
Newbie
 
Join Date: Apr 2005
Posts: 20
Track down attack target

Hello,
I'm small hosting provider. On one dedicated server I have around 100 cPanel accounts.

That server is under constant, although not powerful DoS attack.

Since my company domain is not targeted on another server I believe that it is not me but one of my customers that attack is against.

Is there a way, tool, service provider than can help me pin down which account is being hit?

All accounts are on server main shared IP.

Would spreading them on another IPs help? Or would I still see attacks only on main shared IP?

Thanks.

Reply With Quote
Sponsored Links
  #2  
Old 03-23-2009, 08:02 PM
datarealm datarealm is offline
View Beta Profile
Junior Guru Wannabe
 
Join Date: Aug 2002
Posts: 66
To start with you could check the web logs for the sites on the server to see if a particular site has a disproportionately large log file. If that's the case, check the logs to see what's going on.

If they are not targeting a particular web site, use tcpdump to check some of the traffic coming to the box. If there is a large amount of traffic from a particular source you could drop the data with iptables, or ask your upstream to block it for you.

__________________
Datarealm Internet Services, Inc
Shared hosting
Dedicated Servers
sales @ rackmounted.com

Reply With Quote
  #3  
Old 03-23-2009, 08:43 PM
LoganNZ LoganNZ is offline
View Beta Profile
Hosting Systems Specialist
 
Join Date: Feb 2004
Location: New Zealand
Posts: 1,202
I doubt its a constant ddos attack, i would say its a script or user account which is using resources.

__________________
DigitalGoods.info
FREE Shared, Mega Resellers + Dedicated Servers

Reply With Quote
Sponsored Links
  #4  
Old 03-24-2009, 06:38 AM
papaja papaja is offline
View Beta Profile
Newbie
 
Join Date: Apr 2005
Posts: 20
I'm using netstat -anp | grep 'tcp\|udp' | sed -n -e '/[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}/p' | awk '{print$5}' | sed 's/::ffff://' | cut -d: -f1 | sort | uniq -c | sort -n

to check number of connections from particular IPs. I see IPs from Brazil, Russia, Peru, Mozambique, Vietnam... spawning hundreds of connections. Those are countries that most likely are not interested nor can understand content on my client's sites... so I think it is attack.

Anyway, if you can help me confirm your statement, I'll try it since I'm new in this and can be wrong.

Reply With Quote
  #5  
Old 03-24-2009, 12:49 PM
chaosuk chaosuk is offline
View Beta Profile
WHT Addict
 
Join Date: Jul 2008
Location: France
Posts: 105
i have been working on this with him, you wont find anything in the logs because the connection is never fully completed and therefore there is no access logs. He has this attack under control for the time being and once we find the intended target it will be very easy to stop it.

Reply With Quote
  #6  
Old 03-24-2009, 08:05 PM
vpsville vpsville is offline
View Beta Profile
Web Hosting Master
 
Join Date: Sep 2005
Location: Canada
Posts: 600
You can temporarily block the origin IP's, the attack will go away after a few days and you can remove the blocks then.

__________________
VPSVille.com
Toronto, London, Dallas, Los Angeles
Quality VPS hosting on Premium bandwidth

Reply With Quote
  #7  
Old 03-24-2009, 10:02 PM
hostingheaven hostingheaven is offline
View Beta Profile
Newbie
 
Join Date: Dec 2006
Posts: 13
Snort will help you here.

http://www.snort.org/

Reply With Quote
  #8  
Old 03-25-2009, 01:06 AM
canubeat canubeat is offline
View Beta Profile
Newbie
 
Join Date: Mar 2009
Posts: 7
You can block those attacks little bit ( not fully) using

Defeating Traffic Flooders
PHP DoS Shield


Try using tweety1.0

Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement: