hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Is this a DDoS attack?
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

Is this a DDoS attack?

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 08-04-2009, 01:57 PM
pedro2010 pedro2010 is offline
WHT Addict
 
Join Date: Apr 2009
Location: Spain
Posts: 129

Is this a DDoS attack?


Hi,
I have a windows server, and today it has a large inbound traffic, so I tried to disable all web service, and after that, the result of netstat -an shows no connection at all, but the server still has large inbound traffic,

Do you have any idea about this?

What should I do now?

Reply With Quote


Sponsored Links
  #2  
Old 08-04-2009, 07:33 PM
Crashus Crashus is offline
Corporate Member
 
Join Date: Apr 2009
Posts: 801
try to disable ICMP in your firewall (ping to your server)

Reply With Quote
  #3  
Old 08-05-2009, 02:24 AM
plumsauce plumsauce is offline
******* Unleaded
 
Join Date: Feb 2004
Posts: 3,790
Quote:
Originally Posted by Crashus View Post
try to disable ICMP in your firewall (ping to your server)
In fact that increases traffic to your server when services are down because it can't send back an "unreachable" response.

@OP

you say "large inbound traffic", you need to be more specific.

for example protocol, target port?

__________________
edgedirector.com
managed dns global failover and load balance (gslb)
exactstate.com
uptime report for webhostingtalk.com

Reply With Quote
Sponsored Links
  #4  
Old 08-05-2009, 04:34 AM
MikeDVB MikeDVB is offline
Web Host Extraordinaire!!!
 
Join Date: Dec 2007
Location: Indianapolis, Indiana USA
Posts: 14,333
It's near impossible to answer your question based on what little information you have provided. As plumsauce asked - please provide more details. If you don't know how to find these details then you may want to look into paying somebody to look into it for you.

__________________
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
For high-end shared accounts ideal for business, check out our Semi-Dedicated offerings!
http://www.mddhosting.com/ - Providing Quality Services since 2007

Reply With Quote
  #5  
Old 08-05-2009, 06:36 AM
pedro2010 pedro2010 is offline
WHT Addict
 
Join Date: Apr 2009
Location: Spain
Posts: 129
hi,
I have disabled all servcie, but when I check the ethenet card, it shows about 50Mbps inbound traffic, I do not know its target port as the result of "netstat -an" shows nothing.

Reply With Quote
  #6  
Old 08-05-2009, 11:08 AM
mrwillt mrwillt is offline
Newbie
 
Join Date: Jul 2009
Location: Leeds - UK
Posts: 14
Another thing to note possibly, is it actually causing your server to slow? 50Mbps isn't "huge" so would be good to try and figure out what sort of packets are being sent to the server.

If the server is becoming unresponsive, the first conclusion could be a DOS however its a word people love to throw around without a little research.

Have you disabled FTP? thats a classic for getting hacked.

Reply With Quote
  #7  
Old 08-05-2009, 11:48 AM
eth10 eth10 is offline
Temporarily Suspended
 
Join Date: Jul 2009
Posts: 178
Hello check it a single IP address is creating lot of traffic.if yes block them.No need to disabling services for that

Reply With Quote
  #8  
Old 08-05-2009, 06:05 PM
MikeDVB MikeDVB is offline
Web Host Extraordinaire!!!
 
Join Date: Dec 2007
Location: Indianapolis, Indiana USA
Posts: 14,333
You could perhaps contact your Data Center and have them investigate this for you as they should be able to do something about it (hopefully) if you are actually under attack.

If you are paying for inbound traffic 50mbps is going to rack up fast.

__________________
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
For high-end shared accounts ideal for business, check out our Semi-Dedicated offerings!
http://www.mddhosting.com/ - Providing Quality Services since 2007

Reply With Quote
  #9  
Old 08-05-2009, 06:07 PM
mrwillt mrwillt is offline
Newbie
 
Join Date: Jul 2009
Location: Leeds - UK
Posts: 14
Quote:
Originally Posted by eth10 View Post
Hello check it a single IP address is creating lot of traffic.if yes block them.No need to disabling services for that
Good point, but highly unlikely that it will be coming from 1 IP if it were to be a DOS attack.

Most likely the complete opposite and you'll see thousands upon thousands of connections probably with 3-4 connections open per IP.

Sadly I'm no Microsoft expert and office is shut so can't ask the guys that would know, but with Linux you can script a small bash script that will filter out ip's above X connections.

__________________
Will Thomas - Britband Media Ltd
Low cost UK VPS - switchlink.co.uk
Automated remote backup - Instant Setup - Full control

Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
Is this a DDoS Attack or no? okhud Dedicated Server 41 07-13-2009 02:21 PM
DDoS attack newbie_security Hosting Security and Technology 12 05-26-2009 06:11 PM
Ddos attack - help us : ( sakibin Dedicated Server 8 03-19-2008 10:11 AM
am i under a ddos attack pbigmoon Hosting Security and Technology 15 06-24-2007 12:15 AM
Ddos Attack Need Help Please Navid1 Hosting Security and Technology 1 12-31-2006 01:38 AM

Related posts from TheWhir.com
Title Type Date Posted
Three DNS Hosting Providers Report Possibly Linked DDoS Attacks Web Hosting News 2013-06-05 16:50:15
Blogging Site LiveJournal Hit by Ongoing DDoS Attack Web Hosting News 2011-12-08 16:35:38
4Chan Website Back Online After Days of Sustained DDoS Attack Web Hosting News 2011-11-16 15:44:05
Web Host Netregistry Hit by DDoS Attack Web Hosting News 2011-09-26 14:11:33
WHIR TV - Rick from Neustar Discusses DDOS Threats and Defense Blog 2011-09-23 13:52:45


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?