hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : VPS suspended - DDoS
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

VPS suspended - DDoS

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 10-08-2009, 02:25 AM
Markovic Markovic is offline
Junior Guru
 
Join Date: Jun 2009
Posts: 182

VPS suspended - DDoS


Hello,

I won't name my VPS provider here but my VPS got suspended because I was being DDoSed and they c/ped me this:

Oct 7 00:57:43 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:57:48 vps kernel: printk: 5 messages suppressed.
Oct 7 00:57:48 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:57:53 vps kernel: printk: 93 messages suppressed.
Oct 7 00:57:53 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:57:58 vps kernel: printk: 2 messages suppressed.
Oct 7 00:57:58 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:58:03 vps kernel: printk: 105 messages suppressed.
Oct 7 00:58:03 vps kernel: ip_conntrack: CT 5500: table full, dropping packet.
Oct 7 00:58:08 vps kernel: printk: 106 messages suppressed.
Oct 7 00:58:08 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:58:14 vps kernel: printk: 67 messages suppressed.
Oct 7 00:58:14 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:58:17 vps kernel: possible SYN flooding on port 80. Sending cookies.
Oct 7 00:58:19 vps kernel: printk: 90 messages suppressed.
Oct 7 00:58:19 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:58:25 vps kernel: printk: 119 messages suppressed.
Oct 7 00:58:25 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:58:28 vps kernel: printk: 120 messages suppressed.
Oct 7 00:58:28 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:58:33 vps kernel: printk: 5 messages suppressed.
Oct 7 00:58:33 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:58:38 vps kernel: printk: 83 messages suppressed.
Oct 7 00:58:38 vps kernel: ip_conntrack: CT 5500: table full, dropping packet.
Oct 7 00:58:44 vps kernel: printk: 34 messages suppressed.
Oct 7 00:58:44 vps kernel: Orphaned socket dropped (376,752 in CT5500)
Oct 7 00:58:48 vps kernel: printk: 136 messages suppressed.
Oct 7 00:58:48 vps kernel: Orphaned socket dropped (392,784 in CT5500)
Oct 7 00:58:54 vps kernel: printk: 104 messages suppressed.
Oct 7 00:58:54 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:58:58 vps kernel: printk: 15 messages suppressed.
Oct 7 00:58:58 vps kernel: Orphaned socket dropped (387,774 in CT5500)
Oct 7 00:59:04 vps kernel: printk: 111 messages suppressed.
Oct 7 00:59:04 vps kernel: Orphaned socket dropped (398,796 in CT5500)
Oct 7 00:59:09 vps kernel: printk: 71 messages suppressed.
Oct 7 00:59:09 vps kernel: Orphaned socket dropped (398,796 in CT5500)
Oct 7 00:59:13 vps kernel: printk: 28 messages suppressed.
Oct 7 00:59:13 vps kernel: Orphaned socket dropped (399,798 in CT5500)
Oct 7 00:59:18 vps kernel: printk: 71 messages suppressed.
Oct 7 00:59:18 vps kernel: TCP: too many of orphaned sockets (400 in CT5500)
Oct 7 00:59:18 vps kernel: possible SYN flooding on port 80. Sending cookies
Oct 7 00:59:23 vps kernel: printk: 183 messages suppressed.
Oct 7 00:59:23 vps kernel: Orphaned socket dropped (399,798 in CT5500)
Oct 7 00:59:28 vps kernel: printk: 347 messages suppressed.
Oct 7 00:59:28 vps kernel: Orphaned socket dropped (392,784 in CT5500)

I would like to know what EXACLY does it mean.

Thank you

Reply With Quote


Sponsored Links
  #2  
Old 10-08-2009, 09:17 AM
inspiron inspiron is offline
Support Facility
 
Join Date: Jun 2009
Posts: 2,318
What kernel version do you use?

__________________
Support Facility | 24/7 web hosting technical support services
Technical support | Server management | Data migration

Technical Articles

Reply With Quote
  #3  
Old 10-08-2009, 09:54 AM
assistanz247 assistanz247 is offline
Web Hosting Master
 
Join Date: Nov 2004
Location: India
Posts: 1,069
Contact your Node administrators and ask them to check the kernel versions some kernels that includes 2.6.8 is having this issues.

__________________
Outsourced Webhosting Support / cPanel Server Management Since 2004
Technical Support / Web Development / Billing Support

Reply With Quote
Sponsored Links
  #4  
Old 10-08-2009, 09:57 AM
assistanz247 assistanz247 is offline
Web Hosting Master
 
Join Date: Nov 2004
Location: India
Posts: 1,069
Ask your Node admin to get a new version of kernels like 2.6.18 for your VPS and that will solve this issues.

__________________
Outsourced Webhosting Support / cPanel Server Management Since 2004
Technical Support / Web Development / Billing Support

Reply With Quote
  #5  
Old 10-08-2009, 10:13 AM
eth10 eth10 is offline
Temporarily Suspended
 
Join Date: Jul 2009
Posts: 178
Is it not the responsibility of the admin to take care of this issue instead of suspending it ?

Reply With Quote
  #6  
Old 10-08-2009, 03:41 PM
khunj khunj is offline
Web Hosting Guru
 
Join Date: Mar 2009
Location: /home/khunj
Posts: 313
It means you are under attack. You are receiving too many packets, the kernel is dropping them because your syn backlog and connection tracking table are full.
It always happens during such an attack.

__________________
NinTechNet : IT Security, Virus & Hacking Recovery, Monitoring

Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
(USA) DDOS Protected VPS plans - DDOS-VPS are fully DDOS Protected! scan-host VPS Hosting Offers 3 06-08-2009 01:53 PM
(USA) DDOS Protected VPS plans - DDOS-VPS are fully DDOS Protected! scan-host VPS Hosting Offers 0 06-01-2009 02:39 AM
Got DDoS? BLCC DDoS Protection sale! Stop HTTP GET attacks in their tracks! IRCCo Jeff Dedicated Hosting Offers 7 01-17-2007 12:49 PM
Suspended site is not suspended junglecat Dedicated Server 4 12-23-2006 10:19 PM

Related posts from TheWhir.com
Title Type Date Posted
DDoS Mitigation Provider Prolexic Blocks Extended DDoS Attack Against Ecommerce Website Parts Geek Web Hosting News 2012-11-07 10:57:01
Security Firm Prolexic Launches Online Resource Portal for DDoS Mitigation Web Hosting News 2012-01-19 12:55:48
Web Host Yola Uses DDoS Mitigation Service Prolexic Web Hosting News 2011-12-07 20:42:42
New on WHIR TV: Kevin Hatfield of ServerOrigin Talks DDoS Protection Blog 2011-11-10 15:19:09
WHIR TV - Rick from Neustar Discusses DDOS Threats and Defense Blog 2011-09-23 13:52:45


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?