How To Detect Is It Domain Name Server (DNS) Or Http Down?
			Aug 1, 2009
				If i put domain.com on uptime checker,and downtime is detected,downtime will be reported if dns is down or if http server is down.So question is what i need to do to see what exactly went down?For network uptime i can ping ip adress,but for these two i really don't know.
	
	View 3 Replies
  
    
	ADVERTISEMENT
    	
    	
        Mar 10, 2008
        I've setup a dedicated server that is currently running with a domain bound to it. However this time I want to setup a centos 5.1 + latest apache 2 + bind 9 server that can only be connected to by IP address and doesn't have a domain name. So what do I need to modify in the below files to do so:
First of all will I even need bind at all? I already have it setup and (mis-)configured but I guess if I don't need it I can just take if off of autostart and stop the process "named".
Named.conf
options {
pid-file "/var/named/chroot/var/run/named/named.pid";
directory "/var/named/chroot/var/named";
query-source address * port 53;
allow-query { any; };
allow-transfer { };
recursion no;
notify no;
version "unknown";
};
logging {
category default { null; };
};
zone "server.domain.com" { type master; file "server.domain.com.db"; };
I don't even want the zone have domain.com in its name but that's just there so I could show you how I'd include server.domain.com.db.
server.domain.com.db
$TTL 14400
@       IN      SOA     ns1.domain.com.      root.server.domain.com. (
                                                2007052503
                                                14400
                                                3600
                                                1209600
                                                86400 )
server.domain.com.    14400    IN    NS    ns1.domain.com.
server.domain.com.    14400    IN    NS    ns2.domain.com.
localhost    14400    IN    A    127.0.0.1
www    14400    IN    A    78.129.174.164
I'm not sure what to do about those references to domain.com here, they shouldn't be needed but without them I don't know what to put here. ^^
Obviously I can't use those nameservers...
resolv.conf
nameserver 127.0.0.1
nameserver 78.129.143.155
nameserver 87.117.198.200
nameserver 87.117.196.200
The only thing missing from this file is "search domain.com" at the top, is that needed even though I won't really have any domains used by this server?
/etc/hosts:
# Do not remove the following line, or various programs
# that require network functionality will fail ....
	View 7 Replies
    View Related
  
    
	
    	
    	
        Apr 6, 2009
        I have a server of my own. Unfortunatlly 20% of the time, the server is down even though my connection to internet always up.
I am checking the event log but cannot see anything odd...
OS:Windows server 2003
Is there any tool to detect why the server is down most of the time?
I can post the event viewer errors that I can find suspeicious if needed.
	View 2 Replies
    View Related
  
    
	
    	
    	
        Oct 29, 2007
        How does one go about detecting what mail server software you have installed and running on your server?
	View 2 Replies
    View Related
  
    
	
    	
    	
        Mar 22, 2007
        I am suspecting that we have spyware or virus on our server. How do I detect and remove it from windows 2003 server?
	View 6 Replies
    View Related
  
    
	
    	
    	
        Jun 22, 2007
        how i can limit http and mysql connection limit on per domain basis. 
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jun 1, 2007
        my friend's server is being attacked, the http processes shoots up causing the server load to go above 200 in minutes of starting httpd which causes server to die. 
this is how the apache web server's access_log would log a normal http request;
------------------------------------------------------
"xx.xxx.xx.xx - - [01/Jun/2007:22:13:21] "GET /folder/name.gif HTTP/1.1" 200 877 [url]"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)"
------------------------------------------------------
Today when the http load increased we saw hundreds of following requests;
------------------------------------------------------
"xx.xxx.xx.xx - - [01/Jun/2007:22:13:21] "GET /? HTTP/1.1" 200 16305 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
------------------------------------------------------
You see the difference between a legitimate http access log entry and the above one is that the legitimate one shows the filename(GET /folder/name.gif) and domain name being requested whereas the second one shows ("GET /?")
Above requests continously originate from 30 to 40 different ip addresses. Most of them russian ips, and many form US and canada to.
When i do a grep "GET /?" in access log there are thousands of these which started just today.
I cannot block each ips because i feel they have hundreds of IPs to initiate these requests from.
	View 14 Replies
    View Related
  
    
	
    	
    	
        Oct 21, 2007
        I am trying to install a FTP Server in my computer so that I can simply login into my own computer to grab important files at work... since carrying laptop and loosing flash drives are becoming annoying .
In my home computer I have Linksys Router, and Verizon as my ISP (blocks port 80, 21 I believe).
Since Verizon blocks those ports the configuration has become a nightmare.
Using BulletProof FTP Server I made the FTP Server listen to port 5000. And in my router's forwarding section I opened the port 5000, and made it listen to 192.168.1.100 (Port Range Forwarding, TCP UDP both).
I did the same for my Apache server and made it to work with port 443. 
When I access [url] the web server loads up fine.
But when I try [url] it doesn't load up, where 1.2.3.4 is my IP.
When I visit just my IP in the web browser, it loads up the Router Configuration page.
And the FTP server doesn't connect when I try with the 
	View 1 Replies
    View Related
  
    
	
    	
    	
        May 11, 2009
        I need to find out what would be the best software to run an image website for one of my clients, there is only one domain so I've considered using LiteSpeed Standard (Free)... What server do you think would be the best?
All I need is PHP support for the image viewer software.
Apache
Lighttpd
LiteSpeed
nginx
	View 14 Replies
    View Related
  
    
	
    	
    	
        Jun 28, 2007
        SO the last few months I been trying like crazy to tweak Apache or find a better http setup such as running lighttpd with Apache, etc. I have been frustrated by the way Apache easily fork bombs under any decent load or dos attack. You get about 100 bots all making 30+ connections a piece on Apache and it kills it.
Bot kids have adapted to ddos protection and connection flooding banning by sending low bandwidth attacks that do not make enough connections to get banned if you do have protection, its real low bandwidth incoming but is like a massive vampire attack outgoing.  And it destroys Apache no matter what you do, what modules you have, etc. You basically have to go in and manually ban or set your connection tracking limit down to where it starts banning regular users too.
So I seen on here somewhere someone recommending litespeed to someone so I went and checked it out and was amazed by the performance. I installed the trial enterprise in a p4 server I been having problems out of lately crashing all because a busy site and I installed it in my main server.
The only thing I needed to do was compile my own php5 for it, which is real easy via their wiki instruction. After a few snags here in there I finally got it working tip top on both servers, both of which are cpanel.
So with the p4 that was always crashing and keeping hi load, We would end up having to remote reboot that box almost once a week not due to any misconfiguration or wrong setup, just couldnt take all that Apache usage and would die. We instantly noticed a difference with litespeed. The average load used to be about 1-2 always, with litespeed the average stayed about ..2 even under heavy traffic. So this was a big improvement and we have not had to reboot that box since.
My main server which I take my high risk clients on, core2duo 2.4. I thought there for a Lil bit the sites were starting to outgrow the server as its average load always was around 1 which was fairly acceptable seeing the traffic it gets so normal for Apache. 
During the low bandwidth ddos attacks I would have to go in and manually ban as well as setting connection limit way down just to keep it from lagging, most of the time it still did. So I was really wanting to do something for this server to optimize http without upgrading, because it seems most of your hardware upgrades are to suit Apache anyway.
So I installed litespeed on my main server, ran into a few snags here and there but eventually got it under control. Just the last few days I got to see it put to the test. 
I took on a client who was being extorted by a ddoser who recently got him kicked off his previous host. SO as soon as dns resolves here comes the crapstorm. A low bandwidth http attack, a lot got by ddos firewall on the network level which these are hard to stop because they are so similar to a legit user.
So I started getting hundreds of csf connection tracking blocked emails, was checking the site periodically and it loaded fine. So I logged in the box, looked at the load. 
Was at .24. When I done netstat command there was hundreds of syns coming in and about 250 ips all connected about 50 times, this would normally kill Apache no matter what CPU/ram and all that you have. So I set connection tracking down to a reasonable level, 60 connections and I figured I would just let them get themselves banned. Looking in the live stats in the litespeed admin panel which is real cool BTW. I was seeing about 400 requests a second. This was eating a Lil bandwidth, all outgoing as that is how the attack works like a massive vamp attack. So about 2000 connection tracking emails later finally gets em all banned. The entire time the load on that box never even got to 1!
So im pretty much amazed how fast and light this http server is. And especially how well it handles dos. I about know for a fact even if you was on a non protected network it could handle as much http as your pipe will give it, and do all this at a low resource load.
This will end up saving me money on hardware upgrades in the future as well. Long review, long story, but I been so amazed by this http server I had to make a review on it. Im sure some geniouses will try to say "If you do this and that with apache you can make it just as good"  But check it out for yourselves and see.
	View 14 Replies
    View Related
  
    
	
    	
    	
        Oct 8, 2007
        There seems to be some problem with my server, none of the websites hosted on my server are accessible, the http requests either return a blank page or a page with a red quare on the upper left hand corner.
I am not sure if this is some kind of infection or DNS problem or a problem with memory apache is taking up
as i have thousands of virtualhost entries in my access log accumulated over the years out of which only a few 100 websites i am serving presently, but never deleted the non-exitent virtualhost blocks.
At times the websites are opening but most of the times they are not. And when they do not open my http requets are not logged in apacha access log.
Even the customers have reported the same problem.
Also, just four days back i had a strange issue where all
http requests to my server would take me to [url].
I can SSH to server, and everything else is working fine.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Aug 29, 2007
        tried to download files from http links to my ftp server. i looked all over the forums but could not find any services. google spitted out this one. [url]Well, it really does help to upload http links to an ftp server and move files from one ftp server to another. does anyone know other services or free scripts that help to do this?
	View 0 Replies
    View Related
  
    
	
    	
    	
        Mar 15, 2007
        I'm using IIS v5.1 on WinXP SP1 and I encountered this error (Page cannot be displayed.....HTTP 500 - internal server error) all of a sudden. now, i've been using my Web server with no hitches, but now I can't open any pages on the server that run server side scripts so i reinstalled it and still get the same "Page cannot be displayed" or I get part of the source code for the server side script. Pinging the server shows that its ok, it replies. and regular pages with no scripts still run with the http protocol in the address. Any ideas on how to get past this problem? 
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jun 27, 2013
        its possible to do a P2V migration of a Apache http server 2.2
Present environment:
Windows 2003 
Apache http server 2.0.63
There are 2 webservers (running Apache) for load balancing. The backend server runs an application which uses an oracle database. Is a P2V migration of the web servers possible?
	View 2 Replies
    View Related
  
    
	
    	
    	
        Sep 22, 2009
        I installed apache, mysql, php on my windows vista laptop, and want to test http downloading. This means when selecting a file (for example, contact.php) from a page, and then click download, it will be downloaded to my desktop.
 
Do we need to install any other softwares to do that?
	View 10 Replies
    View Related
  
    
	
    	
    	
        Jun 16, 2009
        I have done this with .htaccess on apche but I am looking to do HTTP to HTTPS redirect for all requests on Zeus server using rewite.script
what I want basically is that all request to [url]goes to [url]
	View 0 Replies
    View Related
  
    
	
    	
    	
        Nov 26, 2008
        to display the server load average through HTTP. How may I do that?
Please note that I have all insecure functions disabled, such as exec, system, etc... But I have root access.
	View 11 Replies
    View Related
  
    
	
    	
    	
        Jun 13, 2008
        I have a Linux server running some reasonable setups:
Opteron 180, 4 GB RAM, running 8x 36gb 15k scsi with hardware raid 10 -- this is one of the servers from WebNX advertised here not long ago
Running CentOS 4(?), Apache2/MySql 4/PHP5.2, the normal stuff.
I have only one main site on the server, which runs a pretty old PostNuke CMS in Chinese (0.7.2.3 Phoenix) + PNphpBB2 + Gallery 1.5.7 (all integrated into PostNuke). This site is pretty light in "human" traffic, getting about 20K hits per day.
Now, the problem I have noticed with this site, is related to the many MP3 files stored in the Gallery albums. There are lots of HTTP requests to these files, most maybe from Chinese search engine bots (judging from IP), that slows the server to a crawl and even crashes Apache. This happens in the late hours here when it's day time in China. As a matter of fact I just did a reboot, and in 5 minutes there are more than 1000 HTTP requests to MP3 files resulting in a traffic of 2.1+ Gb. So within minutes, the server is brought to its knees again and I can't even get the "apache status" from CPanel now: "Unable to retrieve apache status". 
The company that manages the server for me said there's no security problem here. We have installed an Apache extension to limit the number of simultaneous requests to media files to 1. However that doesn't seem to help. 
	View 6 Replies
    View Related
  
    
	
    	
    	
        May 6, 2013
        I have an Xitami server and am migrating to apache httpd. I have the regular server working fine. I tried configuring ssl, but no requests are coming through. I know 443 is open on the router because it works fine under Xitami. I checked the logs and it si starting fine. I am attaching my httpd.conf and the startup log. If I try to access the website using https, it just times out and nothing goes in the log file. I replaced my domain with domain.com. I have tried many different examples, but cannot get it to work and am not sure what to do. 
	View 5 Replies
    View Related
  
    
	
    	
    	
        Apr 21, 2009
        How do you know your clients are sending bulk/spam emails?
I don't seem to understand the reports in "Email >> View Mail Statistics" section of WHM.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Jul 25, 2009
        I have a private vps server works under linux ( centos ), sometimes am getting msg from csf/firewall subject:
lfd on website.com: Suspicious process running under user user account
when i check my cpanel/whm vps ( service status ) its shows that the memory limit 80% - 85% , It's had a good forum works with vb, but am wonder how to check my vps memory, i mean how to detect if there any script, or malware, or anything takes the vps memory out...
Is there any way to check,know what works under my vps, so it's take my memory limit 85%?
i check the tmp folder,
root@www [/home]# cd /tmp
root@www [/tmp]# ls -la
total 364
drwxrwxrwt  6 root root   4096 Jul 25 02:14 ./
drwxr-xr-x 21 root root   4096 Jul 18 02:21 ../
drwxrwxrwt  2 root root   4096 Jun 30 05:50 .ICE-unix/
drwxrwxrwx 18 root root   4096 Jul  2 17:33 eaccelerator/
lrwxrwxrwx  1 root root     27 Jul 18 02:13 mysql.sock -> ../var/lib/mysql/mysql.sock=
drwxr-xr-x  3 root root   4096 Jun 30 05:29 pear/
drwx------  3 root root   4096 Jul  5 18:31 spamd-23647-init/
-rw-------  1 root root 343335 Jul 19 02:50 whatis.bk6140
root@www [/tmp]# cd /home
and the df space
root@www [~]# df -h
Filesystem            Size  Used Avail Use% Mounted on
/dev/simfs             80G  4.1G   76G   6% /
root@www [~]#
and the services running is 
USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
root         1  0.0  0.0   2060   156 ?        Ss   Jun30   1:23 init [3]      
root      7465  0.0  0.0   2444   156 ?        S    Jul03   0:00 /bin/sh /usr/bin/mysqld_safe --datadir=/var/lib/mysql --pid-file=/var/lib/mysql/www.website.com.pid
mysql     7491  0.0  2.5  33452 10440 ?        Sl   Jul03  11:33 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/www.website.com.pid --skip-external-locking
root     10236  0.0  6.0  27396 24764 ?        Ss   Jul24   0:07 /usr/bin/spamd -d --allowed-ips=127.0.0.1 --pidfile=/var/run/spamd.pid --max-children=3 --max-spare=1
root     11447  0.0  1.9  18364  8020 ?        S    Jul24   0:00 cpsrvd - waiting for connections
root     11865  0.0  0.7  13672  3260 ?        S    Jul06   0:00 /usr/local/apache/bin/httpd -k start -DSSL
root     13537  0.0  3.1  15092 13064 ?        Ss   00:00   0:02 lfd - sleeping
root     13703  0.0  0.3   3808  1284 ?        SN   Jul06   0:01 cpanellogd - sleeping for logs
root     13739  0.0  0.6   5856  2844 ?        Ss   Jul06   0:00 cPhulkd - processor
root     13795  0.0  1.5  14760  6304 ?        S    Jul06   0:00 cpdavd - accepting connections on 2077 and 2078
root     18161  0.0  0.0   1716   380 ?        Ss   Jun30   0:24 syslogd -m 0
root     18164  0.0  0.0   1668    72 ?        Ss   Jun30   0:00 klogd -x
dbus     18193  0.0  0.0   2736   212 ?        Ss   Jun30   0:00 dbus-daemon --system
root     18213  0.0  0.0   2716   172 ?        Ss   Jun30   0:00 xinetd -stayalive -pidfile /var/run/xinetd.pid
root     18399  0.0  5.9  27604 24404 ?        S    Jul24   0:06 spamd child
root     19461  0.0  0.1   3228   684 ?        Ss   Jun30   0:08 crond
root     19616  0.0  0.0   1820   124 ?        Ss   Jun30   0:00 /usr/sbin/portsentry -
	View 7 Replies
    View Related
  
    
	
    	
    	
        May 4, 2008
        My server run after 10h sevices ftp is down (network error: connection timed out). may be flood ftp.
how to Detect flood ftp.
	View 4 Replies
    View Related
  
    
	
    	
    	
        May 22, 2007
        I have a few incomplete steps to see if I got some intruder in my Linux system.. But i really would like to have all your suggestions to make a good doc about this matter, 
1.- Download and run Rkhunter & Chkrootkit
2.- Run "w", and "netstat -nalp |grep "SHPORTHERE" to see whos connected using SSH
3.- Search for ssh and ftp accepted logins.
Code:
last
cat /var/log/secure* | grep ssh | grep Accept
cat /var/log/secure* |grep ftp |grep Accept
less /var/log/messages | grep ftp
4.-  Watch current connections and scan your ports.
Code:
netstat -nalp
nmap 1-65535 localhost
5.- Search for suspicious content on common explotable dirs.
Code:
rm -rf /tmp/sess*
rm -rf /var/dos-*
rm -rf /var/tmp/ssh-*
rm -rf /var/tmp/dos-*
ls /tmp -lab
ls /var/tmp -labR
ls /dev/shm -labR
ls /usr/local/apache/proxy -labR
ls /usr/local/samba -labR
6.- Checking for anomalies on this files. 
Code:
less /etc/passwd 
less /etc/shadow
less /etc/groups
7.- Search for new users at sudoers, check wtmp and telnet is not running.
Code:
cat /etc/sudoers
who /var/log/wtmp
cat /etc/xinetd.d/telnet
8.- Find bash history files
Code:
find '/' -iname .bash_history
9 .- Verify the Crontab table
Code:
crontab -l
10 .- Update the slocate database and search for exploits.
Code:
updatedb &
For cPanel servers:
Code:
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20' /usr/local/apache/logs/*
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20' /home/*/statistics/logs/*
For Ensim servers:
Code:
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20'/home/virtual/site*/fst/var/log/httpd/*
Search for shell code:
Code:
cat /path/of/your/web/logs/* |grep "/x90/"
11.- Search for hidden dirs
Code:
locate "..."
locate ".. "
rlocate " .."
locate ". "
locate " ."
12.- Search for perl-scripts running
Code:
ps -aux | grep perl
13 .- Checking nobody user and open files.
Code:
service httpd stop
lsof -u nobody
	View 14 Replies
    View Related
  
    
	
    	
    	
        Jul 24, 2009
        When i try to open any website hosted on my server (around 50 of them) i am being taken to following malware website;
[url]
[url]
This is a problem with my Limnux server running Apache and not a virus on my local computer as customers from all over are reporting the same issue.
As soon as i restart Apache eveything returns to normal with no such redirects. 
I think my server is being attacked causing http requests to get redirected to some malicious website. 
This issue would resurface almost every hour and would not go away till i restart apache.
So far my Datacenter techs. have not been able to identify the cause of this.
	View 14 Replies
    View Related
  
    
	
    	
    	
        Mar 30, 2008
        i get this error after installation my vb in my site
	View 14 Replies
    View Related
  
    
	
    	
    	
        Jan 10, 2008
        in one of our dedicated servers, when we go to WHM/Service Status / CPU Memory MySQL usage.. http server and MySQL process appears all 3 times...
is that normal?
i attach an email to be more clear.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Jul 31, 2008
        currently i am on OVH...and ovh's speeds are amazing when it comes to torrenting..and stuff..no problems whatsoever till now..but i am looking for a modest budget server than will give me good http speeds average 400-500KB/sec ...i dont care much abt the hard drive space..even a 40 geg hard drive will do..but all i need is a good RAM..i am expecting 300-400 max users to download from the server using http..concurrent connections may be not more than 150..so i definitely need a good RAM..3 gegs i presume? budget: preferably less than 100 dollars
	View 2 Replies
    View Related
  
    
	
    	
    	
        Apr 24, 2014
        I'm trying to set up password protection on an Apache HTTP server, and it's not working.
First, the environment: Apache 2.4.4 installed with XAMPP Control Panel 3.2.1 under Windows 7 Professional.
http.config says "AllowOverride All."
The .htaccess file in the protected directory says:
Code:
htpasswd -c .htpasswd samples
htpasswd prompted me for the password twice, and I entered it twice. When it quit I had a file named .htpasswd in the subsidy directory. I typed it and its contents looked correct according to the examples I've seen. 
Then I restarted Apache and tried to load a page from the directory. The browser simply prompted me for the username and password over and over. 
The Apache error log says, "AH01617: user samples: authentication failure for "/subsidy/filename.html": Password Mismatch." 
I deleted the .htpasswd file and ran htpasswd again, specifying a different (very simple) password. I also confirmed that caps lock was not on both before and after. I restarted the server, tried to load a page, and got the same problem. 
Apache seems to think I'm entering the wrong password, but that seems impossible when I've just defined it myself -- and I've tried twice, intentionally choosing a very simple password the second time. If the message means what it says, the cause must be something very different from the obvious one. 
	View 1 Replies
    View Related
  
    
	
    	
    	
        Jan 31, 2014
        I'm running Apache 2.4.7 on a RHEL 6.4 server.  I'm using the Oracle WebLogic Proxy Plugin ver 12.c to connect to a back end server.What's happening is that Apache answers URL.. and proxies the request via the WebLogic Proxy Plugin to internal.blah.com.  Unfortunately, the downstream system encounters a problem and issues an http 302 redirect to internal.blah.com/whathappened. I would like to have Apache intercept this http 302 and redirect the client to URL...
	View 1 Replies
    View Related
  
    
	
    	
    	
        Nov 22, 2013
        I am tried to integrate Apache HTTP server and JBoss app server 7 with mod_jk module plugin in Apache.I have two instances of Jboss running and Apache server sends requests to them.I have added following code in "httpd.conf" of Apache:
Code:	
LoadModule proxy_module modules/mod_proxy.so
LoadModule proxy_connect_module modules/mod_proxy_connect.so
LoadModule proxy_http_module modules/mod_proxy_http.so
JkWorkersFile "D:/Program Files/Apache Group/Apache2/conf/workers.properties"
JkShmFile     "D:/Program Files/Apache Group/Apache2/logs/mod_jk.shm"
JkLogFile     "D:/Program Files/Apache Group/Apache2/logs/mod_jk.log"
[Code] ....
But, though I have configured this way, when my worker1 goes down,Apache is not sending requests to worker2 and I get "Service Temporarily Unavailable" message. 
	View 1 Replies
    View Related