Currently, we use powerdns with mysql replication on multiple servers. This solution is kindda okay for now but I'd like to know if there is any other better solutions than powerdns.
For the last 6 months our site has been under severe brute force, syn flood attack. They keep bombarding a single URL of the server and it is xml file. They are not attacking any other URL.
We have removed the xml page from our site but still they keep on sending requests, this is for the last 6 months non stop.
The IP has been changed just to see and they are sending several thousand requests per second. The requests come from different IPS and different ranges, so you can not even block the IP’s. They seem to be coming from a legitimate IP’s.
Due to this I have had to pay for an extremely expensive server which holds 8 GB of RAM and quad core processor etc, however, even with this the server server still reaches critical level, just because these requests are eating up my resources.
Our technical team has been working on all aspects of apache server security, external modules, firewall, hardware firewall from beginning but still we are not able to stop them.
We have installed following modules.
4) mod_security
5) mod_evasive
6) Firewall
7) SYS_Cookies enabled
We have worked with the hosting company and their technical team leader, he installed the best CISCO hardware firewall and tried to stop them, but in vain.
We have checked our server to see if anything from our site is causing the request, no extra file uploaded on to the server. For example if some file has been upload or some text has been added to the file (checked if we’ve been hacked). Even though we checked for any hacks, I am still wondering if there is something we do not know about. Can a hack lead to huge amounts of traffic?
We need some help to stop these attacks. We have searched a lot and have found that sites that get attacked like this have only one option is to shut down till it stops. I really hope that will not be the case for us. Please let us know if any one has any ideas to deal with this.
Also could it be our own part of php code which can do this? We are ready to check every php file to make sure it does not have any line of code which can be dangerous?
We worked with hardware firewall company to drop a request on the spot coming for the single URL but it is getting setup.
We have antivirus running on server however if any specific antivirus or antimalware is needed, we can try that.
Following are the details I have got from my linux admin. This will help you to trace the issue in better way. Problem: Apache SYN_RECV
OS - RHEL5 kernels - 2.6.18-92.1.22.el5-x86_64 2.6.18-92.el5-x86_64
OS Type: cat /etc/issue Red Hat Enterprise Linux Server release 5.2 (Tikanga) > cat /proc/version Linux version 2.6.18-92.1.22.el5 (mockbuild@hs20-bc2-5.build.redhat.com) (gcc version 4.1.2 20071124 (Red Hat 4.1.2-42)) #1 SMP Fri Dec 5 09:28:22 EST 2008
Following we have done till now is mentioned below for the configurations.
############### sysctl.conf
############## # Kernel sysctl configuration file for Red Hat Linux # # For binary values, 0 is disabled, 1 is enabled. See sysctl(8) and # sysctl.conf(5) for more details.
# Controls IP packet forwarding net.ipv4.ip_forward = 0
# Do not accept source routing net.ipv4.conf.default.accept_source_route = 0
# Controls the System Request debugging functionality of the kernel kernel.sysrq = 0
# Controls whether core dumps will append the PID to the core filename # Useful for debugging multi-threaded applications kernel.core_uses_pid = 1
# Controls the use of TCP syncookies net.ipv4.tcp_syncookies = 1
# Controls the maximum size of a message, in bytes kernel.msgmnb = 65536
# Controls the default maxmimum size of a mesage queue kernel.msgmax = 65536
# Controls the maximum shared segment size, in bytes kernel.shmmax = 68719476736
# Controls the maximum number of shared memory segments, in pages kernel.shmall = 4294967296 net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_synack_retries = 2 # Enable IP spoofing protection, turn on Source Address Verification net.ipv4.conf.all.rp_filter = 1 # Enable TCP SYN Cookie Protection net.ipv4.tcp_syncookies = 1
# 65536 seems to be the max it will take net.ipv4.ip_conntrack_max = 1048576 net.ipv4.tcp_rmem = 4096 87380 8388608 net.ipv4.tcp_wmem = 4096 87380 8388608 net.core.rmem_max = 8388608 net.core.wmem_max = 8388608 net.core.netdev_max_backlog = 5000 net.ipv4.tcp_window_scaling = 1
I am running a very successful wiki based website that has outgrown our current web host. The site runs very slow because our host says we are hitting the memory limit on the server (currently under a shard hosting plan).
Thousands of visitors per day Ten thousand page views per day (all PHP) 20GB bandwidth per month MySQL database
I'm trying to tar a folder that has 100's of thousands of files and I ensured that no files are being added or modified in that folder while the below command is being executed:
nice --adjustment=20 tar -cf users_from.tar users_from
I've tried it multiple times and it always stops before it finishes and ends up with a corrupted .tar file which gives errors when extracted and is obviously missing a lot of files. Sometimes it creates 200+ MB, sometimes 50 MB before it stops.
I also have enough RAM + swap for the operation so that can't be the cause. So is it just impossible to tar a directory with so many files and is it even possible to get a list of the files in that directory?
My sever is running mailscanner-4.56.8-1. Of late many of our customers complain that mails send To and From our server take hours to be delievered.
I tested this myself by sending test emails to and from my hotmail account which took long time to be received and delivered.
Also, in /var/log/maillog i see entries such as the one below; "Jan 4 20:39:36 www MailScanner[8461]: New Batch: Found 17678 messages waiting "
So i understand there is about 18 thousand emails in MailScanner /var/spool/mqueue.in folder.
To test i stopped MailScanner and started Sendmail, i send an email to my hotmail id and it got delievered immediately, but when i restart MailScanner and resend the same message it took 20mins to get delievered.
- how do i improve MailScanner processing so that messages are delivered faster? - Do i need to change the "Max Children = 5" variable in /etc/MailScanner/MailScanner.conf? - how do i force delivery of the 18thousand emails in mqueue.in folder?
For the last 5 days, exim has been retrying to resend email to a recipent every 1 millisecond.
As result, logs are huge, and load is being affected.
So I'd like to know how can I set/configure exim to ingore sending to any email I'd tell it.
I mean is there any config file I can look into, to set a ignore list, or even how to have it so that it retries sending every 1 hour, instead of every 1 millisecond.
I am having problem with a server. On all sites on the server start appearing core.xxxx files that in result fill server. Quotas were disabled because some people had issues logging in on because of error.
Quote:
Sorry for the inconvenience!
The filesystem mounted at /home/*** on this server is running out of disk space. cPanel operations have been temporarily suspended to prevent something bad from happening.
Please ask your system admin to remove any files not in use on that partition.
how to remove all of them so they dont appear again, on some sites there are thousands of core.xxxx files and weigh over 60GB.
Sep 4 19:11:11 debian sm-mta[25383]: l84FYDPw016811: to=, ctladdr= (2001/2001), delay=01:36:58, xdelay=00:00:00, mailer=esmtp, pri=930403, relay=lsean.ezweb.ne.jp., dsn=4.0.0, stat=Deferred: Connection timed out with lsean.ezweb.ne.jp. We're absolutely unable to track or find out who is sending it or how to stop this.
So I'm wondering if it is possible to prevent sendmail from sending to:
lsean.ezweb.ne.jp, OR docomo.ne.jp, OR softbank.ne.jp
/var/mail/vhostswww logs are not showing helpful info at all. Eg:
Code: --l84GRnX5029819.1188924137/debian--
Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset=ISO-2022-JP Mime-Version: 1.0 From: hanako.@docomo.ne.jp Subject: To: a_j.n-y_bluespider-tattoo@softbank.ne.jp Message-Id: <200709041410.l84EA0Fh007971@debian> Date: Tue, 4 Sep 2007 16:10:00 +0200 Tue, 4 Sep 2007 16:10:00 +0200 by debian (8.13.4/8.13.4/Submit) id l84EA0Fh007971; Received: (from vhostswww@localhost) for ; Tue, 4 Sep 2007 16:10:00 +0200 by debian (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l84EA0jk007973 Received: from debian (localhost [127.0.0.1]) Return-Path:
<<< 503 No recipients specified 550 5.1.1 ... User unknown <<< 550 Invalid recipient: >>> DATA ... while talking to mx.softbank.ne.jp.: ----- Transcript of session follows -----
(reason: 550 Invalid recipient: )
----- The following addresses had permanent fatal errors -----
from localhost [127.0.0.1] The original message was received at Tue, 4 Sep 2007 16:10:00 +0200
--l84GRnX5029819.1188924137/debian
This is a MIME-encapsulated message
Auto-Submitted: auto-generated (failure) Subject: Returned mail: see transcript for details boundary="l84GRnX5029819.1188924137/debian" Content-Type: multipart/report; report-type=delivery-status; MIME-Version: 1.0 To: Message-Id: <200709041642.l84GRnX5029819@debian> From: Mail Delivery Subsystem Date: Tue, 4 Sep 2007 18:42:17 +0200 Tue, 4 Sep 2007 18:42:17 +0200 by debian (8.13.4/8.13.4/Debian-3sarge3) id l84GRnX5029819; Received: from localhost (localhost) Return-Path: From MAILER-DAEMON Tue Sep 4 18:42:17 2007
--l84GRnX4029819.1188924135/debian--
Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset=ISO-2022-JP Mime-Version: 1.0 From: hanako.@docomo.ne.jp Subject: To: a_j.n-y_bluespider-tattoo@softbank.ne.jp Message-Id: <200709041411.l84EB8CS011861@debian> Date: Tue, 4 Sep 2007 16:11:08 +0200 Tue, 4 Sep 2007 16:11:08 +0200 by debian (8.13.4/8.13.4/Submit) id l84EB8CS011861; Received: (from vhostswww@localhost) for ; Tue, 4 Sep 2007 16:11:09 +0200 by debian (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l84EB8f6011862 Received: from debian (localhost [127.0.0.1]) Return-Path:
<<< 503 No recipients specified 550 5.1.1 ... User unknown <<< 550 Invalid recipient: >>> DATA ... while talking to mx.softbank.ne.jp.: ----- Transcript of session follows -----
(reason: 550 Invalid recipient: )
----- The following addresses had permanent fatal errors -----
from localhost [127.0.0.1] The original message was received at Tue, 4 Sep 2007 16:11:09 +0200
--l84GRnX4029819.1188924135/debian
This is a MIME-encapsulated message
Auto-Submitted: auto-generated (failure) Subject: Returned mail: see transcript for details boundary="l84GRnX4029819.1188924135/debian" Content-Type: multipart/report; report-type=delivery-status; MIME-Version: 1.0 To: Message-Id: <200709041642.l84GRnX4029819@debian> From: Mail Delivery Subsystem Date: Tue, 4 Sep 2007 18:42:15 +0200 Tue, 4 Sep 2007 18:42:15 +0200 by debian (8.13.4/8.13.4/Debian-3sarge3) id l84GRnX4029819; Received: from localhost (localhost) Return-Path: From MAILER-DAEMON Tue Sep 4 18:42:15 2007
--l84GRnX3029819.1188924134/debian-- How would I solve this problem as it's making our server load skyhigh 24/7.
Additional info about system: > Debian Linux, latest kernel > Sendmail (we've tried postfix, exim, with same results) > Non cPanel system.
I have 2 wordpress blogs, and I'd like a few different domains to be shared on each of them.
Using some exemples, suppose I have domains from domainA.com to domainE.com. domainA.com is my main domain and the others are addon domains.
Today Blog1 is using blog.domainA.com, and domainB.com and domainC.com use WebRedirect to blog.domainA.com. And Blog2 uses domainD.com with WebRedirect on domainE.com too.
To access a post like /2008/02/02/this-is-a-nice-post, it is available only at blog.domainA.com, and not by domains B and C. I'd like they 3 to be able to access all posts directly, without redirecting to domain A.
To do that, I suppose I'd need to do some config on cPanel. And also on wordpress, even if I replicate it over other domains it insists to redirect to its configured domain.
I was thinking on the possibility of using symbolic link (ln -s) on their folders to blog.domainA.com folder, but I don't have access to shell on SSH so I'd like to know if it would work before trying.
In a real exemple of what I want, these domains all share the same phpBB forum: forumpcs.com.br, extremepc.com.br, forumdohardware.com.br.
Do u know if symbolic link would work to share the same wordpress? And how to make wordpress stop redirecting to blog.domainA.com?
Hello, I've tried several companies and I almost gave up the search for what I need. Maybe someone here can help me find a hosting solution with these requirements: 1) A reseller account / Multi domains for different websites 2) ASP + .net + MS Access with mutli-lingual support 3) PHP 5 + MySQL 5 4) Allow Remote access to mysql thru port (not phpMyAdmin) 5) International Fast connection 6) 24/7 support 7) Location: US
We now have a WHM Vps and also a Dedicated for reselling VPS both located in the UK. At the moment our WHM Vps backs up to an 'Unlimited shared hosting package' but we're sure we're going to be kicked off sooner or later because were using about 50GB storage. We were wondring what everyone else uses to backup? Another disk attached to the server?
Offsite? And how you deal with the extra bandwidth a backup would use.
We now need a solution that can backup our new VPS server and our WHM server. It needs to be in the UK/EU to comply with data protection.
we have a vps hosting package through liquidweb which offers 200gb of bandwidth.
Recently we got a bill with an overage fee of $2527.5 for 3370GB additional bandwidth. I looked at all the cpanel logs and since we had the hosting account we never went over 10gb including the month they said we went over 3370 GB. I put a ticket into liquidweb and they said we launched "Multi-media services" during the same month of the overage, resulting in the overage. We did no such thing, the only thing we did was add content to our website. In the end they want us to pay the bill without offering any log or idea where the bandwidth came from. I'm just wondering if theres anything we can do other then just taking a bill for $2500 of unknowns.
Been trying to decide the best solution to my problem with my current hosting limitations (site has outgrown current shared hosting...getting lots of suspensions due to high load or "exceeds CPU" errors.
Since I am a developer/designer, I'm wondering if a reseller account would be a solution to my problem.
I was looking at managed VPS as well and trying to educate myself on all the ins and outs.
With a reseller account, are you still sharing with others?
What are the limitations?
Would I have better performance with a reseller account than a regular budget priced shared account? (currently w/BlueHost)
Please educate me so I can FINALLY make a decision. I'm so sick of the problems I've been having lately and eager to find a good solution.
We need a High Speed "FTP Storage Solution" for transferring our files securely between our offices.
requirements are simple: 1. High Speed / Good Port Speed in Megs. 2. Unlimited Sub-Accounts 3. Restrict Access by Sub-Account 4. FTP Based Access is Important 5. Ability to Create Read Only / Write Only Sub-Accounts
Space: 2 GB + Bandwidth: 20GB + Speed: Speed is Key For us. He need high speed Solution. Something in tune of Many MeGPS connectivity. Not shared.
im getting a server redone soon and looking for a small temp backup solution I got about 40gb of data that I need to backup and will need double in transfer. Also hopefully can run some basic web services to do somepicture hosting for auctions I run. Uses a few 100mb/mo. Im looking for rec. of cheap VPS hosting that offer big space/transfer and dont charge a really high setup fee I dont need any kind ofcontrol panel.
we have 5 Rack with about 110 servers and 200mbit of connection, every rack use 1 cisco catalyst 2950 without any hw firewall (we use iptables) now we want organize all with a cisco pix 535 firewall and a traffic shaping solution, what do u think of this configuration?
Ethernet connection from datacenter | | 1 Gigabit swith with the 200mbit connection | | 2 Cisco Pix 535 in fail over | | Traffic shaping server | | | | | | | switch1 switch2 switch3 switch4 switch5
I have a few VPS's, the main one has cPanel/WHM and runs all my sites / email / DNS and MySQL DB's. Heres a little info:
VPS1 - CentOS 4.4, cPanel/WHM, runs all domains (OpenVZ) VPS2 - CentOS 4.4, Webmin, Slave DNS to VPS1 using Webmin cluster (OpenVZ) VPS3 - CentOS 4.4, Webmin, Slave DNS to VPS1 using Webmin cluster (Xen)
However, if VPS1 fails for say 24 hours, im screwed!
So, my question is can I get some kind of redunadancy built in somewhere. For example if someone is trying to access my domain "mydomain.com" and the main VPS is down, then the request for the site would go to VPS2, or VPS3...
The same for the mail server, if some is sending mail to one of the domains on the VPS, and the main VPS was down, the mail would be sent to my other VPS's.
I just don not like the fact there is a single point of failure!
I do have WHM managed Weekly and Monthly backups of all cPanel accounts etc.
i am currently using Ultimahosts.net shared hosting, and i am more than happy with them. Their support & DotnetPanel are two best things.
Now i am planning to move my sites to Windows VPS. i cannot host it with them because their packages for VPS are bit expensive for me. As it starts from 69$.
i am looking for someone with their level of service & support. Can you guys suggest me any windows VPS solutions. i want to sleep peacefully after signing up.
i signed up one VPS with easyCGI last night and their sales person promise me to get it ready within 4 hours, after 16 hours from that i just canceled my order without using anything because they didn't process my order in 16 hours (i hope i will get my money back!).
i have read too many views about 1&1, gate.com,godady, solarvps, powervps,jodohost etc... but as i found some -ve comments i dont think i can carry on with them.
i am thinking of something solid & permanent. i dont wanna to move my sites every 2 months ........
i am looking something around 50$. Thanks in advance for any good suggestions. Please do not reply any marketing/sales stuff. i am looking for genuine feedback.
As many of hosts doesn't offer too much SQL so i am thinking something with 512MB RAM and running SQL express on the same machine.
We are a group who are working on an internet TV project. We are hoping to achieve over 4000 viewers at the end of next year. We are trying to see what would be a best solution:
Should we buy the bandwidth and server up front and work our way up to the objective or should we start small and buy a bandwidth dedicated server for the start.
I would appreciate your guidance about how to build such a server and how to buy the bandwidth and also the cost for such a thing.
we have about 95 linux server with Cpanel and we use the backup solution in whm and send file on two Dell 2900 with 8 HD 250Gb sata in raid5 but we see that the backup servers are really slow in the data transfer i think that the raid 5 and all the ftp session slow it, what server backup solution do u can suggest for this structure?
we have about 100 servers in colocation with a 200mbps connecetion, every server have install a software firewall on, this night we got a DDoS (4 hours down) and naturally we was unable to find the source or destination of attack so now we have think to add a firewall solution on the connection, can u give me a good firewall solution for this structure? we have think on a cisco pix 525 but seem to be expensive 10.000$
i want to kill apache/http and restart it again automatically. i need this because sometime we are not in front of the server to fix an overload issue immediately, which can affect a server very badly. i believe many of us already face this kind of situation and hope there is some kind of script or way to do this.