How Do You Detect And Block Ddos Or  Large Number Of Connection 
			Nov 7, 2008
				sometimes, some people may try to guess the password of ssh,whm,ftp,...etc,
or any ddos attack,
do you only use iptables to place this problem?
or do you install any other scripts to secure your server?
my serve is centso.
	
	View 6 Replies
  
    
		
ADVERTISEMENT
    	
    	
        May 19, 2009
        is there any proved method to determine what kind of attack you are under? Our server has been under attack for more than a day now but so far we have not been able to find out what kind of attack it is exactly. The server maintence company we are using says it's a DDoS attack but they don't say how they found this out. Also, they are not telling us what kind of DDoS attack it is.
	View 14 Replies
    View Related
  
    
	
    	
    	
        May 30, 2007
        I'm currently using iptables to ban IP addresses from the servers, like:
Code:
iptables -A INPUT -s xxx.xxx.xxx.xxx -j DROP
I ran a "spam trap" for the last few months and now I have over 11000 IP addresses who were trying to spam on my website (guestbooks, phpBB and forms) and I want to ban them all (pretty sure bots run from them).
 
My question - is iptables the way to do it? I mean does banning such a large number of addresses have any significant performance or other issues I should be aware of (except of the fact I may be banning some legitimate traffic)? Is the -A INPUT the way to ban them all or is there a more appropriate way of baning such a number of addresses?
 
I'm on CentOS 4.5 i686, Apache/1.3.37, Pentium D 930, 2GB RAM. 
	View 11 Replies
    View Related
  
    
	
    	
    	
        Jun 7, 2009
        server for send large number of emails per day?
What would be the best solution for that?
VPS ? Dedicated ? and Do I need to have Cpanel too?
	View 6 Replies
    View Related
  
    
	
    	
    	
        Oct 29, 2006
        i just wana know is it safe to do remote daily backup for about 70,000 files?
file sizes is about 200kb and every day i have about 1000 new file, so rsync first should check old files becouse i am deleting about 30-50 of them daily and them backup new 1000 files ,
so how much it will take every time to compare that 70,000 files?
i have 2 option now:
1-using second hdd and raid 1
2-using rsync and backuping to my second server , so i can save about $70 each month.
	View 9 Replies
    View Related
  
    
	
    	
    	
        Oct 23, 2009
        running Plesk qmail server. My local mail queue is growing rapidly and very slow dlivery m gettings too many spam emails from outbound. I am using DNSBL server sbl.spamhaus.org maped but it is out of control. how to protect my box from SPAM.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Jul 9, 2014
        I have somewhere at 2000 domains.
I need to change path to vhost from W:host to D:vhost
I copied all files from W to D drive and created symbollinks. Now all files stored in D:vhost and symbollincs pointing to W:vhost.
If I will use reconfigurator, will it recopy existing files or just will skip them? Because I have millions files in my vhost dir
Also i thought about change drive letter in windows OS. It wil be enough to just stop IIS service and plesk services for switching disk letter?
Can i just some how say plesk that he should search all vhost files in D:vhost? With out process of copying files,becouse thay already exist there are.
	View 2 Replies
    View Related
  
    
	
    	
    	
        Apr 26, 2007
        I'd like to block off large ranges of IP's, much like the iptables does for a Linux server.  I want to cut out China and a few others completely?  Can I do that just with the standard Win 2003?  I know the IIS has tables, but I need to also include all things outside the IIS too.  What software is better for this?
	View 4 Replies
    View Related
  
    
	
    	
    	
        Jun 5, 2008
        I am a staff member at Markee Dragon (www.markeedragon.com), a large gaming targeted forum. We have a slight dilemma. We are looking for ways to stop as many proxies as possible from entering the website. We don't want the hassle of single IP banning and are looking for something somewhat automated. From my experience there is not much you can do with proxies but hopefully I am wrong and someone knows a solution to this. 
The reason we are trying to have proxies blocked is because of the nature of the website. 
We are a trading site and scamming has given Markee Dragon somewhat of a bad name and we are trying to combat against that. Most of the scammers who are banned just evade the bans through proxies.
	View 7 Replies
    View Related
  
    
	
    	
    	
        Jul 18, 2008
        I have apf installed on my server and it looks likely be inreachable,
and i try to reboot the server,
after rebooting, i can not connect from my pc to it any more,
i go to console and test,the server can ping and traceroute the out servers,
i think the newwork is online and the afp black the coming connection.
i try to run "apf -f" to stop the apf,
and my friend can connect the server laster.
i think it may be because the apf black the out-coming connection,
now,i need to check why the apf black others and try to fix it and restart the aps,
can anyone teach me how can i do now?
my server os is centos
	View 5 Replies
    View Related
  
    
	
    	
    	
        Aug 4, 2009
        i have problem when using ddos deflate for ddos protection in my server,
i get this message,
Quote:
Banned the following ip addresses on Tue Aug  4 13:12:37 WIT 2009
67.21.44.60 with 4011 connections
ddos deflate is blocking my server ip, what's wrong?
: 67.21.44.60 not real my server ip just for sample
	View 8 Replies
    View Related
  
    
	
    	
    	
        Oct 18, 2009
        Like exceeding 60 connections per minute same IP =  automatically blocked.
How do I set it up?
	View 4 Replies
    View Related
  
    
	
    	
    	
        May 26, 2008
        I use deflate to prevent ddos attack.
But after I start deflate, I still keep seeing a lot of connection from certain IP.
netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
87 218.86.252.158
363 219.150.191.62
501 60.216.238.212
I want to block those IPs permanently.
How can I do that.
	View 7 Replies
    View Related
  
    
	
    	
    	
        Dec 5, 2008
        My server is under DDOS attack. Its getting more than 1000 SYN_RECV requests. Please let me know how can I protect my server from it.
	View 7 Replies
    View Related
  
    
	
    	
    	
        Jan 29, 2008
        how can i know the list of IP that is block by APF and anti-dos?
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jan 25, 2008
        one user trying to send GET command to our server , when I viewing Apache Status in WHM I found about 100 connection from one IP (requestet none page only show GET / HTTP/1.0) , is this DDOS attack?
	View 14 Replies
    View Related
  
    
	
    	
    	
        Oct 5, 2007
        I'm new to Private Virtual Server and the package offered by different company are quite confusing.
I was on RackForce and their basis VPS package dds200-L can host 100 domain names on Plesk and unlimited domain names on WHM/Cpanel.
On 1and1 it didn't say if Plesk support 100 or unlimited domain names. My question is, do we always have the liberty to host unlimited domain names on our PVS?
Can anyone recommend a good VPS hosting company?
	View 14 Replies
    View Related
  
    
	
    	
    	
        Apr 7, 2008
        I have ftp server (pure-ftp). with firewall.
i allowed 20 and 21 port in "CSF" firewall
now when i or our client connect to the server connection done.
and the they fire dir or ls command they will receive error
"425 Could not open data connection to port 2535: Connection timed out"
what is the problem.i have already allowed passive port 2500:3500 then why i received this types of error
	View 3 Replies
    View Related
  
    
	
    	
    	
        Nov 7, 2008
        it's come under my attention that dragonara.net has been ddosing me today since morning from the ip:
194.8.75.229
What's so ironic about it is that the ip is from a UK DDOS protection site so i'm expecting some email with their services in the next hour or so. Stay clear of them they are fakes and e-terrorists.
	View 14 Replies
    View Related
  
    
	
    	
    	
        Apr 21, 2009
        How do you know your clients are sending bulk/spam emails?
I don't seem to understand the reports in "Email >> View Mail Statistics" section of WHM.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Jul 25, 2009
        I have a private vps server works under linux ( centos ), sometimes am getting msg from csf/firewall subject:
lfd on website.com: Suspicious process running under user user account
when i check my cpanel/whm vps ( service status ) its shows that the memory limit 80% - 85% , It's had a good forum works with vb, but am wonder how to check my vps memory, i mean how to detect if there any script, or malware, or anything takes the vps memory out...
Is there any way to check,know what works under my vps, so it's take my memory limit 85%?
i check the tmp folder,
root@www [/home]# cd /tmp
root@www [/tmp]# ls -la
total 364
drwxrwxrwt  6 root root   4096 Jul 25 02:14 ./
drwxr-xr-x 21 root root   4096 Jul 18 02:21 ../
drwxrwxrwt  2 root root   4096 Jun 30 05:50 .ICE-unix/
drwxrwxrwx 18 root root   4096 Jul  2 17:33 eaccelerator/
lrwxrwxrwx  1 root root     27 Jul 18 02:13 mysql.sock -> ../var/lib/mysql/mysql.sock=
drwxr-xr-x  3 root root   4096 Jun 30 05:29 pear/
drwx------  3 root root   4096 Jul  5 18:31 spamd-23647-init/
-rw-------  1 root root 343335 Jul 19 02:50 whatis.bk6140
root@www [/tmp]# cd /home
and the df space
root@www [~]# df -h
Filesystem            Size  Used Avail Use% Mounted on
/dev/simfs             80G  4.1G   76G   6% /
root@www [~]#
and the services running is 
USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
root         1  0.0  0.0   2060   156 ?        Ss   Jun30   1:23 init [3]      
root      7465  0.0  0.0   2444   156 ?        S    Jul03   0:00 /bin/sh /usr/bin/mysqld_safe --datadir=/var/lib/mysql --pid-file=/var/lib/mysql/www.website.com.pid
mysql     7491  0.0  2.5  33452 10440 ?        Sl   Jul03  11:33 /usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --pid-file=/var/lib/mysql/www.website.com.pid --skip-external-locking
root     10236  0.0  6.0  27396 24764 ?        Ss   Jul24   0:07 /usr/bin/spamd -d --allowed-ips=127.0.0.1 --pidfile=/var/run/spamd.pid --max-children=3 --max-spare=1
root     11447  0.0  1.9  18364  8020 ?        S    Jul24   0:00 cpsrvd - waiting for connections
root     11865  0.0  0.7  13672  3260 ?        S    Jul06   0:00 /usr/local/apache/bin/httpd -k start -DSSL
root     13537  0.0  3.1  15092 13064 ?        Ss   00:00   0:02 lfd - sleeping
root     13703  0.0  0.3   3808  1284 ?        SN   Jul06   0:01 cpanellogd - sleeping for logs
root     13739  0.0  0.6   5856  2844 ?        Ss   Jul06   0:00 cPhulkd - processor
root     13795  0.0  1.5  14760  6304 ?        S    Jul06   0:00 cpdavd - accepting connections on 2077 and 2078
root     18161  0.0  0.0   1716   380 ?        Ss   Jun30   0:24 syslogd -m 0
root     18164  0.0  0.0   1668    72 ?        Ss   Jun30   0:00 klogd -x
dbus     18193  0.0  0.0   2736   212 ?        Ss   Jun30   0:00 dbus-daemon --system
root     18213  0.0  0.0   2716   172 ?        Ss   Jun30   0:00 xinetd -stayalive -pidfile /var/run/xinetd.pid
root     18399  0.0  5.9  27604 24404 ?        S    Jul24   0:06 spamd child
root     19461  0.0  0.1   3228   684 ?        Ss   Jun30   0:08 crond
root     19616  0.0  0.0   1820   124 ?        Ss   Jun30   0:00 /usr/sbin/portsentry -
	View 7 Replies
    View Related
  
    
	
    	
    	
        May 4, 2008
        My server run after 10h sevices ftp is down (network error: connection timed out). may be flood ftp.
how to Detect flood ftp.
	View 4 Replies
    View Related
  
    
	
    	
    	
        May 22, 2007
        I have a few incomplete steps to see if I got some intruder in my Linux system.. But i really would like to have all your suggestions to make a good doc about this matter, 
1.- Download and run Rkhunter & Chkrootkit
2.- Run "w", and "netstat -nalp |grep "SHPORTHERE" to see whos connected using SSH
3.- Search for ssh and ftp accepted logins.
Code:
last
cat /var/log/secure* | grep ssh | grep Accept
cat /var/log/secure* |grep ftp |grep Accept
less /var/log/messages | grep ftp
4.-  Watch current connections and scan your ports.
Code:
netstat -nalp
nmap 1-65535 localhost
5.- Search for suspicious content on common explotable dirs.
Code:
rm -rf /tmp/sess*
rm -rf /var/dos-*
rm -rf /var/tmp/ssh-*
rm -rf /var/tmp/dos-*
ls /tmp -lab
ls /var/tmp -labR
ls /dev/shm -labR
ls /usr/local/apache/proxy -labR
ls /usr/local/samba -labR
6.- Checking for anomalies on this files. 
Code:
less /etc/passwd 
less /etc/shadow
less /etc/groups
7.- Search for new users at sudoers, check wtmp and telnet is not running.
Code:
cat /etc/sudoers
who /var/log/wtmp
cat /etc/xinetd.d/telnet
8.- Find bash history files
Code:
find '/' -iname .bash_history
9 .- Verify the Crontab table
Code:
crontab -l
10 .- Update the slocate database and search for exploits.
Code:
updatedb &
For cPanel servers:
Code:
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20' /usr/local/apache/logs/*
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20' /home/*/statistics/logs/*
For Ensim servers:
Code:
egrep -i '(chr(|system()|(curl|wget|chmod|gcc|perl)%20'/home/virtual/site*/fst/var/log/httpd/*
Search for shell code:
Code:
cat /path/of/your/web/logs/* |grep "/x90/"
11.- Search for hidden dirs
Code:
locate "..."
locate ".. "
rlocate " .."
locate ". "
locate " ."
12.- Search for perl-scripts running
Code:
ps -aux | grep perl
13 .- Checking nobody user and open files.
Code:
service httpd stop
lsof -u nobody
	View 14 Replies
    View Related
  
    
	
    	
    	
        Apr 6, 2009
        I have a server of my own. Unfortunatlly 20% of the time, the server is down even though my connection to internet always up.
I am checking the event log but cannot see anything odd...
OS:Windows server 2003
Is there any tool to detect why the server is down most of the time?
I can post the event viewer errors that I can find suspeicious if needed.
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jul 31, 2009
        i have some issue,
sometimes,a user may be banned by our firewall,
or the dns of his pc does not work well,...and so on,
by the way,
they can not link to server,
and it spend a lot of time to check where is wrong from his pc aside.
i want to ask if it is possible i use a php script or a exe let him to execute,
and it will help me detect user's pc configuation,
it include his IP/DNS/fateway/trace and ping result,...and so on.
	View 4 Replies
    View Related
  
    
	
    	
    	
        Jul 25, 2008
        Is there any way to distinguish a dedicated server from VPS using Linux commands and detect the implemented virtualization technology like XEN and OpenVZ, ...?
I have received a dedicated server and in cPanel its written Virtuozzo but they tell me it's XEN , beside this what's the reason to implement a virtualization technic while they give me a dedicated server? Maybe to obtain cheaper cPanel license, 
	View 8 Replies
    View Related
  
    
	
    	
    	
        Nov 13, 2008
        Do web hosts have the means to self-detect or self-correct problems with people's websites? If so, is there a name for this ability? 
Seems that every host I've used has to be *told* about major problems, such as the server or database being down completely. I'm tired of going out of town fearing a site crash. I don't expect them to catch every problem, but when the failure is so blatant, it would be nice if they caught it...
How would I find a host who does this?
	View 11 Replies
    View Related
  
    
	
    	
    	
        Aug 1, 2009
        If i put domain.com on uptime checker,and downtime is detected,downtime will be reported if dns is down or if http server is down.So question is what i need to do to see what exactly went down?For network uptime i can ping ip adress,but for these two i really don't know.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Aug 15, 2008
        how i can detect and disable C99 shell and another shell script exp:r57 ....
	View 9 Replies
    View Related
  
    
	
    	
    	
        Sep 28, 2009
        I know the ISP is RADIGRAFICA COSTARRICENSE, and the server location is San José in Costa Rica.
I googled the ISP name RADIGRAFICA COSTARRICENSE, trying to find out the company site which offer's web hosting service, but I can only find racsa.co.cr; however, this doesn't look like a web hosting company.
	View 2 Replies
    View Related