Web Design Forums

Server Administration Help

Need help installing or configuring your Linux, Apache, PHP & MySQL server? Perhaps your Windows IIS Server too? Post your problems here!

DDoS Attacks? What are the signs?



Site of the Month Voting - Now Open. CAST YOUR VOTE NOW!

Reply
 
LinkBack Thread Tools
Old October 10 '08, 01:41 AM (#1)
Boogle is offline
WDF Member
 
Boogle's Avatar
 
Join Date: April 2008
Location: UK
Posts: 63
Boogle will become famous soon enoughBoogle will become famous soon enough
DDoS Attacks? What are the signs?

I’m require a little information about DDoS attacks.

I have a website that some people would frown upon, therefore in some countries it may require the user to be a little more discreet so they don’t raise any suspicion from the authorities from where they reside. Now, I’ve noticed a certain IP, 86.96.228.89, is using over 30 gig a day, It’s a proxy server in Dubai. I know they filter lots of “sites” so could it be half the population are viewing the site via that proxy so they don’t get rumbled. Or does it bare any resemblance to a Dos attack? Do DDoS attacks increase the bandwidth usage?

Anyway, any help would be much appreciated.

Thank you.

BTW, I have mod_evasive and mod_security.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old October 10 '08, 02:14 AM (#2)
Wired is offline
WDF Alien Overlord
 
Wired's Avatar
 
Join Date: April 2003
Posts: 6,369
Wired is just really niceWired is just really niceWired is just really niceWired is just really nice
Send a message via AIM to Wired
Is it constant bandwidth suck, or is it randomly? Does the usage pattern meet the usage pattern coming from other IPs?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old October 11 '08, 12:21 AM (#3)
Shadowfiend is offline
Code beautifully and honorably
 
Shadowfiend's Avatar
 
Join Date: June 2005
Location: Atlanta, GA
Posts: 4,143
Shadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond repute
DoS attacks (denial of service) may match your description. DDoS (distributed denial of service), not so much, since all of the traffic concerned is coming from a single host, and therefore not particularly distributed.

In your case, how does the traffic coming from that IP compare to that coming from others? Also, is it significantly slowing your site down? DoS attacks are meant to cripple sites, and usually cause extremely high load. They also tend to be less about bandwidth and more about CPU time, which typically is achieved by maximizing the number of requests to your server rather than the amount of data downloaded per request. So the other question is, how many simultaneous connections are typically open to this one host, on average?

Last edited by Shadowfiend; October 11 '08 at 12:22 AM. Reason: `simultaneous' means `at a time'
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old October 11 '08, 08:52 AM (#4)
Boogle is offline
WDF Member
 
Boogle's Avatar
 
Join Date: April 2008
Location: UK
Posts: 63
Boogle will become famous soon enoughBoogle will become famous soon enough
Thanks for your answers guys.

The traffic coming from that one IP is probably 10 times the amount as everyone else’s. There is also another IP that is using around 20 gig of bandwidth a day from the exact same location. It’s not effecting the site whatsoever, we can easily manage Terabytes of bandwidth per day.

I’m 90% certain its nothing malicious. I’ve done a bit more research and spoken with my programmer, we think it is that everyone is using the same proxy to access our site, both IP’s are in Dubai so I’m guessing people are trying to avoid raising any suspicion from their ISP. I’ve also noticed a massive flux in traffic from that region too. I’ve modified mod evasive and changed its email alert address so I now receive emails from Apache. Should anyone attempt a dos attack I can easily block there IP.

I also have a Cisco firewall, would that stop a dos attack?

Cheers
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old October 11 '08, 11:57 AM (#5)
Shadowfiend is offline
Code beautifully and honorably
 
Shadowfiend's Avatar
 
Join Date: June 2005
Location: Atlanta, GA
Posts: 4,143
Shadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond reputeShadowfiend has a reputation beyond repute
I'm not too familiar with how Cisco firewalls handle DoS attacks, but it's possible. Still, if the traffic isn't even putting a dent in your capacity, then that in no way qualifies as denial of service
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old October 11 '08, 10:44 PM (#6)
Wired is offline
WDF Alien Overlord
 
Wired's Avatar
 
Join Date: April 2003
Posts: 6,369
Wired is just really niceWired is just really niceWired is just really niceWired is just really nice
Send a message via AIM to Wired
Do you have a login access to your site? If so, you can guesstimate if it's a bandwidth horny...err HUNGRY... user, or if it's just a high number of users on that same proxy (assuming that's what it is).
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old September 5 '09, 09:24 PM (#7)
8307c4 is offline
New Member!
 
8307c4's Avatar
 
Join Date: September 2009
Posts: 2
8307c4 is an unknown quantity at this point
Nope, if it was a DOS attack your site would already crash regularly, a DOS attack
is usually an unrelenting series of service requests.
Although at times it may be intent on sucking up bandwidth, the standard DOS attack
comes more in the form of multiple data requests in very short succession.
By multiple I'm talking as many as possible, thousands a second and more, most
servers won't stand up to one for more than say, 20-30 seconds at a time.
If such is the case, one can temporarily ban the offending IP via .htaccess, then start
doing some research into effective scripting that helps prevent it (because banning IP's
becomes unfruitful quick).

More, or just as likely the source of your problem is image harvesting software, I forget
the proper term but it's basically this program people use to gather only images from
however many Web sites, it works a bit like a search engine except the user never has
to visit any of the Web sites.
These bots will consume your bandwidth.

There exist htaccess scripts designed to help prevent this nonsense somewhat as well.
Basically you will want to deny access to any and all non-friendly bots, via the htaccess file.

Last edited by 8307c4; September 5 '09 at 09:29 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

  Web Design Forums » Hosting and Server Setup » Server Administration Help

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
ActiveX Flaw, 2 attacks in 3 days tibberous General Discussion 1 December 7 '03 12:19 PM
This can't be good (DDOS attack?) Brak General Discussion 1 December 6 '03 09:27 PM

 
User Infomation
Your Avatar

Site Of The Month
Nominate Your Site Now!

Advertisement
WolfCMS.org

Latest Articles
- by RickM
- by bfsog

Advertisement

Partner Links



All times are GMT -4. The time now is 02:09 PM.


WebDesignForums.net is Copyright © 2010 RikeMedia.

SEO by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164