Hello,
First of all, I apologize if thread location is not correct. Please move to related place.
I think my server is under DDOS attacks.
I installed PRM (rfxn.com) to limit resources.
sometimes prm send many emails about max process usage.. i.e. EVENT: HARD FAIL MAX_PROC use:70/max:30 (limit is 30 process pre user)
unfortunately all of this emails is send at same time and at least 95% of this alerts are for unused sites. So I'm sure that this is an attack.
But I can not find any suspicious connection in netstat -plan|grep :80|awk {'print $5'}|cut -d: -f 1|sort|uniq -c|sort -n or suspicious process in top or process manager.
How can I find more about this and how can I conflict with it?
thank you



LinkBack URL
About LinkBacks
Reply With Quote





