Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    fpr
    fpr is offline
    Member fpr's Avatar
    Join Date
    Oct 2006
    Posts
    22

    Angry DDOS / FLood

    I have problen with a attack and i cant block it, this attack make cpanel and whm go to down.

    root@svr [/usr/local/apache/htdocs]# netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr
    458 187.69.19.253
    27
    12 189.52.1.6
    7 189.31.49.79
    6 201.22.166.68
    6 200.96.151.16
    6 189.59.197.59
    6 189.24.41.96
    5 200.141.184.15
    5 200.103.28.43
    5 189.75.168.8
    4 83.36.190.184
    4 189.114.44.11
    4 127.0.0.1
    3 201.0.132.249
    3 189.19.144.38
    3 189.127.161.37


    I use server:
    Core2Quad
    4GB DDR2 RAM
    2x500GB
    uplink 100mbps


    the traffic that is causing this attack is less than 1mb, but the dropping of the services WHM / cPanel.

    Every time i recevied msg:
    Internal Server Error
    The server is too busy to handle your request. Please wait a few minutes and try again.

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default

    Quote Originally Posted by fpr View Post
    I have problen with a attack and i cant block it, this attack make cpanel and whm go to down.

    root@svr [/usr/local/apache/htdocs]# netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr
    458 187.69.19.253
    27
    12 189.52.1.6
    7 189.31.49.79
    6 201.22.166.68
    6 200.96.151.16
    6 189.59.197.59
    6 189.24.41.96
    5 200.141.184.15
    5 200.103.28.43
    5 189.75.168.8
    4 83.36.190.184
    4 189.114.44.11
    4 127.0.0.1
    3 201.0.132.249
    3 189.19.144.38
    3 189.127.161.37


    I use server:
    Core2Quad
    4GB DDR2 RAM
    2x500GB
    uplink 100mbps


    the traffic that is causing this attack is less than 1mb, but the dropping of the services WHM / cPanel.

    Every time i recevied msg:
    Internal Server Error
    The server is too busy to handle your request. Please wait a few minutes and try again.
    The main problem is just from this IP:
    187.69.19.253

    Why dont you block that one IP?

    If you have APF:
    apf -d 187.69.19.253

  3. #3
    fpr
    fpr is offline
    Member fpr's Avatar
    Join Date
    Oct 2006
    Posts
    22

    Default

    i make it and:
    iptables -I INPUT -p tcp -s 187.69.19.253 -j DROP

    and not work.

  4. #4
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default

    Quote Originally Posted by fpr View Post
    i make it and:
    iptables -I INPUT -p tcp -s 187.69.19.253 -j DROP

    and not work.
    This was a cross post, and it appears the OP is no longer monitoring this one.

    You can view the more active thread here:
    DDOS / FLood : Hosting Security and Technology : Web Hosting Talk

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Apr 2008
    Location
    PK
    Posts
    443

    Default

    Quote Originally Posted by fpr View Post
    i make it and:
    iptables -I INPUT -p tcp -s 187.69.19.253 -j DROP

    and not work.
    Did you restart Apache after that to break the current connections. You may install a custom firewall which would help you block ips easier. CSF and APF are two obvious choices on cPanel servers.
    1 solution works for all problems. Trying harder!
    HostMasterTips - Understanding Tech Support

Similar Threads & Tags
Similar threads

  1. Replies: 1
    Last Post: 05-12-2011, 12:05 PM
  2. Mail Flood
    By niatech in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-17-2008, 11:13 AM
  3. Pop3 flood
    By ivankovalenko in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 05-04-2006, 04:24 AM
  4. Syn Flood
    By nghialy in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 08-08-2005, 07:05 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube