Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Secret Agent
    Guest

    Default Bandwidth spikes, can't trace

    I am having a hard time tracing this server's bandwidth spikes.

    I found udp files in /tmp and removed them. That solved the problem. The partition is already secured with /scripts/securetmp as well.

    I am just not able to trace anything else. Can someone explain the best procedures to trace bandwidth spikes (low cpu usage constant during spikes)

    Please see attachment. I found udp.txt again in /tmp somehow.

    This is after I removed the file earlier, changed ssh port, disabled all accounts (about 10 total) any shell access, disabled (already was) direct root access and literally about 15 other security steps including apf, bfd, etc.

    This is the /etc/fstab also

    Code:
    LABEL=/                 /                       ext3    defaults,usrquota        1 1
    LABEL=/boot             /boot                   ext3    defaults        1 2
    LABEL=/backup           /backup                 ext3    defaults        1 2
    none                    /dev/pts                devpts  gid=5,mode=620  0 0
    none                    /proc                   proc    defaults        0 0
    none                    /dev/shm                tmpfs   rw,noexec,nosuid,nodev        0 0
    /dev/sda2               swap                    swap    defaults        0 0
    /dev/cdrom              /mnt/cdrom              udf,iso9660 noauto,owner,kudzu,ro 0 0
    /dev/fd0                /mnt/floppy             auto    noauto,owner,kudzu 0 0
    Attached Files
    Last edited by Secret Agent; 01-18-2006 at 04:11 PM.

  2. #2
    Secret Agent
    Guest

    Default

    Can someone kindly help me here? I found it again, removed it and the bandwidth is still high

  3. #3
    Registered User
    Join Date
    Dec 2004
    Posts
    1

    Default

    i seen this happen from a outdated phpBB forum

    Theres a exploit that allows them to wrie to the /tmp path... the script you posted was a flood script to attack other users.

    My recommendation is just patch and update all installations of phpBB on your server.

Similar Threads & Tags
Similar threads

  1. After 11.25 upgrade to 11.28 huge cpu spikes
    By MakeHosting in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 02-09-2011, 11:39 PM
  2. Periodic Server Load Spikes
    By ramorse in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-28-2008, 12:07 AM
  3. How to track traffic spikes
    By wookiee in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-23-2006, 11:32 PM
  4. *URGENT* Server Spikes?!
    By surfdue in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-22-2006, 12:57 AM
  5. CPU Spikes
    By WestBend in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 09-09-2004, 08:02 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube