Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Oct 2007
    Posts
    43

    Default Being or not Being DDoS'ed?

    Hello,

    I have a cPanel server which acts a webserver, we have high traffic on few sites, WP sites, but since the last few days my webserver has been acting very weird making the server to be very overloaded and unaccessible.
    My partner told me we may been under a DDoS attack as a netstat command is showing a lot of TIME_WAIT connections,

    [root@server ~]# netstat -tan | grep ':80 ' | awk '{print $6}' | sort | uniq -c
    26 CLOSE_WAIT
    5 CLOSING
    101 ESTABLISHED
    38 FIN_WAIT1
    68 FIN_WAIT2
    52 LAST_ACK
    1 LISTEN
    29 SYN_RECV
    2256 TIME_WAIT

    If I type a 'ps aux' command i get tons and tons of httpd proccesses.
    I have KeepAlive On and KeepAliveTimeout to 4. I have apf with DoS prevention and mod_Evasive.
    I have tried several posts here but with no luck. If the TIME_WAIT decreases the server start responding properly.

    I dont know what to do and I need to get my sites back online.
    Does anyone know how to handle this TIME_WAIT issue thing?


    Thank you in advance.

  2. #2
    Member
    Join Date
    Oct 2008
    Posts
    10

    Default

    Install iftop to the system to get a feel for the amount of data going in and out of the system.

    Try installing mod_evasive as well for Apache, that may help. If its truly just HTTP flooding, install CSF and that should cure most of your problems with mod_evasive. If your still having problems you can email me off the email form in my profile or pm me and I can help you out with mitigating an http flood.

  3. #3
    Member
    Join Date
    Oct 2007
    Posts
    43

    Default

    Hello,

    As I said on my first post, we are already using mod_evasive and its not helping at all.
    We also have APF with DoS prevention as well, still no help.
    Is there any way to kill all those TIME_WAIT connections? They seem to be stalled.

    Any other suggestion will be highly appreciated.

    Thank you guys.

Similar Threads & Tags
Similar threads

  1. Apache DDoS
    By Cristi4n in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 04-21-2007, 02:20 AM
  2. DDOS Attact Please Help Me
    By winteruk in forum cPanel and WHM Discussions
    Replies: 15
    Last Post: 03-23-2007, 07:37 PM
  3. Ddos?
    By Tagor in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 01-25-2006, 03:17 PM
  4. DDos
    By allenhui in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 05-03-2004, 09:35 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube