Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jul 2004
    Posts
    95

    Exclamation Especific HTTP Atack - how to stop it?

    Hi,

    Look this messages on my /etc/httpd/logs/access_log

    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:12 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:12 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:12 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:12 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:12 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:12 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:12 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:12 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:12 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:12 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:13 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:13 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:13 -0300] "-" 408 -
    /etc/httpd/logs/access_log:201.58.101.80 - - [16/Mar/2006:17:20:13 -0300] "-" 408 -
    There are thousands of this, and when i block it, begin with another ip.

    Before i did a netstat -anp |grep 'tcp' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n and i found 1600 conections by this ip. I have modsecurity and libsafe installed, but they are not helping very well.

    Some one could give-me some sugestions how to stop this kind of atack?

    thanks

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by IRCBrasil
    Look this messages on my /etc/httpd/logs/access_log

    There are thousands of this, and when i block it, begin with another ip.

    Before i did a netstat -anp |grep 'tcp' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n and i found 1600 conections by this ip. I have modsecurity and libsafe installed, but they are not helping very well.

    Some one could give-me some sugestions how to stop this kind of atack?
    With 1,600 concurrent connections, you are under a nasty DDoS attack. Have you tried, although I don't believe they would make big difference, APF and BFD? I also suggest installing Mod Evasive, and Tripwire. Did you harden your server? Also make sure you don't have bad or insecure Php files?
    Last edited by AndyReed; 03-16-2006 at 04:29 PM.
    Andy Reed
    RHCE and CCNA
    ServerTune.com

  3. #3
    Member
    Join Date
    Jul 2005
    Posts
    74

    Default

    You should contact your provider ( Datacenter probably ), they probably know how to help you with this...

  4. #4
    Member konrath's Avatar
    Join Date
    May 2005
    Location
    Brasil
    Posts
    312

    Default

    Quote Originally Posted by IRCBrasil
    Hi,

    Look this messages on my /etc/httpd/logs/access_log



    There are thousands of this, and when i block it, begin with another ip.

    Before i did a netstat -anp |grep 'tcp' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n and i found 1600 conections by this ip. I have modsecurity and libsafe installed, but they are not helping very well.

    Some one could give-me some sugestions how to stop this kind of atack?

    thanks


    You have DDOS instaled?

    # wget http://www.inetbase.com/scripts/ddos/install.ddos
    # sh install.ddos

  5. #5
    Member
    Join Date
    Mar 2006
    Posts
    58

    Default

    Hello,

    It can be stopped only the Data center by which they will nullroute the main shared Ip for some time still this stops.

    Regards,
    Marcus
    The New Phase Of Support

Similar Threads & Tags
Similar threads

  1. WHM ¿Block mails from especific domain?
    By shenzy in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-28-2009, 11:30 AM
  2. Help with BFD rule to stop multiple http requests
    By Bravo in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 07-16-2007, 06:56 AM
  3. A BIG SPAMMER ATACK - help
    By duranduran in forum E-mail Discussions
    Replies: 7
    Last Post: 05-20-2007, 01:30 PM
  4. Server used by atack
    By Alexandre Duran in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 04-26-2005, 12:52 AM
  5. This Is A Spammer Atack ?
    By Alexandre Duran in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 12-28-2004, 05:46 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube