Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    bhd
    bhd is offline
    Member
    Join Date
    Sep 2003
    Location
    JNB ZA
    Posts
    144

    Default Monster load spikes due to hostile spider

    We have just blocked customscoop.com. It appears they run a new gathering service and have a spider running across several servers which intermittently opens a bazillion threads at a time to a single source (not very polite!) killing the server it is trying to spider in the process. They were opening about 500 threads at a time to a message board and pushing the load average up to 100+ for periods of 10-15 minutes.

    If you have had any massive load spikes in the past few weeks with no logical explanation, you may want to search your log files for any of the following IP addresses: 64.49.241.192 - 64.49.241.223

    Better still stick 64.49.241.192/27 into your APF deny_hosts

    We've had this on 3 servers already ... there's a hostile spider on the loose so be warned!

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge gorilla's Avatar
    Join Date
    Feb 2004
    Location
    Sydney / Australia
    Posts
    736

    Default

    Have you contacted rackspace regarding this ? as it seem its one of their IPs http://www.whois.sc/64.49.241.192
    Last edited by gorilla; 04-10-2005 at 09:21 AM.

  3. #3
    bhd
    bhd is offline
    Member
    Join Date
    Sep 2003
    Location
    JNB ZA
    Posts
    144

    Default

    I saw. It is Rackspace. However this is not really an abuse issue which is why I never reported it -- although the consequences of what these guys are doing is just as bad as a DOS attack I guess.

  4. #4
    Member
    Join Date
    Feb 2005
    Location
    North Carolina
    Posts
    237

    Default

    Not to defend these guys, but customscoop.com looks like a legit operation that I'm certain would want to know we are starting to block their IP's because of the "tiger" in their robot. I would hope this is not what they intended, as it would have a serious impact on their credibility and business model (maybe we should let someone from news.com know about this - a little negative press press can do wonders). If you have the inclination, you may want to drop them a note.

  5. #5
    bhd
    bhd is offline
    Member
    Join Date
    Sep 2003
    Location
    JNB ZA
    Posts
    144

    Default

    Hehe, a tiger eh. That's about the size of it. Frankly, I don't want to give anyone bad publicity ... just wanted to stop the tiger from killing our servers

    The upside is, I was motivated to write a perl script to track events just like this. What I mean by "just like this" is simply that it is very difficult (for me at least) to find the source of a 100+ server load when it's only there for a few minutes.

    1. Scanning log files don't help.
    2. Doing things like top > filename generate massive files and, in my case, were never run at the right time so I never got to see what I was looking for.
    3. When the load average is so high, logging in with SSH is impossible anyways.

    The script I wrote can run several commands (of your choice ... like ps, netstat etc) at once and capture to a text file. It sits in a loop monitoring load and only begins logging when the load hits a preset level ... that way it only logs when a spike is ocurring. That's how I found this spider with the tiger in it's tank.

    If anyone is interested, I can post a link to the zip file.

  6. #6
    cPanel Partner NOC cPanel Partner NOC Badge gorilla's Avatar
    Join Date
    Feb 2004
    Location
    Sydney / Australia
    Posts
    736

    Default

    love to have a look at your script

  7. #7
    bhd
    bhd is offline
    Member
    Join Date
    Sep 2003
    Location
    JNB ZA
    Posts
    144

    Default

    You can download it here

Similar Threads & Tags
Similar threads

  1. Periodic Server Load Spikes
    By ramorse in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 09-07-2009, 11:41 PM
  2. Periodic Server Load Spikes
    By ramorse in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-28-2008, 12:07 AM
  3. High iowait causing load spikes but for no reason?
    By Metro2 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 07-03-2007, 04:13 PM
  4. Exim causes load spikes on mails with 10+ recipients
    By ankesen in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-24-2006, 04:46 AM
  5. Sever load spikes, crashing -- Cp-Wrap the culprit?
    By isnoop in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 07-28-2003, 06:33 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube