Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member This forum account has been confirmed by cPanel staff to represent a vendor. Radio_Head's Avatar
    Join Date
    Feb 2002
    Posts
    2,064

    Default named problems (high cpu usage!)

    I noticed that named(bind) is using a lot of cpu latest hours , 10% to 30%
    costantly ,

    2325 named 25 0 3920 S 15.9 0.3 0:26 /usr/sbin/named -u named



    which could be the problem and how to find which is the user abusing of bind ?

    Thank you!
    Stop SPAM & VIRUS :: ASSP Deluxe for cPanel http://www.grscripts.com
    █ ASSP Deluxe is supported by Fritz Borgstedt,ASSP main developer.

  2. #2
    Member
    Join Date
    Feb 2005
    Posts
    60

    Default

    I noticed the same thing on my Fedora 2 server.
    I killed those processes and restarted bind.

  3. #3
    Member This forum account has been confirmed by cPanel staff to represent a vendor. Radio_Head's Avatar
    Join Date
    Feb 2002
    Posts
    2,064

    Default

    solved.

    Someone was attacking with dns queries (using tons of different ip address per second)
    a domain name which was closed , but it was still pointing my nameservers .
    If you have the same problem leave me a pm and I will tell you how to solve this kind of problem (I prefer don't post here the solution otherwise the hacker could find turnaround).

    Bye
    Stop SPAM & VIRUS :: ASSP Deluxe for cPanel http://www.grscripts.com
    █ ASSP Deluxe is supported by Fritz Borgstedt,ASSP main developer.

  4. #4
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2003
    Location
    Hosting from: Panama, Hong Kong, Singapore, Malaysia, China, India, USA and Australia
    Posts
    68

    Default

    can you post a way to trace back the dns query synflood to the victim ip?

    thank you

    Scott
    International Offshore Hosting from Hong Kong, Singapore, Panama, Malaysia, India, China, Australia and the USA.

    Authorized cPanel PartnerNOC in 8 countries.

    www.katzglobal.com

  5. #5
    Member This forum account has been confirmed by cPanel staff to represent a vendor. Radio_Head's Avatar
    Join Date
    Feb 2002
    Posts
    2,064

    Default

    due to continuos requests I will post here the solution .

    Solution

    a) investigate which is the domain name which is flooding your named
    (using ndc query logging on and examing /var/log/messages)

    b) if the domain is flooded.com check a whois of this domain name

    c) if flooded.com is using your dns (probably yes) create an account for him
    or simply create a dns entry for him .

    d) (optional). Redirect flooded.com to your master account to get more traffic


    After executed point c) named will return to work normally .
    (In other words if a domain name use your dns but it's not listed as a WHM account
    with his own dns , the hacker could bring an attack to your named , slowing down it.
    I don't know in which way the bring tha attack however ,perhaps requesting multiple dns queries . Hope it helps.
    Last edited by Radio_Head; 06-05-2005 at 01:59 AM.
    Stop SPAM & VIRUS :: ASSP Deluxe for cPanel http://www.grscripts.com
    █ ASSP Deluxe is supported by Fritz Borgstedt,ASSP main developer.

Similar Threads & Tags
Similar threads

  1. Need Help , High load avg and high cpu usage
    By minitech in forum Optimization
    Replies: 2
    Last Post: 03-15-2011, 01:39 PM
  2. Replies: 1
    Last Post: 02-11-2010, 01:58 AM
  3. named high cpu usage
    By DjiXas in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-21-2008, 08:02 AM
  4. named-unusually high cpu
    By Hyperpipe in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-27-2004, 07:05 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube