Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Dec 2003
    Posts
    31

    Default Urgent request : Server sending ~25mpbs UDP traffic out, need help. $ can be paid

    Hi

    This is what i recieved from my provider

    Dear customer,

    It has come to our notice that starting from 1600hrs today (2/3/05), one of
    the IP addresses assigned to you (xxxx) has been sending a flood of
    UDP packets (~25Mbps) to xxxx port 53.

    This is the second time in less than 4 weeks that your server has been
    compromised and used to flood external machines.

    As a precautionary measure, all traffic to/fro your server except for
    Singapore One traffic will be blocked with immediate effect. This will allow
    you to have access to your server to investigate this problem.

    Please note that full access will only be restored upon satisfactory and
    reasonable explanation as to how this incident was allowed to occured and
    measures taken to prevent it from happening again. Your feedback will be
    reviewed during office hours only.

    Thanks for your attention and best regards,
    Is there any reputable system admin within this forum willing to help ? I can pay (not alot) and also give you a monthly server managing job if you'd like. Again, i cant pay alot. Please as this is urgent, if you can help PM/post below with your MSN address. Thanks

  2. #2
    Member
    Join Date
    Feb 2004
    Posts
    203

    Default

    Have you a phpBB forum?

  3. #3
    Member
    Join Date
    Dec 2003
    Posts
    31

    Default

    Yeah a couple of them ...

  4. #4
    Member
    Join Date
    Feb 2004
    Posts
    203

    Default

    Update to last version (2.0.13)


  5. #5
    Member
    Join Date
    Dec 2003
    Posts
    31

    Default

    So how do i clean up the mess ?

  6. #6
    Member
    Join Date
    Jan 2005
    Posts
    43

    Default

    flash7 just answered ur question

  7. #7
    Member ntwaddel's Avatar
    Join Date
    Nov 2003
    Location
    Templeton, CA
    Posts
    173

    Default

    ps aux and see if there are any wierd processes running

    its probably running out of your /tmp, i would check there to see if theres any strange scripts in there

  8. #8
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    We can clean up the mess. Send us an email note at: support@servertune.com

    Thanks
    Andy Reed
    RHCE and CCNA
    ServerTune.com

Similar Threads & Tags
Similar threads

  1. UDP Port 3074 - does it count traffic?
    By craigedmonds in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 11-23-2010, 03:25 PM
  2. Massive outgoing UDP traffic port 53
    By whplus in forum Security
    Replies: 1
    Last Post: 11-05-2010, 05:33 AM
  3. Spewing UDP traffic
    By fragbait in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 12-04-2009, 06:40 PM
  4. Urgent: smartd send me sending mail from server
    By its_joy in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 12-29-2007, 01:22 PM
  5. 25mbps traffic on UDP port 80: How do I block this?
    By AbeFroman in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 08-19-2004, 11:15 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube