Is this a DDos attack ? Can or i have to block it ?

Bidi

Well-Known Member
Oct 3, 2012
100
6
68
Romania, Transilvania
cPanel Access Level
DataCenter Provider
Hello guys since 3 days ago csf is sending me emails with this

Code:
Time:        Mon Nov 18 00:40:05 2013 +0200
IP:          92.53.42.60 (MK/Macedonia/ctel-92-53-42-60.cabletel.com.mk)
Connections: 275
Blocked:     Temporary Block

Connections:
tcp: 92.53.42.60:65375 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65248 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65217 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65387 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65350 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65369 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65109 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65297 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65308 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65261 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65374 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65338 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65060 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65312 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65330 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65172 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65083 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65291 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65262 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65313 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65346 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65221 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65272 -> 188.213.216.8:80 (TIME_WAIT)
tcp: 92.53.42.60:65273 -> 188.213.216.8:80 (TIME_WAIT)
But is not only from this ip every day ar like 10 20 new ips, what is this ? And if it affect my server how can i block them ?
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,913
2,205
363
Hello :)

The alert you pasted indicates the IP address was blocked automatically by CSF, so you should not have to manually block these IP addresses unless the same ones continue to reach this limit.

Thank you.
 

Bidi

Well-Known Member
Oct 3, 2012
100
6
68
Romania, Transilvania
cPanel Access Level
DataCenter Provider
Hello :)

The alert you pasted indicates the IP address was blocked automatically by CSF, so you should not have to manually block these IP addresses unless the same ones continue to reach this limit.

Thank you.
I still have this problem but it comes from hundreds of ips and one more think i had just visit my website and guess what he banned me assweal :| and i had just one browser page opened with my website how is this posible ?

And why it show tcp6 ?
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,913
2,205
363
Please consider contacting CSF directly or through their support forums if you feel this is a flaw with their firewall application.

Thank you.
 

quizknows

Well-Known Member
Oct 20, 2009
1,008
87
78
cPanel Access Level
DataCenter Provider
If your site has a lot of images it can cause a clients browser to create multiple simultaneous connections to your server.

You can try raising or disabling CT_LIMIT in your csf conf.

However, I don't think this is a CSF issue... 275 connections is a lot.

Perhaps make sure your Apache settings are correct... lower timeout value, make sure keepalive is on, and perhaps lower max requests per child. Something related to your site or Apache config has to be causing a visitor to open that many port 80 connections. The shell output from 'httpd fullstatus' might help as well.