Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

DDOS Attack

  • 23-07-2009 09:38PM
    #1
    Closed Accounts Posts: 1,444
    ✭✭✭


    I've a dedicated server and I fear I'm being DDOSed. It's doing nothing but serve email and the odd webpage. It's just every couple of days it either grinds to a halt or crashes altogether.

    Anyone have any pointers on analysing the problem? I'm going to get on to my server provider and get them to hit the reset button for me now.


Welcome!

It looks like you're new here. Sign in or register to get started.

Comments

  • Registered Users, Registered Users 2 Posts: 139 {^Syntax^}
    ✭✭


    Can you analyze the logs on the firewall?


  • Closed Accounts Posts: 1,444 Cantab.
    ✭✭✭


    {^Syntax^} wrote: »
    Can you analyze the logs on the firewall?

    I don't have a dedicated firewall. I'm considering paying the extra $30 a month for a Cisco firewall.

    I am however using ufw (Ubuntu Firewall) -- a software firewall. I'll have a look at the logs and see what I come up with.


  • Registered Users, Registered Users 2 Posts: 4,660 Gavin
    ✭✭✭


    Ask your service provider, they should be able to tell you what is going on, at least if it's network related.

    You could also just run tcpdump for a while and see what's coming into the machine.


  • Closed Accounts Posts: 752 JimmyCrackCorn!
    ✭✭✭


    Gavin wrote: »
    Ask your service provider, they should be able to tell you what is going on, at least if it's network related.


    ^^^
    As above


    You could also just run tcpdump for a while and see what's coming into the machine.

    You will have to talk to your service provider if you cannot log packets and analyse it yourself to confirm something bad is happening.

    Start with the basics go through all the logs (traffic and server) to see is there anything in there. It could be as simple as a badly timed cron job or you may have something.


    One thing to note a cisco firewall wont magically stop a DDOS attack.


  • Registered Users, Registered Users 2 Posts: 1,311 Procasinator
    ✭✭✭


    Check for heap dumps and the like, it might not even be a DDoS, though it if it is a low-traffic box it does sound irregular.

    Logs would be the first port of call though.


  • Advertisement

Welcome!

It looks like you're new here. Sign in or register to get started.
Advertisement