Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

DDOS Attack

  • 23-07-2009 8:38pm
    #1
    Closed Accounts Posts: 1,444 ✭✭✭


    I've a dedicated server and I fear I'm being DDOSed. It's doing nothing but serve email and the odd webpage. It's just every couple of days it either grinds to a halt or crashes altogether.

    Anyone have any pointers on analysing the problem? I'm going to get on to my server provider and get them to hit the reset button for me now.


Comments

  • Registered Users, Registered Users 2 Posts: 139 ✭✭{^Syntax^}


    Can you analyze the logs on the firewall?


  • Closed Accounts Posts: 1,444 ✭✭✭Cantab.


    {^Syntax^} wrote: »
    Can you analyze the logs on the firewall?

    I don't have a dedicated firewall. I'm considering paying the extra $30 a month for a Cisco firewall.

    I am however using ufw (Ubuntu Firewall) -- a software firewall. I'll have a look at the logs and see what I come up with.


  • Registered Users, Registered Users 2 Posts: 4,676 ✭✭✭Gavin


    Ask your service provider, they should be able to tell you what is going on, at least if it's network related.

    You could also just run tcpdump for a while and see what's coming into the machine.


  • Closed Accounts Posts: 752 ✭✭✭JimmyCrackCorn!


    Gavin wrote: »
    Ask your service provider, they should be able to tell you what is going on, at least if it's network related.


    ^^^
    As above


    You could also just run tcpdump for a while and see what's coming into the machine.

    You will have to talk to your service provider if you cannot log packets and analyse it yourself to confirm something bad is happening.

    Start with the basics go through all the logs (traffic and server) to see is there anything in there. It could be as simple as a badly timed cron job or you may have something.


    One thing to note a cisco firewall wont magically stop a DDOS attack.


  • Registered Users, Registered Users 2 Posts: 1,311 ✭✭✭Procasinator


    Check for heap dumps and the like, it might not even be a DDoS, though it if it is a low-traffic box it does sound irregular.

    Logs would be the first port of call though.


  • Advertisement
Advertisement