Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
If we do not hit our goal we will be forced to close the site.

Current status: https://keepboardsalive.com/

Annual subs are best for most impact. If you are still undecided on going Ad Free - you can also donate using the Paypal Donate option. All contribution helps. Thank you.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.
Hi all, please see this major site announcement: https://www.boards.ie/discussion/2058427594/boards-ie-2026

DDOS Attack

  • 23-07-2009 08:38PM
    #1
    Closed Accounts Posts: 1,444 ✭✭✭


    I've a dedicated server and I fear I'm being DDOSed. It's doing nothing but serve email and the odd webpage. It's just every couple of days it either grinds to a halt or crashes altogether.

    Anyone have any pointers on analysing the problem? I'm going to get on to my server provider and get them to hit the reset button for me now.


Comments

  • Registered Users, Registered Users 2 Posts: 139 ✭✭{^Syntax^}


    Can you analyze the logs on the firewall?


  • Closed Accounts Posts: 1,444 ✭✭✭Cantab.


    {^Syntax^} wrote: »
    Can you analyze the logs on the firewall?

    I don't have a dedicated firewall. I'm considering paying the extra $30 a month for a Cisco firewall.

    I am however using ufw (Ubuntu Firewall) -- a software firewall. I'll have a look at the logs and see what I come up with.


  • Registered Users, Registered Users 2 Posts: 4,660 ✭✭✭Gavin


    Ask your service provider, they should be able to tell you what is going on, at least if it's network related.

    You could also just run tcpdump for a while and see what's coming into the machine.


  • Closed Accounts Posts: 751 ✭✭✭JimmyCrackCorn!


    Gavin wrote: »
    Ask your service provider, they should be able to tell you what is going on, at least if it's network related.


    ^^^
    As above


    You could also just run tcpdump for a while and see what's coming into the machine.

    You will have to talk to your service provider if you cannot log packets and analyse it yourself to confirm something bad is happening.

    Start with the basics go through all the logs (traffic and server) to see is there anything in there. It could be as simple as a badly timed cron job or you may have something.


    One thing to note a cisco firewall wont magically stop a DDOS attack.


  • Registered Users, Registered Users 2 Posts: 1,311 ✭✭✭Procasinator


    Check for heap dumps and the like, it might not even be a DDoS, though it if it is a low-traffic box it does sound irregular.

    Logs would be the first port of call though.


  • Advertisement
Advertisement