Server Outage

Having problems with the board or the online guidebook?
Suggestions welcome.
User avatar
ray
Site Admin
Posts: 841
Joined: Thu Sep 19, 2002 2:48 pm

Post by ray »

I really don't think it's an intentional DOS attack. I think it's Bank One's caching web proxy trying to suck down my whole site once an hour so they can save bandwidth on their end.

The fact that it's once an hour makes me believe this.

It has really been a pain in the ass trying to track this down. I'd love to get my hands around the responsible person's neck.
marathonmedic
Posts: 1557
Joined: Fri Feb 20, 2004 3:01 am

Post by marathonmedic »

Isn't that the American way? Use someone else's resources so you can save money? I think you should demand a small commission on all transactions that happen as a result of your pirated bandwidth.
Ticking is gym climbing outdoors.
User avatar
ray
Site Admin
Posts: 841
Joined: Thu Sep 19, 2002 2:48 pm

Post by ray »

Well, I'm happy to say that I'm pretty sure I've blocked the source IP addresses that were causing the server to die.

So if you know anyone on 159.53.0.0/16 then you may want to inform them of why they can't access the site.
climbhigh
Posts: 387
Joined: Tue Oct 08, 2002 2:43 pm

Post by climbhigh »

I got more done at work the last couple days than I have in a long time. I hate it !
Wes
Posts: 6530
Joined: Thu Sep 19, 2002 3:46 pm

Post by Wes »

Crazy for sure. Could also be something like webwacker running on a set schedule.

Wes
"There is no secret ingredient"

Po, the kung fu panda
Alan Evil
Posts: 3592
Joined: Fri Oct 10, 2003 1:08 pm

Post by Alan Evil »

I guess it's time to go introduce a number 5 cam to the asshole of the President of Bank One. I've always hated that bank anyway.
[size=75]You are as bad as Alan, and even he hits the mark sometimes. -charlie

"Not all conservatives are stupid, but most stupid people are conservative." - John Stuart Mill[/size]
Boyd
Posts: 108
Joined: Fri Apr 09, 2004 3:25 am

Post by Boyd »

vietcong can make bombs from bottle caps...and they can take down a website.

I had a similar attack via smtp...which might be your problem. note: i have no clue, but i can explain my experience.

I had a flood of smtp requests bring down my server. It wasn't a dos attack but a spam attack that zapped my memory and cache so no server could work. Boom. I made iptables more hard. MAPS hard.....but do this to see who is the mail-send perp (if applicable): grep "Oct" /var/log/secure | grep smtp | sed 's/ / /g' | cut -d' ' -f1,2,9 | sort | uniq -c | sort -nr | head | sed 's/from=//g'
Post Reply