dlewis23 Posted December 22, 2006 CID Share Posted December 22, 2006 Ok ive got a damn hacker that is trying to DOS my site and i can't get it to stop ive tried everything that i can think of. right now i have throlted the connection speed down from 100mbps to 10mbps so that the hacker does not use a ton of bandwidth. and today i went to turn it backup from 10mbps to 100mbps and once i did that the usage went from 10mbps consistent usage to 97mbps usage. Does anyone have any idea of anything that i can try? Quote Link to comment Share on other sites More sharing options...
Shug7272 Posted December 22, 2006 CID Share Posted December 22, 2006 First off where in the hell is your site and why havent I been invited. Quote Link to comment Share on other sites More sharing options...
tommie gorman Posted December 22, 2006 CID Share Posted December 22, 2006 First off where in the hell is your site and why havent I been invited. I knew we forgot someone. Quote Link to comment Share on other sites More sharing options...
Shug7272 Posted December 22, 2006 CID Share Posted December 22, 2006 Quote Link to comment Share on other sites More sharing options...
Blunted 2 Posted December 22, 2006 CID Share Posted December 22, 2006 well you have to see the ip's of the people trying to dos you and its probably more than 1 address. alot of people who do this stuff have a dos network setup just for this crap. Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 22, 2006 Author CID Share Posted December 22, 2006 well you have to see the ip's of the people trying to dos you and its probably more than 1 address. alot of people who do this stuff have a dos network setup just for this crap. well i had this problem on monday and was put on a special firewall that will watch and block traffic like this and it blocked a bunch of IPS over 250 then i had the problem again on wednesday and again it blocked over 250 ip address so they just keep changing there ip address. Quote Link to comment Share on other sites More sharing options...
php Posted December 22, 2006 CID Share Posted December 22, 2006 block all icmp traffic? Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 22, 2006 Author CID Share Posted December 22, 2006 block all icmp traffic? yes, didnt make a difference Quote Link to comment Share on other sites More sharing options...
tommie gorman Posted December 22, 2006 CID Share Posted December 22, 2006 Just curious, I thought a router was a great stop for this type of stuff? (don't worry, I already know I am confused) Just wondered. Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 22, 2006 Author CID Share Posted December 22, 2006 Just curious, I thought a router was a great stop for this type of stuff? (don't worry, I already know I am confused) Just wondered. not for a DOS attack. the router to stop this costs $60 a day to use. Quote Link to comment Share on other sites More sharing options...
tommie gorman Posted December 22, 2006 CID Share Posted December 22, 2006 So it is actually rentable? I know, a bit high. Just curious again. Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 22, 2006 Author CID Share Posted December 22, 2006 So it is actually rentable? I know, a bit high. Just curious again. yes its rentable. they gave it to my the first two times for free but the 3rd will cost. Quote Link to comment Share on other sites More sharing options...
tommie gorman Posted December 22, 2006 CID Share Posted December 22, 2006 Thanks. That is truly sad they are so bored as to do these types of things. Hackers are so truly lame. Quote Link to comment Share on other sites More sharing options...
Swimmer Posted December 22, 2006 CID Share Posted December 22, 2006 Well it isnt a DoS attack.. If settings are being changed then your box has been compromised. If it was compromised through a brute force attack then it should be in the logs, if they were not already removed or edited. One thing you could try, if you have a static IP, would be to allow only that IP address the use of the ssh port though IP tables. Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 23, 2006 Author CID Share Posted December 23, 2006 Well it isnt a DoS attack.. If settings are being changed then your box has been compromised. If it was compromised through a brute force attack then it should be in the logs, if they were not already removed or edited. One thing you could try, if you have a static IP, would be to allow only that IP address the use of the ssh port though IP tables. the box has not been compromised, ive had 5 different techs go in and look at it and nothing has been changed. And i do have a static ip and only allow my ip to connect to ssh, i also run a different port then 22 Quote Link to comment Share on other sites More sharing options...
FallowEarth Posted December 23, 2006 CID Share Posted December 23, 2006 What does netstat show on the box? Is any process showing high bandwidth or CPU usage? Any strange ports in use? I agree with Swimmer that it would be good to go through your firewall logs. Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 23, 2006 Author CID Share Posted December 23, 2006 What does netstat show on the box? Is any process showing high bandwidth or CPU usage? Any strange ports in use? I agree with Swimmer that it would be good to go through your firewall logs. netstat shows over 300 connections and they are consistantly getting blocked, but once they are blocked then new ip's connect. There are no strange ports in use its all http traffic. I don't have to go through my firewall logs i get a email every morning saying who connected or tried to connect to ssh ftp, sftp etc. etc. and and im the only one connecting. People are trying to connect but they can't Quote Link to comment Share on other sites More sharing options...
Sparticus Posted December 24, 2006 CID Share Posted December 24, 2006 netstat shows over 300 connections and they are consistantly getting blocked, but once they are blocked then new ip's connect. There are no strange ports in use its all http traffic. I don't have to go through my firewall logs i get a email every morning saying who connected or tried to connect to ssh ftp, sftp etc. etc. and and im the only one connecting. People are trying to connect but they can't Would that be when I try to ping it, I can't? Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 24, 2006 Author CID Share Posted December 24, 2006 Would that be when I try to ping it, I can't? no that would be because i blocked icmp traffic. Quote Link to comment Share on other sites More sharing options...
basic Posted December 24, 2006 CID Share Posted December 24, 2006 Have you checked for rootkits? Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 24, 2006 Author CID Share Posted December 24, 2006 Have you checked for rootkits? the box has not been compromised. its just a simple DOS attack. thats not stopping. Quote Link to comment Share on other sites More sharing options...
Sparticus Posted December 24, 2006 CID Share Posted December 24, 2006 What if you just shutdown your site for a while? Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 24, 2006 Author CID Share Posted December 24, 2006 What if you just shutdown your site for a while? im starting to think i may have to do that. Quote Link to comment Share on other sites More sharing options...
basic Posted December 24, 2006 CID Share Posted December 24, 2006 http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx Quote Link to comment Share on other sites More sharing options...
dlewis23 Posted December 24, 2006 Author CID Share Posted December 24, 2006 http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx its not windows. and i don't have a rootkit Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.