Site under attack..what to do?
Post new topic   Reply to topic   Printer Friendly Page     Forum IndexSecurity
Author Message
bullrees
Newbie


Joined: Jun 20, 2007
Posts: 28

PostPost subject: Site under attack..what to do?
Posted: Thu Mar 20, 2008 11:49 pm
Reply with quote

My site suddenly got alot of visitors.No idea what I did to these kids but it was over 380 at one point.It didn't really slow the site at all but it still concerns me.Is there a way I can get the ip of anyone on the site?I tried the raw logs but hard to tell who is legit from there.



bullrees's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
linux/Apache1.3.33/MySQL Version 5.0.81-community-log (client: 5.0.81)/PHP Version 5.2.9/DF9.2.1
Back to top
View user's profile
Phoenix
Site Admin


Joined: Apr 19, 2004
Posts: 8729
Location: Netizen

PostPost subject: Re: Site under attack..what to do?
Posted: Thu Mar 20, 2008 11:59 pm
Reply with quote

Maybe not kids, unless those hits are all sorts of pathetic exploit attempts. Most likely some genuine or wannabe search engine bot - you'll need to lookup the IP(s) and trace it(them) on the net.

If they are hitting too fast, and you have flooding turned on, that system will eventually deal with them.

Since your website is such a secret, maybe they won't find you again Wink


Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website
bullrees
Newbie


Joined: Jun 20, 2007
Posts: 28

PostPost subject: Re: Site under attack..what to do?
Posted: Fri Mar 21, 2008 12:13 am
Reply with quote

I didn't have flooding on at the begining because it tends to ban legit members..I turned it on when I was told of the problem.The visitors were at 100 then.

I turned the forums to registered only(normaly visitors can view) but forgot I had a "last forum posts" center block.That's when it went to 380.I set the center forum block to members only and that seemed to help the most.

I contacted my host to see if they could help but didn't get any info that I couldn't do myself.

The website is a clan website and we have our fist clan match tomorrow.We only have 80 or so members so it was a bit of a surprise.

Not sure what you mean about secret unless it's cause I didn't say.. knightsgaming.com


bullrees's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
linux/Apache1.3.33/MySQL Version 5.0.81-community-log (client: 5.0.81)/PHP Version 5.2.9/DF9.2.1
Back to top
View user's profile
Phoenix
Site Admin


Joined: Apr 19, 2004
Posts: 8729
Location: Netizen

PostPost subject: Re: Site under attack..what to do?
Posted: Fri Mar 21, 2008 12:16 am
Reply with quote

Nano added your old www - it was blank when I made my comment.

Well, if the flood system is not an option, and I can understand why, you'll have to resort to IP bans through your htaccess file, or upgrade to 9.2.1 and ban them through the admin security panel.


Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website
bullrees
Newbie


Joined: Jun 20, 2007
Posts: 28

PostPost subject: Re: Site under attack..what to do?
Posted: Fri Mar 21, 2008 12:28 am
Reply with quote

EDIT:the flood was turned on for the major part of the attack but didn't catch anyone.

I can ban their ip on my current version but how do I find the ip if they don't login?

I thought I saw an ip log thing before but don't see it now.

Like I said..the host didn't even want to dig through the raw access logs for me.


bullrees's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
linux/Apache1.3.33/MySQL Version 5.0.81-community-log (client: 5.0.81)/PHP Version 5.2.9/DF9.2.1
Back to top
View user's profile
Phoenix
Site Admin


Joined: Apr 19, 2004
Posts: 8729
Location: Netizen

PostPost subject: Re: Site under attack..what to do?
Posted: Fri Mar 21, 2008 12:36 am
Reply with quote

Well, hosts are like that - impossible for them to deal with such issues.

Install IP Tracker - makes it easy to track mongrels like that.

In any event, their IP should be visible or clickable in the Who Where block.


Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website
sultan
Nice poster


Joined: Nov 01, 2005
Posts: 68

PostPost subject: Re: Site under attack..what to do?
Posted: Fri Mar 21, 2008 2:15 am
Reply with quote

Phoenix wrote:
Install IP Tracker - makes it easy to track mongrels like that.
I agree. IP Tracker is one of the best tools in my arsenal for cases like this. Once I kill their session in PHPMyadmin and use IP Tracker to get IP and then block the IP via CPG Admin area (after the fact) or htaccess file (During event) as I get to it faster from PHPMyadmin in my situation.


sultan's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
[CentOS release 4.6 (Final)] | [Apache 1.3.37] | [MySQL 4.1.21-standard-log (client: 4.1.21) | [PHP 4.4.7] | [DF 9.2.1] | [FPro 2.0.2]
Back to top
View user's profile Visit poster's website
bullrees
Newbie


Joined: Jun 20, 2007
Posts: 28

PostPost subject: Re: Site under attack..what to do?
Posted: Fri Mar 21, 2008 2:20 am
Reply with quote

thanks for the help guys..I will get ip tracker.They seemed to get bored when they couldn't effect the site but nice to know what to do in the future.

Thx again


bullrees's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
linux/Apache1.3.33/MySQL Version 5.0.81-community-log (client: 5.0.81)/PHP Version 5.2.9/DF9.2.1
Back to top
View user's profile
leductho
Newbie


Joined: Dec 19, 2007
Posts: 4

PostPost subject: Re: Site under attack..what to do?
Posted: Mon Jun 09, 2008 6:26 am
Reply with quote

That's DDos, nothing you can do accept ban that IP.

leductho's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache 2.2.6 /MySQL/PHP5.2.5/DragonflyCMS 9.21
Back to top
View user's profile Visit poster's website
DJ Maze
Developer


Joined: Apr 19, 2004
Posts: 5668
Location: http://tinyurl.com/5z8dmv

PostPost subject: Re: Site under attack..what to do?
Posted: Mon Jun 09, 2008 6:52 am
Reply with quote

leductho wrote:
That's DDos, nothing you can do accept ban that IP.

Not really a DDoS. You know how a DDoS works and how a searchbot or harvester works?


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 12 / 2.2.15 / 5.1.47 / 5.3.3 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger
leductho
Newbie


Joined: Dec 19, 2007
Posts: 4

PostPost subject: Re: Site under attack..what to do?
Posted: Mon Jun 09, 2008 7:08 am
Reply with quote

DJ Maze wrote:
leductho wrote:
That's DDos, nothing you can do accept ban that IP.

Not really a DDoS. You know how a DDoS works and how a searchbot or harvester works?

I don't know much about DDos but I can make your website like that. There many kinds of DDos now. Do you have any way to avoid that?


leductho's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache 2.2.6 /MySQL/PHP5.2.5/DragonflyCMS 9.21
Back to top
View user's profile Visit poster's website
NanoCaiordo
Developer


Joined: Jun 29, 2004
Posts: 3676
Location: Melbourne, AU

PostPost subject: Re: Site under attack..what to do?
Posted: Mon Jun 09, 2008 8:19 am
Reply with quote

leductho wrote:
That's DDos, nothing you can do accept ban that IP.
leductho wrote:
I don't know much about DDos

Anyways thats a BOT requesting 1 page every 2 seconds. No flooding, no DDoS, no worries.

To avoid this, grab the UA and related IPs (IP range if possible) then we will update the BOT list.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
MySQL 5.1 / PHP 5.3 / NextGen()
Back to top
View user's profile Visit poster's website
leductho
Newbie


Joined: Dec 19, 2007
Posts: 4

PostPost subject: Re: Site under attack..what to do?
Posted: Mon Jun 09, 2008 11:44 pm
Reply with quote

I'm using your DF 9.21. I really love it. And here is the same thing I've tested in my site with security on.
Sorry for keep posting things but I think this is a good topic for DF user.


leductho's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache 2.2.6 /MySQL/PHP5.2.5/DragonflyCMS 9.21
Back to top
View user's profile Visit poster's website
NanoCaiordo
Developer


Joined: Jun 29, 2004
Posts: 3676
Location: Melbourne, AU

PostPost subject: Re: Site under attack..what to do?
Posted: Tue Jun 10, 2008 10:12 am
Reply with quote

NanoCaiordo wrote:
No flooding, no DDoS, no worries.

To avoid this, grab the UA and related IPs (IP range if possible) then we will update the BOT list.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
MySQL 5.1 / PHP 5.3 / NextGen()
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic   Printer Friendly Page     Forum IndexSecurity All times are GMT
Page 1 of 1


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

Dedicated Server & Bandwidth Sponsored by DedicatedNOW
User Info [x]

Welcome Anonymous

Nickname
Password
(Register)

Last CVS commits [x]

Languages [x]

Community [x]

Support for DragonflyCMS in a other languages:

Deutsch
Español

X-links [x]
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

Preview theme [x]
Each user can view the site with a different theme.
Themes marked with a * also change the forum look.


You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
This page generated in 0.5618 seconds with 16 DB Queries in 0.0396 seconds
Memory Usage: 3 MB
Interactive software released under GNU GPL, Code Credits, Privacy Policy