Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > Network / Server Status
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network / Server Status Please check often for network / Server updates here!

Reply
 
Thread Tools Display Modes
  #16  
Old 11-15-2006, 03:50 PM
Infinitation Infinitation is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Status report? Is there anyone available to post a quick reply as to where we are at with the issue? My clients have been without e-mail for an entire day and my frustration level with not having an acceptable answer for them is growing.
Reply With Quote
  #17  
Old 11-15-2006, 04:06 PM
aaron
Guest
 
About the attack

Today's problems with mail7 were due to a DDoS attack against the mail services (actually only port 25) on that machine.

Being that the attack is generating valid TCP connections, and sending valid (in TCP terms) data it is *very* hard to mitigate. Being that its not a standard synflood, the syn proxy methods had little avail.

I am seeing over 2000 uniq IP connections per second. I estimate the machines in this botnet to be well over 40K, since my state table stays between 30K-40K all the time.

Trust we are doing everything possible to get through this attack.
Reply With Quote
  #18  
Old 11-15-2006, 04:18 PM
Infinitation Infinitation is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
No doubt there and thanks for the update, is this going to be resolved by the morning?
Reply With Quote
  #19  
Old 11-15-2006, 04:36 PM
elbuentrovas elbuentrovas is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Finally someone responds... That's all we ask.

Thank you Aaron.
__________________
Rodrigo Méndez
Bitlab Multimedia (México)
www.bl.com.mx
Reply With Quote
  #20  
Old 11-15-2006, 06:14 PM
citywebsystems citywebsystems is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Thanks Aaron! Good luck.
Reply With Quote
  #21  
Old 11-15-2006, 09:11 PM
dvanburen's Avatar
dvanburen dvanburen is offline
Administrator
Admin
 
The attack seems to have dropped off. If anyone has problems sending AND receiving, please submit a ticket containing the public IP for the problematic computer.
__________________
David
Vortech, Inc.
Phone: 407.323.5634
http://vortechhosting.com
Reply With Quote
  #22  
Old 11-16-2006, 02:24 AM
kapuwa kapuwa is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
FYI: accourding to tech support mail7 and mail8 is having the same issue again
Reply With Quote
  #23  
Old 11-16-2006, 07:13 AM
aaron
Guest
 
Hey Folks,

Get into the habit of using port 2525 for outgoing SMTP to our servers. We have reached the point that larger ISP's reach with incomming SMTP. (Meaning a majority of incomming traffic from non UNIX hosts is spam, virii, etc). Its very simple for me to filter out traffic using passive OS fingerprinting. This was the major breakthrough last night in the attack.

So use port 2525 from now on at least on Mail7. Now you if happen to run *BSD, Linux, Solaris, etc you will not have a problem on port 25
Reply With Quote
  #24  
Old 11-16-2006, 07:56 AM
DustinStream DustinStream is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
So... Just to be clear...

Aaron, so the only thing we should do on our end right now to help out is to start switching any OUTGOING smtp connections of us or our clients to 2525, instead of 25, correct?

Three questions:

1) Only for mail7, or for any vortech mail servers?
2) No changes to incoming at all?
3) Will this change affect any of the php/asp mail scripts on web sites we have on your boxes, or are they fine?


Thank you very much for attention to this matter. It was a doozy, but I know its been your #1 priority to remedy, and I very much appreciate that.

-Dustin
Reply With Quote
  #25  
Old 11-16-2006, 08:02 AM
aaron
Guest
 
Just for 7 for now.

No changed for incomming.

Scripts go though another mail server all together, no they will not be affected.
Reply With Quote
  #26  
Old 11-16-2006, 08:45 AM
DustinStream DustinStream is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Here's a long shot.... is there any way in H-Sphere to see which clients are using Mail7? Or do I have to open up each account to see what mail server they are on?

Thanks,

Dustin
Reply With Quote
  #27  
Old 11-16-2006, 09:48 AM
aaron
Guest
 
Use a site like dnsreport.com to look at the MX record. Or use dig, nslookup, etc on a UNIX like OS.
Reply With Quote
  #28  
Old 11-16-2006, 10:01 AM
DustinStream DustinStream is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
sorry, I meant was there a report in H-sphere that would list all of the client accounts by their mail server, thereby allowing me to not have to look at each individual domain in hsphere, dnslookup, etc.

With 60-70 sites to look and see if they're on mail7, it gets tedious. (of course, I'm doing now what I should have done a long time ago, and making a full database of that info on my end)

-Dustin
Reply With Quote
  #29  
Old 11-16-2006, 10:29 AM
aaron
Guest
 
You can click the account ID, then click mail info from the CP.
Reply With Quote
  #30  
Old 11-16-2006, 11:15 AM
DustinStream DustinStream is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Are we down again?
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
1.30.06 - Mail7 aaron Network / Server Status 11 02-01-2006 12:31 AM
Mail7 2PM 10/07/2005 dvanburen Network / Server Status 3 10-07-2005 02:40 PM
spamGuard Mail - Mail7 and unix - unix14 admin News and Announcements 45 03-23-2005 12:50 PM
New Mail Server mail7.hsphere.cc admin News and Announcements 6 12-30-2004 11:52 PM


All times are GMT -5. The time now is 02:33 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.51706 seconds with 19 queries
[Output: 102.92 Kb. compressed to 94.16 Kb. by saving 8.76 Kb. (8.51%)]