Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > Network / Server Status
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network / Server Status Please check often for network / Server updates here!

Reply
 
Thread Tools Display Modes
  #1  
Old 09-19-2004, 11:43 PM
alexc
Guest
 
2004-09-19 Windows servers

Someone appears to be running a DoS attack against NT31 and is taking out the whole cabinet with it. We're working on it.
Reply With Quote
  #2  
Old 09-19-2004, 11:46 PM
Bladesnitz
Guest
 
Actually, from a 3rd party observation, its taking the whole network Get em' Alex.
Reply With Quote
  #3  
Old 09-19-2004, 11:56 PM
bootNumlock's Avatar
bootNumlock bootNumlock is offline
Brangwyn fan club member
Vortech Inc. Customer
 
Location: chicago
I'm with Matt on this one... the graph's look a little orange and most of my sites are creepin'
__________________
boot numlock
Reply With Quote
  #4  
Old 09-20-2004, 12:25 AM
tkraffty's Avatar
tkraffty tkraffty is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: san jose, ca
ouch - seeing ups and downs across the board, customer already called about email...

guess you're rebooting routers/machines etc. or your DoS friend is being pretty damn systematic and/or hogging the whole pipe.. egad
Reply With Quote
  #5  
Old 09-20-2004, 12:55 AM
alexc
Guest
 
He's being methodical and is rotating hosts/networks. James has spent the past hour shooting them down as they come in. We'll try to divert traffic away from that switch altogether and let the router take the load. Service to NT31 will be iffy at best for the time being.
Reply With Quote
  #6  
Old 09-20-2004, 01:02 AM
antic's Avatar
antic antic is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Perth, Western Australia
Hey guys, good luck! About how long does it take for a DoS attack to clear up? Or for whomever it is to get bored?
__________________
 Thunderbird Error
The POP server is in Depeche Mode
Reply With Quote
  #7  
Old 09-20-2004, 01:05 AM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Most DDoS's use "zombie" machines.. usually some twit just sets off the attack and letts the zombie machines do all the work, some can last days before they finally stop.
Reply With Quote
  #8  
Old 09-20-2004, 01:56 AM
cambodia's Avatar
cambodia cambodia is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Phnom Penh . Cambodia
Send a message via ICQ to cambodia Send a message via AIM to cambodia Send a message via Yahoo to cambodia Send a message via Skype to cambodia
i heard if we use best equipment with fast alert it never run longer than 15minute ?
__________________
I Love Cambodia
Reply With Quote
  #9  
Old 09-20-2004, 02:20 AM
Bladesnitz
Guest
 
Quote:
Originally Posted by cambodia
i heard if we use best equipment with fast alert it never run longer than 15minute ?

Well, with unscrupulous invidividuals selling hordes of zombie machines on the internet, depending on their intent, they could keep even the most equipped networks down for hours on end. Eg. Akamai, SCO, etc.

20,000 Zombies - 2000$ ...

http://www.usatoday.com/tech/news/co...bieprice_x.htm

Of course, Alex and James seemed to have gripped it fairly quick as I didn't notice any prolonged outage from here... A few blips here and there for about 20 minutes, but I didn't see anything too terrible
Reply With Quote
  #10  
Old 09-20-2004, 02:50 AM
Vantage's Avatar
Vantage Vantage is offline
Registered User
Junior Member
 
Location: Orlando Fl
Send a message via ICQ to Vantage Send a message via AIM to Vantage
Everything should be working well now...

Im going to be monitoring it on and off all night.. Just to be safe.

p.s.
There is no way to stop a big enough DDoS. So far I have blocked over 5500 IPs and all UDP service to the box.... Looks to have mostly stopped it but..... They are still trying...

Last edited by Vantage : 09-20-2004 at 02:53 AM.
Reply With Quote
  #11  
Old 09-20-2004, 12:21 PM
tkraffty's Avatar
tkraffty tkraffty is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: san jose, ca
Hi - had a 1/2 hour outage reported from a site on NT18 this morning at 8:45AM. Is these issues still related to the DoS attack? Just wondering if there's still some lingering effects, and what my day is going to look like in terms of customer suport
Reply With Quote
  #12  
Old 09-20-2004, 04:07 PM
Silverbug's Avatar
Silverbug Silverbug is offline
Custom Built Solutions
Vortech Inc. Customer
 
Location: AK, New Zealand
Send a message via ICQ to Silverbug Send a message via MSN to Silverbug Send a message via Skype to Silverbug
Quote:
So far I have blocked over 5500 IPs and all UDP service to the box....
so when this happens you just block the ip of the computer that hammering the server?
__________________
Paul Foley
Sniper Systems Ltd

Reply With Quote
  #13  
Old 09-20-2004, 07:12 PM
Vantage's Avatar
Vantage Vantage is offline
Registered User
Junior Member
 
Location: Orlando Fl
Send a message via ICQ to Vantage Send a message via AIM to Vantage
Silverbug,
It depends on the specific incident.
In this case we had a wide variety of IPs all from the same geographic area. They were using a number of attack methods and there attack seamed to be localized on one IP (Shared IP of NT31).
Due to the type of attacks we were seeing it was difficult to block the attackers in "one fell swoop".
I dont want to bore you with the whole story but it appears that they were prepaired to take down that server by any means they had available.
The only real choice I had was to Block large blocks of IPs. After I had blocked about 5500 IPs they decided to go with a spoofed UDP flood. UDP is VERY easy to spoof and it doesnt realy matter where the traffic originated from.. if the IP they are spoofing isnt blocked then the attack will get through, even if you are blocking the true IP of the attacker.
This is when I rate limited the default NT31 IP and blocked all UDP... 20 Min or so later they gave up... They IPs remain blocked until I stop seeing nasty traffic comming from them...
Reply With Quote
  #14  
Old 09-20-2004, 07:29 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Theres not really a lot else ya can do SilverBug, though most routers do provide tools for mitigating attacks as well like SYN packet limiting etc also.
Reply With Quote
  #15  
Old 09-20-2004, 07:31 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Just a side thought here .. is there actually anything other than DNS running that would actually even require UDP to get in past the border router? could UDP not be completely dropped other than UDP53->DNS Servers?
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
2004-09-29: CP and Windows Servers Bladesnitz Network / Server Status 64 11-12-2004 10:22 AM
2004-05-31 unix servers alexc Network / Server Status 18 06-01-2004 02:45 PM
02/25/2004 - ns-ns3.hsphere.cc & MS SQL servers Carly Network / Server Status 1 02-25-2004 08:29 PM
01/13/2004 - All Windows and MSSQL Servers bigdave Network / Server Status 12 01-14-2004 04:48 PM
01/08/2004 - Scheduled Maintanence for ALL Servers bigdave Network / Server Status 0 01-07-2004 11:15 PM


All times are GMT -5. The time now is 02:51 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.72178 seconds with 19 queries
[Output: 108.98 Kb. compressed to 100.09 Kb. by saving 8.88 Kb. (8.15%)]