Временно закрыли доступ от неукраинского интернета. Так что пока все тихо.
На выходных подумаю как разруливать дальше.
Временно закрыли доступ от неукраинского интернета.
Так что в таком режиме сайты работают без тормозов.
2Gb RAM
Какая часть ксеона реально выделена сказать сложно.
absurdo добавил 11.02.2011 в 21:28
Сколько приблизительно может стоить такая атака? Интересно во сколько это обошлось конкурентам.
absurdo добавил 11.02.2011 в 21:39
58.8.231.254 - - [11/Feb/2011:07:49:47 +0200] "GET / HTTP/1.1" 500 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:11:33:12 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.8.1.1) Gecko/20061204 Firefox/2.0.0.1" 58.8.231.254 - - [11/Feb/2011:14:48:24 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:14:53:55 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:14:54:13 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:14:55:32 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:14:55:58 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:14:56:02 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:14:56:39 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:14:57:28 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:00:48 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:01:19 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:03:07 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:03:46 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:11:22 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:20:33 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:25:18 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:25:30 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:25:44 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:25:56 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:13 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:14 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:17 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:28 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:30 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:29 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:32 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:31 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:35 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:43 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:26 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 58.8.231.254 - - [11/Feb/2011:15:26:26 +0200] "GET / HTTP/1.1" 301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
О чем это говорит?
Выше я выкладывал отчеты netstat.
Что можете сказать о такой атаке?
это значит что первый айпишник установил 15 соединений а последний 605?
netstat -n | grep :80 |wc -l
648
775
absurdo добавил 11.02.2011 в 15:51
netstat -n | grep :80 | grep SYN |wc -l
118
absurdo добавил 11.02.2011 в 15:55
netstat -anp |grep 'tcp\|udp' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
(No info could be read for "-p": geteuid()=503 but you should be root.) 1 109.230.213.34 1 207.46.12.237 1 207.46.199.42 1 67.195.37.188 1 93.73.23.116 2 112.185.233.195 2 115.118.111.119 2 46.185.17.48 2 78.27.129.139 2 87.101.168.185 2 91.201.66.116 2 94.179.193.81 2 94.59.87.96 3 58.9.133.206 3 95.132.238.127 4 123.109.196.204 4 95.132.205.133 5 125.164.154.162 5 197.224.113.230 5 200.150.190.6 5 59.92.46.136 5 62.149.2.1 6 195.29.157.86 9 13 0.0.0.0 15 41.248.99.213 23 151.56.42.103 24 95.10.183.89 34 41.199.176.60 47 182.53.217.156 50 41.218.234.109 76 41.211.26.80 103 41.232.70.152 605 58.8.231.254
absurdo добавил 11.02.2011 в 15:58
netstat -n -p | grep SYN_REC | awk '{print $5}' | awk -F: '{print $1}'
(No info could be read for "-p": geteuid()=503 but you should be root.)58.8.231.25458.8.231.25441.211.26.80180.183.246.5458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.25458.8.231.254180.183.246.54180.183.246.5441.211.26.8058.8.231.25458.8.231.25458.8.231.254180.183.246.54180.183.246.54180.183.246.54180.183.246.54180.183.246.54180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.254122.164.26.28180.183.246.5458.8.231.25458.8.231.25458.8.231.25441.211.26.8041.211.26.8041.211.26.80180.183.246.54180.183.246.5458.8.231.254180.183.246.54180.183.246.5458.8.231.254180.183.246.54180.183.246.54180.183.246.5458.8.231.25458.8.231.254180.183.246.54180.183.246.5458.8.231.25458.8.231.25458.8.231.254210.212.179.172180.183.246.5458.8.231.254180.183.246.5458.8.231.254180.183.246.5458.8.231.254180.183.246.5458.8.231.25458.8.231.254180.183.246.5441.211.26.8058.8.231.254180.183.246.54180.183.246.54180.183.246.5458.8.231.25441.211.26.80180.183.246.5441.211.26.8058.8.231.254180.183.246.5458.8.231.25441.211.26.80180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.25441.211.26.80180.183.246.54180.183.246.54180.183.246.5458.8.231.254180.183.246.5458.8.231.25458.8.231.25441.211.26.8041.211.26.8058.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.254180.183.246.54180.183.246.54180.183.246.54180.183.246.54180.183.246.5458.8.231.25458.8.231.254180.183.246.54180.183.246.54180.183.246.5458.8.231.25441.211.26.8058.8.231.25441.211.26.80180.183.246.5458.8.231.25458.8.231.25458.8.231.254180.183.246.54180.183.246.54180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.5441.211.26.8041.211.26.80180.183.246.54180.183.246.5441.211.26.8058.8.231.25458.8.231.25441.211.26.80180.183.246.5458.8.231.25441.211.26.80180.183.246.5458.8.231.25458.8.231.25458.8.231.25441.211.26.80180.183.246.54180.183.246.5441.211.26.8058.8.231.25458.8.231.254180.183.246.5441.211.26.8041.211.26.80180.183.246.54180.183.246.54180.183.246.5458.8.231.25458.8.231.25458.8.231.25441.211.26.8041.211.26.80180.183.246.54180.183.246.5458.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25441.211.26.80180.183.246.5458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.254180.183.246.54180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.254125.164.154.16258.8.231.254180.183.246.5458.8.231.254212.49.93.24358.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25441.211.26.80180.183.246.5441.211.26.8058.8.231.25458.8.231.25458.8.231.254180.183.246.54180.183.246.5458.8.231.25458.8.231.25458.8.231.254180.183.246.5441.211.26.8058.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.25441.211.26.8058.8.231.25458.8.231.25458.8.231.25441.211.26.8041.211.26.80180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25459.92.46.13658.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.254180.183.246.5458.8.231.25458.8.231.25441.211.26.80180.183.246.5441.211.26.80180.183.246.5458.8.231.25458.8.231.25458.8.231.254180.183.246.54180.183.246.5441.211.26.8041.211.26.80180.183.246.5458.8.231.25458.8.231.25458.8.231.254180.183.246.54180.183.246.5458.8.231.25441.211.26.80180.183.246.5458.8.231.254180.183.246.54180.183.246.5458.8.231.25458.8.231.25441.211.26.80180.183.246.54180.183.246.5458.8.231.254180.183.246.54180.183.246.5458.8.231.25441.211.26.80180.183.246.54180.183.246.54180.183.246.54180.183.246.5441.211.26.8058.8.231.25458.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.25441.211.26.80180.183.246.54180.183.246.5458.8.231.254180.183.246.5458.8.231.254180.183.246.54180.183.246.5441.211.26.80180.183.246.5441.211.26.8058.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.25441.211.26.8041.211.26.8058.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.254210.212.179.17258.8.231.254180.183.246.5458.8.231.254180.183.246.54180.183.246.54180.183.246.54180.183.246.5458.8.231.25458.8.231.254180.183.246.54180.183.246.54180.183.246.54180.183.246.5458.8.231.25458.8.231.254212.49.93.24358.8.231.25441.211.26.80180.183.246.5441.211.26.80180.183.246.5458.8.231.25441.211.26.8058.8.231.25458.8.231.25441.211.26.8058.8.231.25458.8.231.25458.8.231.25441.211.26.8041.211.26.8058.8.231.25458.8.231.254180.183.246.54180.183.246.54180.183.246.5441.211.26.80180.183.246.5458.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25441.211.26.8041.211.26.8058.8.231.25441.211.26.80180.183.246.5458.8.231.25458.8.231.25441.211.26.80180.183.246.54180.183.246.5441.211.26.80180.183.246.5458.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.54180.183.246.54180.183.246.54180.183.246.5458.8.231.25458.8.231.254180.183.246.5458.8.231.25441.211.26.80180.183.246.54180.183.246.5458.8.231.25458.8.231.254180.183.246.5458.8.231.254180.183.246.54180.183.246.5458.8.231.25458.8.231.254180.183.246.54180.183.246.54180.183.246.5458.8.231.25441.211.26.8041.211.26.8058.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.25458.8.231.254125.164.154.162180.183.246.54180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.9.133.20658.8.231.25458.8.231.25441.211.26.8058.8.231.254180.183.246.5458.8.231.25458.8.231.254180.183.246.54125.164.154.16258.8.231.25446.119.88.22458.8.231.25458.8.231.254180.183.246.5441.211.26.8058.8.231.254180.183.246.5441.211.26.8041.211.26.8058.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.54180.183.246.5458.8.231.25458.8.231.25441.211.26.8058.8.231.254180.183.246.54180.183.246.5441.211.26.8058.8.231.25458.8.231.25458.8.231.25458.9.133.20658.8.231.25458.8.231.25441.211.26.8058.8.231.25441.211.26.8058.8.231.25458.8.231.25458.8.231.25441.211.26.8059.92.46.13658.8.231.25458.8.231.254180.183.246.54197.224.113.23058.8.231.25441.211.26.8058.8.231.254180.183.246.5458.8.231.254180.183.246.5441.211.26.80180.183.246.5458.8.231.25458.8.231.25458.8.231.25458.8.231.254180.183.246.5458.8.231.254180.183.246.54180.183.246.54180.183.246.5458.8.231.254180.183.246.5441.211.26.8058.8.231.25441.211.26.8058.8.231.25458.8.231.25441.211.26.8058.8.231.25458.8.231.25458.8.231.25458.8.231.25441.211.26.8041.211.26.8058.8.231.25458.8.231.254180.183.246.5458.8.231.25458.8.231.254180.183.246.5441.211.26.8058.8.231.25458.8.231.254180.183.246.5458.8.231.254180.183.246.5441.211.26.8058.8.231.25458.8.231.254180.183.246.54180.183.246.5458.8.231.254180.183.246.54180.183.246.5458.8.231.254180.183.246.5458.8.231.254180.183.246.5441.211.26.80180.183.246.5458.8.231.25441.211.26.80180.183.246.5458.8.231.25458.8.231.254180.183.246.5458.8.231.25458.8.231.25458.8.231.254180.183.246.54180.183.246.5458.8.231.25458.8.231.25441.211.26.80180.183.246.54180.183.246.5458.8.231.254
Пока посмотрю как с этим справится мой хостер.
На всякий случай пишите в личку, кто имеет опыт настройки nginx и борьбы с DDoS.
absurdo добавил 11.02.2011 в 15:20
Говорят что около 1000 tcp пакетов в секунду.
Не поможет?
Я в шоке, куда бежать... что делать...
Гребаные конкуренты.
Движок Wordpress
Ддосят не смертельно, иногда сайт таки открывается (1 раз из 10 может), грузится с минуту.
ВДС находится на поддержке хостера, можно взять рут-доступ, но тогда администрирование ложится на плечи клиента.
спасибо, как ответят отпишусь