Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 12-22-2011, 09:25 PM
Rocket1 Rocket1 is offline
 
Join Date: May 2007
Posts: 27
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Help! Server Attack

On a non-managed Linux dedicated via GoDaddy. We have had an issue over the last two weeks with our server shutting down. Below is a response from the server peeps on the cause. Any suggestions would be greatly appreciated.

=============================

First off we are showing a large number of failed log in attempts and failed DNS lookups. These are results of attackers attempting to brute force your password, and domains resolving to your servers IP. You should be able to block most of this traffic through firewall rules.

The second issue, is that your mysql service is consuming 100% of the cpu, and you are maxing out your email relays. Normally these would be separate issues but they are directly related to each other. The reason why your email relays are getting maxed out is that your server is trying to send you email notices that your vbulletin database queries are failing. These same database queries are causing your mysql service load to spike.

My suggestion would be to review online for ways to harden a Linux server. This will provide you with suggestions on changes you can make to your server configuration that would make it so attacks against the server do not have as much of an effect on the operating level of the server.

==================

Anyone have any tricks to help out with this?
Reply With Quote
  #2  
Old 12-23-2011, 11:16 AM
MegaManSec MegaManSec is offline
 
Join Date: Aug 2011
Posts: 97
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I can help with this, I have alot of experience when it comes to security, DOS, and hacking in linux.
If you trust me, PM me your ssh details, and I'll set it all up.(then I'll tell you what I did)
If not,

Download ddosdeflate, turn off emailing on mysql error, iptables the attackers, etc etc..

Thanks, loaep
Reply With Quote
  #3  
Old 12-23-2011, 12:17 PM
doopz doopz is offline
 
Join Date: Feb 2003
Posts: 64
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by loaep View Post
I can help with this, I have alot of experience when it comes to security, DOS, and hacking in linux.
If you trust me, PM me your ssh details, and I'll set it all up.(then I'll tell you what I did)
If not,

Download ddosdeflate, turn off emailing on mysql error, iptables the attackers, etc etc..

Thanks, loaep
Hmm, how about he fixes the problem of why vbulletin is sending out MySQL errors ? That seems like a better suggestion to me.

Close down services such as FTP/SSH and only allow them for your own IP(s). You can also try and disable DNS lookups for them, but i suspect that closing down the hammered services will be enough.

I'm available for help if you need it.
Reply With Quote
  #4  
Old 12-23-2011, 12:20 PM
MegaManSec MegaManSec is offline
 
Join Date: Aug 2011
Posts: 97
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by doopz View Post
Hmm, how about he fixes the problem of why vbulletin is sending out MySQL errors ? That seems like a better suggestion to me.

Close down services such as FTP/SSH and only allow them for your own IP(s). You can also try and disable DNS lookups for them, but i suspect that closing down the hammered services will be enough.

I'm available for help if you need it.
most likely because the error is 'mysql is gone' aka. there is no mysql server, because the ram is @ 100%..
you cant stop that.
You can however block the ip's, and set up a script to automaticly do it.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:36 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06067 seconds
  • Memory Usage 2,187KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (4)post_thanks_box
  • (4)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (4)post_thanks_postbit_info
  • (4)postbit
  • (4)postbit_onlinestatus
  • (4)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete