1. Please take a little time for this simple survey! Thank you for participating!
    Dismiss Notice
  2. Dear Pleskians, please read this carefully! New attachments and other rules Thank you!
    Dismiss Notice
  3. Dear Pleskians, I really hope that you will share your opinion in this Special topic for chatter about Plesk in the Clouds. Thank you!
    Dismiss Notice

ddos??

Discussion in 'Plesk for Linux - 8.x and Older' started by nero0247, Jul 25, 2006.

  1. nero0247

    nero0247 Guest

    0
     
    How do I keep this from happening. It seems to be using a lot of processes and therefore lagging or timming out apache. there are several ip address doing this. please help

    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/xmlrpc
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/xmlrpc
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/xmlsrv
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/blog
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/xmlsrv
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/blog
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/drupal
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/community
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/drupal
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/blogs
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/community
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/blogs
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/blogs
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/blog
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/blogs
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/blogtest
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/blog
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/b2
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/blogtest
    [Mon Jun 26 01:16:36 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/b2evo
    [Mon Jun 26 01:16:37 2006] [error] [client 8.6.223.22] File does not exist: /var/www/vhosts/default/htdocs/b2
     
  2. 0031

    0031 Guest

    0
     
    If you know IP addresses - you may simply block them with iptables.. use 'drop' target ;)

    But actually I thought that "file does not exist" is sufficiently fast in Apache...
     
  3. nero0247

    nero0247 Guest

    0
     
    i do

    i do know the ip address but it is amazing to look through the logs and see 100s of people doing this and then you will see "exhausted". is there something i can do to see if there is a script doing this?
     
  4. 0031

    0031 Guest

    0
     
    grep 'File does not exists' error_log | awk '{print substr($8,0, length($8)-1)}' | sort | uniq

    And BTW that's not 100s of people, that 100s of zombies/bots
     
  5. nero0247

    nero0247 Guest

    0
     
    nothing

    grep 'File does not exists' error_log | awk '{print substr($8,0, length($8)-1)}' | sort | uniq

    that command did nothing but drop me a prompt. what else can i do?
     
  6. 0031

    0031 Guest

    0
     
    Re: nothing

    My fault :) replace "exists" with "exist" in the search string.
     
Loading...