homepage Welcome to WebmasterWorld Guest from 184.73.104.82
register, free tools, login, search, pro membership, help, library, announcements, recent posts, open posts,
Become a Pro Member

Home / Forums Index / WebmasterWorld / Webmaster General
Forum Library, Charter, Moderators: phranque

Webmaster General Forum

    
Ever increasing Bandwidth
Ideas on what causes it?
webboy1

10+ Year Member



 
Msg#: 8765 posted 6:46 pm on May 23, 2005 (gmt 0)

Hi,

I have a feeling someone may have hacked our server and might be abusing our bandwidth. Our Bandwidth usage has increased 10-20GB per month for the last 4-5 months. We are now apparently using 70GB more than we were apparently using in December ..... and it is still climbing at an alarming rate.

The trouble is, we have not put any new websites live that would generate anything close to this level of traffic - and even the december figure appears incredibly high. We have analysed the stats for our sites, and according to the logs, all our sites together are using under 5GB of traffic each month ..... but something is causing the overall reading of the server to be almost 100GB. So what could be causing the other 95GB of bandwidth usage?

Worse still, it is costing us several hundred pounds each month to cover the cost.

We are using a Windows Server. Does anyone have any ideas of what could be causing this, where I can find files on the server that might be causing this ..... or recommend any software (preferably free at first) that can scan / monitor total server bandwidth usage.

The guys who host our server are not very helpful. I think they are quite happy for this to continue - they are after all getting an extra few hundred 's per month because of it. They seem to have no great motivation to help us.

Please please please help. All advice is more than welcome.

Appreciated.
Brian

 

encyclo

WebmasterWorld Senior Member encyclo us a WebmasterWorld Top Contributor of All Time 10+ Year Member



 
Msg#: 8765 posted 7:17 pm on May 23, 2005 (gmt 0)

Have you done a full security scan of your server? 95Gb a month of illegal movies served via an IRC channel or other similar ways could well be the culprit. Your hosting company sounds distinctly unhelpful to the extent that I would start searching for a new provider as well.

I assume that you're on a fully dedicated server, so you could start by checking hard disk usage (AVI files take up a lot of space) and running services. I'm a Linux guy and don't have any experience in running Windows servers, but I'm sure others will be able to suggest Windows-specific tools, but you can use Unix tools such as Nessus [nessus.org]. A few other ideas here:

[insecure.org...]

OCSupertones

5+ Year Member



 
Msg#: 8765 posted 7:59 pm on May 23, 2005 (gmt 0)

That much bandwidth must be file downloads.

If it was a few Gb, then it might be someone hotlinking, but that is a lot of files to hotlink.

What stat programs do you run? You can find out what files are being called a lot with awstats and webalizer.

Brandon

webboy1

10+ Year Member



 
Msg#: 8765 posted 8:28 am on May 24, 2005 (gmt 0)

We use stats software called Web Log Expert. It appears to be pretty good, but doesn't seem to be showing any strange happenings, or files downloading.

I am going to spend the morning crawling our server looking for anything that shouldn't be there. For instance, to my knowledge, none of the site on our server use video. So I will be looking for video files etc.

Thanks for your responses.

Any more more advice would be great.

Cheers.

JKMitchell

5+ Year Member



 
Msg#: 8765 posted 8:53 am on May 24, 2005 (gmt 0)

I am going to spend the morning crawling our server looking for anything that shouldn't be there

I guess you've checked all the log files (including messages.log as well as the site logs).

You could also look for large files :

find / -size +100k -print -xdev

looks for files over 100k in size in all directories from '/' downwards. If it's videos etc they would tend to be larger files I would guess.

Let us know how you get on ;-)

JKMitchell

5+ Year Member



 
Msg#: 8765 posted 8:55 am on May 24, 2005 (gmt 0)

Sorry just read the thread and you are using a Windows server - my suggestions above are linux based <slaps wrist>

Can you use the "search" command with a minimum size to find large files?

webboy1

10+ Year Member



 
Msg#: 8765 posted 9:06 am on May 24, 2005 (gmt 0)

Not sure if I can do this ..... but i will certainly give it a try.

webboy1

10+ Year Member



 
Msg#: 8765 posted 9:12 am on May 24, 2005 (gmt 0)

Windows does allow me to search by file size, but nothing seems to be out of place.

I have just been informed by our host that our Bandwidth for the month of may so far stand 69GB!

Yet my site stats say the sites have only used around 3GB.

I will have to keep looking.

bloke in a box

10+ Year Member



 
Msg#: 8765 posted 10:30 am on May 24, 2005 (gmt 0)

I would change hosts straight away tbh.

publish

5+ Year Member



 
Msg#: 8765 posted 11:05 am on May 24, 2005 (gmt 0)

I don't know how much it helps, but my comments would be:

From your server stats you should be able to see which files are using the most bandwidth - in other words which files are most accessed.

Basically, spend time looking closely through your server logs to see exactly what's happening.

And I would say move to another host ASAP. First of all, it sounds like you're paying way too much for bandwidth. And secondly, the impression I get is that you don't have a hugely responsive host.

After much searching, I use a host that have proven to be reliable and have many positive things said about them by people in the hosting industry (I'm always nervous about hosts and make sure to do a lot of research beforehand).

For $20 a month I get almost 200GB of bandwidth (and almost 8GB of disk space). And then $1 per GB of bandwidth over. I have a domain with them purely for downloads and it works well. They are Linux servers though, not Windows, which may not be appropriate for you.

I can't say their details here, but feel free to sticky me.

JKMitchell

5+ Year Member



 
Msg#: 8765 posted 11:30 am on May 24, 2005 (gmt 0)

Yet my site stats say the sites have only used around 3GB.

Can you check your email logs - not likely to have used 66Gb in a month unless you have someone sending 1000's per hour.

Also it may be worth checking for an IRC bot (not sure about windows versions but a Google search would no doubt bring something up).

wheel

WebmasterWorld Senior Member wheel us a WebmasterWorld Top Contributor of All Time 10+ Year Member



 
Msg#: 8765 posted 2:04 am on May 25, 2005 (gmt 0)

If it's not showing in your apache logs, I would be suspicious of an email hack. I've had the wonderful experience of that before myself, and yes, they can burn 100gigs in a month.

And again, change hosts.

webboy1

10+ Year Member



 
Msg#: 8765 posted 8:19 am on May 25, 2005 (gmt 0)

I think changing hosts is something we will now have to seriously consider. Ufortunately as most of you will know, its not quite as easy as just changing. We have around 15 sites on this server. Changing would not only involved transfering sites, but also repointing domain names, emails, reconfiguring databases etc.

We will be changing, it just might take a little while to work out the logistics of doing it all smoothly.

Can you tell me how I find if someone is using our email facility.

Also, if it is someone using our bandwidth to download video clips etc (as some of you suggested it might be), can you give me any advice on how I go about finding the files on the server that are allowing it. Are there common file types or extensions, or even .dll files related to this that might stick out if I were looking?

All help so far is much appreciated.

Essex_boy

WebmasterWorld Senior Member essex_boy us a WebmasterWorld Top Contributor of All Time 10+ Year Member



 
Msg#: 8765 posted 8:26 am on May 25, 2005 (gmt 0)

I assume your host has a good reputation and is not cooking the books?

Global Options:
 top home search open messages active posts  
 

Home / Forums Index / WebmasterWorld / Webmaster General
rss feed

All trademarks and copyrights held by respective owners. Member comments are owned by the poster.
Home ¦ Free Tools ¦ Terms of Service ¦ Privacy Policy ¦ Report Problem ¦ About ¦ Library ¦ Newsletter
WebmasterWorld is a Developer Shed Community owned by Jim Boykin.
© Webmaster World 1996-2014 all rights reserved