Forum Moderators: phranque

Message Too Old, No Replies

Need help with attacks.

Flood attack, i think.

         

Kaboo

4:33 pm on Jan 21, 2010 (gmt 0)

10+ Year Member



Hi, i run Apache 2.2.12 on a 32 bit Windows Server 2003 machine.
My site was running normally, but today i'm being attacked, the attacker does 1920 requests, and BAM! Site offline :-(, i must wait he stop or i can restart apache so my site works for 1~2 minutes.

After lots of researches i decided to install mod_evasive and mod_security but he still can put my site down.
Here are the Server-Status statistics, taken while he was attacking:

Server uptime: 16 minutes 37 seconds
Total accesses: 1905 - Total Traffic: 13.7 MB
1.91 requests/sec - 14.1 kB/second - 7.4 kB/request
1920 requests currently being processed, 0 idle workers

And in the server-status almost all the requests are like that:
Srv PID Acc MSS Req Conn Child Slot Client VHost Request
0-189440/0/11R 44620.00.000.01 ?..reading..
0-189440/0/0R 4500.00.000.00 ?..reading..
0-189440/0/0R 4500.00.000.00 ?..reading..
0-189440/0/0R 4500.00.000.00 ?..reading..
0-189440/0/11R 4500.00.000.07 ?..reading..

Please, everything i've tried didn't work and i just don't have more ideas, anything would be helpful.

Thanks! And sorry for english errors!

jdMorgan

6:51 pm on Jan 21, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



While mod_evasive is good, this might be a job for which a firewall is better suited -- I mean a hardware firewall that you can set to drop packets from certain IP address ranges before they even can get to your server. Most decent mid-priced routers have a simple firewall built-in these days, so you might want to look into that approach.

Jim