Help - Search - Members - Calendar
Full Version: i was able to take down my floodguarded computer
The Planet Forums > Security > DoS & D-DoS Mitigation
Anonymous
all it took was to open about 1500 sockets on port 80 and the server was hosed in 22 seconds. Where was the flood guard?
orb_sp
Had you allowed 7 days for the automatic training of FloodGuard?
Anonymous
FloodGuard doesn't work.
HomePCIT
Well with that argument you've convinced me that it doesn't work.

You can't just say 'It doesn't work' to someone. What's your justification?
Why doesn't it work?
How did it not work for you?
Did you work with support to correct any issues?
What arguments or details do you have for it not working?
Root
I think all that happened was Apache crashed. Someone claimed they did that very same thing on my server and Apache did go down while they were attacking. I am not sure how they did it but I would definitely like some way to prevent it or minimize the effects of it. If it helps at the same time I received e-mails from cPanel about this.

The first e-mail was blank with just a subject of "[maxfilescheck] Apache on has exceeded the maximum amount of open files".
The second e-mail
CODE
Subject: [maxclientscheck]  has exceeded the MaxClients limit

Apache has reached the MaxClients

limit.  cPanel has increased the MaxClients limit to 260 (10 higher).



You may wish to suspend the user with the largest access log as they

are generally the person using up all of the avalible connections. However, your should

have your system admin verify this first.



Top 3 Largest access logs

====================================

55572    /usr/local/apache/domlogs/site1.com

31984    /usr/local/apache/domlogs/site2.com

19104    /usr/local/apache/domlogs/site3.com
This has happened to my server several times now, the MaxClients was first set at 150 and gets increased every time it occurs.
cem
Try setting it much higher ?
Root
That doesn't seem logical to me...why set it higher so the resource usage increases, but that's just my thinking.
hp
over 250 requests and apache may crash - it should block requests over 250 but it may crash.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.