Results 1 to 8 of 8

Thread: Website Bombarded overnight

  1. #1
    Senior Member
    Join Date
    Aug 2007
    Location
    South Shields
    Posts
    273
    Thanks
    37
    Thanked
    11 times in 8 posts
    • dankellys's system
      • Motherboard:
      • Gigabyte GA-Z77-D3H
      • CPU:
      • 3rd Generation Intel® Core™ i5 3570K 3.40GHz
      • Memory:
      • Crucial Ballistix Sport 8GB (2x4GB) DDR3
      • Storage:
      • Seagate 1TB ST1000DM003 + Samsung 128GB SSD
      • Graphics card(s):
      • 2GB XFX Radeon HD 7870 Core Edition, 4800MHz
      • PSU:
      • OCZ ZS Series 550W
      • Case:
      • Zalman Z9-U3 Mid
      • Operating System:
      • Windows 7 Pro x64
      • Monitor(s):
      • ViewSonic VIE 23 IPS 1920x1080 6MS
      • Internet:
      • Virgin Media 60Mb B/B

    Website Bombarded overnight

    For about the last week or so, one of the websites I host for one of my clients has been getting bombarded with traffic overnight. It has gone from using about 500mb of bandwidth per month, to using 1GB PER DAY! The website is for a local windows and conservatories installation company, and has no reason to be having such high volumes of traffic, especially overnight. Is there any way of tracing this back, and stopping this rogue traffic?

    The site has a handful of jpg images on, but nothing of a large size (about 1000px on longest edge), and is just a bog-standard Wordpress brochure site.
    Main Rig: BOARD: Gigabyte GA-Z77-D3H / CHIP: 3rd Generation Intel® Core™ i5 3570K 3.40GHz / RAM: Crucial Ballistix Sport 8GB (2x4GB) DDR3 / DRIVES: Seagate 1TB ST1000DM003 + Samsung 128GB SSD / CASE: Zalman Z9-U3 Mid / PSU: OCZ ZS Series 550W / GRAPHICS: 2GB XFX Radeon HD 7870 Core Edition, 4800MHz / MONITOR: ViewSonic VIE 23 IPS 1920x1080 6MS
    Photography: Body: Nikon D3200 / Lenses: Nikkor 18-55mm Kit Lens, Nikkor 55-200mm f/4-5.6G / Filters: Haida 10 Stop ND Filter, Misc CPL Filter


  2. #2
    Editable... jimbouk's Avatar
    Join Date
    Aug 2005
    Location
    Bristol
    Posts
    3,071
    Thanks
    321
    Thanked
    278 times in 226 posts
    • jimbouk's system
      • Motherboard:
      • Asrock B450M-HDV R4.0
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4 3200 MHz C16
      • Storage:
      • Sabrent Rocket Q 1TB NVMe PCIe M.2 2280
      • Graphics card(s):
      • Sapphire Pulse RX 580 8GB
      • PSU:
      • Seasonic Core Gold GC-650
      • Case:
      • Lian-Li PC-V1100 ATX
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • AOC CU34G2/BK 34" Widescreen
      • Internet:
      • EE FTC

    Re: Website Bombarded overnight

    Server logs should give you ip addresses, which will give you countries. Then just start blocking in chunks.

  3. #3
    Senior Member
    Join Date
    Aug 2007
    Location
    South Shields
    Posts
    273
    Thanks
    37
    Thanked
    11 times in 8 posts
    • dankellys's system
      • Motherboard:
      • Gigabyte GA-Z77-D3H
      • CPU:
      • 3rd Generation Intel® Core™ i5 3570K 3.40GHz
      • Memory:
      • Crucial Ballistix Sport 8GB (2x4GB) DDR3
      • Storage:
      • Seagate 1TB ST1000DM003 + Samsung 128GB SSD
      • Graphics card(s):
      • 2GB XFX Radeon HD 7870 Core Edition, 4800MHz
      • PSU:
      • OCZ ZS Series 550W
      • Case:
      • Zalman Z9-U3 Mid
      • Operating System:
      • Windows 7 Pro x64
      • Monitor(s):
      • ViewSonic VIE 23 IPS 1920x1080 6MS
      • Internet:
      • Virgin Media 60Mb B/B

    Re: Website Bombarded overnight

    Cheers, looked like the traffic was coming from an IP address in Germany. Blocked now
    Main Rig: BOARD: Gigabyte GA-Z77-D3H / CHIP: 3rd Generation Intel® Core™ i5 3570K 3.40GHz / RAM: Crucial Ballistix Sport 8GB (2x4GB) DDR3 / DRIVES: Seagate 1TB ST1000DM003 + Samsung 128GB SSD / CASE: Zalman Z9-U3 Mid / PSU: OCZ ZS Series 550W / GRAPHICS: 2GB XFX Radeon HD 7870 Core Edition, 4800MHz / MONITOR: ViewSonic VIE 23 IPS 1920x1080 6MS
    Photography: Body: Nikon D3200 / Lenses: Nikkor 18-55mm Kit Lens, Nikkor 55-200mm f/4-5.6G / Filters: Haida 10 Stop ND Filter, Misc CPL Filter


  4. #4
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Website Bombarded overnight

    if you are hosting on a *nix machine, you might like to look at fail2ban, www.fail2ban.org - it may be available from your distro's repository.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  5. #5
    Registered+
    Join Date
    Aug 2012
    Location
    Near Wolverhampton
    Posts
    41
    Thanks
    2
    Thanked
    0 times in 0 posts
    • DarthRager's system
      • Motherboard:
      • Gigabyte GA-z68XP-UD3P
      • CPU:
      • Core i7 2700k
      • Memory:
      • 16GB
      • Graphics card(s):
      • 1 x EVGA GTX 680 Signature 1 @ 1280
      • PSU:
      • Corsair AX750
      • Case:
      • Corsair 650D
      • Operating System:
      • Windows 7 64 bit / Ubuntu 13.04
      • Monitor(s):
      • Asus 23" PA238Q
      • Internet:
      • Around 1MB/s at max.. UK..

    Re: Website Bombarded overnight

    If you're hosting client sites shouldn't you have like.. unlimited bandwith?

    My server is £11 a month, unlimited bandwith and a 500GB HDD...

    Then there's nothing wrong with *shock horror* 1GB a bandwith a day.
    Steam: 3is_less_than_9

  6. #6
    Senior Member
    Join Date
    Aug 2013
    Location
    North Wales
    Posts
    1,849
    Thanks
    165
    Thanked
    271 times in 202 posts
    • virtuo's system
      • Motherboard:
      • Gigabyte Aorus Master X570
      • CPU:
      • Ryzen 9 5950x
      • Memory:
      • 64Gb G.Skill TridentZ Neo 3600 CL16
      • Storage:
      • Sabrent 2TB PCIE4 NVME + NAS upon NAS upon NAS
      • Graphics card(s):
      • RTX 3090 FE
      • PSU:
      • Corsair HX850 80+ Platinum
      • Case:
      • Fractal Meshify 2 Grey
      • Operating System:
      • RedStar 3, Ubuntu, Win 10
      • Monitor(s):
      • Samsung CRG90 5140x1440 120hz
      • Internet:
      • PlusNet's best, but still poor, attempt

    Re: Website Bombarded overnight

    Quote Originally Posted by DarthRager View Post
    Then there's nothing wrong with *shock horror* 1GB a bandwith a day.
    If it was legitimate traffic then 1GB a day wouldn't be a problem, but if I saw bandwidth usage for any site increase by 60x in a very short period of time, then I'd be looking for files or services that have "found their way" on to the server. Regardless of how unlimited my usage is, I wouldn't want anything dodgy running in the background. I've seen a lot of FTP servers, IRC servers and proxy scripts secretly installed on less than secure web servers before. And they chew through the bandwidth.

  7. #7
    Registered+
    Join Date
    Aug 2012
    Location
    Near Wolverhampton
    Posts
    41
    Thanks
    2
    Thanked
    0 times in 0 posts
    • DarthRager's system
      • Motherboard:
      • Gigabyte GA-z68XP-UD3P
      • CPU:
      • Core i7 2700k
      • Memory:
      • 16GB
      • Graphics card(s):
      • 1 x EVGA GTX 680 Signature 1 @ 1280
      • PSU:
      • Corsair AX750
      • Case:
      • Corsair 650D
      • Operating System:
      • Windows 7 64 bit / Ubuntu 13.04
      • Monitor(s):
      • Asus 23" PA238Q
      • Internet:
      • Around 1MB/s at max.. UK..

    Re: Website Bombarded overnight

    Quote Originally Posted by virtuo View Post
    If it was legitimate traffic then 1GB a day wouldn't be a problem, but if I saw bandwidth usage for any site increase by 60x in a very short period of time, then I'd be looking for files or services that have "found their way" on to the server. Regardless of how unlimited my usage is, I wouldn't want anything dodgy running in the background. I've seen a lot of FTP servers, IRC servers and proxy scripts secretly installed on less than secure web servers before. And they chew through the bandwidth.
    I suppose that is a possibility.
    Steam: 3is_less_than_9

  8. #8
    Senior Member
    Join Date
    Aug 2013
    Location
    North Wales
    Posts
    1,849
    Thanks
    165
    Thanked
    271 times in 202 posts
    • virtuo's system
      • Motherboard:
      • Gigabyte Aorus Master X570
      • CPU:
      • Ryzen 9 5950x
      • Memory:
      • 64Gb G.Skill TridentZ Neo 3600 CL16
      • Storage:
      • Sabrent 2TB PCIE4 NVME + NAS upon NAS upon NAS
      • Graphics card(s):
      • RTX 3090 FE
      • PSU:
      • Corsair HX850 80+ Platinum
      • Case:
      • Fractal Meshify 2 Grey
      • Operating System:
      • RedStar 3, Ubuntu, Win 10
      • Monitor(s):
      • Samsung CRG90 5140x1440 120hz
      • Internet:
      • PlusNet's best, but still poor, attempt

    Re: Website Bombarded overnight

    Did the access logs show what resource(s) the IP in Germany was requesting? I think just blocking that IP might be ignoring the bigger issue that someone has managed to install something on the server. Is Wordpress up to date?

    Edit: Didn't notice the age of the thread, take it the site's been fine since?

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •