shurix Posted December 26, 2010 Report Share Posted December 26, 2010 (edited) Šodien saskāros ar kaut ko nebijušu. Papētot access log failu izsecināju, ka noticis dos uzbrukums? Uz shared hosta pārtērēta iedalītā jauda un konts bloķēts. Kādi man ir varianti, kaut ko aizsargāt? Vai arī pašam hostingam nevajadzēja kaut kādas aizsardzības likt? Ik pa laikam ip ar pamainās. Visas dienas garumā kaut kas līdzīgs šim: 46.109.59.215 - - [26/Dec/2010:16:03:41 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:42 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:41 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:41 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:41 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:41 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:41 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:41 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:41 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:32 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:42 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:42 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:42 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" 46.109.59.215 - - [26/Dec/2010:16:03:44 +0200] "GET / HTTP/1.1" 406 270 "-" "Lynx/2.8.5dev.7 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.7" Edited December 26, 2010 by shurix Quote Link to comment Share on other sites More sharing options...
Grey_Wolf Posted December 27, 2010 Report Share Posted December 27, 2010 paskaties vai kaads no GET pieprasijumiem neaiziet muziigjaa ciklaa, DOS jau parasti notiek no vairakam IP .. (tieshi tas jau ir merkjis -> no virakam [mx daudz] vienlaiciigi veikt pieprasijumus ... Quote Link to comment Share on other sites More sharing options...
Kaklz Posted December 27, 2010 Report Share Posted December 27, 2010 DOS ar 10 pieprasījumiem sekundē? :D Quote Link to comment Share on other sites More sharing options...
shurix Posted December 27, 2010 Author Report Share Posted December 27, 2010 Mūžīgā ciklā tas ir pats lapas scripts vai netaisa to ciklu? Ja pareizi sapratu tad netaisa nē, jo visiem apmeklētājiem viss normāli izņemot vienu. Quote Link to comment Share on other sites More sharing options...
briedis Posted December 27, 2010 Report Share Posted December 27, 2010 DOS ar 10 pieprasījumiem sekundē? :D +1 :D ja man lapā sēž ap 50 cilvēkiem, tad jau man te nonstopā DDOS'o :)) Quote Link to comment Share on other sites More sharing options...
daGrevis Posted December 27, 2010 Report Share Posted December 27, 2010 Kas ir DOS (vai DDOS)? xD Quote Link to comment Share on other sites More sharing options...
codez Posted December 27, 2010 Report Share Posted December 27, 2010 DOS ar 10 pieprasījumiem sekundē? :D DOS - Denial of service Džekam pārsniedza šārētā hostinga limitu un atslēdza servisu - tātad DOS Quote Link to comment Share on other sites More sharing options...
daGrevis Posted December 27, 2010 Report Share Posted December 27, 2010 Ķipa kaut kā cenšas iebarot to, ka lapu atvēris īsts lietotājs, bet īstenībā to dara kaut kāds bots, kurš pat neielādē lapas HTML, CSS utml., lai tas notiktu ātrāk. Un tad vairumā to darot pārsniedz limitu, laikam. =) Tā sapratu. Quote Link to comment Share on other sites More sharing options...
shurix Posted December 27, 2010 Author Report Share Posted December 27, 2010 Viss jau būtu smieklīgi, ja man būtu ūber kaste, kas to visu var turēt. Tā kā tādas nav tad problēma diezgan sāpīga. Quote Link to comment Share on other sites More sharing options...
marrtins Posted December 27, 2010 Report Share Posted December 27, 2010 (edited) Par 13.60 Ls/mēn sakomplektēšu Tev ūber VPS :) Edited December 27, 2010 by marrtins Quote Link to comment Share on other sites More sharing options...
daGrevis Posted December 27, 2010 Report Share Posted December 27, 2010 Un kā šo var apiet? To vispār var kaut kā apiet? Nu, protams, var banot attiecīgās IP. Vēl varianti? Quote Link to comment Share on other sites More sharing options...
marrtins Posted December 27, 2010 Report Share Posted December 27, 2010 Varianti ir daudz - atkarībā no uzbrukumu intensitātes. Šajā gadījumā šādu "DOS" vispār var ignorēt. Ja tas palīdz nomierināties, var pabloķēt IP. Btw, kas tas ir par hosteri? Quote Link to comment Share on other sites More sharing options...
Mr.Key Posted December 27, 2010 Report Share Posted December 27, 2010 Ne jau viss uzrādās access logā. Quote Link to comment Share on other sites More sharing options...
marrtins Posted December 27, 2010 Report Share Posted December 27, 2010 Bet topika autors jau arī neko citu mums nav iedevis :) Quote Link to comment Share on other sites More sharing options...
shurix Posted December 27, 2010 Author Report Share Posted December 27, 2010 (edited) Ko vēl vajag? Atkal pus stundu no vietas nobombardēja, webs paralizēts :/ Kā nobano ip tā turpina ar citu. Laikam vienīgais variants mainīt hostingu. Edited December 27, 2010 by shurix Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.