PDA

View Full Version : Unexplained Mass increase in traffic


danit
6-17-04, 06:54 AM
My site www.thewyrd.com was taken down due to excees bandwith consumption
yet my site is a forum (phpBB) with around 50 users and 4000-5000 posts.
my site chews very little bandwith yet im told i have gone over my limit.


Im suspicious of these stats could this be a DoS attack?
"Your total HTTP transfer for the last 14 days is 5884.0616 MBs (5.75 GBs). The total number of requests your site has received is 20748, making your average MB per request 0.28 MBs."


http://www.uploadyourimages.com/view/578008392481_transfer.png

http://www.uploadyourimages.com/view/618318392481_transfer.png

Pig
6-17-04, 09:22 AM
Ouch. It is also likely that you were hacked by someone exploiting a security hole in phpbb. Whenever you use popular software you increase your risk of attack. It is vital that you keep up to date on all patches. Do you have all the security patches installed?

Evolution
6-17-04, 11:49 AM
I've had the same problem with a site a co-admin. I can't get in touch with the registered owner, as he's currently on vacation but I can't imagine we actually exceeded 5GB yesterday, when we don't really approach that on busy days. Yesterday wasn't even busy. Can an administrator please contact me so we can look to get back online? I'll check for security patch updates as soon as the website is active again. I suspect we were hacked. Thanks.

Evolution
6-17-04, 11:51 AM
Also, I have a general question in relation to bandwidth-related outages. Why is the ACP inaccessible when the bandwidth has been exceeded? Wouldn't it make sense for the administrators to be able to log in and see what caused the spike?

danit
6-17-04, 11:58 AM
Ouch. It is also likely that you were hacked by someone exploiting a security hole in phpbb. Whenever you use popular software you increase your risk of attack. It is vital that you keep up to date on all patches. Do you have all the security patches installed?

I take security as 1st priority i have all Security patches for phpBB and for all mods.

All files in ftp and the database seem to be intact

Evolution
6-17-04, 12:03 PM
I take security as 1st priority i have all Security patches for phpBB and for all mods.

All files in ftp and the database seem to be intact

I'm assuming our security patches are current too. I've never been the one responsible for them, but the site op is really on top of things. Our site is bryforums.com. Everything seems intact on the ftp from our end as well.

Evolution
6-17-04, 01:06 PM
Like I've said, the site-op's on vacation and I don't know procedure here for support really. Could somebody please help me out? Or do I just need to wait til the site comes back up? My only concern is that the same thing could just happen again if I don't figure out where the problem is. Thanks.

mjp
6-17-04, 01:22 PM
You have to contact support to get the site re-enabled.

It would be very unusual to use over 5gb of bandwidth in forum traffic alone...your database connection(s) would fail long before that many pages could be requested.

More often the cause of a sudden jump like that is a large file being downloaded by a lot of people.

Evolution
6-17-04, 01:35 PM
The max file size for user upload through the forums is 150kb. And there have been no large user uploads via ftp in the past week. Traffic wasn't heavy yesterday and there are no large files being served. So I'm stumped. I'll contact support. Thanks.

Pig
6-17-04, 01:39 PM
If someone uploaded something through a back door, it would not be restrcited to 150 kb.

Evolution
6-17-04, 01:47 PM
If someone uploaded something through a back door, it would not be restrcited to 150 kb.

Right. Where can I check security patches to make sure there are no easily accessible backdoors?

Pig
6-17-04, 02:05 PM
Go to phpbb.com and see if there is a more recent version than what you are running.

danit
6-18-04, 07:23 AM
my problem is over (at least for now)

Im still unsure of how i went over my limit