[CentOS] 140,000 PPS Unicast Traffic - Finding the Cause

Associate
Joined
18 Nov 2008
Posts
2,430
Location
Liverpool
Dear OcUK Linux Gods,

My dedicated server yesterday spiked up to 140k PPS of Unicast traffic. This was presumed to be part of a DDoS attack and the servers port was disabled.

I've been given remote KVM access but am finding it difficult to find the cause. The techs at the hosting company identified a number of shell scripts running and disabled them but won't re-open the port until I have found the cause.

The best way I have to find it is in the apache access_log but it's 6GB and without internet access I've no way of viewing it (Trying to view it over KVM just crashes it understandably).

Is there any common linux attacks I can look for? I can ask the company to sort it but the server is used for none profit purposes and already costs me money so the idea of paying an engineer £30 per hour isn't ideal for me.

Thanks in advance to anybody with any ideas.
 
Reinstalling it and starting from scratch was my first though, but I'll have to pay to have it reinstalled and as someone not overly familiar with Linux it was a pain to set it up originally and I'd like to avoid that, though admittedly I see the security concerns.

Since the OP I've updated a considerable amount of packages including the important ones like Apache, MySQL and PHP, I'm currently running through Nessus vulnerability reports and fixing everything it's identified, I'll also be googling round for common ways to secure PHP and Apache.

Sadly like you said, I'll always be wondering if some hidden file is going to pop up and cause all hell.
 
Back
Top Bottom