UK WEB HOSTING FORUM FOR DISCUSSION ON WEB HOSTING SERVICE AND SUPPORT
LINUX HOSTING WINDOWS HOSTING PACKAGES SHOPPING CART OSCOMMERCE ZEN CART AGORA
ECOMMERCE HOSTING ASP MSSQL FRONTPAGE HOSTING PHP MYSQL HOSTING DISCUSSION FORUM
CPANEL RESELLER HOSTING DEDICATED SERVER VPS HOSTING PLESK VIRTUOZZO
Quick Search
Your forum announcement here!

  UK Web Hosting | Dedicated Server Windows and Linux VPS Forum > eUKhost - News > Network Status

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-08-2007, 15:01
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,261
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default DDoS attack on 78.129.133.15

Right now we are dealing with Severe DDoS attack on 78.129.133.15 and all efforts to filter this inbound traffic have failed.

We are replacing main IP of the server right now so all websites hosted on this server should be online within an hour.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #2 (permalink)  
Old 03-08-2007, 16:33
new member
 
Join Date: Aug 2007
Posts: 1
Default

The server is up but the Ip's are still down here so web domains are not viewable yet, today was an hard day for both you and us! Sob
Reply With Quote
  #3 (permalink)  
Old 03-08-2007, 18:47
Rock's Avatar
System Administrator
 
Join Date: Dec 2006
Posts: 576
Post

Apologies for not keeping you updated regarding the server status. It was indeed a hard day for all of us. All the websites are back online at the moment with a new IP : 78.129.133.118. The server will be put behind a hardware firewall within few days to avoid such future attacks & to keep the attackers at bay. Please place a ticket to our support dept 'windows@eukhost.com' if you still have any issues with your website.
__________________

Rock _a.k.a._ Jack L.

http://www.eUKhost.com
Windows Hosting || Windows Reseller Hosting
Reply With Quote
  #4 (permalink)  
Old 04-08-2007, 13:31
new member
 
Join Date: Aug 2007
Posts: 3
Default

so are all websites back up and running now?
Reply With Quote
  #5 (permalink)  
Old 04-08-2007, 18:11
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,472
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

I assume so seen as though the IP has been replaced. Sorry to hear about the attack .
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #6 (permalink)  
Old 04-08-2007, 19:36
Rock's Avatar
System Administrator
 
Join Date: Dec 2006
Posts: 576
Post

Quote:
Originally Posted by suziq View Post
so are all websites back up and running now?
Yes, all the websites are back online & running. If your scripts use the old IP in them (eg: database connection strings), the scripts will not be able to connect to the database. In that case please have them changed with the new IP [78.129.133.118], or let us know & we'll get it fixed for you.
__________________

Rock _a.k.a._ Jack L.

http://www.eUKhost.com
Windows Hosting || Windows Reseller Hosting
Reply With Quote
  #7 (permalink)  
Old 06-08-2007, 19:55
Premium Member
 
Join Date: Jan 2007
Posts: 209
Default

How much was the traffic and from what regions, if i may know? Was the target a single machine? Why aren't all you machines behind hardware firewalls?

Regds
IJ
Reply With Quote
  #8 (permalink)  
Old 06-08-2007, 20:48
Junior Member
 
Join Date: Jul 2007
Posts: 24
Default

Even my one is down now : 78.129.128.20


[paolo@linux ~]$ ping -c8 durchbrechen.com
PING durchbrechen.com (78.129.128.20) 56(84) bytes of data.

--- durchbrechen.com ping statistics ---
8 packets transmitted, 0 received, 100% packet loss, time 7010ms

[paolo@linux ~]$ ping -c8 eukhost.com
PING eukhost.com (87.117.224.51) 56(84) bytes of data.
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=1 ttl=53 time=66.9 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=2 ttl=53 time=67.3 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=3 ttl=53 time=66.6 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=4 ttl=53 time=67.0 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=5 ttl=53 time=66.8 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=6 ttl=53 time=68.7 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=7 ttl=53 time=67.1 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=8 ttl=53 time=67.2 ms

--- eukhost.com ping statistics ---
8 packets transmitted, 8 received, 0% packet loss, time 7000ms
rtt min/avg/max/mdev = 66.661/67.261/68.750/0.631 ms
Reply With Quote
  #9 (permalink)  
Old 06-08-2007, 23:44
Rock's Avatar
System Administrator
 
Join Date: Dec 2006
Posts: 576
Lightbulb

Here's from my local machine:

root@tech [~]# ping -c8 durchbrechen.com
PING durchbrechen.com (78.129.128.20) 56(84) bytes of data.
64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=0 ttl=63 time=0.192 ms
64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=1 ttl=63 time=0.185 ms
64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=2 ttl=63 time=0.269 ms
64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=3 ttl=63 time=0.185 ms
64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=4 ttl=63 time=0.179 ms
64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=5 ttl=63 time=0.182 ms
64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=6 ttl=63 time=0.189 ms
64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=7 ttl=63 time=0.186 ms

--- durchbrechen.com ping statistics ---
8 packets transmitted, 8 received, 0% packet loss, time 7001ms
rtt min/avg/max/mdev = 0.179/0.195/0.269/0.033 ms, pipe 2

What is your local network's IP ? I doubt it being blocked on the server firewall.
__________________

Rock _a.k.a._ Jack L.

http://www.eUKhost.com
Windows Hosting || Windows Reseller Hosting
Reply With Quote
  #10 (permalink)  
Old 07-08-2007, 03:46
AndyD's Avatar
Member
 
Join Date: Apr 2007
Posts: 52
Default

Quote:
Durchbrechen :: Even my one is down now : 78.129.128.20
Your website seems to be on eUKhost's one of other server typhoon.eukhost.com (78.129.128.20) and not the one that was affected by DOS attack i.e., WIN.specialservers.com (78.129.133.118 )
Moreover, a ping to your domain from my local machine worked perfect even! I would thereby suggest you to make a traceroute/tracert to your domain or server's IP (78.129.128.20) from your local machine to see if it completes or time-outs and then contact eUKhost support accordingly. Also make sure that you provide them your local network's IP (which you can obtain from http://whatismyip.com/) to check if it's blocked on the server (do this only if you have a static IP). They would work out on your problem for sure.
Good Luck!!
__________________
@= EukHost =@
Linux / Windows Dedicated Servers || Linux VPS Hosting || Windows VPS Hosting

"The secret of greatness is simple: do better work than any other man in your field - and keep on doing it"
Reply With Quote
  #11 (permalink)  
Old 07-08-2007, 10:49
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,261
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by Durchbrechen View Post
Even my one is down now : 78.129.128.20


[paolo@linux ~]$ ping -c8 durchbrechen.com
PING durchbrechen.com (78.129.128.20) 56(84) bytes of data.

--- durchbrechen.com ping statistics ---
8 packets transmitted, 0 received, 100% packet loss, time 7010ms

[paolo@linux ~]$ ping -c8 eukhost.com
PING eukhost.com (87.117.224.51) 56(84) bytes of data.
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=1 ttl=53 time=66.9 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=2 ttl=53 time=67.3 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=3 ttl=53 time=66.6 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=4 ttl=53 time=67.0 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=5 ttl=53 time=66.8 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=6 ttl=53 time=68.7 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=7 ttl=53 time=67.1 ms
64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=8 ttl=53 time=67.2 ms

--- eukhost.com ping statistics ---
8 packets transmitted, 8 received, 0% packet loss, time 7000ms
rtt min/avg/max/mdev = 66.661/67.261/68.750/0.631 ms
Your IP got blocked on server due to multiple login failures. I have removed it and your website should work fine from your end.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #12 (permalink)  
Old 07-08-2007, 12:14
Junior Member
 
Join Date: Jul 2007
Posts: 24
Default

Quote:
Originally Posted by eUKhost.com View Post
Your IP got blocked on server due to multiple login failures. I have removed it and your website should work fine from your end.
wow ! There wasn't anything precious in it ....

In any case now it's all ok. Many thanks

cheers
Paolo
Reply With Quote
  #13 (permalink)  
Old 07-08-2007, 14:34
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,261
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by Durchbrechen View Post
wow ! There wasn't anything precious in it ....

In any case now it's all ok. Many thanks

cheers
Paolo
You are welcome
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #14 (permalink)  
Old 22-10-2007, 00:01
Premium Member
 
Join Date: Feb 2007
Posts: 131
Default

Quote:
Originally Posted by swexpert View Post
Why aren't all you machines behind hardware firewalls?
Did this question get answered?

Thanks
Morledge
__________________
Morledge
Web Design Nottingham | Limo Hire | Bird Table
Reply With Quote
  #15 (permalink)  
Old 22-10-2007, 05:05
Premium Member
 
Join Date: Jan 2007
Posts: 209
Default

Hello,
Nopes. none of the questions were answered. However, from the conversations, I now assume they do have hardware firewalls on *some* of the servers, not all.

Regds
IJ
Reply With Quote
  #16 (permalink)  
Old 22-10-2007, 06:55
WelshTom's Avatar
Moderator
 
Join Date: May 2007
Location: Newport, Wales
Posts: 788
Send a message via AIM to WelshTom Send a message via MSN to WelshTom Send a message via Yahoo to WelshTom
Default

Yes, however, I do believe the majority of the servers to be directly behind firewalls. The servers which were compromised as a result of this DDoS attack were quickly installed with new firewalls to prevent any further problems.
__________________
Thomas Williams
Founder of TWR Web Design
http://www.twrwebdesign.co.uk/
Reply With Quote
  #17 (permalink)  
Old 22-10-2007, 09:11
jc8654's Avatar
Moderator
 
Join Date: May 2007
Location: Manchester, United Kingdom
Posts: 1,219
Send a message via MSN to jc8654
Default

I also believe this to be the case as using Windows inbuilt traceroute shows the last two steps to be missing for the majority of servers I've checked. This is a sign of the firewall.
__________________
Jonathan Crass
Joint Partner in Checker Design

North East Website design
UK based monitoring
Cheap UK Web Hosting

Save Jodrell Bank: www.savejodrellbank.org.uk

eUKhost Forum Moderator
Reply With Quote
  #18 (permalink)  
Old 22-10-2007, 10:21
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,261
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

We have Cisco ASA 5510 Firewall for our windows servers. Hardware firewall makes no difference for Linux Servers so we have Hardware Firewall for windows servers only.

Even Cisco ASA 5510 cannot handle over 100 Mbps attack but it is helpful for security of windows servers. Firewalls are good to deal with DDoS of upto 10 - 30 Mbps but anything beyond that needs experience to reverse those attacks.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #19 (permalink)  
Old 22-10-2007, 21:50
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,472
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Yes that is true - if an attacker is determined they'll find a way past any system - look how many times banks and government agencies have been compromised and they have some of the best security software / hardware and personell working for them in the world!
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #20 (permalink)  
Old 23-10-2007, 00:25
jc8654's Avatar
Moderator
 
Join Date: May 2007
Location: Manchester, United Kingdom
Posts: 1,219
Send a message via MSN to jc8654
Default

Hackers although annoying at the time help make the internet a safer place as if they get into a system, people then make that same system safer.
__________________
Jonathan Crass
Joint Partner in Checker Design

North East Website design
UK based monitoring
Cheap UK Web Hosting

Save Jodrell Bank: www.savejodrellbank.org.uk

eUKhost Forum Moderator
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 07:59.

 

Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by Web Hosting 3.1.0
Copyright © 2001-2008, eUKhost.com. All rights reserved.

 
Site Map

knowledgebase articles

popular blog categories