Page 1 of 2 12 LastLast
Results 1 to 20 of 21
  1. #1
    eUKhost.com's Avatar
    eUKhost.com is offline Chief Marketing Officer
    Join Date
    Sep 2005
    Posts
    6,039

    Default DDoS attack on 78.129.133.15

    Right now we are dealing with Severe DDoS attack on 78.129.133.15 and all efforts to filter this inbound traffic have failed.

    We are replacing main IP of the server right now so all website hostings hosted on this server should be online within an hour.
    UK Web Hosting || Business Hosting || eUKhost Knowledgebase
    Toll Free : 0808 262 0255 || Skype : mark_ducadi
    A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
    __________________________________________________

    Please email cmo[at]eukhost.com if you have any questions or need my assistance

  2. #2
    detordiggei is offline new member
    Join Date
    Aug 2007
    Posts
    1

    Default

    The server is up but the Ip's are still down here so web domains are not viewable yet, today was an hard day for both you and us! Sob

  3. #3
    Rock's Avatar
    Rock is offline Technical Support (eUKhost.com)
    Join Date
    Oct 2006
    Location
    localhost
    Posts
    3,373

    Post

    Apologies for not keeping you updated regarding the server status. It was indeed a hard day for all of us. All the website hostings are back online at the moment with a new IP : 78.129.133.118. The server will be put behind a hardware firewall within few days to avoid such future attacks & to keep the attackers at bay. Please place a ticket to our support dept 'windows@eukhost.com' if you still have any issues with your website hosting.

    Rock _a.k.a._ Jack
    Windows Hosting || Windows Reseller Hosting
    Cloud Hosting 100% UPTIME! || Powerful Dedicated Servers
    Follow eUKhost on Twitter || Join eUKhost Community on Facebook

    For complaints, grievances or suggestions kindly email our FeedBack Dept.
    Proper action will be taken accordingly & instantaneously!

  4. #4
    suziq is offline new member
    Join Date
    Aug 2007
    Posts
    3

    Default

    so are all website hostings back up and running now?

  5. #5
    DPS Computing's Avatar
    DPS Computing is offline Voluntary Moderator and Customer of eUKhost
    Join Date
    Apr 2007
    Location
    Manchester, United Kingdom
    Posts
    8,418

    Default

    I assume so seen as though the IP has been replaced. Sorry to hear about the attack .
    David Smith
    DPS Computing
    http://www.dpscomputing.com (Computing, Reviews, News) - We're still plodding on adding new content and features (August 2011)
    http://www.djdavid.co.uk - Massive update! (September 2011) - It's now not neglected!!
    http://davidsmith.dpscomputing.com (My Personal Website) - New Site (10/2009)

  6. #6
    Rock's Avatar
    Rock is offline Technical Support (eUKhost.com)
    Join Date
    Oct 2006
    Location
    localhost
    Posts
    3,373

    Post

    Quote Originally Posted by suziq View Post
    so are all website hostings back up and running now?
    Yes, all the website hostings are back online & running. If your scripts use the old IP in them (eg: database connection strings), the scripts will not be able to connect to the database. In that case please have them changed with the new IP [78.129.133.118], or let us know & we'll get it fixed for you.

    Rock _a.k.a._ Jack
    Windows Hosting || Windows Reseller Hosting
    Cloud Hosting 100% UPTIME! || Powerful Dedicated Servers
    Follow eUKhost on Twitter || Join eUKhost Community on Facebook

    For complaints, grievances or suggestions kindly email our FeedBack Dept.
    Proper action will be taken accordingly & instantaneously!

  7. #7
    swexpert is offline Premium Member
    Join Date
    Jan 2007
    Posts
    210

    Default

    How much was the traffic and from what regions, if i may know? Was the target a single machine? Why aren't all you machines behind hardware firewalls?

    Regds
    IJ

  8. #8
    Durchbrechen is offline Junior Member
    Join Date
    Jul 2007
    Posts
    29

    Default

    Even my one is down now : 78.129.128.20


    [paolo@linux ~]$ ping -c8 durchbrechen.com
    PING durchbrechen.com (78.129.128.20) 56(84) bytes of data.

    --- durchbrechen.com ping statistics ---
    8 packets transmitted, 0 received, 100% packet loss, time 7010ms

    [paolo@linux ~]$ ping -c8 eukhost.com
    PING eukhost.com (87.117.224.51) 56(84) bytes of data.
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=1 ttl=53 time=66.9 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=2 ttl=53 time=67.3 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=3 ttl=53 time=66.6 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=4 ttl=53 time=67.0 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=5 ttl=53 time=66.8 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=6 ttl=53 time=68.7 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=7 ttl=53 time=67.1 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=8 ttl=53 time=67.2 ms

    --- eukhost.com ping statistics ---
    8 packets transmitted, 8 received, 0% packet loss, time 7000ms
    rtt min/avg/max/mdev = 66.661/67.261/68.750/0.631 ms

  9. #9
    Rock's Avatar
    Rock is offline Technical Support (eUKhost.com)
    Join Date
    Oct 2006
    Location
    localhost
    Posts
    3,373

    Lightbulb

    Here's from my local machine:

    root@tech [~]# ping -c8 durchbrechen.com
    PING durchbrechen.com (78.129.128.20) 56(84) bytes of data.
    64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=0 ttl=63 time=0.192 ms
    64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=1 ttl=63 time=0.185 ms
    64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=2 ttl=63 time=0.269 ms
    64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=3 ttl=63 time=0.185 ms
    64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=4 ttl=63 time=0.179 ms
    64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=5 ttl=63 time=0.182 ms
    64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=6 ttl=63 time=0.189 ms
    64 bytes from typhoon.eukhost.com (78.129.128.20): icmp_seq=7 ttl=63 time=0.186 ms

    --- durchbrechen.com ping statistics ---
    8 packets transmitted, 8 received, 0% packet loss, time 7001ms
    rtt min/avg/max/mdev = 0.179/0.195/0.269/0.033 ms, pipe 2

    What is your local network's IP ? I doubt it being blocked on the server firewall.

    Rock _a.k.a._ Jack
    Windows Hosting || Windows Reseller Hosting
    Cloud Hosting 100% UPTIME! || Powerful Dedicated Servers
    Follow eUKhost on Twitter || Join eUKhost Community on Facebook

    For complaints, grievances or suggestions kindly email our FeedBack Dept.
    Proper action will be taken accordingly & instantaneously!

  10. #10
    AndyD is offline Member
    Join Date
    Apr 2007
    Posts
    54

    Default

    Durchbrechen :: Even my one is down now : 78.129.128.20
    Your website hosting seems to be on eUKhost's one of other server typhoon.eukhost.com (78.129.128.20) and not the one that was affected by DOS attack i.e., WIN.specialservers.com (78.129.133.118 )
    Moreover, a ping to your domain from my local machine worked perfect even! I would thereby suggest you to make a traceroute/tracert to your domain or server's IP (78.129.128.20) from your local machine to see if it completes or time-outs and then contact eUKhost support accordingly. Also make sure that you provide them your local network's IP (which you can obtain from http://whatismyip.com/) to check if it's blocked on the server (do this only if you have a static IP). They would work out on your problem for sure.
    Good Luck!!
    @= EukHost =@
    Linux / Windows Dedicated Servers || Linux VPS Hosting || Windows VPS Hosting

    "The secret of greatness is simple: do better work than any other man in your field - and keep on doing it"

  11. #11
    eUKhost.com's Avatar
    eUKhost.com is offline Chief Marketing Officer
    Join Date
    Sep 2005
    Posts
    6,039

    Default

    Quote Originally Posted by Durchbrechen View Post
    Even my one is down now : 78.129.128.20


    [paolo@linux ~]$ ping -c8 durchbrechen.com
    PING durchbrechen.com (78.129.128.20) 56(84) bytes of data.

    --- durchbrechen.com ping statistics ---
    8 packets transmitted, 0 received, 100% packet loss, time 7010ms

    [paolo@linux ~]$ ping -c8 eukhost.com
    PING eukhost.com (87.117.224.51) 56(84) bytes of data.
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=1 ttl=53 time=66.9 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=2 ttl=53 time=67.3 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=3 ttl=53 time=66.6 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=4 ttl=53 time=67.0 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=5 ttl=53 time=66.8 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=6 ttl=53 time=68.7 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=7 ttl=53 time=67.1 ms
    64 bytes from www.eukhost.com (87.117.224.51): icmp_seq=8 ttl=53 time=67.2 ms

    --- eukhost.com ping statistics ---
    8 packets transmitted, 8 received, 0% packet loss, time 7000ms
    rtt min/avg/max/mdev = 66.661/67.261/68.750/0.631 ms
    Your IP got blocked on server due to multiple login failures. I have removed it and your website hosting should work fine from your end.
    UK Web Hosting || Business Hosting || eUKhost Knowledgebase
    Toll Free : 0808 262 0255 || Skype : mark_ducadi
    A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
    __________________________________________________

    Please email cmo[at]eukhost.com if you have any questions or need my assistance

  12. #12
    Durchbrechen is offline Junior Member
    Join Date
    Jul 2007
    Posts
    29

    Default

    Quote Originally Posted by eUKhost.com View Post
    Your IP got blocked on server due to multiple login failures. I have removed it and your website hosting should work fine from your end.
    wow ! There wasn't anything precious in it ....

    In any case now it's all ok. Many thanks

    cheers
    Paolo

  13. #13
    eUKhost.com's Avatar
    eUKhost.com is offline Chief Marketing Officer
    Join Date
    Sep 2005
    Posts
    6,039

    Default

    Quote Originally Posted by Durchbrechen View Post
    wow ! There wasn't anything precious in it ....

    In any case now it's all ok. Many thanks

    cheers
    Paolo
    You are welcome
    UK Web Hosting || Business Hosting || eUKhost Knowledgebase
    Toll Free : 0808 262 0255 || Skype : mark_ducadi
    A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
    __________________________________________________

    Please email cmo[at]eukhost.com if you have any questions or need my assistance

  14. #14
    Morledge is offline Premium Member
    Join Date
    Feb 2007
    Posts
    144

    Default

    Quote Originally Posted by swexpert View Post
    Why aren't all you machines behind hardware firewalls?
    Did this question get answered?

    Thanks
    Morledge

  15. #15
    swexpert is offline Premium Member
    Join Date
    Jan 2007
    Posts
    210

    Default

    Hello,
    Nopes. none of the questions were answered. However, from the conversations, I now assume they do have hardware firewalls on *some* of the servers, not all.

    Regds
    IJ

  16. #16
    WelshTom is offline Senior Member
    Join Date
    May 2007
    Location
    Newport, Wales
    Posts
    998

    Default

    Yes, however, I do believe the majority of the servers to be directly behind firewalls. The servers which were compromised as a result of this DDoS attack were quickly installed with new firewalls to prevent any further problems.

  17. #17
    jc8654's Avatar
    jc8654 is offline Voluntary Moderator
    Join Date
    May 2007
    Location
    Cambridge, UK
    Posts
    1,593

    Default

    I also believe this to be the case as using Windows inbuilt traceroute shows the last two steps to be missing for the majority of servers I've checked. This is a sign of the firewall.
    Jonathan Crass
    Joint Partner in Checker Design
    Joint Partner in Jst Hosting

    UK Website design
    UK based monitoring
    Cheap UK Web Hosting

    eUKhost Forum Moderator

  18. #18
    eUKhost.com's Avatar
    eUKhost.com is offline Chief Marketing Officer
    Join Date
    Sep 2005
    Posts
    6,039

    Default

    We have Cisco ASA 5510 Firewall for our windows servers. Hardware firewall makes no difference for Linux Servers so we have Hardware Firewall for windows servers only.

    Even Cisco ASA 5510 cannot handle over 100 Mbps attack but it is helpful for security of windows servers. Firewalls are good to deal with DDoS of upto 10 - 30 Mbps but anything beyond that needs experience to reverse those attacks.
    UK Web Hosting || Business Hosting || eUKhost Knowledgebase
    Toll Free : 0808 262 0255 || Skype : mark_ducadi
    A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
    __________________________________________________

    Please email cmo[at]eukhost.com if you have any questions or need my assistance

  19. #19
    DPS Computing's Avatar
    DPS Computing is offline Voluntary Moderator and Customer of eUKhost
    Join Date
    Apr 2007
    Location
    Manchester, United Kingdom
    Posts
    8,418

    Default

    Yes that is true - if an attacker is determined they'll find a way past any system - look how many times banks and government agencies have been compromised and they have some of the best security software / hardware and personell working for them in the world!
    David Smith
    DPS Computing
    http://www.dpscomputing.com (Computing, Reviews, News) - We're still plodding on adding new content and features (August 2011)
    http://www.djdavid.co.uk - Massive update! (September 2011) - It's now not neglected!!
    http://davidsmith.dpscomputing.com (My Personal Website) - New Site (10/2009)

  20. #20
    jc8654's Avatar
    jc8654 is offline Voluntary Moderator
    Join Date
    May 2007
    Location
    Cambridge, UK
    Posts
    1,593

    Default

    Hackers although annoying at the time help make the internet a safer place as if they get into a system, people then make that same system safer.
    Jonathan Crass
    Joint Partner in Checker Design
    Joint Partner in Jst Hosting

    UK Website design
    UK based monitoring
    Cheap UK Web Hosting

    eUKhost Forum Moderator

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Content Relevant URLs by vBSEO 3.6.0