Webstatt.org - Community seit 2006 - 2012 (2024?)

Hilfe! Werde bombadiert!

Avatar user-182
02.06.2007 12:16

Was soll ich tun?

Meine Trafficanzeige schnellt in die Höhe (hab jetzt gegen Nachmittag schon 2,6 GB Traffic, normal sind ca 300 MB am Tag) und es geht immer weiter!

Nur alleine wegen dem imeem-Downloader auf frankyonline.de:
64.131.65.26 - - [02/Jun/2007:14:16:02 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
67.159.5.55 - - [02/Jun/2007:14:16:03 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
67.159.5.55 - - [02/Jun/2007:14:16:03 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:03 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:03 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
67.159.5.55 - - [02/Jun/2007:14:16:03 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:04 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:04 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
67.159.5.55 - - [02/Jun/2007:14:16:04 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:04 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:04 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
67.159.5.55 - - [02/Jun/2007:14:16:05 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:05 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:05 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:05 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:06 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
67.159.5.55 - - [02/Jun/2007:14:16:06 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
67.159.5.55 - - [02/Jun/2007:14:16:06 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:06 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:07 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:07 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
67.159.5.55 - - [02/Jun/2007:14:16:07 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
67.159.5.55 - - [02/Jun/2007:14:16:07 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:07 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:07 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:08 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:08 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
67.159.5.55 - - [02/Jun/2007:14:16:08 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:09 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:09 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:09 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:09 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:10 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:10 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
64.131.65.26 - - [02/Jun/2007:14:16:10 +0200] "POST /imeem-download.php HTTP/1.0" 403 6 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"


Was soll ich tun? Wie funktioniert das mit der hosts.deny? Einfach nur pro Zeile eine IP? Hab' erstmal nur ne htaccess genommen, aber trotzdem gehts immer höher.. was kann ich tun?!

ErrorDocument 403 "denied"
Order allow,deny
Deny from 67.159.5.55
Deny from 64.131.65.26
allow from all


Viele Grüße,
Franky

// Hab nur 25 GB traffic / Monat, das wird teuer arghhh x/

Seid ihr auch schon wix'r? xD
Avatar user-349
02.06.2007 12:26

Hast du root-Zugriff auf eine Shell?
Wenn ja, kick die Verbindung gleich beim reinkommen, sprich netfilter/iptables!

user-303
02.06.2007 12:43

iptables -I INPUT -s böse_IP -j DROP

Avatar user-182
02.06.2007 14:18

Mhh, iptables ist nicht installiert und installieren klappt irgendwie auch nicht traurig

vs6609:~# apt-get install iptables
Reading Package Lists... Done
Building Dependency Tree... Done
The following NEW packages will be installed:
iptables
0 upgraded, 1 newly installed, 0 to remove and 25 not upgraded.
4 not fully installed or removed.
Need to get 0B/403kB of archives.
After unpacking 1364kB of additional disk space will be used.
Setting up util-linux (2.12r-19) ...
update-rc.d: /etc/init.d/hwclock.sh: file does not exist
dpkg: error processing util-linux (--configure):
subprocess post-installation script returned error exit status 1
Errors were encountered while processing:
util-linux
E: Sub-process /usr/bin/dpkg returned an error code (1)
vs6609:~#


Was kann ich trotzdem tun? Und was ist "/etc/init.d/hwclock.sh"?

Seid ihr auch schon wix'r? xD
user-321
02.06.2007 15:03

probier mal die ip per htaccess zu sperren

http://www.abakus-internet-marketing.de/foren/viewtopic/t-14013.html

Avatar user-262
02.06.2007 17:21

das prob hatten wir auch mal bei nem projekt
sieht wohl nach nem ddos angriff aus

kannst kaum was dagegen machen eigentlich, außer größere server zu besorgen die sowas nicht auslastet

www.casimir-music.com Donnie: Why do you wear that stupid bunny suit? Frank: Why are you wearing that stupid man suit?
Avatar user-182
02.06.2007 17:35

Mhh... ausgelastet ister ja nicht.. nur Traffic *grml*
Naja, nur kacke das iptables nicht funktioniert..

Seid ihr auch schon wix'r? xD
user-303
02.06.2007 17:41

Original von user-262
das prob hatten wir auch mal bei nem projekt
sieht wohl nach nem ddos angriff aus

das ist doch kein ddos!!
besten falls ein dos, aber auch ein sehr schlechter...

Avatar user-262
04.06.2007 14:59

was weiß ich wollte mich nur wichtig machen Fettes Grinsen
aber so ein bischen so ist es doch ?

vll nicht so krass ...

www.casimir-music.com Donnie: Why do you wear that stupid bunny suit? Frank: Why are you wearing that stupid man suit?
user-303
04.06.2007 16:51

ein dos legt ein system lahm, das da is nur traffic verursachen...

Avatar user-262
04.06.2007 17:31

achso ok zwinkern

www.casimir-music.com Donnie: Why do you wear that stupid bunny suit? Frank: Why are you wearing that stupid man suit?