LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > LSWS 4.1 Release > Ddos

Reply
 
Thread Tools Display Modes
  #1  
Old 07-05-2011, 12:44 PM
myserver24 myserver24 is offline
New Member
 
Join Date: Jul 2011
Posts: 6
Question Ddos

hello
we use litespeed 4.1.1 Ent on our centos 5.4 (cpanel) server.
today this server's load that i monitor , Suddenly got heavy (e.g from 0.55 to 25.14) and all services run away from access.
also it has csf & lfd , mod_deflate , mod_security.
when load increase, i check network I/O with iftop but it show RX & TX lower than 500kbps(b=byte).

i tell this problem to datacenter and they tell we this might a ddos attack.

now how can i find attacker ip or target of this attack?
Reply With Quote
  #2  
Old 07-05-2011, 01:48 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,337
do 'top' from command line and see which process(es) consume the most resources (cpu cycles, i/o wait, etc) which helps identify the cause of high system load.

for ddos attack mitigation, refer to this doc http://www.litespeedtech.com/how-tos.html#qa_dos
Reply With Quote
  #3  
Old 07-05-2011, 02:03 PM
myserver24 myserver24 is offline
New Member
 
Join Date: Jul 2011
Posts: 6
Unhappy ddos

i config litespeed with this value:
Static Requests/second - 10
Dynamic Requests/second - 2
Outbound Bandwidth (bytes/sec) - 0
Inbound Bandwidth (bytes/sec) - 0
Connection Soft Limit - 20
Connection Hard Limit - 30
Grace Period (sec) - 30
Banned Period (sec) - 3600

Max Connections : 900
Connection Timeout (secs) : 15
Max Keep-Alive Requests : 90
Smart Keep-Alive : Yes
Keep-Alive Timeout (secs) : 3

and but now that problem didn't solve
Reply With Quote
  #4  
Old 07-05-2011, 04:03 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,337
Do you see any IP listed in "Anti-DDoS Blocked IP" of real-time stats page of LSWS Admin Console? if none or not many, then your high system load could be caused by something else instead of excessive-established-connection kind of ddos attack.

Did you run 'top' from command line and see which process(es) consume the most resources (cpu cycles, i/o wait, etc) which helps identify the cause of high system load?
Reply With Quote
  #5  
Old 07-05-2011, 11:36 PM
myserver24 myserver24 is offline
New Member
 
Join Date: Jul 2011
Posts: 6
Question Ddos

Quote:
Originally Posted by webizen View Post
Do you see any IP listed in "Anti-DDoS Blocked IP" of real-time stats page of LSWS Admin Console? if none or not many, then your high system load could be caused by something else instead of excessive-established-connection kind of ddos attack.

Did you run 'top' from command line and see which process(es) consume the most resources (cpu cycles, i/o wait, etc) which helps identify the cause of high system load?
thank you for replay.
when load increase, i run "Top" and "aTop" and "hTop" and:
"ps -eo pid,user,%cpu,%mem,etime,args"

but all of this tools show that load is heavy and lsphp5 use load then i search user of pid with:
"ps -ef | grep [PID]"
but show root in user field.

what can i do?
Reply With Quote
  #6  
Old 07-06-2011, 01:27 AM
myserver24 myserver24 is offline
New Member
 
Join Date: Jul 2011
Posts: 6
Question ddos

i attached my admin console snapshot and the total request of a domain increase suddenly and also my load increase, too.

link of image:
http://www.mediafire.com/?yoel674s2nylqyy

Last edited by myserver24; 07-06-2011 at 01:38 AM..
Reply With Quote
  #7  
Old 07-06-2011, 07:43 AM
cmanns cmanns is offline
Senior Member
 
Join Date: Jun 2010
Posts: 100
Quote:
Originally Posted by myserver24 View Post
i attached my admin console snapshot and the total request of a domain increase suddenly and also my load increase, too.

link of image:
http://www.mediafire.com/?yoel674s2nylqyy
Try something like this

http://uploadpla.net/files/6686_m098...php-config.png

enable more child's if you got like one busy vhost but not to what you got it.

Then enable XCache
__________________
-William C.Manns Owner of XenServ Co
Need LiteSpeed Hosting, Server Tuning, or Other Help I'm your guy

http://xenserv.com http://evilpuma.com
Reply With Quote
  #8  
Old 07-06-2011, 10:14 AM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,337
Quote:
Originally Posted by myserver24 View Post
i attached my admin console snapshot and the total request of a domain increase suddenly and also my load increase, too.

link of image:
http://www.mediafire.com/?yoel674s2nylqyy
From you admin cp screenshot, your bottleneck seems to be slow php (likely database needs tuning). opcode cache (such as xcache) will also help alleviate the situation.
Reply With Quote
  #9  
Old 07-06-2011, 11:32 AM
myserver24 myserver24 is offline
New Member
 
Join Date: Jul 2011
Posts: 6
Question Ddos

Quote:
Originally Posted by cmanns View Post
Try something like this

http://uploadpla.net/files/6686_m098...php-config.png

enable more child's if you got like one busy vhost but not to what you got it.

Then enable XCache
thank you for replay, i will test above setting and replay result.
Reply With Quote
  #10  
Old 07-06-2011, 11:34 AM
myserver24 myserver24 is offline
New Member
 
Join Date: Jul 2011
Posts: 6
Question Ddos

Quote:
Originally Posted by webizen View Post
From you admin cp screenshot, your bottleneck seems to be slow php (likely database needs tuning). opcode cache (such as xcache) will also help alleviate the situation.
thank your for replay,so what should i do to solve this problem?
please guide me step by step.
Reply With Quote
Reply

Tags
attack, ddos, increase, load, target

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 03:53 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.