LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > General > 403s and bandwidth still being used

Reply
 
Thread Tools Display Modes
  #1  
Old 10-08-2009, 09:17 PM
felosi felosi is offline
Senior Member
 
Join Date: Jun 2007
Posts: 249
Default 403s and bandwidth still being used

As I stated in this thread - http://www.litespeedtech.com/support...2&postcount=31
I notice that when a site is being attacked, we have the user agent or whatever blocked on the server level via modsec or rewrite in .htaccess it still consumes lots of bandwidth and resources as if it was really getting the image.

Here is one example. These guys been under attack over a month now from a very determined idiot. We have blocked empty user agent, direct requests to images, etc and all bots do get a 403 yet there is still a great deal of bandwidth and resource usage.

Here is an excerpt from access domlog:
Code:
71.143.241.113 - - [08/Oct/2009:14:50:04 -0700] "GET /images/parts/b01_rename.jpg HTTP/1.1" 403 483 "-" "-"
94.5.111.17 - - [08/Oct/2009:14:50:04 -0700] "GET /images/parts/b01_rename.jpg HTTP/1.1" 403 483 "-" "-"
77.85.189.228 - - [08/Oct/2009:14:50:04 -0700] "GET /images/parts/b01_rename.jpg HTTP/1.1" 403 483 "-" "-"
92.20.16.32 - - [08/Oct/2009:14:50:04 -0700] "GET /images/parts/b01_rename.jpg HTTP/1.1" 403 483 "-" "-"
71.143.241.113 - - [08/Oct/2009:14:50:04 -0700] "GET /images/parts/b01_rename.jpg HTTP/1.1" 403 483 "-" "-"
121.45.36.227 - - [08/Oct/2009:14:50:04 -0700] "GET /images/parts/b01_rename.jpg HTTP/1.1" 403 483 "-" "-"
79.177.68.68 - - [08/Oct/2009:14:50:04 -0700] "GET /images/parts/b01_rename.jpg HTTP/1.1" 403 483 "-" "-"
85.228.186.140 - - [08/Oct/2009:14:50:04 -0700] "GET /images/parts/b01_rename.jpg HTTP/1.1" 403 483 "-" "-"
89.243.44.198 - - [08/Oct/2009:14:50:04 -0700] "GET /images/parts/b01_rename.jpg HTTP/1.1" 403 483 "-" "-"
190.30.142.230 - - [08/Oct/2009:14:50:04 -0700] "GET /images/parts/b01_rename.jpg HTTP/1.1" 403 483 "-" "-"

As you can see all are being blocked with 403. When I check the processes this user is using all their lsphp processes at very high cpu usage. These are only requests at that time - no legit users.

IN litespeed admin it will show like 1500 or so requests in processing, none coming through though. But server load is fairly high and the lshttpd processes are running at high cpu as well.

Now here is the kicker, We have been blocking like this since we moved to this server. I have even been running my barf script to firewall the ips making the requests. Here is the bandwidth usage since the first of the month:
strategy user.com 1034.79 Gig 1059622.61 M 1953.13 Gig

I suppose at times some successful requests were made before we got all the webserver blocking methods up but I would guess that 99% of the time they all got 403s.

When someone gets a 403 does that user or server have to execute a php process to do so?

When getting the 403 error, about how much bandwidth is supposed to be used per time?

Please help me get this figured out. AT the moment I had to put them on secureport where there is click to enter page at the router level. It has stopped it dead but generally I want to be able to handle these type of attacks on the server level
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 11:29 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.