Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. dos attacks...

dos attacks...

Scheduled Pinned Locked Moved The Lounge
comquestion
8 Posts 6 Posters 1 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L Offline
    L Offline
    l a u r e n
    wrote on last edited by
    #1

    one of my clients web servers is under attack i think ... in the log files i can see 1000 page access attempts per minute all from the same ip address and all for nonsense page urls is this what an attack looks like? ive never seen one before :|


    "there is no spoon"
    biz stuff about me

    N R A J 4 Replies Last reply
    0
    • L l a u r e n

      one of my clients web servers is under attack i think ... in the log files i can see 1000 page access attempts per minute all from the same ip address and all for nonsense page urls is this what an attack looks like? ive never seen one before :|


      "there is no spoon"
      biz stuff about me

      N Offline
      N Offline
      Nish Nishant
      wrote on last edited by
      #2

      It definitely looks like a DOS attack - though it could also be some script kiddie using a vulnerability scanner that's checking for any exploitable web-scripts on the server. Anyway can't she block the IP at the router? Nish


      My blog on C++/CLI, MFC/Win32, .NET - void Nish(char* szBlog); My MVP tips, tricks and essays web site - www.voidnish.com

      J 1 Reply Last reply
      0
      • L l a u r e n

        one of my clients web servers is under attack i think ... in the log files i can see 1000 page access attempts per minute all from the same ip address and all for nonsense page urls is this what an attack looks like? ive never seen one before :|


        "there is no spoon"
        biz stuff about me

        R Offline
        R Offline
        Roger Wright
        wrote on last edited by
        #3

        l a u r e n wrote: nonsense page urls Are the urls unusually long? It might be an attempt to exploit a buffer overrun vulnerability, rather than a DoS attack. Maybe a small script to send them all back to the source address is in order.:rolleyes: "If it's Snowbird season, why can't we shoot them?" - Overheard in a bar in Bullhead City

        L 1 Reply Last reply
        0
        • N Nish Nishant

          It definitely looks like a DOS attack - though it could also be some script kiddie using a vulnerability scanner that's checking for any exploitable web-scripts on the server. Anyway can't she block the IP at the router? Nish


          My blog on C++/CLI, MFC/Win32, .NET - void Nish(char* szBlog); My MVP tips, tricks and essays web site - www.voidnish.com

          J Offline
          J Offline
          Jurgen Eidt
          wrote on last edited by
          #4

          Besides this, the attack is good for making the log file more difficult to read. I have curious vistors who access my site via robots. Some sections of the provided log file is limited to the top 20 entries which are filled by them. I guess this happens quite often and for now no one cares that much but in my opinion its a criminal action. Contacting the provider hosting the attacker is sometimes difficult. One of my guests is 203.222.167.98, which belongs to sprint.com. They simply don't care. Jürgen Eidt http://cpicture.de/en [^]

          1 Reply Last reply
          0
          • R Roger Wright

            l a u r e n wrote: nonsense page urls Are the urls unusually long? It might be an attempt to exploit a buffer overrun vulnerability, rather than a DoS attack. Maybe a small script to send them all back to the source address is in order.:rolleyes: "If it's Snowbird season, why can't we shoot them?" - Overheard in a bar in Bullhead City

            L Offline
            L Offline
            l a u r e n
            wrote on last edited by
            #5

            i actually blocked their whole class d address range in the hosts.deny file hehehe :)


            "there is no spoon"
            biz stuff about me

            R 1 Reply Last reply
            0
            • L l a u r e n

              i actually blocked their whole class d address range in the hosts.deny file hehehe :)


              "there is no spoon"
              biz stuff about me

              R Offline
              R Offline
              Roger Wright
              wrote on last edited by
              #6

              Simplicity reigns supreme.:-D "If it's Snowbird season, why can't we shoot them?" - Overheard in a bar in Bullhead City

              1 Reply Last reply
              0
              • L l a u r e n

                one of my clients web servers is under attack i think ... in the log files i can see 1000 page access attempts per minute all from the same ip address and all for nonsense page urls is this what an attack looks like? ive never seen one before :|


                "there is no spoon"
                biz stuff about me

                A Offline
                A Offline
                Anders Molin
                wrote on last edited by
                #7

                Dos is normally not HTTP requests from a single IP. It's more like a scanner of some sort trying different well-known pages to see if there are some on the server which can be exploited... I see it in my logs all the time. Either blog the IP or just let it pass ;) - Anders Bill's Bar
                My Photos

                WDevs - The worlds first DSP, free blog space, email and more. Now also with forums :)

                1 Reply Last reply
                0
                • L l a u r e n

                  one of my clients web servers is under attack i think ... in the log files i can see 1000 page access attempts per minute all from the same ip address and all for nonsense page urls is this what an attack looks like? ive never seen one before :|


                  "there is no spoon"
                  biz stuff about me

                  J Offline
                  J Offline
                  jan larsen
                  wrote on last edited by
                  #8

                  It could also be a plugin in a users browser. We had the same problem at client last year, and it turned out, that over 50% of the weird requests comes from a media plugin that tries to cache media files that, or may not exist, on the server. "After all it's just text at the end of the day. - Colin Davies "For example, when a VB programmer comes to my house, they may say 'does your pool need cleaning, sir ?' " - Christian Graus

                  1 Reply Last reply
                  0
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Don't have an account? Register

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • World
                  • Users
                  • Groups