|
Blue Forest http://www.lslnet.com at 20:18 on April 6, 2006
Pitiful, MYSQL Based encountered DDOS attack!
Pitiful, MYSQL Based encountered DDOS attack!
You greatly, I trust of a mainframe-Shanghai 155M bandwidth, the higher level in several forums. Start at 11:30 and found online, there were not many of them, only 800 people, but show too many connections, and sometimes not even into the Forum, then look into the process through ssh, httpd daemon many found, it may be several dozens bars. check the top 40% of CPU use, memory only 10M% (total 512M+1024M SWAP) thought it was a normal phenomenon line number, but who knows at the moment, the entire server PING completely illogical, because the Trusteeship Council, but now they can not get through telephone, SERVER complete paralysis there, Oh. . . . . . luck, and no one would know that such a situation would not happen to you?
The system is because I APACHE1.3.27 FREEBSD 4.8 + + + MYSQL Based 3.3.55 + PHP4.3.1 PERL5.000, in the Trusteeship Council, I specifically checked the safety revised rc.conf, sysctl.conf, the closure of the port useless. I was afraid that I was attacking. . .
I have some questions to ask you this : children
1, and whether or not my fault I have to prove DDOS? If the 3306 attack MYSQL Based there will be too many connections.
2, why not visit a complete mainframe, ssh, ftp, SMTP, http, and so not all network services.
3, how to prevent future?
Will expert help, help me solve this problem are extremely grateful! |
Pitiful, MYSQL Based encountered DDOS attack!
Netstat can connect with, or subdirectory
Mysql not subject to protection tools :
Mysql started when an additional parameters --bind-address=127.0.0.1 designated mysql linsten port, but not people outside of your mysql database. |
Pitiful, MYSQL Based encountered DDOS attack!
In fact, for such people usually do not need to answer : : : : Because they did not share any out the solution to the problem : only one head of diving : : : : : : : : : : : : waiting for an answer : |
Pitiful, MYSQL Based encountered DDOS attack!
[quote][i] Note from the original "proftpd"] In fact, for such people : : : : not answered because they did not usually shared out any solution to the problem : : : : Just a heads of diving : : : : : : : : : : waiting for an answer : [/quote published [/i]
Thank you for reminding me, please answer my question, I begin today, not chinaunix diving : |
Pitiful, MYSQL Based encountered DDOS attack!
Too many connections
Variables how you look at the largest connectivity?
Wait_timeout is there?
If a 10% occupancy, it is necessary to start considering a number of different ports mysql mysql service bar. . . . . . |
Pitiful, MYSQL Based encountered DDOS attack!
But they found, 80 others to attack the port, the server down, again and restart, I passed netstat-an found a long list of a bunch of IP addresses behind the port is one of a series of disaggregated data, memory use TOP observation, found in 1997, okay. BSD up unable to see, I quickly restart the x, and there are hundreds more immediately M out, huh, huh :
I have to prepare for the installation of a mysql up, and using different port : D
I emphasized the link to the largest number is 10000
My.conf inside, I also changed the setting up skip-networking
Hope that those attacks could stop, I really Hao Fan! |
Pitiful, MYSQL Based encountered DDOS attack!
You can also set up httpd.conf die, so a few can be connected to the scope of the country can accept no more than 10 people opened a website to see the same time, this is not, is a machine. |
Pitiful, MYSQL Based encountered DDOS attack!
Ah, yes, but someone always seemed to me that way DDOS, strange! |
Pitiful, MYSQL Based encountered DDOS attack!
[quote][i] Note from the original "zyme"] You can also set up httpd.conf die, so a few can be connected to the scope of the country can accept no more than 10 people opened a website to see the same time, this is not, is a machine. [/quote [/i] Released :
: (I opened the pages ----24 months, and Outlook. |
Pitiful, MYSQL Based encountered DDOS attack!
[quote][i] Note from the original "daoshi"] : (----24 months I opened the page and there outlook.[/quote [/i] released :
So, you are machines! ! ! : Lol : : wink : |
Pitiful, MYSQL Based encountered DDOS attack!
Mysql attack on the performance of PHP is not able to visit all, and index.html is normal, then look at the log mysql has clearly see what is in constant Shuabing, cpu load to a high 99%
I first encountered this situation |
Pitiful, MYSQL Based encountered DDOS attack!
Mysql remote machines to provide your visit?
If the local connection, please switch off the mysql TCP listen and do not know mysql possible. PgSQL acquiescence listen and do not open the TCP. |
Pitiful, MYSQL Based encountered DDOS attack!
I did not open the 3306 port, and I worry about this question : |
| |