Tema: DDOS
Autorius: mix
Data: 2014-03-26 18:27:00
Sveiki

turiu viena zaislini vps su keliais wordpresais ir joomlom.
Siandien gavau is tiekejo laiska:

Dear Abuse team:

We have detected that a considerable amount of users from your network
might be heavily abusing the service. Perhaps they have been comprised
and belong to a botnet. We would appreciate if you can take care of this
issue as soon as possible.

The abuse comes in the form of DDoS using SYN Flood attack towards port
80 of IP 134.90.145.206 and it started at approximately 11:50 CET (+0100).

The following is a list of IPs that belong to you and generate traffic
towards this IP.

=== Evidence ===
Date first seen          Duration  Src AS      Src IP Addr      Dst IP Addr 
Packets    Bytes      bps    Bpp Flows


Ant serverio nurodytu metu matau cpu, mysql padidejusia veiksena )
trafikas akivaizdziai neisauges.
prasukau chkrootkit, rkhunteri ir clamscana - itartino jie nieko nerado.


Padekit surast zveri )?