silence
Well-known member
Alright so my VPS started randomly issuing attacks on IPs and I couldn't figure out where it was coming from.
My host has disabled us for the second time and I really need some insight on what I can do in order to resolve this.
I did malware scans with ClamAV and chkrootkit but found nothing.
The first notice I got was the following:
I reinstalled the entire VPS, put XenForo on it and everything seemed fine for a few days.
Then I got another event log:
I have issued a support request previously about the first event log since it looked like CloudFlare was somehow using up all my bandwidth but I'm not sure if it's there end since I resolve all CF IPs properly.
Now the third event log:
Can someone give me some help with this, as I have no idea what to do and cannot figure out what is launching these attacks.
Thanks!
My host has disabled us for the second time and I really need some insight on what I can do in order to resolve this.
I did malware scans with ClamAV and chkrootkit but found nothing.
The first notice I got was the following:
Code:
Your VDS has been running large DoS attacks, containing junk packets consistent with a rudimentary attack tool. The most recent one:
13:06:37.512586 IP (tos 0x0, ttl 64, id 6096, offset 0, flags [DF], proto UDP (17), length 795)
xx.xx.xx.xx.33118 > 114.141.72.225.80: UDP, payload 767
0x0000: 4500 031b 17d0 4000 4011 8959 c0df 1a5b E.....@.@..Y...[
0x0010: 728d 48e1 815e 0050 0307 7b49 457a 031a r.H..^.P..{IEz..
0x0020: 0000 4000 ff11 e1af c0df 1a5b 728d 48e1 ..@........[r.H.
0x0030: 0000 0050 0306 62e9 0000 0000 0000 0000 ...P..b.........
0x0040: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0050: 0000 ..
13:06:37.512615 IP (tos 0x0, ttl 64, id 51589, offset 0, flags [DF], proto UDP (17), length 797)
xx.xx.xx.xx.33118 > 114.141.72.235.80: UDP, payload 769
0x0000: 4500 031d c985 4000 4011 d797 c0df 1a5b E.....@.@......[
0x0010: 728d 48eb 815e 0050 0309 7b47 457a 031c r.H..^.P..{GEz..
0x0020: 0000 4000 ff11 e1a3 c0df 1a5b 728d 48eb ..@........[r.H.
0x0030: 0000 0050 0308 62db 0000 0000 0000 0000 ...P..b.........
0x0040: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0050: 0000 ..
13:06:37.512652 IP (tos 0x0, ttl 64, id 27986, offset 0, flags [DF], proto UDP (17), length 799)
xx.xx.xx.xx.33118 > 114.141.72.236.80: UDP, payload 771
0x0000: 4500 031f 6d52 4000 4011 33c8 c0df 1a5b E...mR@.@.3....[
0x0010: 728d 48ec 815e 0050 030b 7b45 457a 031e r.H..^.P..{EEz..
0x0020: 0000 4000 ff11 e1a0 c0df 1a5b 728d 48ec ..@........[r.H.
0x0030: 0000 0050 030a 62d6 0000 0000 0000 0000 ...P..b.........
0x0040: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0050: 0000 ..
I reinstalled the entire VPS, put XenForo on it and everything seemed fine for a few days.
Then I got another event log:
Code:
Your VDS is back to using tons of bandwidth all the time. This time, it looks like the issue may be your Cloudflare settings and not an attack that your VDS is running. You will need to investigate and resolve this.
I have issued a support request previously about the first event log since it looked like CloudFlare was somehow using up all my bandwidth but I'm not sure if it's there end since I resolve all CF IPs properly.
Now the third event log:
Code:
Your VDS has continued to launch attacks.
It is clear that you have just been reloading the same software back on and it is just being re-compromised. You need to actually investigate and resolve it this time. If you can't find how this person is gaining control of the VDS, you will need to shut it down entirely.
09:11:00.569949 IP (tos 0x0, ttl 64, id 33332, offset 0, flags [DF], proto UDP (17), length 1041) xx.xx.xx.xx.42971 > 103.26.180.35.80: UDP, payload 1013
0x0000: 4500 0411 8234 4000 4011 2c6c d834 94c9 E....4@.@.,l.4..
0x0010: 671a b423 a7db 0050 03fd d4c7 457a 0410 g..#...P....Ez..
0x0020: 0000 4000 ff11 6e35 c07e 2d71 671a b423 ..@...n5.~-qg..#
0x0030: d757 0050 03fc 1721 0000 0000 0000 0000 .W.P...!........
0x0040: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0050: 0000 ..
09:11:00.569952 IP (tos 0x0, ttl 64, id 33333, offset 0, flags [DF], proto UDP (17), length 1043) xx.xx.xx.xx.42971 > 103.26.180.35.80: UDP, payload 1015
0x0000: 4500 0413 8235 4000 4011 2c69 d834 94c9 E....5@.@.,i.4..
0x0010: 671a b423 a7db 0050 03ff d4c6 457a 0412 g..#...P....Ez..
0x0020: 0000 4000 ff11 6e32 c07e 2d72 671a b423 ..@...n2.~-rg..#
0x0030: d758 0050 03fe 171b 0000 0000 0000 0000 .X.P............
0x0040: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0050: 0000 ..
09:11:00.569964 IP (tos 0x0, ttl 64, id 33334, offset 0, flags [DF], proto UDP (17), length 1045) xx.xx.xx.xx.42971 > 103.26.180.35.80: UDP, payload 1017
0x0000: 4500 0415 8236 4000 4011 2c66 d834 94c9 E....6@.@.,f.4..
0x0010: 671a b423 a7db 0050 0401 d4c5 457a 0414 g..#...P....Ez..
0x0020: 0000 4000 ff11 6e2f c07e 2d73 671a b423 ..@...n/.~-sg..#
0x0030: d759 0050 0400 1715 0000 0000 0000 0000 .Y.P............
0x0040: 0000 0000 0000 0000 0000 0000 0000 0000 ................
0x0050: 0000 ..
Can someone give me some help with this, as I have no idea what to do and cannot figure out what is launching these attacks.
Thanks!