Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: Investigate DDoS attack
PostPosted: Tue May 06, 2014 8:32 pm 
Offline
Newbie

Joined: Tue May 06, 2014 8:29 pm
Posts: 2
I have been sent an alert by the Linode (1024 plan) team stating the following:

"An outbound DoS attack originating from your Linode was detected. As such, a filter was put in place to prevent further damage to our infrastructure. At this point you will need to investigate the outbound DoS attack and address the issue before we can remove the filter."


I need help to understand what this means and how I can investigate this!

Please help!


Top
   
PostPosted: Tue May 06, 2014 8:39 pm 
Offline
Senior Member

Joined: Mon Jul 05, 2010 5:13 pm
Posts: 392
That means your Linode is attacking other systems. The rough steps for fixing this are as follows:

1. Shut down your Linode
2. Boot into Rescue Mode ( https://library.linode.com/rescue-and-r ... escue-mode )
3. Figure out how somebody compromised your Linode
4. Redeploy from fresh disk images
5. When you configure the new system, fix whatever issue let them compromise you this time

- Les


Top
   
PostPosted: Tue May 06, 2014 9:10 pm 
Offline
Newbie

Joined: Tue May 06, 2014 8:29 pm
Posts: 2
Thats what Linode seems to think.
I am not sure how to go about step 3:

3. Figure out how somebody compromised your Linode

Our server makes outgoing requests to other servers every couple of hours to get status updates on a large number of orders (in the hundreds). Could this be the cause of the issue? is it possible that the traffic is legit but Linode is just being cautious and labelling this as a "compromise".

Please advise how I can go about "Figure out how somebody compromised your Linode"


Top
   
PostPosted: Tue May 06, 2014 11:02 pm 
Offline
Senior Member

Joined: Mon Jan 02, 2012 12:45 pm
Posts: 365
Linode doesn't track your outbound traffic. If they are telling you that your VPS is participating in a DDoS then Linode has received a report from the target that traffic is coming from your VPS's IP.

This is a recent occurrence, so you should look for any PHP files that were uploaded or modified within the last 48 - 72 hours. Depending on what type of website(s) you are running your vulnerability could be different things.

You can check your logs to see what type of inbound FTP activity you may have had within the last few days. And make sure your FTP service is configured not to allow anonymous FTP users (I've seen it before other servers).


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group