THERADIOTUBBY Posted January 31, 2009 Posted January 31, 2009 Not sure how much info to put here Running school website on iis on server 2003 - wwwdotsaccdotnottsdotschdotuk - only port 80 mapped through firewall Website html with some asp, also runs moodle and sql forum Tuesday this week notice all internet for school very slow- router pings very high. Turns out webserver receiving massive traffic all to homepage - default.asp - literally millions of hits per day iis log (massive) all of the form 2009-01-30 18:54:56 W3SVC1 WEBSITE 10.60.208.31 GET /Default.asp - 80 - 85.229.218.177 HTTP/1.0 - - - - 200 0 64 0 39 181 hits coming from paraguay, sweden, mexico etc Learning about attacks very quickly. Has anyone any advice? Server currently offline will turn back on if needed
kmount Posted January 31, 2009 Posted January 31, 2009 First of all, check whether it's infected by some kind of virus/malware which is attracting the hits. Secondly, filter the list and obtain a list of IPs to send to your ISP for blocking at their end (useless blocking them at your end as you only have a small pipe and it will still be saturated). You should be fine after that.
PiqueABoo Posted January 31, 2009 Posted January 31, 2009 Secondly, filter the list and obtain a list of IPs to send to your ISP for blocking at their end If that isn't small I'd get the ISP to blackhole all traffic aimed at the web-server IP for a while.. figure out whether there is anything wrong locally and if not (or when fixed) get the web server moved to another address.
THERADIOTUBBY Posted February 1, 2009 Author Posted February 1, 2009 When reconnected after a day everything ok - thought i'd fixed it - until a fixed time when all attacks started again Points to something on server attracting them Looked at port activity, ran virus scans to no avail Any ideas?
danIT Posted February 1, 2009 Posted February 1, 2009 Which version of Moodle are you using? Check you Moodle directory for any files which shouldnt be there, specifically look for any .php files which have been changed recently, or any files which were .html/.htm which are now .php
danIT Posted February 1, 2009 Posted February 1, 2009 Have you found any new php files, are files edited recently? I would suggest deleting your moodle install directory, save config.php before doing this, then stick a fresh copy of moodle in its place and add your config.php and replace any cutom blocks or code you have added. I've heard of similar attacks on moodle....
danIT Posted February 1, 2009 Posted February 1, 2009 Google has cached your Moodle site and tells me its 1.8.1, so i 99% gurantee moodle is your problem!
THERADIOTUBBY Posted February 1, 2009 Author Posted February 1, 2009 what exactly might these edits look like?????
danIT Posted February 1, 2009 Posted February 1, 2009 I dont know exactly, without being able to look at your server /moodle directory, pm me ftp details and ill have a quick look if you like?. Essentialy a number of .php files will either be added with similar names to existing Moodle files or existing files will be edited to include a line like below: */function tdo(){echo base64_decode('hu4fhr6jsbskai94 Can you do a grep for base64_decode?
THERADIOTUBBY Posted February 18, 2009 Author Posted February 18, 2009 Tried all above all virus/malware/rootkit sweeps blank Internet provider has been very helpful has blocked main culprits Used wireshark to grab packets attacking port 80 literally millions Loads containing text 'you've been owned' I would greatly appreciate any views on the following options; Move server to a new external ip - but what attracted them in the first place? Wipe server and reinstall - but if code is in php/asp web pages when they are restored will it all start again Any other suggestions?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now