Go Back   Webmaster Malaysia Forum » Web Hosting & Domain Name » Paid Hosting Discussion Forum

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #16 (permalink)  
Old 16-05-2005, 01:54 PM
Novice Webmaster
 
Join Date: Jul 2002
Location: KL
Posts: 40
Rep Power: 0
zumaidi is on a distinguished road
it is located under public_html/forum/

This is the phpBB folder.
Btw, there is another fille - log.txt which contains the same thing.

I open it using notepad.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #17 (permalink)  
Old 16-05-2005, 03:11 PM
michaelfoo's Avatar
Senior Webmaster
 
Join Date: Aug 2003
Location: Selangor, Malaysia
Posts: 610
Rep Power: 77
michaelfoo is on a distinguished road
Send a message via MSN to michaelfoo
Hi zumaidi,
It appears to be attacked by a bot that is trying to scan for servers that hosted phpBB forums. The log files were created by the bot itself.

Since the bot is scanning for other servers that hosted phpBB, it requires a lot of CPU resources. Now instead of having your visitors to use up the resources, the resources are being used by the bot. It other words, it can be said that your forum has been hacked.

If I have not mistaken, it is a bug with the versions before 2.0.11. If you have upgraded your phpBB forum to the latest version, you should be on the safe side.

Thanks.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #18 (permalink)  
Old 16-05-2005, 08:35 PM
Novice Webmaster
 
Join Date: Feb 2005
Location: Malaysia
Posts: 33
Rep Power: 0
jetzkr8 is on a distinguished road
Quote:
Originally Posted by Filuren
i think ddos attack would just bring the whole box down rather than seeing cpu overload.......
Not if you are on clustered network. I had my domain sharing with another domain being under DoS attack. Only http services were effected during the entire attack of about 5 days. Email and Control Panel services as well as others on separate physical boxes were not effected. Pretty tough going if you have all your services lumped into one box, and probably pay the price along the way.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #19 (permalink)  
Old 18-06-2005, 12:45 PM
New kid on the block
 
Join Date: Jun 2005
Location: Penang
Posts: 4
Rep Power: 0
leehanhe is on a distinguished road
Send a message via MSN to leehanhe
Hello Zumaidi,

From the messages that you posted, the attacker have utilized the vulnerability in phpBB and uploaded some bad script to the server /tmp directory.

Those script normally is IRCbot or some spamming script. It will utilized the CPU resources when doing some job such as hosting an IRC server or spamming.

This kind of situation can be resolve by installing a firewall which blocking all unused network ports.

You should disable the custom avatar upload, gallery or any module that can upload files to the server. This can minimized the possibility for an attacker to upload malicious script to the server and execute it remotely.

If your site was hosting on a shared hosting environment, sometime antivirus will utilized the CPU when scanning large size email or the server being used by the spammer to spamming. (Sending to thousand of email address in the same time)

So, upgrade your forum time to time if there is any new release.
Do offen backup your MySQL database during non-peak time by using Cpanel.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
My website makes IE crash kenspear Websites Review and Suggestion 1 03-07-2006 12:21 PM
This guy makes USD 20k per month with adsense phantomic Revenue and Monetization 7 24-05-2006 02:16 PM



All times are GMT +8. The time now is 10:35 PM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0 vBulletin skin by ForumMonkeys.com.


WebmasterMalaysia.com is Proudly Hosted by Exabytes Semi Dedicated Server.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60