downtime oct. 16

Announcements and for questions/problems..
Post Reply
User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

downtime oct. 16

Post by bad_brain »

first: no it wasn't an attack... :lol:

seems the last reboot was a little too long ago so the system became a little buggy, a process had a hang and caused a loop which occupied all memory.
this time I wasn't in the shower, I was sleeping...that's why the downtime was that long....a simple reboot fixed it... :wink:

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

meh ... and here I was, loading the skiddie guns all night
"The best place to hide a tree, is in a forest"

User avatar
Gogeta70
^_^
^_^
Posts: 3275
Joined: 25 Jun 2005, 16:00
18

Post by Gogeta70 »

You weren't the only one, dnr has a bunch of info on the latest spammer XD
¯\_(ツ)_/¯ It works on my machine...

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

gogeta70 wrote:You weren't the only one, dnr has a bunch of info on the latest spammer XD
ahaha xD

Hey you never know, we might have fun with that anyway :roll:
"The best place to hide a tree, is in a forest"

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

k, further analysis points to this:
at 0:23 local time the database is backed up, and accidentally the mail server needed a lot of resources at the same time....but because the backup script was running the mail server had not enough resources left, this caused some weird loop where the mail server opened new internal connections on every retry until there were so many processed that the server crashed.

the chances that the backup script AND the mail server need resources at the same time are very low because the backup script runs only once a day and usually needs only 2 minutes.....but to avoid such problems in the future I will do the backups on the database mirror server instead of the main server. on the mirror server there are a lot less processes running, and traffic (mail traffic especially) is almost zero. and even if such a problem appears again it will only crash the mirror server, not the main one.

:)

raiever
forum buddy
forum buddy
Posts: 16
Joined: 10 Oct 2009, 16:00
14
Location: My house
Contact:

Re: downtime oct. 16

Post by raiever »

[quote="p4inl0v3r"][quote="bad_brain"]this time I wasn't in the shower, I was sleeping...that's why the downtime was that long....a simple reboot fixed it... :wink:[/quote]

*note : gift b_b an alram clock which goes off when server crashes on his birthday :lol:[/quote]

Love that idea!! lol *hands 5 dollars* theres some money for it haha

User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Post by DNR »

question - I noticed the FTP server was operational - if there is a DoS, would both ports be down?

DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
Lundis
Distorter of Reality
Distorter of Reality
Posts: 543
Joined: 22 Aug 2008, 16:00
15
Location: Deadlock of Awesome
Contact:

Post by Lundis »

Did the viagra merchants spike you or what? :lol:

If the server got so overloaded that it crashed the server, then FTP shouldn't work either, am I wrong? (Unless it's running on another server internally)

User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Post by DNR »

me thinks it depends on the exploit, HTTP is a separate service on its own while its on the same machine that also handles FTP service. One may not necessarily effect the entire server. It can also depend on the server OS, I am more familiar with IIS and Novell servers.

reedit:
Network DoS vs. Web App DoS

Whereas network level DoS attacks aim to flood your pipe with lower-level OSI traffic (SYN packets, etc...), web application layer DoS attacks can often be achieved with much less traffic. Just take a look at Rsnake's Slowloris app if you want to see a perfect example of the fragility of web server availability. The point here is that the amount of traffic which can often cause an HTTP DoS condition is often much less than what a network level device would identify as anomalous and therefore would not report on it as they would with traditional network level botnet DDoS attacks.
that should explain my question, which I sort of answered anyways..
Check out this link:
DIY:Defending against DDoS - some nice tactics
http://www.darkreading.com/security/att ... =220600886" onclick="window.open(this.href);return false;

No viagra needed here, I get hardons all the time, can't you tell?
:lol:
DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

I think you confuse the servers DNR, on the suck-o.com server there is no ftp at all, your account is on another one.... :wink:

but in general (not in context with this incident) a server system usually doesn't crash completely at once, usually the services die one by one....first the ones with the most RAM usage, and last the ones with a low RAM usage, so it can happen http, mysql and mail are already crashed but ftp or irc are still available (for a short time).

Post Reply