Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Calling all cyber forensics experts
vanity | September 28, 2004 | me

Posted on 09/28/2004 12:08:06 PM PDT by tdadams

I need some hypotheticals from the smart internet gurus here at Free Republic. I'm fairly web savvy myself, but this has me stumped for the time being.

I have a fairly popular website that over the last four months has seen its hits go from about 3,000 a day to about 20,000 a day. At times it has peaked at just over 25,000 a day. Bandwidth is normally about 700 meg a day.

This is exciting and good on one hand, but it's also a non-commercial, non-profit site, so the rising bandwidth charges are worrisome.

Well today, as I checked my statistics, it shows usage yesterday was 135,000 hits and 5.5 gig of bandwidth.

This strikes me as being beyond a reasonable deviation. I would expect this kind of spike if my site had been named a "Yahoo Pick of the Day" or something, but the logs show no such referrers.

Over eighty percent of the hits have gone to one page on my site that's loaded with hi-res graphics, which strikes me as odd. It makes me think this is some sort of denial of service attack. Only it seems that the hits aren't concentrated from a single IP address or bank of IP addresses. The distribution of the IP ranges is pretty uniform.

I have had some persistent attempts by spammers leaving "guestbook spam" in my guestbook, which gets deleted immediately. Perhaps I've pissed them off and they're launching an attack against me.

This has me really stumped. Has anyone seen a similar pattern with their site? Does anyone have any clues what might be going on?

I already have my webhost looking into it.


TOPICS: Computers/Internet
KEYWORDS: internet; webhosting; websites; webusage

1 posted on 09/28/2004 12:08:06 PM PDT by tdadams
[ Post Reply | Private Reply | View Replies]

To: tdadams

Check for Nimda.


2 posted on 09/28/2004 12:09:06 PM PDT by Old Sarge (ZOT 'em all, let MOD sort 'em out!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: tdadams

I would think you need to check the server for possible porn/illegal files (ftp site).


3 posted on 09/28/2004 12:12:56 PM PDT by 4CJ (Laissez les bon FReeps rouler)
[ Post Reply | Private Reply | To 1 | View Replies]

To: tdadams


What do the Referrers suggest?

Perhaps a popular blog or forum somewhere linked to your gallery.


4 posted on 09/28/2004 1:02:08 PM PDT by Malsua
[ Post Reply | Private Reply | To 1 | View Replies]

To: tdadams

Someone hot-linking to some of your hi-res graphics?


5 posted on 09/28/2004 1:02:45 PM PDT by So Cal Rocket (Proud Member: Internet Pajama Wearers for Truth)
[ Post Reply | Private Reply | To 1 | View Replies]

To: So Cal Rocket; Malsua

I do have some hotlinking going on and that doesn't bother me too much. I've monitored that and it has minimal impact on my bandwidth.

But this spike is far too large to be explained by that. I jumped from an average of about 20K hits a day to 135K overnight and nothing in the logs seem to indicate a single source. Like I said, I'm stumped.

To get that kind of spike, I'd have to get linked by Drudge, Yahoo, or MSN. I just can't figure out where the spike came from.


6 posted on 09/28/2004 1:46:27 PM PDT by tdadams ('Unfit for Command' is full of lies... it quotes John Kerry)
[ Post Reply | Private Reply | To 5 | View Replies]

To: tdadams
To get that kind of spike, I'd have to get linked by Drudge, Yahoo, or MSN. I just can't figure out where the spike came from.

Then most of the hits would have the same referrer.

It's possible you're getting hit by a zombie network, but you're not a big fish, why would anyone care? You make any enemies recently? The behavior is also not consistant. Mostly zombies just send Syns or malformed packets or whatever(too many ways to list) and your ISP is probably handling that at the router level.

I still think someone with an interest in your travels found the page. Did you link to some posts here at FR? Does your ISP statistic reports provide a unique Visitors lists? rather than just hits? One page can be hundreds of hits.

Fan boards can drive many hits. I linked my City of Heroes Movie on the Vault for about 6 hours and had 1000 downloads. At 25mb a pop, I quickly turned it off minus 10GB of my monthy bandwidth. It doesn't take much.

7 posted on 09/28/2004 3:53:39 PM PDT by Malsua
[ Post Reply | Private Reply | To 6 | View Replies]

To: Malsua
Did you link to some posts here at FR? Does your ISP statistic reports provide a unique Visitors lists? rather than just hits? One page can be hundreds of hits.

Yes, I've posted some links here, but I normally see a small spike from that, no more than an extra 500 hits or so, not 110,000. I do have reports on unique visitors, but haven't been able to decipher a noticeable pattern yet.

8 posted on 09/28/2004 5:01:07 PM PDT by tdadams ('Unfit for Command' is full of lies... it quotes John Kerry)
[ Post Reply | Private Reply | To 7 | View Replies]

To: tdadams
Only it seems that the hits aren't concentrated from a single IP address or bank of IP addresses. The distribution of the IP ranges is pretty uniform.

"When 'bots Attack".

9 posted on 09/28/2004 5:08:40 PM PDT by Bloody Sam Roberts (Gotta get me bones to Michigan some day.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bloody Sam Roberts
When 'bots Attack

Apparently so. My stats this morning show 196K hits and 7.7 gigs of bandwidth for yesterday. Someone's having a laugh at my expense.

10 posted on 09/29/2004 4:09:38 AM PDT by tdadams ('Unfit for Command' is full of lies... it quotes John Kerry)
[ Post Reply | Private Reply | To 9 | View Replies]

To: tdadams
There's an interesting story here about another ddos attack. You might be able to glean some useful tidbits to assist in defense of your 'castle'.
11 posted on 09/29/2004 6:20:35 AM PDT by Bloody Sam Roberts (Which Star Trek Capt. would you want for President? Picard or Kirk? In wartime, the choice is easy.)
[ Post Reply | Private Reply | To 10 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson