Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


what is happening to my vps?
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

what is happening to my vps?

namhuynamhuy Member

1 week

1 hour

Uhmm didn't know until I log in solus, what is happening to my vps?

Comments

  • namhuynamhuy Member

    Jack said: Have you opened a ticket at the provider?

    not yet, i wanna know if there is something i can do on my part first

  • blackblack Member

    What's the problem? Looks like a normal graph to me.

  • namhuynamhuy Member

    why incoming traffic suddenly jump to 1 m/s since may 18. I have this vps for months and the configs are the same for months

  • blackblack Member

    @namhuy said:
    why incoming traffic suddenly jump to 1 m/s since may 18. I have this vps for months and the configs are the same for months

    Check trafshow and look at the destination port where heavy traffic is going to. Then do netstat -lnp to see which process is serving them. If it's a web server, check web server logs.

    Thanked by 1namhuy
  • BoxodeBoxode Member

    DDoS?

  • darkshiredarkshire Member
    edited May 2014

    SoDD?

  • namhuynamhuy Member

    I have been looking at trafshow and netstat, mostly http traffic and sometimes google dns queries, nothing out of ordinary, but according to solus stat I have spike every 20 mins or so

  • Your VPS took a maternity leave...

    Thanked by 1darkshire
  • GunterGunter Member

    Perhaps it got hacked and an email/webpage scraper is running?

  • zionvpszionvps Member

    install iftop and run it. you will see what is the bandwidth spike

    Thanked by 1namhuy
  • zionvpszionvps Member

    also, if you are hosting static files, it could be your site has less traffic, and people come in intervals. when they request a file the graph fires up. i suspect this because 1m is quite low bandwidth being consumed

  • sz1hostingsz1hosting Member
    edited May 2014

    comment removed due to insults

    Thanked by 1Maximum_VPS
  • sz1hosting said: Change your password to a complicated one via ssh

    Or turn off passwords completely and use certs

  • namhuynamhuy Member

    sz1hosting said: Change your password to a complicated one via ssh then investigate whats going on look at the running processors - services etc and ask google for info about them.

    when does those logs become ssh problem !?

    btw, found the problem ( not really though). it's one of the nginx rewrite rule I play with lately. I redirect bad request, bad bots and such to ovh 10g file, somehow nginx download that 10g file too when bad requests happen. I'm going to test one by one now which rule cause the problem x_x

    Thanked by 1Mark_R
  • sz1hostingsz1hosting Member
    edited May 2014

    ok

  • namhuynamhuy Member

    sz1hosting said: Oh a lot of work! ^_^

    stop spamming please

  • sz1hostingsz1hosting Member
    edited May 2014

    whatever, trying to be nice and friendly....

  • FalzoFalzo Member

    @namhuy said: I redirect bad request, bad bots and such to ovh 10g file...

    read this before here on LET, but think thats a bad practice at all.

    while understanding the well-intended proposition on doing this, I think this is not an appropriate counter-measure, because it does harm a lot of others, by simply adding wasted traffic to the world.
    you are also abusing services of OVH, which maybe influences their customers in any way.
    and, at last, you're like abusing your own provider by having problems on configuring it not boomeraning. ;-)

    no offense meant, but would suggest on finding another way dealing with bad requests (fail2ban etc.)

  • namhuynamhuy Member

    no offense but i think it's more fun to give those w/ bad intent a little bit of bad taste. Any how

    if ($http_user_agent = "") seems to caused the problem, I was trying to prevent empty user agent. I guess wordpress some how use empty user agent for some weirdo reason?

  • awsonawson Member
    access_by_lua "
      local ua = ngx.req.get_headers()['User-Agent']
      if ua == '' or ua == nil then
        return ngx.exit(ngx.HTTP_FORBIDDEN)
      end";
    
    Thanked by 2namhuy Falzo
  • namhuynamhuy Member
    edited May 2014

    @awson do i need to install any extra package on centos?

  • awsonawson Member

    @namhuy said:
    awson do i need to install any extra package on centos?

    The LUA module is in nginx-extras

Sign In or Register to comment.