Answer the question
In order to leave comments, you need to log in
What can generate outbound traffic on a VPS under Ubuntu so powerfully?
Cases of container blocking by hosting for "suspicious outgoing traffic" have become more frequent. They report that it happens up to 42Gbps, although I don’t quite understand how this is possible with a 100mbps channel. This happens on a working machine running Ubuntu with LEMP; earlier once every six months, and now the second time in a month. After blocking, they provide me with information, but I can’t figure out what to do with it, because all the IP addresses are familiar and understandable to me, I can’t suspect them. And the processes are the usual pool of processes on the server, as it seemed to me (I don’t delve into system administration). Tell me, how can I calculate what generates outgoing traffic in this way?
Support in every possible way hints at the little guy, and only throws links to simple ruthunters. Well, I ran through the server, didn’t find anything, changed the root password just in case, set fail2ban .. I don’t know, I just don’t understand which way to dig.
Answer the question
In order to leave comments, you need to log in
First, check your backups. If they are not there, backup everything.
Then close all unnecessary ports in iptables.
Next, find out from technical support which IPs and ports the traffic goes to. Nothing is clear from "technical info when blocking". What kind of 42 Gbit is also not clear.
Well, prepare a new "obviously clean" server, configure everything according to Feng Shui, transfer backups there. If this is not a technical support error, then there is malware on the server. the server is compromised and must be stopped.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question