A
A
Alexander Globov2014-02-11 08:11:41
System administration
Alexander Globov, 2014-02-11 08:11:41

What should I do if DDOS comes through my Hetzner server?

Hello! Yesterday I received a "letter of happiness" from [email protected] about a DDOS attack going through my server. They gave 24 hours for everything.
Here is the text of the message from the victim:


Hi
My IP yy.yy.yy.yy is being ddosed from your network
All ips that attack me belong to Hetzner
Attack speed is more than 1gbit\s
PROTO=UDP SPT=10000 DPT=80 DST=yy.yy.yy.yy
IP addresses that are attacking me:
Feb 9 19:26:25 srv1 kernel: [ 69.722057] Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=d8:9d:67:16:93:b0:00:0e:39 :42:bc:00:08:00 SRC=xx.xx.xx.xx DST=yy.yy.yy.yy LEN=1396 TOS=0x00 PREC=0x00 TTL=246 ID=50113 PROTO=UDP SPT=10000 DPT =80 LEN=1376

Never had to deal with this before. I started digging on the Internet and found that they can DDOS through recursive queries in the bind9 DNS server
forum.searchengines.ru/showthread.php?t=785341
But I don’t have it installed in principle.
I also found articles about using NTP server bugs:
habrahabr.ru/post/209438
But the command
ntpdc -c monlist адрес_сервера
responds with Timed out. Therefore, this hole is also closed.
Tell me where else to look? What other ways are there to DDOS through my server?

Answer the question

In order to leave comments, you need to log in

3 answer(s)
M
mikes, 2014-02-11
@sanekglobov

there are many ways to use you as an attacker.
first through iptables "stop the oxygen" from the logs you have data of what to close
and then as the first step check netstat -p --udp if you are spamming via udp and see what happens

O
Oleg, 2014-02-11
@makol

Don't you think that the letter itself is an attempt at a divorce?

P
Puma Thailand, 2014-02-11
@opium

It is logical that you were scammed and DDoSed from the server.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question