Is someone sabotaging my website?

Submolecule

Expert Member
Joined
Nov 26, 2008
Messages
1,001
Reaction score
5
Location
Durban
There are two visitors to my website that use collectively using about 4 gig of my transfer allowance per month. This does not seem to make sense to me as the website only has a couple of pages to view and no videos, flash or any other bandwidth hungry content. Is someone sabotaging my website?

This is not a problem at the moment as I am hosted overseas and have ample bandwidth to spare, but the day will come where I would like to move to Local hosting and will not be able to as the bandwidth cost will be too high.

Is someone sabotaging my website? Can i track the IP's? What can I do to stop this?
 
Have you tried contacting your web host? If they are in control of the servers, then they should be able to determine what you need.

Push come to shove you can try using your statistics and see if there is an IP Address that tops the charts.
 
How many emails do you send using that email account? Your SMTP traffic is likely to add up if you send numerous emails with video clips and the like each day..
 
In all probability you have some leechers on your hand.

I've found pictures linked directly to my websites from other high-traffic websites eating up a substantial amount of my bandwidth in a month (not 4 gig though)

I assume you have something like AWStats showing you the bandwidth usage/visitors?
 
It can be anyone creating links to your website.

Like a DoS attack by slow motion... :)

http://www.tech-faq.com/dos-denial-of-service-attack.shtml

http://en.wikipedia.org/wiki/Denial-of-service_attack
Methods of attack

A "denial-of-service" attack is characterized by an explicit attempt by attackers to prevent legitimate users of a service from using that service. Attacks can be directed at any network device, including attacks on routing devices and web, electronic mail, or Domain Name System servers.

A DoS attack can be perpetrated in a number of ways. The five basic types of attack are:
Consumption of computational resources, such as bandwidth, disk space, or processor time
Disruption of configuration information, such as routing information.
Disruption of state information, such as unsolicited resetting of TCP sessions.
Disruption of physical network components.
Obstructing the communication media between the intended users and the victim so that they can no longer communicate adequately.

A DoS attack may include execution of malware intended to:
Max out the processor's usage, preventing any work from occurring.
Trigger errors in the microcode of the machine.
Trigger errors in the sequencing of instructions, so as to force the computer into an unstable state or lock-up.
Exploits errors in the operating system to cause resource starvation and/or thrashing, i.e. to use up all available facilities so no real work can be accomplished.
Crash the operating system itself.
iFrame (D)DoS, in which an HTML document is made to visit a webpage with many KB's of information many times, until they achieve the amount of visits to where bandwidth limit is exceeded.
 
Last edited:
How many emails do you send using that email account? Your SMTP traffic is likely to add up if you send numerous emails with video clips and the like each day..

I send out a fair amount each day, but not with video are similar attachments, the biggest email that I send would be pdf files, but that I send out four or five times a month, the rest are regular text emails.

Push come to shove you can try using your statistics and see if there is an IP Address that tops the charts.

I assume you have something like AWStats showing you the bandwidth usage/visitors?

Yes thats exactly what I have and that is where I saw the two top IP using all the bandwidth.

Like a DoS attack by slow motion...

The thought crossed my mind that it could be ddos attack but then if someone is ddosing me then they are not doing a good job.

I have the two IP addresses, can I trace or see where those are coming from?
 
Same thing happened to me a while ago. Turns out some English guy with a 10mbit line was trying to rip the contents of my site with wget, and wget kept repeating one of the files and yeah, he left it on over night. I had only showed a few people the site at the time however, and after looking at the IP addresses i knew it was him and asked him to stop. :) If I were you I'd just take the 2 IP addresses and ban them from your site.
 
Its not ddos if its coming from two ips.. do a whois on the ip`s and see who owns them and what they are.

Is your site cgi/php/asp/html?

Do you have a sendmail form anywhere on your site? Can anyone upload anything to your site? Or submit anything to your site?

In Awstats.. which page is using those 4gb? It should list that.
 
I have the two IP addresses, can I trace or see where those are coming from?

From where are the IP Addresses (http://www.geobytes.com/ipLocator.htm) and are they showing signs of DoS behaviour?

If your web host uses cPanel, you can use the IP Deny Manager to ban these IP Addresses but be careful, they may be our local transparent proxy IP Addresses or even legitimate traffic.

I think you would have probably been contacted by now if it was 4 gigabytes of spam traffic from vulnerable mail script (unless the web host doesn't mind you sending spam).
 
As mentioned above, some stats program (like AWStats) should show where the traffic is going on your web (http) portion.
 

Use you CPanel and goto "Awstats" or check your "Latest visitors" to see what they are doing.

Identify the IP address and then goto "IP Deny" and enter their IP address not your own:D to block them.

"LeechProtect" is a great feature as I had literally hundred of webcam websites "pinching" my webcam images,
their is always a workaround if he really wants to pinch your files. If the referrer is not my website, .htaccess
redirects to an Image page to goto the main website

Make sure your Vivvo CMS is patched for the latest security patches, as I had "software" installed
on one of my test sites and I had some really strongly worded emails to stop this practice of phishing
customer info for a financial company in London.

Found the infected files and deleted them

Local Music - www.morethanmusic.co.za:2082
Local Games - www.lazygamer.co.za:2082
Local Radio - www.rockoutradio.co.za:2082

EMail server:
I see your sites run Exim SMTP as most CPanel installations do, make sure you are not acting as a relay for spammers

Google Bot:
You can control how aggressive the bot crawls your site

Website.grader.com:
morethanmusic.co.za - 660 inbound links, excellent, gr8 looking sites
(so plenty of folks have got links on their websites to your website.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X