MDDHosting Forums: [Resolved] Cypress Outage - DDoS Attack Verified - MDDHosting Forums

Jump to content

  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

[Resolved] Cypress Outage - DDoS Attack Verified

#1 User is offline   Scott S 

  • MDDHosting Staff
  • PipPip
  • Group: Staff Administrator
  • Posts: 139
  • Joined: 24-February 09
  • Gender:Male
  • Location:GMT-8:00

Posted 12 March 2011 - 05:15 PM

Update #2 (7:00PM EST):
The DDoS attack on Cypress is now resolved.
Everything on the Cypress server should be returning to normal. We have null routed the affected IP addresses and moved all clients to a new shared IP. If you are still having issues, try clearing your DNS cache and then open a support ticket so we can look into your account specifically.

If you are the target of the attack, we will open a ticket with you and let you know. If you didn't see any such ticket, then the attack wasn't targeting you :)

The remainder of this post will remain unchanged to keep a full record of events intact.

====================

Update #1:
For those of you just joining us: We are seeing a 1,300 mbps DDoS attack aimed at our Cypress server. We are currently working with our datacenters networking team to null route affected IPs and migrate clients on those IP's to a new one. If you are using external DNS, such as CloudFlare, and you do NOT have a dedicated IP, please open a ticket so that we may get the new IP address to you when it is available.

The remainder of this post will remain how it was originally to keep a full record of events intact.

====================

We are aware of a current issue with the Cypress server and we are currently investigating the cause of this issue. More information will be made available as soon as we have it.
Scott S. - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all services!
http://www.mddhosting.com/ - Follow us on Twitter! @MDDHosting
0

#2 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 12 March 2011 - 05:23 PM

It looks as though a rather large packet flood hit the web server just now, the attack size is not terribly large however with the amount of requests that hit the server it wasn't able to keep up and ended up choking out.

We're working on identifying the attack, mitigating it, and we're going to do what we can to prevent it from happening again however the internet is a hostile environment and attacks are inevitable.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#3 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 12 March 2011 - 05:32 PM

http://www.screen-sh...-03-12_1725.png

It seems that today's issue and yesterday's issue are similar and likely related. It's a large influx of traffic into the server that causes the connection tracking in the server to fail resulting in the server becoming unresponsive. We're still working on identifying the source/destination and investigating ways to prevent this from happening again.

The server is online however it does take 10 to 15 minutes for it to "catch up" after being rebooted.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#4 User is offline   Brian Stevenson 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 17
  • Joined: 11-March 11

Posted 12 March 2011 - 05:35 PM

View PostMikeDVB, on 12 March 2011 - 05:32 PM, said:

http://www.screen-sh...-03-12_1725.png

It seems that today's issue and yesterday's issue are similar and likely related. It's a large influx of traffic into the server that causes the connection tracking in the server to fail resulting in the server becoming unresponsive. We're still working on identifying the source/destination and investigating ways to prevent this from happening again.

The server is online however it does take 10 to 15 minutes for it to "catch up" after being rebooted.

Thanks for the update.
0

#5 User is offline   TotalZen 

  • Newbie
  • Pip
  • Group: Clients
  • Posts: 21
  • Joined: 29-April 10
  • Gender:Male

Posted 12 March 2011 - 05:42 PM

Yeah thanks for being right on top of this Mike :)
0

#6 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 12 March 2011 - 06:02 PM

We just got with the network operations team at our facility and they're definitely seeing an ingress 500 MBPS+ hitting the server. We're putting a null-route in place for the target at which point the server will come back online.

The IP that is going to be null-routed does have several customers on it and we will be migrating them individually to new IPs so that we can identify the target of the attack more specifically and then that one particular account will be null routed until the attack subsides.

If you have any questions we do ask that you try and ask them here unless they are account specific so that we can provide centralized disbursement of information.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#7 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 12 March 2011 - 06:12 PM

The attack is in excess of 1.3 GBPS / 1,300 MBPS at last check and we're still working with the networking team.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#8 User is offline   Brian Stevenson 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 17
  • Joined: 11-March 11

Posted 12 March 2011 - 06:16 PM

View PostMikeDVB, on 12 March 2011 - 06:02 PM, said:

We just got with the network operations team at our facility and they're definitely seeing an ingress 500 MBPS+ hitting the server. We're putting a null-route in place for the target at which point the server will come back online.

The IP that is going to be null-routed does have several customers on it and we will be migrating them individually to new IPs so that we can identify the target of the attack more specifically and then that one particular account will be null routed until the attack subsides.

If you have any questions we do ask that you try and ask them here unless they are account specific so that we can provide centralized disbursement of information.

Is the new ip address temporary or permanent? I'll need to update my nameserver as I have my DNS hosted at cloudflare.

Peace,
Brian
0

#9 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 12 March 2011 - 06:22 PM

It would be temporary, if you're on a dedicated IP already then your IP will not be changed however if you're on a shared IP then there is a good chance it will change. Go ahead and open a ticket Brian and I'll get the new IP to you there.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#10 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 12 March 2011 - 06:24 PM

All sites on the affected IP were migrated to new IP addresses. Do feel free to open a ticket if you're not using our DNS however if you are using our DNS you won't need to do anything.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#11 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 12 March 2011 - 06:28 PM

As we thought, the attack followed the DNS change so we're initiating a reboot to get the server back to a state where it's not overwhelmed and we can identify the target IP and then null route that specific IP so that everybody else is online without issues.

We hope to have this resolved within the next 10 to 15 minutes.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#12 User is offline   Lincoln 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 6
  • Joined: 12-March 11

Posted 12 March 2011 - 06:28 PM

How does the number of DDOS attacks Cypress experiences compare to the other servers? It seems like its always Cypress that's getting attacked all the time?
0

#13 User is offline   Scott S 

  • MDDHosting Staff
  • PipPip
  • Group: Staff Administrator
  • Posts: 139
  • Joined: 24-February 09
  • Gender:Male
  • Location:GMT-8:00

Posted 12 March 2011 - 06:33 PM

View PostLincoln, on 12 March 2011 - 06:28 PM, said:

How does the number of DDOS attacks Cypress experiences compare to the other servers? It seems like its always Cypress that's getting attacked all the time?


I'm not aware of the statistics on this off hand. We do post a public record of events such as this on these forums, so you should be able to look through the history and see when other servers got hit. Once this issue is resolved, we may be able to spend more time looking into the history of such things.
Scott S. - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all services!
http://www.mddhosting.com/ - Follow us on Twitter! @MDDHosting
0

#14 User is offline   TotalZen 

  • Newbie
  • Pip
  • Group: Clients
  • Posts: 21
  • Joined: 29-April 10
  • Gender:Male

Posted 12 March 2011 - 06:33 PM

View PostLincoln, on 12 March 2011 - 06:28 PM, said:

How does the number of DDOS attacks Cypress experiences compare to the other servers? It seems like its always Cypress that's getting attacked all the time?


It's probably the same site that's being targeted repeatedly, I would guess.
0

#15 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 12 March 2011 - 06:38 PM

View PostLincoln, on 12 March 2011 - 06:28 PM, said:

How does the number of DDOS attacks Cypress experiences compare to the other servers? It seems like its always Cypress that's getting attacked all the time?
To my knowledge Cypress has never been hit with a DDoS we weren't able to quickly mitigate in the past and it has been quite a while since our last really damaging DDoS attack. We do leave all of the threads here on the forum so you're welcome to look into it.

View PostTotalZen, on 12 March 2011 - 06:33 PM, said:

It's probably the same site that's being targeted repeatedly, I would guess.

No - if you become the target of a DDoS you get moved to a Dedicated IP and you stay there - if you ARE repeatedly hit to the point that it's causing issues for our other customers we would have no choice but to ask you to move to a service where you wouldn't affect others such as a dedicated server.

The site that is under attack has just been identified and has never been attacked before in it's 2+ years of being hosted with us. We will be getting in contact with the site operator meanwhile everything should normalize for everybody else within the next few minutes.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#16 User is offline   TotalZen 

  • Newbie
  • Pip
  • Group: Clients
  • Posts: 21
  • Joined: 29-April 10
  • Gender:Male

Posted 12 March 2011 - 06:43 PM

View PostMikeDVB, on 12 March 2011 - 06:38 PM, said:

No - if you become the target of a DDoS you get moved to a Dedicated IP and you stay there - if you ARE repeatedly hit to the point that it's causing issues for our other customers we would have no choice but to ask you to move to a service where you wouldn't affect others such as a dedicated server.

The site that is under attack has just been identified and has never been attacked before in it's 2+ years of being hosted with us.


I see, good to know.
0

#17 User is offline   le.gentleman 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 3
  • Joined: 12-March 11

Posted 12 March 2011 - 06:44 PM

Thanks for working on it. DDoS attacks can happenbut you always recognize the problem right away and work on it. I really appreciate this kind of work ethic.

My URL is registered with 1and1 (I know they are far from good but so far I did never have issues with them).
Will I have to change the name server as well?
0

#18 User is offline   Scott S 

  • MDDHosting Staff
  • PipPip
  • Group: Staff Administrator
  • Posts: 139
  • Joined: 24-February 09
  • Gender:Male
  • Location:GMT-8:00

Posted 12 March 2011 - 06:48 PM

View Postle.gentleman, on 12 March 2011 - 06:44 PM, said:

My URL is registered with 1and1 (I know they are far from good but so far I did never have issues with them).
Will I have to change the name server as well?


If you're using our nameservers, you will not need to change anything. If you're using something other than our nameservers, such as CloudFlare or an external DNS server then yes, you will need to contact our support department for your new IP address.
Scott S. - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all services!
http://www.mddhosting.com/ - Follow us on Twitter! @MDDHosting
0

#19 User is offline   le.gentleman 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 3
  • Joined: 12-March 11

Posted 12 March 2011 - 06:52 PM

Thanks Mike, I am indeed on your nameservers :).
0

#20 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 12 March 2011 - 06:57 PM

View Postle.gentleman, on 12 March 2011 - 06:52 PM, said:

Thanks Mike, I am indeed on your nameservers :).

That was actually Scott that responded to you :)

Beyond that, everybody should be back online as we've moved the site under attack to it's own IP address and null routed that IP. If you are still having issues by all means do open a ticket so we can look specifically into your account.
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users