Page 1 of 1

DDoS check ?

Posted: Fri Jul 31, 2009 3:49 pm
by momo61
What's the best way to check if someone is DDoS'ing your server on Windows Server 2003 ?

:lol:

Re: DDoS check ?

Posted: Fri Jul 31, 2009 10:08 pm
by MELERIX
checking active connections.

Re: DDoS check ?

Posted: Sat Aug 01, 2009 12:10 am
by ThePhoenixBird
Check IIS/Apache logs and see connections if you see several connections from the same IP that would be a attacker machine.

Normally DDoS uses thousands of computers making attacks

Re: DDoS check ?

Posted: Sat Aug 01, 2009 3:21 pm
by momo61
ThePhoenixBird wrote:Check IIS/Apache logs and see connections if you see several connections from the same IP that would be a attacker machine.

Normally DDoS uses thousands of computers making attacks
ok. since there was this guy who was somehow lagging the server. I thought it was DDoS first, but apparently he used PHX in some way.

Re: DDoS check ?

Posted: Sat Aug 01, 2009 4:41 pm
by toastgodsupreme
momo61 wrote:
ThePhoenixBird wrote:Check IIS/Apache logs and see connections if you see several connections from the same IP that would be a attacker machine.

Normally DDoS uses thousands of computers making attacks
ok. since there was this guy who was somehow lagging the server. I thought it was DDoS first, but apparently he used PHX in some way.
There's a number of ways to do it with phx. Item drop, item delete, and I'm sure a few ways I don't know yet.

Re: DDoS check ?

Posted: Sun Aug 02, 2009 10:25 am
by momo61
toastgodsupreme wrote:
momo61 wrote:
ThePhoenixBird wrote:Check IIS/Apache logs and see connections if you see several connections from the same IP that would be a attacker machine.

Normally DDoS uses thousands of computers making attacks
ok. since there was this guy who was somehow lagging the server. I thought it was DDoS first, but apparently he used PHX in some way.
There's a number of ways to do it with phx. Item drop, item delete, and I'm sure a few ways I don't know yet.
Subclass changing (good thing i activated subclass flood protector)

it's redoncilous ^^ (redicilous)