site under ddos and i'm not getting any support

Hello,

I’ve been directed to send emails to abuse team about the DDOS attack on one of my clients sites. Sent two emails - no replies.

I spoke via Live Chat to tech support - no clear answer on the next steps.

Called both phone numbers - no answer on toll-free, answering machine on the second one.

What do i do? Jodo took down the site since its under ddos, whats next?

Help please.

Aleks

I have already replied your ticket, please check our reply.

thank you!

again, should i just sit and wait or there are some steps i can take on my end to resolve this?

At this point, we can’t host your site. It is STILL being bombarded, I tried to be nice and bring it online and it still had attacks coming strong just as our staff told you.
I am trying to take it back offline now so that other clients won’t suffer.

Sorry but at this point I can’t afford to be ‘nice’ anymore, it is a major problem to host your site with its codebase and these attacks, as it takes the entire server basically down.

We tried moving the pool have blocked over 50 IPs and subnets from accessing, and still 100’s of IPs attacking.

We’ll gladly help you get the files and database, etc that you need but the site is under pretty heavy bombardment, even with the IP offline it was taking over 60,000 packets per second and 70mb/s in attacks being blocked. We null routed some to bring this down more, but such is not a valid final solution.

Stephen, thank you for more information and for trying to be ‘nice’.

So thats your policy? If i’m under attack (for no apparent reason), you just kick me out?
I’ve been a loyal customer for years and years, never missed a payment and had a minimal amount of support tickets in the past…

Can we try one more thing before i pack and move ALL my sites from your platform? I’m going to change the DNS records for the attacked domain so it doesnt point to jodohost, after that i would like to make one of the aliases a main entry domain - is that possible? Do you think it will help?

no it won’t help at all.

i am sorry for this but the ENTIRE server is down when I bring your IP online, it is not a matter of wanting to ‘kick you out’ it is, take the IP offline or every site on the shared server is down, I don’t have much choice here.
changign the DNs is just going to redirect the attack, not help the situation. if the attack gets sent to a shared IP on the server, we’ll be up a creek with it, as it is intensive attacks, and continues to grow as time goes on(when up)

This is never a move I like to take, but not left with many options on it.

There is one company that offers a ‘proxyshield premium’ that protects against this type of attack (it is not a flood in the normal sense, it is requests to your website in HUGE numbers every second, to default.asp), the protection for it STARTS at $1000 a month.

With the level of attacks seen yesterday, we’d have to be more costly than that to keep it online to be honest.

what i’m suggesting is that the main domain is not going to be pointed to Jodohost AT ALL, on the DNS level. (like it never existed).

I’ll just use one of the other domains to point to the site.

that will mean at least 24 hours down is still needed due to DNS cache pointing to the IP still…that is considering that this isn’t something personal(i really have no idea why anyone does DOS attack ever!) and they renew attacks on the new domain.

i just switched the DNS for the domain to default registrar nameservers. Lets see if it helps tomorrow.

In this current situation i can only imagine its a competition attack…

Thanks!

here’s what we can allow for now:
remove the alias (the hsphere cp controls will allow this)
add the alias as its own domain
set the new domain(old alias) to dedicated IP (will be new IP)

Send a ticket and we can copy the files from the attacked domain folder to the new domain folder.

I am going to be away starting in about 3 hours, but Tanmaya will be in, and other shift managers later, if the attacks continue on the alias domain moved to a domain, and new IP, we will have to take that down as well, but we cna hope and pray that won’t happen!

ok! i will start the process.

do you know the originator of the attack or since its a DDOS its not possible to find out?

Also, i would like to report the incident. Do i just file a report with local police station?

I have a very long list of IP addresses, but it just looks to me to be a botnet of infected PCs :frowning:

As for reporting it, I don’t know exactly what can be done without knowing for a fact what the source is, with these type of attacks that is behind the scene and ‘innocent’ peoples virii/trojan infected PCs are the ones doing the attacks.
I can’t post that IP list here publicly, but in ticket it can be done. I sent the top 30 or so attackers to Tanmaya so he has that, there are far more than that but the top 30 I worked to block first.