bout 15 sites are being effected by a problem on win15 with one asp.net pool
I am working to find some bad code on one site that is cause a 1MB log file to be generated every 10 seconds on the C drive of the server, this is among the fastest log file generations I have ever seen, and I am working on it right now.
Wow, so many requests, I have the server mostly under control, but some ASP.NET is disabled right now as it is making the server unusable with so many requests!
We are now taking the difficult approach of blocking each IP individually at the router level. We plan to also forward the IP list to our Internet provider to block upstream
I just added a large number of dedicated IPs to Win15, so you can switch over to them if you need. We are very sorry about this matter, but to stop the DDoS attack we must unbind the shared IP.
We have over 80 IPs blocked right now, and still some being blocked, but the shared ip sites have been up and running pretty well all things considered.
We have the DDoS down to 2mb or less now, and the target site DNS is now redirected back to the attacks, so when they attack the site it comes back to them, only those working on cached DNs will still be hitting the site.
I think we have all IPs that were DDoSing blocked or otherwise stopped with the DNS change “going live”
If by any chance on of these IPs was yours or a customers and we were incorrect in blocking it, please send a ticket and we will evaulate the logs and unlist if the said IP was not at fault.