Discussion in 'H-Sphere Shared Hosting' started by brawney, May 12, 2004.

    When I checked about 8:00am EST everything was down here at JH. No email (web, pop3, imap, smtp, nothing), no control panel, no forums, no jodohost home page. Nothing. Like they vanished off the face of the earth.

    About 9:30am EST everything came back. Any ideas on this one?
    Check the Announcements forum, there was a Denial of Service (DOS) attack against win6.

    Yash, do you know whether the attack was directed at the server or at a particular site on the server?
    I just saw that. I checked there first and didn't see anything. Yas posted it about the same time I was making my post. ;)
    but this wasn't just win6 - I'm on win5. this was not connected to yesterdays problems then?
    It was against Win6's shared IP addresses.

    This is the most massive attack ive ever seen
    What concerns me is that these types are attacks are always targeted, they are not the result of random choices of IP addresses. So I guess what I would like to know (which is something you probably can never answer) is was the attacked directed at JH or at a customer of JH.
    I can't say if it was against a customer of us, or ourselves.
    Impossible. My best would be a customer since it was just win6. But they probably could be just focusing the entire attack on win6 to make the outcome more succesful

    We will be taking all possible legal remedies
    but how does that explain my website being down on win5? sorry if i'm being ignorant here ?(
    The attack was so massive, upto 1.2gbps that our main router was overwhelmed. As a result, our entire network was down.
    OK - thanks for the explanation.

    Yash - why has my thread asking for an update on yesterdays win5 problem been deleted??? all i wanted to know was whether it had been completely resolved. it was bad enough for atul to consider setting up a temporary backup server!!
    I'm very sorry, I thought that thread was asking why Win5 was down (related to this DDOS incident) therefore I deleted

    Win5's problem is completely resolved. All we had to do was run a scandisk
    Has the DOS attack stopped? I still can not access my site on win6.
    No, the attack is still going on. To get the network back up, Level3 has temporarily disable Win6's shared IP till we can cut the attack

    And we are working on that.. we should have win6 back upsoon
    Thanks Yash,

    When you find out who has done this can you make it public? I think a simple stoning should make the person responsible think twice about doing this again.

    I can't understand the misuse of talent!
    Yes, I will. We won't be letting this person off the hook by any chance
    I'm sure the attacker is visiting our forum from time to time :)
    I think I lost mail messages as well. I usually send a test message from another host when I see that the mail servers are down. This is the first time I saw that the test message I sent was lost. I wonder how many actual customer messages I lost:)
    Amazing, I have lost another day of work due to my site being down for most of the day (GMT +2)

    Someone give me this person's home address and I have them delt with.

    This kind of attack is so bad!
    It will probably arrive, eventually. During the DOS the server was inaccessible, so your other host puts the mail on hold for a certain amount of time before trying again. If retries keep failing, you will get a message that the mailserver has given up retrying.

