Monday, December 08, 2008

Denial of Service Attack

The interesting things happening with the Board just keep on growing. For anyone trying to use the Board today (Monday) around 5:30 you may have seen the Board start serving up "Technical Difficulties" pages for a bit, and then go down. The part where it went down completely was me, trying to keep the server alive while I did troubleshooting.

The immediate problem was an incredible number of apache processes chewing up all the database connections. The cause of the issue was a certain IP address requesting the main page about 3 times a second for an hour or so. The server didn't really like that too much. Once I discovered this I blocked the IP address and brought the server back up. After another 15 minutes of getting HTTP 403 errors sent back to them the IP address stopped requesting pages. Now, whether intentional or not the result of this process is known as a Denial of Service (DOS) attack. So named because, as you may have discovered, when it's occurring the legitimate users, such as yourself, cannot access the content of the website.

I'll keep an eye on the situation and continue to slave away to make sure the Board stays alive for your viewing pleasure.

My current hypothesis on the matter is that the attackers that accessed the server last month are retaliating for me locking them out. But that's just a theory.

2 comments:

Charly said...

The Internet on BYU campus in general was being absurdly slow for me today. I wonder if that compounded the problem.

Eliza said...

I still just don't want to understand who would want to break into the board anyway...

Is there some appeal that I'm not seeing here?