LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-02-2013, 03:33 PM   #1
dime111
LQ Newbie
 
Registered: Jan 2011
Posts: 29

Rep: Reputation: 0
Outgoing ddos problem


Hi,
We have little problem
We Have some cpanel hosting servers with about 600-700 account each
From time to time we receive report from our data center
That there has been outgoing attack from our server
So how may i find which client is doing this ?
tried Maldet from time to time also going to limit outgoing traffic in iptables
But is there anyway / package which can log the outgoing traffic based on Domain ?
All monitoring tools i know of works on layer 3 which wont help in our case
Thanks for your helps
 
Old 05-02-2013, 04:35 PM   #2
Kustom42
Senior Member
 
Registered: Mar 2012
Distribution: Red Hat
Posts: 1,604

Rep: Reputation: 415Reputation: 415Reputation: 415Reputation: 415Reputation: 415
Try doing a google search for:

tshark outgoing http requests

Wireshark can easily capture outgoing HTTP requests on the software level.
 
Old 05-02-2013, 04:36 PM   #3
Kustom42
Senior Member
 
Registered: Mar 2012
Distribution: Red Hat
Posts: 1,604

Rep: Reputation: 415Reputation: 415Reputation: 415Reputation: 415Reputation: 415
http://ask.wireshark.org/questions/2...g-http-traffic
 
Old 05-02-2013, 04:59 PM   #4
dime111
LQ Newbie
 
Registered: Jan 2011
Posts: 29

Original Poster
Rep: Reputation: 0
Thank
So its actually able to log which domain has sent the packets out ? yes ?
Im going to try it
 
Old 05-02-2013, 05:01 PM   #5
Kustom42
Senior Member
 
Registered: Mar 2012
Distribution: Red Hat
Posts: 1,604

Rep: Reputation: 415Reputation: 415Reputation: 415Reputation: 415Reputation: 415
It will only log the interface and the HTTP header. The domain isnt actually sending out the packet, if it has the domain in the header you will be able to see it but an http request is generated and sent via a network interface.

Look for a commonality in teh bad packets then you can drop that traffic regardless of what virtual host is generating it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Problem with outgoing connection nikosd Linux - Networking 3 07-27-2009 07:31 AM
Which qmail log file details outgoing mail? (have huge outgoing mail volume) hilljockey Linux - Server 2 12-08-2008 04:26 PM
Sendmail - outgoing mail problem helshylock Linux - Server 21 08-25-2008 07:52 AM
outgoing mail problem scheidel21 Linux - Networking 1 03-22-2003 02:02 PM
problem with outgoing ftp Thaas Linux - General 2 06-09-2002 03:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:59 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration