dogfrog4/doc potential slow http attack

by WDGF on April 12, 2013

It’s likely dogfrog4 has been undergoing a “slow http” attack (sometimes known as the “slowloris attack” after one of the tools that does it).

We’ve spent quite a bit of time overnight recompiling the web server to add mitigation for this; the mitigation involves timing out requests and banning IPs that are generating slow attacks.

The symptoms we were experiencing yesterday were consistent with a slow http attack – webserver stops responding, load average low, occasional response from webserver, restart fixes the problem, etc.

We’re keeping a careful eye on the situation.

{ Comments on this entry are closed }

Last night an upgrade to cPanel on several of our servers caused the automatic creation of Auto-discover records throughout all sites hosted on these servers.

These Auto-discover records were created regardless of whether the sites email is hosted with us or  hosted externally (Google Apps/Exchange); this caused pop-up messages to display to clients accessing email through our server asking them to update their email clients settings using the Auto-discover record, breaking their email.

We have rolled back these settings on one of our servers (dogfrog4/doc) to what they were set to before the upgrade and will roll back the settings on the other servers shortly; in the meantime we ask that all people still getting this message click on the ‘No” option and refuse to get there settings from the Auto-discover record.

{ Comments on this entry are closed }

Snuppy/dogfrog5 upgrade over Friday 18th Jan evening

January 18, 2013

This weekend, we’ll be replacing Snuppy / dogfrog5, one of our Australian servers, with newer, more powerful hardware. While we are going out of our way to make this move invisible to you in every way, it’s possible that you may have temporary problems accessing your site on the morning after the move.  This note [...]

Read the full article →

Aussie servers move to new datacentre 11pm-3am

December 11, 2012

Overnight tonight, during the period from 11pm to about 3am, we are moving our Australian servers from one datacentre to another. The new datacentre, Global Switch in Sydney, is known as a top tier datacentre. [Late Addition: dogfrog6.net is being moved tonight (18 Dec) from 11pm to 2am. Apologies for the interruption to service.] We [...]

Read the full article →

Dogfrog5.net email delay back; investigating, will update ASAP.

August 15, 2012

The email delay that we had two days ago is back;  many new emails are getting through immediately but emails sent earlier in the day are facing up to 2 hours delay. We’re looking into this; it looks like we’ve been hit with a huge amount of spam.  We’ll continue to monitor and watch this [...]

Read the full article →

Dogfrog5.net email delay (approx 20 – 30 min)

August 13, 2012

Currently have a slight delay on email delivery on Snuppy (around 20 to 30 minutes approximately) due to high mail queues. Update: Managed to get this under control late Monday night.

Read the full article →

Dogfrog5.net outage Sunday morning approx 6:45 – 9:30

August 11, 2012

Dogfrog5 suffered some down time this morning due to a disk I/O problem which caused the main disk to go into lockdown (read-only) mode. The server is up now and we’re keeping a careful eye on it. Apologies to anyone who was inconvenienced. During the period the server was down, email will have been delayed. [...]

Read the full article →

Doc (Dogfrog4.net) back up!

May 7, 2012

Websites and email should now be back up! It appears to have been effectively a minor, script based, Denial of Service attack. We are watching the server closely to prevent a repeat of the incident. Apologies to all affected.

Read the full article →

Doc (Dogfrog4.net) update

May 7, 2012

Techs currently working on issue, websites may be up and down for a short period but other services such as mail should be up and running.

Read the full article →

Doc (Dogfrog4.net) down

May 7, 2012

Dogfrog4.net is not responding to reboot or networks requests. We’re having technicians at the data center look at the issue now. Apologies for any inconveniences this has caused you.

Read the full article →