Portal Home > Knowledgebase > Industry Announcements > Web Hosting Main Forums > Providers and Network Outages and Updates > Underhost off all day due to DDOS


Underhost off all day due to DDOS




Posted by Uni1183, 02-19-2010, 10:07 PM
Underhost has been offline all day due to a DDOS attack.

They don't seem to have the ability to stop or adjust as needed.

underhost.us/forums/network-status/679-nl4-alpha-no-luck.html

Posted by gearworx, 02-19-2010, 10:11 PM
What's the concern here?

Posted by UnderHost, 02-19-2010, 10:14 PM
You are right, NL4 as been done since around 2H PM (EST)

We have more than one shared server, "UnderHost off all day due to DDOS" is a bit misleading. ( http://www.status.wehostyourdreams.com ) our network run fine.

We completely disabled the server since we received DDoS attack with peak to 500mbps it take around 1300GB bandwidth/hour , our datacenter work to mitigate this attack via console and keep the server offline until they are able to ban every offended IP from the networks.

We are not able with software firewall to mitigate 500+ mbps attack, your right! Our offshore datacenter can't offer hardware based firewall.

Welcome on WHT through, the forum are not a support forum if you have any question just contact us via ticket we are always around.

https://customerpanel.ca

Thank you for your cooperation!

Posted by MikeDVB, 02-19-2010, 11:10 PM
A DDoS attack that large would take just about any server at most providers offline - it's unfortunate but it does happen and I wouldn't fault the host for it any more than I'd fault the cashier at a store who got robbed and shot. Nobody wants to see it happen but when it does - it's not the cashier or the store's fault (or the host's)

Posted by UnderHost, 02-20-2010, 07:15 AM
Update: Thank you for your cooperation during this DDoS event, Ips has been blocked directly on our datacenter transit provider. It was an hard DDoS attack, When we powered off the server the DDos was hanging at the cisco router of our datacenter.

Everything goes well now, we are monitoring it closely because if the DDoS is coming back we need to take some actions again.

Thank You.

Posted by Uni1183, 02-22-2010, 02:39 PM
And it's down again.

Posted by MikeDVB, 02-22-2010, 04:25 PM
Quote:
Originally Posted by Uni1183
And it's down again.
It's a DDoS - downtime is the goal of the attacker. It can happen at any provider.

Posted by oliviakitty, 02-22-2010, 04:32 PM
Looks to be back up now...

Posted by UnderHost, 02-22-2010, 06:14 PM
Quote:
Originally Posted by oliviakitty
Looks to be back up now...
Yes, IP attacked has been null routed and we set a new main IP for this particular server.



Was this answer helpful?

Add to Favourites Add to Favourites    Print this Article Print this Article

Also Read
rethinkvps.com down? (Views: 1138)
VPS6? (Views: 939)

Language: