[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] Problem with Mem or DOS Attack?



Received an email from admin on the server that said

"The Cobalt server needs more memory than it currently has.  Consider adding
more DRAM to the server."
This email came in at 18:46

Then in the 1900 Logcheck email I found this.

Feb 17 18:42:28 servername kernel: Warning: possible SYN flood from
61.171.77.120 on my.ip.add.ress:443.  Sending cookies.
Feb 17 18:42:32 servername in.proftpd[2251]: warning: can't get client
address: Broken pipe
Feb 17 18:42:36 servername in.proftpd[2251]: connect from unknown
Feb 17 18:48:18 servername in.qpopper[2494]: warning: can't get client
address: Broken pipe
Feb 17 18:48:18 servername in.proftpd[2493]: warning: can't get client
address: Broken pipe
Feb 17 18:48:27 servername in.proftpd[2493]: connect from unknown
Feb 17 18:48:27 servername in.qpopper[2494]: connect from unknown
Feb 17 18:42:50 servername sendmail[2267]: NOQUEUE: Null connection from
root@localhost
Feb 17 18:48:55 servername sendmail[2495]: NOQUEUE: Null connection from
root@localhost


Entry into the server has not been made as far as I can tell. I have also
checked the web server logs and there was no spike in page requests or on
pages that have scripts to run.




Patrick Agee
maillist@xxxxxxxxxxxxxx