Fructis is a multi-site (and multi-software) VM (Xen) with 2 cores and like 6G of RAM.
It hosts popular Drupal and Wordpress websites and is currently getting hammered. I will put all details below.
I've been blocking IPs but there appears to be a VERY aggressive bot network and mostly changes IPs faster than I can block them
I've updated Drupal but all the Wordpress sites aren't necessarily managed by me.
I've enabled logs for TS but they don't seem to be helping
Perhaps the answer is understanding what kinds of bot attacks are common lately/now? To that end, http://www.webmasterworld.com/home.htm may have helpful information
Details:
root@fructis:/home/nrogara# w
09:28:05 up 10 days, 1:55, 2 users, load average: 31.10, 30.61, 32.31
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
nrogara pts/0 c-24-7-67-188.hs Wed13 1:01m 0.18s 0.00s sshd:
nrogara [priv]
nrogara pts/1 142-254-1-80.dsl 09:00 5.00s 0.06s 0.01s sshd:
nrogara [priv]
root@fructis:/home/nrogara# !net
netstat -tn 2>/dev/null | grep :80 | awk '{print $5}' | cut -d: -f1 |
sort | uniq -c | sort -nr | head
12 72.37.249.84
12 162.243.193.98
7 91.207.5.157
7 74.73.126.40
4 184.73.22.102
3 94.102.49.35
3 199.255.208.91
3 195.211.154.155
3 174.21.231.10
3 108.62.154.15
(again 2 minutes later)
root@fructis:/home/nrogara# netstat -tn 2>/dev/null | grep :80 | awk
'{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr | head
10 95.26.128.85
6 67.170.85.225
5 195.2.240.106
4 24.7.67.188
4 216.246.184.159
3 206.51.125.66
2 91.122.6.86
2 79.143.187.214
2 72.46.156.116
2 50.115.172.177