31102 - Possible DoS Consumption Attack

Customer support forums for Atomic Protector (formerly Atomic Secured Linux). There is no such thing as a bad question here as long as it pertains to using Atomic Protector. Newbies feel free to get help getting started or asking questions that may be obvious. Regular users are asked to be gentle. :-)
User avatar
CRServers
Forum User
Forum User
Posts: 54
Joined: Wed Jul 04, 2012 7:44 am
Location: Costa Rica

31102 - Possible DoS Consumption Attack

Unread post by CRServers »

We are getting lots of these every day now.
The strange thing is that it reports the "attacks" coming from IP 190.10.8.121 which is the server's own IP.

Code: Select all

[warn] ModSecurity: Access denied with code 400. Too many threads [11] of 10 allowed in READ state from 190.10.8.121 - Possible DoS Consumption Attack [Rejected
What is happening here?
Is this a false positive?
How can we get rid of these?

Thanks for your help.
Regards,

Rodrigo
Rodrigo Fernández
Image
http://www.crservers.com
prupert
Forum Regular
Forum Regular
Posts: 573
Joined: Tue Aug 01, 2006 2:45 pm
Location: Netherlands

Re: 31102 - Possible DoS Consumption Attack

Unread post by prupert »

Lemonbit Internet Dedicated Server Management
User avatar
CRServers
Forum User
Forum User
Posts: 54
Joined: Wed Jul 04, 2012 7:44 am
Location: Costa Rica

Re: 31102 - Possible DoS Consumption Attack

Unread post by CRServers »

Yes I did.
But why it is reporting attacks from the server's own IP.
What is going on?
That's the part I want to know.
Regards,
Rodrigo Fernández
Image
http://www.crservers.com
prupert
Forum Regular
Forum Regular
Posts: 573
Joined: Tue Aug 01, 2006 2:45 pm
Location: Netherlands

Re: 31102 - Possible DoS Consumption Attack

Unread post by prupert »

But why it is reporting attacks from the server's own IP.
This means that the requests are coming from your own server. This could be anything from a cron script to a web application that is doing internal HTTP requests. The ASL logs do not contain information as to which script this is doing, but you might be able to find the culprit in the access logs.

This is not a false positive, the rule is simply reporting that requests from your server are generating more than ten concurrent httpd processes busy in reading state. It is highly unlikely that this is acceptable behavior.
Lemonbit Internet Dedicated Server Management
Post Reply