Puzzling Download Attack on my Celestia Server
Posted: 25.05.2007, 15:44
Hi to all,
Yesterday between 6:00 UTC and 8:00 UTC someone caused about 10 GBytes of traffic on my Celestia Download Server. This is a bit weird, because the biggest Addon Collection I host is about 35 MBytes, and all hosted files together sum up to about 180 MBytes. I've set a monthly traffic limit of 5 GBytes to this server which is fairly enough, because the usual monthly traffic for Celestia downloads is about 2-4 GBytes. Due to the limit my server complained and thus brought the whole thing to my attention.
My investigation hat the following results:
- All traffic was caused by one adress: 203.156.213.126
- All traffic was caused on 2007-05-24 6:05 UTC - 7:45 UTC
- This adress could not be resolved to a domain name.
- whois listet the following owner for the adress:
ShangHai Global Network Co.Ltd
F4, No.1465, West Beijing Road,
Shanghai, 200040, China
- Most of my hosted files had been downloaded up to 50 times from that adress.
- Download start times where within seconds for one single filename.
- The used OS and webclient were identified as: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98 )
I wouldn't post this, if a similar incident hadn't took place last month, when about 7 GBytes of traffic where requested from a single adress in Shanghai. So my questions are:
Has anyone of you observed similar events on his server traffic, or am I the only one? Is this a peak caused by a certain publication about Celestia, are these dumb kids or is this a real attack?
Thanks in advance for your answers.
maxim
Yesterday between 6:00 UTC and 8:00 UTC someone caused about 10 GBytes of traffic on my Celestia Download Server. This is a bit weird, because the biggest Addon Collection I host is about 35 MBytes, and all hosted files together sum up to about 180 MBytes. I've set a monthly traffic limit of 5 GBytes to this server which is fairly enough, because the usual monthly traffic for Celestia downloads is about 2-4 GBytes. Due to the limit my server complained and thus brought the whole thing to my attention.
My investigation hat the following results:
- All traffic was caused by one adress: 203.156.213.126
- All traffic was caused on 2007-05-24 6:05 UTC - 7:45 UTC
- This adress could not be resolved to a domain name.
- whois listet the following owner for the adress:
ShangHai Global Network Co.Ltd
F4, No.1465, West Beijing Road,
Shanghai, 200040, China
- Most of my hosted files had been downloaded up to 50 times from that adress.
- Download start times where within seconds for one single filename.
- The used OS and webclient were identified as: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98 )
I wouldn't post this, if a similar incident hadn't took place last month, when about 7 GBytes of traffic where requested from a single adress in Shanghai. So my questions are:
Has anyone of you observed similar events on his server traffic, or am I the only one? Is this a peak caused by a certain publication about Celestia, are these dumb kids or is this a real attack?
Thanks in advance for your answers.
maxim