Form Submission: Webhosting Support Request

ogah

New member
cPanel User Name: ddlgen
Name of Domain: ddlgen.net
Detailed Description: someone with IP 173.245.49.209 doing DDOS attack to my website.
and my website go down.

Additional Information: Not answered
 

Genesis

Administrator
Staff member
Ogah. I can't see an attack. But you have an error going on that has to do with WordPress. Do you know what it could be?
 

Genesis

Administrator
Staff member
OK, I've had a better look and reading through the errors it looks as though you have a script/s that is using more memory than what is allocated for in the configuration. It could be due to a misconfiguration or a conflict. Have you worked on any of the plug-ins recently before the problem occurred - maybe on 10 July - as the errors started on 10th July - last Thursday?
 

Genesis

Administrator
Staff member
This is just a theory and subject to confirmation by Chris (DJB). I notice Bidvertiser was loaded in your cPanel on 10 July, which corresponds with the date of the first entry in your error log. It could be that you didn't load the Bidvertiser script and that it came with a plug-in that you loaded on 10 July.

If you Google Bidvertiser it has known issues with malware - here is just one of the reports I picked up as I was researching Bidvertiser:

We have also used "Bidvertiser" for our adverts on our site - this added a number of regular adverts to our website, most of which were completely inappropriate for our content (most people don't want naked ladies on their screens when viewing technical websites at work!) and from what has been reported to us, tried to hack visitors browser settings and add malware to their machines - for this, we can only apologise - as soon as we were made aware of how big an issue this was, we removed all adverts using Bidvertiser from our website. - See more at: http://www.techygeekshome.co.uk/2014_05_01_archive.html#sthash.pWDNtKnr.dpuf
Source: http://www.techygeekshome.co.uk/2014_05_01_archive.html (Date: 11 May 2014)
 

ogah

New member
at 10th july i change my wp themes and make a litle change in my plugins.
but my site still work fine until yesterday.
i look at last visitor at cpanel and found ubnormal activity from visitor with IP 173.245.49.209
 

ogah

New member
oh...
yes, i use xml bidvertiser and scarp it as direct link.
ok, i will delete the bidveriser script from my plugins.


how about the abnormal visitor?
yesterday i see at latest visitor the report full with that ip


oh sorry
i have check 173.245.49.209 and found this is an ip from cloudflare.
i will inspect my plugin
 

Genesis

Administrator
Staff member
I'm almost certain it is a plug-in or theme issue. Related to the work you did on 10 July. Why not check the WP reviews of the theme you loaded to see whether there are known issues - ditto the plug-ins.

Alternatively if it really gives you too many headaches, if you've got a back-up that pre-dates 10 July, get rid of the 10 July new version, and start from scratch with the back-up.
 

ogah

New member
sadly backup in my hardisc is overwriten by the new script :(
i have re edit my plugins.
but i can not change back my themes (from wp admin) until my site up runing.
 

Genesis

Administrator
Staff member
I'm beginning to think this is more of a Cloudflare problem Ogah. Haven't we had this before in another thread - Cloudflare issues?
 

admin

Administrator
Staff member
My suggestion would be to apply for the double everything package, that will double your account server resources.
 

ogah

New member
normaly my website not use big resorce.
i see from Resource Usage in my cpanel, abnormal usage start at 15 july 13:00

i forget, i have visitor loger.
you can see the last visitor activity, at my file tipak.txt.
i design my loger script resetting the logs file if 200 records reached.
 

Genesis

Administrator
Staff member
@Ogah. It's not just a case of bandwidth and space but of memory. When you are on a shared server then it is logical that the server would be set up in such a way that it would limit you on the memory that you may use, otherwise the shared memory will be exhausted pretty soon for every one else. Your scripts are so complicated in the way they work with one another that they are using much more memory than they should be using. For example, having Cloudflare activated made it worse as Cloudflare has been set up to fight with scripts that it thinks are a security risk. So that may be the reason it went in a loop to the extent it looked like you were being ddosed by its IP. And of course that looping exhausted your memory on a free shared server.

If you want to continue this way then you need to follow DJB's advice and get the maximum memory you can find.

I've put in a few hours tonight trying to figure out a way to remove the 500 error but obviously I can't. If it could have been done, DJB would have done it for you. So looks as though you may need to start from scratch. You have two choices. Get more memory, or if you want to stay with free space, I suggest you make a full backup of all of your files, and export your database. I'll then delete your hosting account and recreate it again so you start completely fresh.

I'd get rid of cloudflare for sure as I've picked up in my researches there are many users like you with scripts that land into problems with cloudflare. Cloudflare wants simple for it to work effectively and may detect security risks in the scripts, and it then acts in a way that creates a memory drain for you. I'd also keep my WP design simple. Read all of the reviews in each theme and plugin very carefully before I install them, as it is easy to pick up on whether a plug-in is unstable by just doing research of other people's experiences before you install it.
 

ogah

New member
how about this IP 195.154.8.92 the hostname is 195-154-8-92.rev.poneytelecom.eu
i have check this belonging Free SAS ISP, not cloudflare IP.
i get this IP from my visitor logger script.

OK Genesis, please recreate my account

thanks
 

GigaGreg

Moderator
Staff member
If you want double everything ogah, then you need to send 200 points to the user called bank and wait for the account upgrade.

There is no actual understanding why someone would have a free isp and would access Internet with it as the connection would be very limited as everything what is free is limited.
 

Genesis

Administrator
Staff member
I've recreated the standard free package for you Ogah. Check hosting details in PM in your Inbox.

If you want to make it double everything, please deposit 100 points into the bank and let me know when you have done so.
:smile: