<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Computer Solutions Blog &#187; Service Issues</title>
	<atom:link href="http://www.computersolutions.cn/blog/category/service-issues/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.computersolutions.cn/blog</link>
	<description>Whats happening at Computer Solutions</description>
	<lastBuildDate>Fri, 13 Jan 2012 02:32:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Outgoing TLS port Denial of Service &#8211; Fixed</title>
		<link>http://www.computersolutions.cn/blog/2010/01/outgoing-tls-port-denial-of-service-fixed/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=outgoing-tls-port-denial-of-service-fixed</link>
		<comments>http://www.computersolutions.cn/blog/2010/01/outgoing-tls-port-denial-of-service-fixed/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 08:24:17 +0000</pubDate>
		<dc:creator>Lawrence Sheed</dc:creator>
				<category><![CDATA[Service Issues]]></category>
		<category><![CDATA[Technical Mumbo Jumbo]]></category>

		<guid isPermaLink="false">http://www.computersolutions.cn/blog/?p=330</guid>
		<description><![CDATA[Noticed that our incoming TLS connection queue was a little high &#8211; running at 60 concurrent connections for an hour or so. A check of the queue revealed that all the connections were coming from a single IP &#8211; and were tying up the queue, making it a denial of service attack. This one ip [...]]]></description>
			<content:encoded><![CDATA[<p>Noticed that our incoming TLS connection queue was a little high &#8211; running at 60 concurrent connections for an hour or so.</p>
<p>A check of the queue revealed that all the connections were coming from a single IP &#8211; and were tying up the queue, making it a denial of service attack.  This one ip address was connecting and reconnecting multiple times, hogging up all the connections.<br />
<span id="more-330"></span><br />
I&#8217;ve blocked that ip address, and restarted the TLS service, its back at normal levels now.</p>
<p>For the interested &#8211; </p>
<p><strong>Connections:</strong></p>
<blockquote><p>mail:/var/log/qmail/qmail-tls# netstat -an &#8211;numeric-ports | grep 587 | grep 58.246.24.242<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:24384     ESTABLISHED<br />
tcp        1      0 61.129.49.190:587       58.246.24.242:39581     CLOSE_WAIT<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:11625     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:42614     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:46630     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:20802     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:51956     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:4463      ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:39878     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:43678     ESTABLISHED<br />
tcp        1      0 61.129.49.190:587       58.246.24.242:39181     CLOSE_WAIT<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:62054     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:64421     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:24326     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:58740     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:25779     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:50209     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:41358     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:32383     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:27925     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:46540     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:7049      ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:13999     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:62962     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:19771     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:43604     ESTABLISHED<br />
tcp        1      0 61.129.49.190:587       58.246.24.242:38757     CLOSE_WAIT<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:39909     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:30470     ESTABLISHED<br />
tcp        1      0 61.129.49.190:587       58.246.24.242:39754     CLOSE_WAIT<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:61393     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:52072     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:22294     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:60398     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:60530     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:36049     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:1426      ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:40190     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:15402     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:23457     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:65187     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:39910     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:23181     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:3286      ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:40540     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:12957     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:39829     ESTABLISHED<br />
tcp        0      0 61.129.49.190:587       58.246.24.242:19748     ESTABLISHED</p></blockquote>
<p><strong>IP Owner:</strong></p>
<blockquote><p>mail:/var/log/qmail/qmail-tls# whois 58.246.24.242</p>
<p>% [whois.apnic.net node-2]<br />
% Whois data copyright terms    http://www.apnic.net/db/dbcopyright.html</p>
<p>inetnum:      58.246.24.240 &#8211; 58.246.24.247<br />
netname:      SH-Ribeira<br />
country:      cn<br />
descr:        Ribeira (Shanghai) Business Consulting Co., Ltd.<br />
admin-c:      YR194-AP<br />
tech-c:       YR194-AP<br />
status:       ASSIGNED NON-PORTABLE<br />
changed:      sh-ipmaster@chinaunicom.cn 20081125<br />
mnt-by:       MAINT-CNCGROUP-SH<br />
source:       APNIC</p></blockquote>
<p>I&#8217;ve sent a note to China Unicom, but don&#8217;t expect any reply.   A google of Ribiera Shanghai doesn&#8217;t reveal any obvious people to complain to either.   </p>
<p>Yet another instance where I should put some active logging into the server to notify me when queue / connection sizes stay at high levels&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computersolutions.cn/blog/2010/01/outgoing-tls-port-denial-of-service-fixed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another outage!</title>
		<link>http://www.computersolutions.cn/blog/2009/12/another-outage/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=another-outage</link>
		<comments>http://www.computersolutions.cn/blog/2009/12/another-outage/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 15:23:10 +0000</pubDate>
		<dc:creator>Lawrence Sheed</dc:creator>
				<category><![CDATA[Service Issues]]></category>
		<category><![CDATA[Technical Mumbo Jumbo]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[outage]]></category>
		<category><![CDATA[shanghai telecom]]></category>
		<category><![CDATA[traffic logs]]></category>

		<guid isPermaLink="false">http://www.computersolutions.cn/blog/?p=290</guid>
		<description><![CDATA[Seems that when it rains, it pours. The gods were not content to give us only one issue today from an external provider, but two! At approximately 7pm the network that includes our mail server was on got hit by a massive denial of service attack. The nice people at Shanghai Telecom decided that they [...]]]></description>
			<content:encoded><![CDATA[<p>Seems that when it rains, it pours.</p>
<p>The gods were not content to give us only one issue today from an external provider, but two!</p>
<p>At approximately 7pm the network that includes our mail server was on got hit by a massive denial of service attack.<br />
The nice people at Shanghai Telecom decided that they would simply shut off routing for the entire subnet as their optimal solution.</p>
<p>We have a nice graph of that happening here:</p>
<p><a href="http://www.computersolutions.cn/blog/wp-content/uploads/2009/12/net01.day_.png"><img class="size-full wp-image-292 alignnone" title="net01.day" src="http://www.computersolutions.cn/blog/wp-content/uploads/2009/12/net01.day_.png" alt="net01.day" width="547" height="270" /></a></p>
<p>Note the sudden precipitous drop in network traffic starting at approximately 7pm, which lasted until approximately 8pm.</p>
<p>We also have images of the DoS attack [although not completely, as our network was null routed (shut off) for the brunt of the attack]</p>
<p>You can see the sudden increase in incoming traffic in this image below (which occurred before they killed the network completely).<br />
The green line which indicates incoming packets suddenly goes sky high before the network people shut off the network.</p>
<p><a href="http://www.computersolutions.cn/blog/wp-content/uploads/2009/12/net02z.day_.png"><img class="size-full wp-image-293 alignnone" title="net02z.day" src="http://www.computersolutions.cn/blog/wp-content/uploads/2009/12/net02z.day_.png" alt="net02z.day" width="547" height="270" /></a></p>
<p>Some of the other servers also got hit by this &#8211; notable our web servers, although they didn&#8217;t cut those off thankfully.<br />
See below for a view of that traffic.</p>
<p><a href="http://www.computersolutions.cn/blog/wp-content/uploads/2009/12/net02z.88.213.day_.png"><img class="alignnone size-full wp-image-294" title="net02z.88.213.day" src="http://www.computersolutions.cn/blog/wp-content/uploads/2009/12/net02z.88.213.day_.png" alt="net02z.88.213.day" width="547" height="270" /></a></p>
<p>As the old curse goes &#8211; may you live in interesting times.<br />
Some days are more interesting than others!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computersolutions.cn/blog/2009/12/another-outage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Outage Issues Resolved (April 16th)</title>
		<link>http://www.computersolutions.cn/blog/2009/04/system-outage-issues-resolved-april-16th/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=system-outage-issues-resolved-april-16th</link>
		<comments>http://www.computersolutions.cn/blog/2009/04/system-outage-issues-resolved-april-16th/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 09:37:31 +0000</pubDate>
		<dc:creator>Lawrence Sheed</dc:creator>
				<category><![CDATA[Service Issues]]></category>
		<category><![CDATA[china telecom]]></category>
		<category><![CDATA[morons]]></category>

		<guid isPermaLink="false">http://www.computersolutions.cn/blog/?p=218</guid>
		<description><![CDATA[From 12:00 &#8211; 2:40pm today Shanghai Telecom was experiencing router problems for servers in the 61.129.88.xx address space in the data centre at WuSheng Lu (the main Shanghai Telecom building). This affected 3 of our servers, and one of our clients managed servers. Shanghai Telecoms official response below: 武胜机房托管了服务器61.129.88段在4月16日12:00-14:00出现无法访问连接，经检查该段均出现该种情况。我们公司技术向电信反映该情况后，经电信查看是由于该段中有主机发送广播包导致路由中毒（环路）而造成的，经过紧急的抢修最终恢复正常。此次给贵公司的日常运作带来很多不便，在此深表歉意。 Unfortunately once they had resolved their [...]]]></description>
			<content:encoded><![CDATA[<p>From 12:00 &#8211; 2:40pm today Shanghai Telecom was experiencing router problems for servers in the 61.129.88.xx address space in the data centre at WuSheng Lu (the main Shanghai Telecom building).<br />
This affected 3 of our servers, and one of our clients managed servers.</p>
<p>Shanghai Telecoms official response below:</p>
<p>武胜机房托管了服务器61.129.88段在4月16日12:00-14:00出现无法访问连接，经检查该段均出现该种情况。我们公司技术向电信反映该情况后，经电信查看是由于该段中有主机发送广播包导致路由中毒（环路）而造成的，经过紧急的抢修最终恢复正常。此次给贵公司的日常运作带来很多不便，在此深表歉意。</p>
<p>Unfortunately once they had resolved their router issues, at around 3pm,  Shanghai Telecom decided to create some new ones, by arbitrarily rebooting all the servers in that address space.<br />
Due to their actions, on reboot, our database server could not fully mount the data partition, and so a number of our client websites were unaccessible, as was our webmail service.</p>
<p>Repairing the damage caused by Shanghai Telecoms actions took around 2 1/2 hours.</p>
<p>Full services resumed at approximately 5:20pm</p>
<p>All services are currently running smoothly, although we do have some reports of connectivity issues from some clients.<br />
If you are still unable to connect to the mail server, please turn off your ADSL modem or Router, and log onto the internet again.<br />
(This will clear any route issues  in your router, and you should be able to connect successfully.)</p>
<p>Apologies for the inconvenience.</p>
<p>Lawrence.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.computersolutions.cn/blog/2009/04/system-outage-issues-resolved-april-16th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

