Hacker attack makes website offline


New Member

Suddenly my website was offline, but there was not a DDoS attack or anything, bandwidth and connection as fine. Tried to restart, didn't help.. couldn't access the admin port either. So I took a look at error.log and found this:

2011-07-29 17:16:19.469 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/login.htm]
2011-07-29 17:16:19.470 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/login.html]
2011-07-29 17:16:19.470 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/login/]
2011-07-29 17:16:19.659 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/login.php]
2011-07-29 17:16:19.660 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/login.asp]
2011-07-29 17:16:19.661 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/adm/]
2011-07-29 17:16:19.661 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/account.html]
2011-07-29 17:16:19.661 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/]
2011-07-29 17:16:19.799 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/login.html]
2011-07-29 17:16:19.800 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/login.htm]
2011-07-29 17:16:19.800 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/home.php]
2011-07-29 17:16:19.800 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/home.asp]
2011-07-29 17:16:19.800 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/controlpanel.html]
2011-07-29 17:16:19.905 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/controlpanel.htm]
2011-07-29 17:16:19.905 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/cp.php]
2011-07-29 17:16:19.908 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/cp.asp]
2011-07-29 17:16:19.908 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/adminLogin.html]
2011-07-29 17:16:22.912 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/adminLogin.htm]
2011-07-29 17:16:23.003 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/admin_login.php]
2011-07-29 17:16:23.003 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/admin_login.asp]
2011-07-29 17:16:23.010 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/controlpanel.php]
2011-07-29 17:16:23.019 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/controlpanel.asp]
2011-07-29 17:16:23.019 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/admin-login.php]
2011-07-29 17:16:23.123 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/admin-login.asp]
2011-07-29 17:16:23.123 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin-login.php]
2011-07-29 17:16:23.123 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin-login.asp]
2011-07-29 17:16:23.273 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/account.php]
2011-07-29 17:16:26.097 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/account.asp]
2011-07-29 17:16:26.117 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/admin.php]
2011-07-29 17:16:26.174 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin/admin.asp]
2011-07-29 17:16:26.227 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin.htm]
2011-07-29 17:16:26.233 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/admin.html]
2011-07-29 17:16:26.233 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/adminitem/]
2011-07-29 17:16:26.286 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/adminitem.php]
2011-07-29 17:16:26.307 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/adminitem.asp]
2011-07-29 17:16:26.327 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/adminitems/]
2011-07-29 17:16:26.353 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/adminitems.php]
2011-07-29 17:16:26.374 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/adminitems.asp]
2011-07-29 17:16:26.402 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/administrator/]
2011-07-29 17:16:26.421 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/administrator/login.php]
2011-07-29 17:16:26.428 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/administrator/login.asp]
2011-07-29 17:16:26.446 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/administrator.php]
2011-07-29 17:16:26.550 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/administrator.asp]
2011-07-29 17:16:26.550 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/administration/]
2011-07-29 17:16:26.553 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/administration.php]
2011-07-29 17:16:26.602 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/administration.asp]
2011-07-29 17:16:29.577 [INFO] [] File not found [/usr/local/lsws/DEFAULT/html/adminLogin/]
It also looks like this in error.log:
2011-07-29 17:28:15.504 [NOTICE] [] Content len: 0, Request line: 'GET / HTTP/1.1'
2011-07-29 17:28:15.504 [INFO] [] Cookie len: 131, mstnc=1; phpbb3_ewxo1_k=; PHPSESSID=g3s4u9qhv810uh5o2rn16bd1p2; phpbb3_ewxo1_u=1; phpbb3_ewxo1_sid=612f9be13f6aa9b69a8e99337baacf2c
2011-07-29 17:28:15.504 [INFO] [] HttpExtConnector state: 8, request body sent: 0, response body size: 0, response body sent:0, left in buffer: 0, attempts: 0.
2011-07-29 17:29:06.486 [INFO] [] Connection idle time: 31 while in state: 5 watching for event: 25,close!
2011-07-29 17:29:06.486 [NOTICE] [] Content len: 0, Request line: 'GET /index.php/character/view/ HTTP/1.1'
2011-07-29 17:29:06.486 [INFO] [] Cookie len: 37, PHPSESSID=n4lqfcijqvl02saq9pkcl4pga2;
2011-07-29 17:29:06.486 [INFO] [] HttpExtConnector state: 8, request body sent: 0, response body size: 0, response body sent:0, left in buffer: 0, attempts: 0.
2011-07-29 17:29:44.022 [INFO] [] Connection idle time: 31 while in state: 5 watching for event: 25,close!
2011-07-29 17:29:44.022 [NOTICE] [] Content len: 0, Request line: 'GET /index.php/character/view/Arthas HTTP/1.1'
2011-07-29 17:29:44.028 [INFO] [] HttpExtConnector state: 8, request body sent: 0, response body size: 0, response body sent:0, left in buffer: 0, attempts: 0.
This is just a few of the maaany lines that was spitting out there each second. I guess this is the reason why I can't reach my website.

Any ideas how I can block such attacks?

Thanks in advance!
Last edited:


New Member
Thanks for your reply,

I blocked in CSF at the time as saw this, but it didn't help... it ended about 5 minutes after I blocked it though, but don't know if that was thanks to CSF or because he stoped.

Anyways, I checked the link you gave me and this is the configurations I have (and had under the attack):
Connection Timeout (secs): 30
Keep-Alive Timeout (secs): 4
Max Keep-Alive Requests: 100
Max Request URL Length (bytes): 2048
Max Request Header Size (bytes): 4098
Max Request Body Size (bytes): 100M
Max Dynamic Response Header Size (bytes): 4K
Max Dynamic Response Body Size (bytes): 100M

Static Requests/second: 20
Dynamic Requests/second: 3
Outbound Bandwidth (bytes/sec): 2000K
Inbound Bandwidth (bytes/sec): 2000K
Connection Soft Limit: 7
Connection Hard Limit: 30
Grace Period (sec): 15
Banned Period (sec): 60

This is my website: w ww. z a nt e r a . n e t (without spaces ofc), it's a quite "normal" site that doesn't make very much heavy queries or so, just showing information collected from MySQL database mostly, and writing some as well.

Can anyone see any improvements I can make in my configurations?

Thanks in advance!