Saturday 24 December 2011

Unresponsive server. Hacked? Crashed? How do I tell what happened?

Unresponsive server. Hacked? Crashed? How do I tell what happened?

Hi, sorry if I'm a little "green,"

I've got an Amazon EC2 linux server. My website stopped responding. I tried to SSH in and also did not get a response. Amazon EC2 Management Console said it was still running fine. I could ping it, but web and ssh were not responding. I rebooted the instance and it came back up working fine.

I'm trying to look through the logs and I'm seeing nothing that helps. Amazon shows a single spike in disk read/write at 7am. My httpd access log showsa stop in file requests at 7am, but domain requests continued. I checked /var/log/secure and /var/log/messages and both don't have anything from 7am until I rebooted 3 hours later. It does show a ton of ssh failed attempts that stopped around 5am.

Is there somewhere else I should look? Is there a change I need to make in logging?

No comments:

Post a Comment