i'm under DOS attack right now, need help

Hello,
my server is under DOS attack for the last 2 hours, actually web (port 80) is attacked, I suspect it it some kind of automated attack , I'm under attack from houndreds of IPs. Here is Apache server status taken from WHM just after apache restart:

Current Time: Monday, 01-Aug-2005 23:05:44 EDT
Restart Time: Monday, 01-Aug-2005 23:05:26 EDT
Parent Server Generation: 2
Server uptime: 18 seconds
Total accesses: 16 - Total Traffic: 8 kB
CPU Usage: u.11 s.22 cu.09 cs.07 - 2.72% CPU load
.889 requests/sec - 455 B/second - 512 B/request
147 requests currently being processed, 0 idle servers
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRWS.............................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................
................................................................

Scoreboard Key:
"_" Waiting for Connection, "S" Starting up, "R" Reading Request,
"W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup,
"L" Logging, "G" Gracefully finishing, "." Open slot with no current process


Srv PID Acc M CPU SS Req Conn Child Slot Host VHost Request
0-2 9320 0/1/1 R 0.03 10 126 0.0 0.000 0.000 ? ? ..reading..
1-2 9321 0/0/0 R 0.00 10 0 0.0 0.00 0.00 ? ? ..reading..
2-2 9323 0/1/1 R 0.02 10 194 0.0 0.00 0.00 ? ? ..reading..
3-2 9324 0/1/1 R 0.03 10 133 0.0 0.000 0.000 ? ? ..reading..
4-2 9326 0/1/1 R 0.03 10 121 0.0 0.000 0.000 ? ? ..reading..
5-2 9332 0/0/0 R 0.00 9 0 0.0 0.00 0.00 ? ? ..reading..
6-2 9339 0/0/0 R 0.00 8 0 0.0 0.00 0.00 ? ? ..reading..
7-2 9340 0/0/0 R 0.00 8 0 0.0 0.00 0.00 ? ? ..reading..
8-2 9361 0/0/0 R 0.00 7 0 0.0 0.00 0.00 ? ? ..reading..
9-2 9363 0/0/0 R 0.00 7 0 0.0 0.00 0.00 ? ? ..reading..
10-2 9364 0/1/1 R 0.01 7 1 0.0 0.00 0.00 ? ? ..reading..
11-2 9365 0/0/0 R 0.00 7 0 0.0 0.00 0.00 ? ? ..reading..
12-2 9370 0/0/0 R 0.00 6 0 0.0 0.00 0.00 ? ? ..reading..
13-2 9371 0/0/0 R 0.00 6 0 0.0 0.00 0.00 ? ? ..reading..
14-2 9372 0/0/0 R 0.00 6 0 0.0 0.00 0.00 ? ? ..reading..
15-2 9373 0/0/0 R 0.00 6 0 0.0 0.00 0.00 ? ? ..reading..
16-2 9374 0/0/0 R 0.00 6 0 0.0 0.00 0.00 ? ? ..reading..
17-2 9375 0/1/1 R 0.01 6 1 0.0 0.00 0.00 ? ? ..reading..
18-2 9376 0/0/0 R 0.00 6 0 0.0 0.00 0.00 ? ? ..reading..
19-2 9377 0/0/0 R 0.00 6 0 0.0 0.00 0.00 ? ? ..reading..
20-2 9382 0/0/0 R 0.00 5 0 0.0 0.00 0.00 ? ? ..reading..
21-2 9383 0/0/0 R 0.00 5 0 0.0 0.00 0.00 ? ? ..reading..
22-2 9384 0/1/1 R 0.01 0 1 0.0 0.00 0.00 ? ? ..reading..

and so on.

The access_log says:

/usr/local/apache/logs]# tail -f access_log
211.229.230.115 - - [02/Aug/2005:01:21:21 -0400] "6bNLilgBIbuJkWI3pww0QhnhnM" 501 -
65.10.248.190 - - [02/Aug/2005:01:21:24 -0400] "Kgd365YCZadmlioSqs8" 501 -
211.195.177.209 - - [02/Aug/2005:01:21:25 -0400] "CSwG8ImRNvWzpEsjntEnASp" 501 -
219.104.191.68 - - [02/Aug/2005:01:21:25 -0400] "9kX7QLZbtIhLKCaq2qm9bpEKgoHNkYOkLJ0CW9igCN8ttTqYGRMH3zNCOfxOIJnlYlnMG31fA1gKpHmJG1oYzS7oDYYIuzgv" 501 -
206.149.212.240 - - [02/Aug/2005:01:21:27 -0400] "UXrSXYDCKyq6RJmJQzhw" 501 -
200.106.17.162 - - [02/Aug/2005:01:21:28 -0400] "LuoWg58vto0JSfk0l6veD1luOAKBK1DaO54rfEP9TKTk3l58paSL10JjCFqCcMUyPCuWD4" 501 -
219.66.107.70 - - [02/Aug/2005:01:21:28 -0400] "s8fEcwNOx0SqYlOGIwqnnp5oxx3TG8qR1mlyN2H4bWgJAvz19RKtuZdQYqsAJdsaay6NydjrKW30RcyUA44womsD" 501 -
61.235.157.180 - - [02/Aug/2005:01:21:29 -0400] "vTiFxczhCX2tQ1XNehWfxyruQLDtH6uaCJuFmxlJggLoEUuC6fhHIB4rpj27" 501 -
221.185.120.244 - - [02/Aug/2005:01:21:29 -0400] "ptmrUX5v" 501 -
70.177.54.195 - - [02/Aug/2005:01:21:29 -0400] "mLRoUP6DdIj52v5voMxmsksz" 501 -
210.213.147.250 - - [02/Aug/2005:01:21:31 -0400] "xfxeKjsQjg5A6SWDkG" 501 -
60.214.223.1 - - [02/Aug/2005:01:21:34 -0400] "-" 408 -
24.45.203.10 - - [02/Aug/2005:01:21:34 -0400] "1sLtDPrGScL0uIoz" 501 -
67.168.31.96 - - [02/Aug/2005:01:21:35 -0400] "-" 408 -
68.219.29.135 - - [02/Aug/2005:01:21:35 -0400] "S9vtUMgKOoMHgi5QARCLQlMWCNGP2Pv6TugQXLSNH01e5e7bTl0OszkQJ1zlVeDQsWUjjt3yKRA8ZbLxJZ" 501 -
68.214.246.135 - - [02/Aug/2005:01:21:36 -0400] "-" 408 -
221.132.7.187 - - [02/Aug/2005:01:21:36 -0400] "-" 408 -
69.201.21.132 - - [02/Aug/2005:01:21:36 -0400] "wi0vzWmb2QDqwVf8OGlUoDyuccuwOlgcPXM1E0HauHL0umj2o6ZEiZVvjH1" 501 -
221.191.55.120 - - [02/Aug/2005:01:21:40 -0400] "-" 408 -
69.242.172.232 - - [02/Aug/2005:01:21:41 -0400] "RSdGzf2jgWx5JwbrQM71ctjrs9SnCPLZm3pYQP8tc" 501 -
200.95.156.166 - - [02/Aug/2005:01:21:42 -0400] "WJOHg" 501 -
68.155.127.250 - - [02/Aug/2005:01:21:42 -0400] "1B3Dkin6amNOiTmTfLnD0Bm" 501 -
64.217.219.199 - - [02/Aug/2005:01:21:42 -0400] "61dF8JLvUm0plGcklTyvqYfhEm4RO2SqdgOH1MFdzIM8SP5yDDXKB4iXLGpD4qiAY9YfbLDFo5J8Q0Pez6LDfy8ogPO70PlbAePyfE8z0LXtRZLeLwLHaWDcTbud6lZXk7fyU9RpxOBNhw7twLljH F72" 501 -
70.244.58.60 - - [02/Aug/2005:01:21:43 -0400] "-" 408 -
200.73.180.67 - - [02/Aug/2005:01:21:45 -0400] "ZKFwRWkHKNA5js0To0WQHjkMpmszcErSUppDGc0fjJKGfaEiUfWbsrZggXIK0bDDpyoFuD9j5e0TkgVJPCPNAdqvk0VuhBugiw1z8yk1nGNjJ1MHQrA085FehIarFI79vwgPX5B9ixtadsUX7NlqN Y6G7Cw8tTpmcBvnKhzE292jQz1vdEzxnJGhGi2mf9byNtzmc57XduxHjOx27FtvMVtWJKpaGmuMvILG2aoY66zZKsNWb8WXS1R2v42tD" 501 -
70.240.73.39 - - [02/Aug/2005:01:21:47 -0400] "-" 408 -
24.158.147.250 - - [02/Aug/2005:01:21:48 -0400] "-" 408 -
220.135.105.161 - - [02/Aug/2005:01:21:48 -0400] "-" 408 -
220.174.3.11 - - [02/Aug/2005:01:21:48 -0400] "U2N0W7Bjy1knbTlBAG4EDou0CurSpz" 501 -



It is attack from so many IPs that I cannot block it on APF.

The attack is on my main servers IP, not on a domain name I host I suppose.

I tried to use standard antidos applications ie. mod_dosesive etc. but since the attack comes from different IPs I cannot block it. PLEASE HELP

 

 

 

 

Top