Nog bezig met analyseren van alle logs, maar dit staat er wel in:
CitaatToon Meer208.115.60.146 - - [18/Oct/2010:21:43:17 +0200] "GET /in/317.html HTTP/1.0" 302 13505 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
174.142.104.57 - - [18/Oct/2010:21:43:17 +0200] "GET /in/317.html HTTP/1.1" 302 13582 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
66.197.252.181 - - [18/Oct/2010:21:43:17 +0200] "GET /in/317.html HTTP/1.1" 301 527 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
173.203.78.165 - - [18/Oct/2010:21:43:17 +0200] "GET /in/317.html HTTP/1.1" 302 13583 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
118.97.36.34 - - [18/Oct/2010:21:43:15 +0200] "GET / HTTP/1.1" 200 15928 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
202.108.50.77 - - [18/Oct/2010:21:43:17 +0200] "GET /in/317.html HTTP/1.1" 302 13527 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
219.136.253.22 - - [18/Oct/2010:21:43:18 +0200] "GET /in/317.html HTTP/1.1" 302 13527 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
174.142.104.57 - - [18/Oct/2010:21:43:17 +0200] "GET / HTTP/1.1" 200 18809 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
189.84.116.88 - - [18/Oct/2010:21:43:17 +0200] "GET / HTTP/1.1" 200 18753 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
118.97.36.34 - - [18/Oct/2010:21:43:18 +0200] "GET /in/317.html HTTP/1.1" 302 13527 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
61.164.109.7 - - [18/Oct/2010:21:43:17 +0200] "GET / HTTP/1.0" 200 18731 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
202.108.50.71 - - [18/Oct/2010:21:43:17 +0200] "GET / HTTP/1.1" 200 18753 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
222.161.3.146 - - [18/Oct/2010:21:43:17 +0200] "GET / HTTP/1.1" 200 18753 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
189.84.116.88 - - [18/Oct/2010:21:43:17 +0200] "GET / HTTP/1.1" 200 18753 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
208.115.60.146 - - [18/Oct/2010:21:43:18 +0200] "GET / HTTP/1.0" 200 18731 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
41.190.16.17 - - [18/Oct/2010:21:43:18 +0200] "GET / HTTP/1.1" 200 18808 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
89.132.185.205 - - [18/Oct/2010:21:43:18 +0200] "GET /in/317.html HTTP/1.0" 302 13505 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
89.132.185.205 - - [18/Oct/2010:21:43:18 +0200] "GET / HTTP/1.0" 200 18731 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
119.167.219.78 - - [18/Oct/2010:21:43:18 +0200] "GET / HTTP/1.0" 200 18731 "http://www.google.com/search?Language=NL" "Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"
Het valt mij op dat alle verzoeken (buiten de aanvallen) kwamen vanuit Google:
http://www.google.com/search?Language=NL
Zou er een Google bom gebeurd zijn? Iemand die opeens kliks inkoopt op zeer populaire woorden?
Wat denken jullie? Mij ziet het er zeer verdacht uit.
Een 2de aanval (echte Ddos) gebeurde vanuit het account van 1 van onze crewleden, die werd tijdelijk verbannen.
Vermoedelijk misbruikt iemand zijn account gewoon.
Voor ik met verklaringen hierover naar buiten kom, overleg ik eerst met hem.
Bedankt voor jullie begrip en sorry voor de last.
Koen
Ps: op een gegeven moment zaten we met bijna 500 mensen tegelijk op CP, allemaal unieke IP's.