Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

What to Do When Your Server Is Hacked and Sends a Flood of Traffic

Sometimes a hacker takes over a server and uses it to attack others. This guide helps you stop it and clean up. It needs root access.

VPS and Cloud Servers2 min read13 steps

What is happening?

A droplet is the name some providers use for a small cloud server. It is like a VPS. If it is compromised, someone else has broken in and controls it.

An outgoing flood is a huge amount of junk traffic sent from your server to another one. A DDoS attack is when many computers send so much traffic that a site cannot cope. Your server may be one of the helpers without you knowing.

Signs of trouble:

  • The server is very slow.
  • Your provider sends a warning about attacks from your server.
  • Network use is very high with no reason.
  • You see programs you do not know.

Steps to stop it

  1. Tell Hostvento support about the problem by opening a ticket at https://secure.hostvento.com/submitticket.php.
  2. Log in over SSH. If you cannot, ask support whether a rescue method is available.
  3. Look at what uses the network and the CPU:
    top
    ss -tunp
    top lists busy programs. ss -tunp lists network connections and the program behind each.
  4. Find the strange program and stop it. Replace 1234 with its process number:
    kill -9 1234
  5. Check for unknown users and tasks:
    cat /etc/passwd
    crontab -l
    ls -la /etc/cron.d
    A cron job is a task that runs on a timer. Attackers often hide one there.
  6. Change every password at once: root, users, databases and control panels.
  7. Look at the file ~/.ssh/authorized_keys and remove keys you do not know.
  8. Update all software:
    sudo apt update && sudo apt upgrade -y
    On AlmaLinux or Rocky use dnf update -y.
  9. Close ports you do not need with a firewall, and turn on SSH key login.

The safest cure

Once a server is hacked, you cannot be sure every hidden door is closed. The safest way is a fresh install.

  1. Copy only your data, such as site files and databases, to a safe place. Scan them first.
  2. Reinstall the operating system.
  3. Restore your data.
  4. Set strong passwords and update everything before you go live.
Tip: Most break-ins start from weak passwords or old software such as an outdated WordPress plugin. Keep both fresh and strong.

Quick recap

  • A hacked server can send attack traffic without you knowing.
  • Tell support, find the bad program and stop it.
  • Change all passwords and remove unknown keys and cron jobs.
  • A fresh install is the safest cleanup.
  • Keep software updated and passwords strong.