Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

find who/what is consuming your server resources? 3

Status
Not open for further replies.

MRGRIM

Technical User
Feb 17, 2005
1
US
hey guys, i'm new to iis, was an apache guy for a while first.
but what i came here to ask is, is there a way to find out who/what is consuming all my iis system/networking resources?
i have a popular website, and and i've noticed lately that ALL my
bandwidth or rather network utilization is being consumed,
and i know my website is NOT that busy, i notice that when i
restart the server, it goes back to normal usage, but after a
couple hours, this happens again, till i again restart the
server. i looked in my log files and found only ONE thing that
i could consider suspicious, and that was somekind of client
device called "WebCopier+v4.2", so i banned that users ip, but
my utilization hasn't changed much. a few days ago, i had a
REALLY bad problem that caused me to have to cut off the
network completely, all of a sudden, as i was watching my
network monitor, the RECIEVE levels went through the roof!
now i am only a webserver with aspx pages, but not a storage
server, or anything that would require me to recieve any
large amounts of data, i only recieve requests. but the
problem was, it was locking up the pc! i've never seen
anything like it. i couldnt do anything on my pc, it was
completely frozen, the only way to stop it, was to unplug
the lan cable. i had windows firewall on, and it's limited
only to what it is currently used for, no unnessecary
permissions have been granted. is there a way to find out
what ip is sending OR recieving a certain amount of traffic,
or to find where a certain traffic is comming from, like the port,
or whatever, and disable it when it becomes a problem?
i'd really apreciate any help at all. thank you all for your time in advance:
ALEX GRIM
-------------
 
I would highly suggest the program called CommView as it will give you real-time answers on who, and what is visiting your site. Also, the IP you banned was a bot, and I doubt that it was the problem because they usually just index the page and move on. Do you have a Mail server running on your machine? If so, then perhaps you have left it in "open relay" mode so your mail server is being used as a relay for the spammers. I have had this inadvertanly happen before and to think that one little checkbox was the culprit!!! Also, is your IIS server patched with the latest patches? If so then ok, if not, then you may have the Nimda or similar virus; it could also be a trojan. I hope this helps you out a bit...

LF

"As far as the laws of mathematics refer to reality, they are not certain; as far as they are certain, they do not refer to reality."--Albert Einstein
 
THANK YOU SO MUCH FOR THE ANSWER TO A QUESTION THAT I WAS ABOUT TO ASK MYSELF. I HAVE BEEN TRYING TO GET ON GRIMMUSIC.COM AND IT CAN'T FIND THE SERVER. HOPEFULLY THE PROBLEM WILL BE SOLVED. GOOD LUCK! xXOo :heart:Lady Rose
 
I've had a similar problem on a Win2K Advanced Server running IIS 5, hosting Kofax Ascent Ricochet, no conventional web pages - every so often Inetinfo.exe will spike to 100%CPU uilitization for 3-4 seconds, 5 or 6 times in a row, and then a minute or so later, it will spike to 100% for 8-10 minutes, then go back to normal. The problem only abates for a few minutes on a reboot. Once I completely removed Ascent Ricochet, uninstalled IIS, had my Server Gurus reinstall IIS, then put Ricochet back, and it stayed normal for a few months, but now it's back the way it was. From the behavior I suspect some kind of trojan or zombie program. I'll find and try CommView and see what I can discover.

Fred Wagner
KQ6Q@arrl.net
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top