Strange issue with 74.125.79.118

Posted by Domenic on Server Fault See other posts from Server Fault or by Domenic
Published on 2011-02-22T12:08:01Z Indexed on 2011/02/22 15:26 UTC
Read the original article Hit count: 221

Filed under:

I'm facing with a strange issue on a Linux server. After frequent crashes the analysis found that the server is led to collapse by a huge number of connections to the ip 74.125.79.118 departing from php scripts of the hosted web sites. After a depth analysis of the files I'm found that are not present any malware infections. Ip 74.125.79.118 is Google. I realize after a Google search that the connections to this ip are generated by embedded video from youtube on web sites, among other Google features like safe search. But I don't understand how this type of behavior can lead to the collapse the server and the uniqueness of the situation leads me to think that the situation is far from being attributable only to Google and Youtube.

Also I've found that blocking connections from eth0 to 74.125.79.118:80 doesn't solve the issue but if I stop DNS traffic from eth0 to internet, connections to 74.125.79.118 stops. I'm really confused about this. Any suggestions?

Cheers.

© Server Fault or respective owner

Related posts about linux