I am not defending Lifco but wondering if these logs can be posted because really you cannot properly check for a DDOS against a server unless you got some sort of remote access directly to the server.... (most will require the assitance of a datacenter for network traffic logs)....
As for ddos... you really want to monitor inbound connections and so forth, unless you are saying he is attempting to overflow apache then ok you will have a connection amount in the apache logs, but this would also use proxied ips.... but if you mean sending all his upload bandwidth data from a home comnnection to a standard 10/100mbit then that sounds fishy.
Can you show me these logs because im finding it abit far fetched as of this moment.
As for ddos... you really want to monitor inbound connections and so forth, unless you are saying he is attempting to overflow apache then ok you will have a connection amount in the apache logs, but this would also use proxied ips.... but if you mean sending all his upload bandwidth data from a home comnnection to a standard 10/100mbit then that sounds fishy.
Can you show me these logs because im finding it abit far fetched as of this moment.
