Slashdot Mirror


When Does Website Monitoring Go Too Far?

jafiwam asks: "Recently, the IT department of the company I work for and a 3rd party monitoring and security firm got into a pissing match about how much monitoring is too much. They either got a hold of a customer list from a former employee or walked our IP space to find our web hosting customers. They then proceeded to sell them monitoring services for things such as server up-time, defacement detection, email up-time and DNS testing. While I welcome anything that lets our customers use the internet effectively, their set of monitoring servers filled an entire 18 gig partition full of web server logs (causing the server to crash on a weekend) and choked an email server with 40k some messages that could not be delivered, and they failed to properly brief the hosting customers about what would happen to their log analysis software when faced with 99% traffic from a small set of IPs. These things caused down-time, lost productivity and a damaged reputation. What is appropriate for monitoring a web site and email server? Who should be allowed to monitor? Where should the give and take lie in this situation? I am interested in finding out what admin-on-the-street has to say about this."

"Though I believe they are a reputable company, they are doing some things I do not think are good: checking for the domain names on the TLD servers once per second, downloading various files from the site once per second, and sending email to themselves once per second.

Our first response was to talk to them and explain what we needed them to do, including a list of IPs that we used for customers so they could adjust their monitoring to suit what we thought was reasonable. They chose to ignore the first discussion and continued to abuse the servers. After the email server required a half-day of cleanup, the CTO simply shut them off at the firewalls. Rather than using the contact information they had, they chose to complain to our mutual customers instead. (I should note we do significant monitoring of the servers ourselves, and typically know if something is wrong within minutes of the event.)

Is this typical behavior of monitoring service companies? I know some of them are not reputable at all (due to spamming) however these guys seem to know what they are doing, and yet managed to effectively attack our mail and web servers, as well as doing some things I would not do to the TLD servers. It is hard to feel justified to shutting off someone else's cash-flow, but at the same time we need to defend servers from over zealous monitoring."

7 of 259 comments (clear)

  1. I know what to do! by rock_climbing_guy · · Score: 4, Funny

    Let's all pitch in on a little scheme. We will each agree to buy a service plan to have one non-existant .com web site monitored. If we could get lots of people to do this, we could DDOS Verisign off the internet!

    --
    Wh47 d1d j00 541, 31337 15n't t3h r0xor5 ne m0r3???
  2. When Does Website Monitoring Go Too Far? by _Pablo · · Score: 2, Funny

    When it exceeds the point of being far enought!

    Kind of depends on how rapidly you can respond to a problem with something being monitored - obviously every second or even every minute is too rapid. Every hour sounds better.

    --
    $2B OR NOT $2B = $FF
  3. We should have a nationwide lawyer database by tjstork · · Score: 1, Funny


    And anyone who is a lawyer, is denied access to all computing systems.

    --
    This is my sig.
  4. Monitoring Report: by Snoopy77 · · Score: 2, Funny

    It seems there has been an unusual amount of downtime to your web and email servers. Probable cause: we over monitored them. Sorry.

    --
    "She's a West Texas girl, just like me" - G.W Bush Iraqis
  5. Slashdot the MFers by mabu · · Score: 3, Funny

    The solution to this is simple. Publish the web address of this loser monitoring company and we'll let Slashdotters "check the integrity of their system."

  6. DOH ! gotta stop smoking weed .. by Tensor · · Score: 2, Funny

    I meant VERISIGN and not Verio

    And SITEFINDER instead of seeker. dammit

    Now why didn't i pressed preview ?

  7. Admin on the street says.. by gosand · · Score: 2, Funny
    I am interested in finding out what admin-on-the-street has to say about this.

    Admin-on-the-street says "I need a job, you insensitive clod"

    --

    My beliefs do not require that you agree with them.