Solved

Strange networking/firewall problem.

Posted on 2008-10-14
5
282 Views
Last Modified: 2012-05-05
I've got a Windows 2003 Web Server at a co-location farm with several web sites using IIS 6.  A strange thing has been happening lately.  Any PHP web page that uses MySQL gets this error:
Warning: mysql_connect() [function.mysql-connect]: Can't connect to MySQL server on 'localhost' (10055)
But MySQL isn't the problem.  SQL Server 2005 is also on the system.  Those sites (also using classic ASP) are working.  
I think this is a networking issue that I just cannot begin to know where it is coming from.
At the moment I can Remote Desktop into the system.  However, last time I rebooted it, any remote port port  except port 80 stopped responding remotely and I had to physically go to the co-lo location and reboot.  When I did that, everything worked again just fine.  At the moment I cannot SSH into the system (I have Open SSH installed).  
When I remote desktop into it, most networking things are blocked.  For instance, I pull up Internet Explorer or Firefox and cannot go to any web site.  I just get "Page cannot be displayed".  However, I can ping any site on the internet just fine.  

The system is behind a NAT firewall/router that I've assigned a static IP and pass through certain ports like 80 for web, 9522 for SSH, 9898 for Remote Desktop, etc.  I've always been able to surf the web from that machine except for some reason I never tried to figure out - I couldn't go to any https sites (port 443).
In a browser I cannot even get to the router admin http://192.168.5.254 like I've always been able to.

Here is why I doubt it is the router though.  MySQL is on the local machine.  I should be able to go into MySQL administrator or just use a web site that connects to it.  But no luck.  Nothing can connect even locally.  So it shouldn't be going through the router.  Even when I do http:/127.0.0.1 in a browser I've always got the main web site to appear.  But not now.  I can however ping 127.0.0.1

I don't have any IPSEC firewall settings in Win 2003.  

I've looked in the Event Log.  Nothing jumps out at me.  I get some MySQL errors and SSH server errors that probably begin once the networking starts messing up.
I have an Administrator login that happened at 4:30am that wouldn't be me or anyone I know.  But maybe an automatic process (or malicious?).  
I don't have any Antivirus, Norton Security, or anything like that.  I ran Lavasoft Adaware and it found nothing.
This is a bit like the Windows firewall is turned on, even though it isn't turned on.

0
Comment
Question by:Thread7
  • 3
  • 2
5 Comments
 
LVL 7

Expert Comment

by:aamodt
Comment Utility
Can't connect to MySQL server on 'localhost' (10055)

Insted of useing PHP to connect to localhost, have you tryed connecting to the 'local' or 'public' IP address?

You might have blocked useage of the localhost alias in your firewall. Don't know whitch firewall you are useing but, proberlly some problem like that.

If it's not the MYSQL service.. it must be the firewall or the routing on your router. If you have configured your IIS or MYSQL server resently it can also make a problem for you.

The Admin login, was is succsesfull with password and sutch? sounds wierd. Maybe your box got hacked? ^^ Try to change the administration password :)

Good Luck!
0
 
LVL 1

Author Comment

by:Thread7
Comment Utility
I can't connect to the firewall adminstration to even open up a public port for MySQL.  But SSH which was working before is no longer working.  Remember several of these problems are  just connecting from one localhost service to another localhost service.  So that is why it is so strange.
0
 
LVL 1

Author Comment

by:Thread7
Comment Utility
I tried starting the IIS FTP service which I normally leave shut down.  I got an error that said not enough storage space available.  The thing is, in Windows Explorer it shows that I have 142 GB of free space left!.

So I am wondering if I did get hacked and someone is serving up bootleg movies/music from my box.
0
 
LVL 7

Accepted Solution

by:
aamodt earned 500 total points
Comment Utility
Yeah sounds abit wierd.. try search for .avi .mp3 files on your hard drive.
0
 
LVL 1

Author Comment

by:Thread7
Comment Utility
Well I started shutting down services 1 by 1.  And all of a sudden everything started working again.  The services I shut down before I checked to see if it was working were:
1. Acronis Schedule Service (This is a program I use to create ghost copies of the hard disk)
2. Acronis VSS Provider
3. Application Management (I think)
4. Background Intelligent Transfer Service (There have been several event log entries about this service that look fishy)  One about it chaging from "demand start" to "auto start".  Then an Error once that said it was unable to start.
5. Cobian 8 Backup Service.  A backup program I have.
6. DHCP Client.  (I have a static IP so I don't need this to run).  Since my problems were networking related, maybe it is this?

The thing is, if I make these services run again.  Everything on the server just works fine.  Hmmm.
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

Suggested Solutions

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
When it comes to showing a 404 error page to your visitors, you do not want that generic page to show, and you especially do not want your hosting provider’s ad error page to show either. In this article, I will show you how to enable the custom 40…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now