1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

DDoS Protection Script For iptables

Discussion in 'Security' started by abuzant, Sep 18, 2008.

  1. lencarifin

    lencarifin Well-Known Member

    Messages:
    132
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    101
    #21
    what to about this scripts is not just to copy and paste, but you MUST learning again, is the inside scripts contains backdoor or else, if you know this scripts was right, safe and there's no problem to import in server, start to using it.
     
    lencarifin, Jan 13, 2011 IP
  2. abuzant

    abuzant Well-Known Member

    Messages:
    956
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    140
    #22
    In general, being aware of such things is good, but if this script was a bad one, I would have been deleted along with it years ago ;)
    Use with a smile, its a safe one.

    PS> assuming you know how to chmod and start bash scripts of course. :p
     
    abuzant, Jan 14, 2011 IP
  3. lencarifin

    lencarifin Well-Known Member

    Messages:
    132
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    101
    #23
    Yes, i can see this is safe to put in server. Sometimes most of layman people doesn't know about script, like me. I was install new plugin to website, replace themes with free premium themes. Most of premium themes have encrypted script on footer. That cause make some script danger, they're create backdoor and finally they're deface my site :(
    It was terrible. So be aware if someone get some program, script, plugin, themes, or any interest digital on ads fly in internet
     
    lencarifin, Jan 14, 2011 IP
  4. panteng

    panteng Peon

    Messages:
    46
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #24
    thanks very much.....
     
    panteng, Jan 16, 2011 IP
  5. AdWorkMedia

    AdWorkMedia Member

    Messages:
    76
    Likes Received:
    1
    Best Answers:
    1
    Trophy Points:
    28
    #25
    Like nimhost said, I would recommend a firewall like CSF to protect again ddos and not some shady script like this.
     
    AdWorkMedia, May 7, 2011 IP
  6. blockdos

    blockdos Active Member

    Messages:
    96
    Likes Received:
    0
    Best Answers:
    3
    Trophy Points:
    71
    #26
    I think the best possible script with ddos protection is CSF using the connection tracking feature. That and a good web server setup/system tuning and some testing/babysitting you can mitigate as much as your resources can handle.
     
    blockdos, May 8, 2011 IP
  7. newhwa

    newhwa Peon

    Messages:
    2
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #27
    I think the script is very helpful, thanks!

    I have a question that, after having implemented this script in initializing process(rc.local), /etc/sysconfig/iptables is no longer works anymore right?
    I mean I can empty
    /etc/sysconfig/iptables, right?
    thanks!
     
    newhwa, Mar 5, 2012 IP
  8. newhwa

    newhwa Peon

    Messages:
    2
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #28
    So, can I just simply remove following 2 lines?
    $MODPROBE ip_conntrack_ftp
    $MODPROBE ip_conntrack_irc
     
    newhwa, Mar 5, 2012 IP
  9. infinitnet

    infinitnet Member

    Messages:
    56
    Likes Received:
    7
    Best Answers:
    1
    Trophy Points:
    35
    #29
    That won't help much. Any iptables rule with "--state" in it automatically loads the nf_conntrack module.

    Also this looks like a useful script, thank you for sharing. It misses a couple of important rules though that you can find here (maybe extend the script provided by the OP): https://javapipe.com/iptables-ddos-protection
     
    infinitnet, May 27, 2016 IP
  10. 24x7servermanagement

    24x7servermanagement Greenhorn

    Messages:
    18
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    23
    #30
    Would like to give a try with this script as CSF firewall is unable to stop the attacks. Is the script CentOS specific ? Can it work on Redhat ?
     
    24x7servermanagement, Jun 10, 2016 IP
  11. infinitnet

    infinitnet Member

    Messages:
    56
    Likes Received:
    7
    Best Answers:
    1
    Trophy Points:
    35
    #31
    If it works on CentOS, it will work on RHEL.
     
    infinitnet, Jun 13, 2016 IP
  12. gexacor

    gexacor Peon

    Messages:
    4
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    1
    #32
    Well, script-ddos defence is not much better than script-hackers I believe :)

    It's not a DDoS protection, it just iptables configuring script and I can't say if it good for anyone else to be honest. I hope so.
    It may help you of course, but will not save you from any real DDoS attack.
     
    gexacor, Jul 3, 2016 IP
  13. Karly_C

    Karly_C Peon

    Messages:
    18
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    3
    #33
    I believe it is a web application firewall, not a network firewall that AdWorkMedia is referring to? Try Cloudbric or Cloudflare.
     
    Karly_C, Aug 30, 2016 IP
  14. Gamer66

    Gamer66 Peon

    Messages:
    2
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    1
    #34
    did i use all this on 1 time to my vpn server or server host or what ?
     
    Gamer66, Apr 12, 2019 IP