Bot Attack, how to protect server

Discussion in 'Site & Server Administration' started by ronskit, Oct 22, 2009.

  1. #1
    Guys, i want some suggestions on how to protect an linux dedicated server from bot attack. Im using linux server with cPanel, using CSF firewall + DOS Deflate.

    It would be great to have your opinions and experience.
     
    ronskit, Oct 22, 2009 IP
  2. SecureCP

    SecureCP Guest

    Messages:
    226
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Not sure of exactly what you mean by bot attack but have you turned on your background process killer?
     
    SecureCP, Oct 22, 2009 IP
  3. slacker8

    slacker8 Peon

    Messages:
    176
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    you probably mean ddos attack? :)
     
    slacker8, Oct 22, 2009 IP
  4. RectangleMan

    RectangleMan Notable Member

    Messages:
    2,825
    Likes Received:
    132
    Best Answers:
    0
    Trophy Points:
    210
    #4
    It's going to depend on the size of the attack versus your hardware capabilities. To start with you'll need to know the type of attack. Which port is it attacking? How many IPs are involved (rough estimate)? Does your firewall allow for a good ruleset?

    Have you also tried to contact the datacenter or your host?
     
    RectangleMan, Oct 22, 2009 IP
  5. organicCyborg

    organicCyborg Peon

    Messages:
    330
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #5
    You can't.

    There's no way to protect yourself completely. Your best bet is to move to a host that specializes in DDoS mitigation. But, even that won't always work. It depends on the size and scale of the attack. If it's small, and just slowing down your machine, you can block some IPs in the firewall and be ok. If it's bigger, you'll need to get your host to do some configuration on their end.
     
    organicCyborg, Oct 22, 2009 IP
  6. organicCyborg

    organicCyborg Peon

    Messages:
    330
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #6
    chrootkit will scan for rootkits, but has nothing to do with protecting from DDoS attacks originated from botnets.
     
    organicCyborg, Oct 22, 2009 IP
  7. SecureCP

    SecureCP Guest

    Messages:
    226
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Their homepage "locally checks for signs of a rootkit"

    nice.
     
    SecureCP, Oct 22, 2009 IP
  8. Bohra

    Bohra Prominent Member

    Messages:
    12,573
    Likes Received:
    537
    Best Answers:
    0
    Trophy Points:
    310
    #8
    Bohra, Oct 23, 2009 IP
  9. rootbinbash

    rootbinbash Peon

    Messages:
    2,198
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    0
    #9
    It depends on the bot and the area where you fail. You should check out snort or mod_security
     
    rootbinbash, Oct 28, 2009 IP