1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

DDOS attack

Discussion in 'Security' started by alm3alm, Jan 8, 2007.

  1. #1
    i got some DDOS attack how can i stop it?
     
    alm3alm, Jan 8, 2007 IP
  2. koolasia

    koolasia Banned

    Messages:
    1,413
    Likes Received:
    59
    Best Answers:
    0
    Trophy Points:
    0
    #2
    koolasia, Jan 8, 2007 IP
  3. leet

    leet Notable Member

    Messages:
    3,423
    Likes Received:
    369
    Best Answers:
    0
    Trophy Points:
    250
    #3
    Are you sure it's just ddos and not a botnet attack?
     
    leet, Jan 8, 2007 IP
  4. alm3alm

    alm3alm Peon

    Messages:
    153
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Employee Response - 2007-Jan-08 09:52
    Hello,

    We have seen DDOS attack in this server and now we have started firewall for your server which was OFF.

    We have seen some IP have established more connection in this server.Please try to block the IP's which causing this issue.

    Please get back to us if you need more assistance.

    Regards,
    Winston.

    my server iis not linux:(

    thx but iam iis
     
    alm3alm, Jan 8, 2007 IP
  5. T0PS3O

    T0PS3O Feel Good PLC

    Messages:
    13,219
    Likes Received:
    777
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Block the IPs and/or switch off the server in the meanwhile before the system gets compromised.
     
    T0PS3O, Jan 8, 2007 IP
  6. koolasia

    koolasia Banned

    Messages:
    1,413
    Likes Received:
    59
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Ah im sure windows must be having somewat like dis software
     
    koolasia, Jan 8, 2007 IP
  7. eXe

    eXe Notable Member

    Messages:
    4,643
    Likes Received:
    248
    Best Answers:
    0
    Trophy Points:
    285
    #7
    koolasia, dos deflate by no means is capable of even mitigating ddos attacks that employ significant bandwidth. I can safely say that there is no slap-on software firewall that can protect a server from ddos attacks.

    alm3alm, what type of an attack is this & how big is it?
    You may find this link useful:
    http://www.wilsonmar.com/1iiscfg.htm

    There are providers who specialize in mitigating ddos attacks, they do this by running a "protected" network (custom hardware firewalling, custom rules to filter traffic at the router/switch level). Some in the business include gigeservers, blacklotus, awknet & sharktech.
     
    eXe, Jan 8, 2007 IP
  8. alm3alm

    alm3alm Peon

    Messages:
    153
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #8
    thx will i dont know the type of DDOS attack how can i know it ??

    about the big of it its very big as the company tell me and we cannot make manual block for thousand of ips
     
    alm3alm, Jan 8, 2007 IP
  9. eXe

    eXe Notable Member

    Messages:
    4,643
    Likes Received:
    248
    Best Answers:
    0
    Trophy Points:
    285
    #9
    Ask your datacenter. Or post your mrtg graphs here.

    Ask them how big it is, how many MB/s or GB/s

    Also, do you know why you are being targeted? And which site is being targeted? Has the attacker contacted you?
     
    eXe, Jan 8, 2007 IP
  10. alm3alm

    alm3alm Peon

    Messages:
    153
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #10
    hello eXe

    they told me its syn flood
     
    alm3alm, Jan 9, 2007 IP
  11. alm3alm

    alm3alm Peon

    Messages:
    153
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #11
    i need help with Inbound SYN Flood Attack plz
     
    alm3alm, Jan 10, 2007 IP
  12. eXe

    eXe Notable Member

    Messages:
    4,643
    Likes Received:
    248
    Best Answers:
    0
    Trophy Points:
    285
    #12
    How many syns/second is it? It's really difficult to keep a server reachable without some kind of filtering at the router level... I suggest you check out those providers I listed above.
     
    eXe, Jan 10, 2007 IP
  13. alm3alm

    alm3alm Peon

    Messages:
    153
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #13
    they told me that

    I do not have those statistics available at this time. We provide DDOS protection from large inbound attacks and large syn attacks. The attack targeting your server is extremely small in traffic, and due to the number of bots it looks like legitimate traffic as each is only opening a small number of connections (like a normal user).
     
    alm3alm, Jan 10, 2007 IP
  14. eXe

    eXe Notable Member

    Messages:
    4,643
    Likes Received:
    248
    Best Answers:
    0
    Trophy Points:
    285
    #14
    Who is your provider?
    Does that mean your server is up?
     
    eXe, Jan 10, 2007 IP
  15. alm3alm

    alm3alm Peon

    Messages:
    153
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #15
    my provider sofylayer

    during attack server yes working but the sites become damn slow untill no responding
     
    alm3alm, Jan 10, 2007 IP
  16. alm3alm

    alm3alm Peon

    Messages:
    153
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #16
    this list of my Active connection during attack

    could anyone help to understand what i got in attachment
     

    Attached Files:

    alm3alm, Jan 11, 2007 IP
  17. rondhro

    rondhro Banned

    Messages:
    45
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #17
    Do three things. First stop icmp so that no one be able to ping you.

    iptables -A OUTPUT -s icmp -j DROP
    Code (markup):
    use that command from your ssh to stop icmp. Then install mod_security which is an apache module which will help you to resolve botnet attacks. For solving bot net attacks, find out the active httpd connections informations using some log tails and block them using mod_security rules.

    Third, use the Dos Deflate software as describe in the first reply on the post :)

    This is really a great tick which can solve lots of dos and botnet attacks :)
     
    rondhro, Jan 30, 2007 IP
  18. chrisstinson

    chrisstinson Peon

    Messages:
    67
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #18
    With Windows Server you may want to enable TCP/IP Filtering on all but the ports you *really* need. So leave open 80,25 TCP and 53 UDP if you're running a basic setup. It also helps to not reply to ANYTHING. Have the firewall set to not reply to pings, etc.

    This won't stop anything (the nature of a ddos), but it will allow your server to handle a bit more abuse before falling.
     
    chrisstinson, Jan 31, 2007 IP
  19. Dude111

    Dude111 Guest

    Messages:
    1,153
    Likes Received:
    21
    Best Answers:
    0
    Trophy Points:
    0
    #19
    Very interesting....I will share this with a friend of mine....

    Thank you for posting :)
     
    Dude111, Feb 2, 2007 IP
  20. lkj

    lkj Peon

    Messages:
    729
    Likes Received:
    17
    Best Answers:
    0
    Trophy Points:
    0
    #20
    Default firewall rules that block ports will not help you defend against ddos that is launched against normal working port that you run, for example, web site tcp port 80.....
     
    lkj, Feb 4, 2007 IP