DDoS Attacks - Need help!

Discussion in 'Site & Server Administration' started by Saurav1909, Jan 23, 2009.

  1. #1
    My site www.rapidlinks.co.uk was on shared hosting, it was fine, VPS, it was fine. 5 days ago I moved to a dedicated server, and since yesterday I have been facing large ddos attacks.

    Is there any way to stop these? I am paying more for the dedicated now and experiencing more downtime :|
    I think they keep changing the IP's so IP banning doesn't help.
     
    Saurav1909, Jan 23, 2009 IP
  2. maestria

    maestria Well-Known Member

    Messages:
    705
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    110
    #2
    Hi,

    there is a apache module called mod-dos evasive which when installed can can stop dos-evasive to an extend.
    We can install and configure the same at $50 for you.
     
    maestria, Jan 23, 2009 IP
  3. eurisko

    eurisko Peon

    Messages:
    30
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    get a firewall.

    Use either smoothwall or vyatta. Both are FREE!! Both can be configured to immediately drop all DDos attacks.
     
    eurisko, Jan 23, 2009 IP
  4. Pathan

    Pathan Well-Known Member

    Messages:
    2,196
    Likes Received:
    218
    Best Answers:
    0
    Trophy Points:
    165
    #4
    Try APF + Ddos Deflate combination it will help you.
     
    Pathan, Jan 23, 2009 IP
  5. Saurav1909

    Saurav1909 Active Member

    Messages:
    526
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    60
    #5
    Not too sure how to install APF, but I have installed DDoS Deflate for now :) Thanks.

    I will look into APF later today and try and install it.
     
    Saurav1909, Jan 24, 2009 IP
  6. Pathan

    Pathan Well-Known Member

    Messages:
    2,196
    Likes Received:
    218
    Best Answers:
    0
    Trophy Points:
    165
    #6
    Pathan, Jan 24, 2009 IP
  7. Tearabite

    Tearabite Prominent Member

    Messages:
    4,629
    Likes Received:
    429
    Best Answers:
    0
    Trophy Points:
    300
    #7
    i'm curious how you are determining that it's a DDoS ?
     
    Tearabite, Jan 24, 2009 IP
  8. devsn

    devsn Active Member

    Messages:
    156
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    70
    #8
    Tearabite, large packets sent to you again and again, which cause a service to fail (like apache)..

    @Topic, APF + Ddos Deflate combination will be the solution, as Pathan said.
     
    devsn, Jan 24, 2009 IP
  9. cmanns

    cmanns Peon

    Messages:
    62
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Would you like a sysadmin?

    btw that site doesn't look large enough to even need a dedicated server.
     
    cmanns, Jan 24, 2009 IP
  10. traffic.web

    traffic.web Guest

    Messages:
    43
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    you need .. apf + csf + mod_esasive + DOS-Deflate ..completed!
    example ddos.conf ;

    FREQ=1
    NO_OF_CONNECTIONS=50
    APF_BAN=1
    KILL=1
    EMAIL_TO=”root”
    BAN_PERIOD=600
     
    traffic.web, Jan 24, 2009 IP
  11. devsn

    devsn Active Member

    Messages:
    156
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    70
    #11
    dedicated server is better than shared hosting, in such a way that, you can secure the server yourself or have someone to help you.

    If you're in a shared hosting, once a shared site has been hacked, then the server is rooted, he can go through the directories and your site is affected..
     
    devsn, Jan 24, 2009 IP
  12. RectangleMan

    RectangleMan Notable Member

    Messages:
    2,825
    Likes Received:
    132
    Best Answers:
    0
    Trophy Points:
    210
    #12
    mod_evasive works well...easy to install and configure too. Start with that for sure.

    Are you running any kernel based firewalls? Normally you can create connection limits per IP for incoming traffic which will help stop ddos attacks.
     
    RectangleMan, Jan 26, 2009 IP