Dos attack protection!?

Discussion in 'Site & Server Administration' started by maar3amt, Sep 28, 2008.

  1. #1
    Hi
    Anyone know a nice soluction for DoSHTTP attacks?
    Software based.


    Thank you
     
    maar3amt, Sep 28, 2008 IP
  2. jliu

    jliu Peon

    Messages:
    235
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #2
    mod_evasive for Apache
     
    jliu, Sep 29, 2008 IP
  3. jayshah

    jayshah Peon

    Messages:
    1,126
    Likes Received:
    68
    Best Answers:
    1
    Trophy Points:
    0
    #3
    DDoS Deflate and APF. Please do search the forums, this has come up thousands of times.

    Jay
     
    jayshah, Sep 29, 2008 IP
  4. maar3amt

    maar3amt Active Member

    Messages:
    34
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    71
    #4
    Thank you.

    Now i have already mod_evasive installed but when i run ./test.pl i get always
    "200 ok" how can i get it work propely?
     
    maar3amt, Sep 30, 2008 IP
  5. maar3amt

    maar3amt Active Member

    Messages:
    34
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    71
    #5
    Mod_evasive is compatible with apache 2.2.3?
     
    maar3amt, Sep 30, 2008 IP
  6. nimhost

    nimhost Active Member

    Messages:
    235
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    58
    #6
    as long as i know nope
    only compatible with 1.3 :)
     
    nimhost, Sep 30, 2008 IP
  7. Bohra

    Bohra Prominent Member

    Messages:
    12,573
    Likes Received:
    537
    Best Answers:
    0
    Trophy Points:
    310
    #7
    Use DDoS Deflate its the best
     
    Bohra, Sep 30, 2008 IP
  8. sadbuttrue

    sadbuttrue Member

    Messages:
    46
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #8
    From which IP-Ranges are you getting ddos?
     
    sadbuttrue, Sep 30, 2008 IP
  9. IwhiC

    IwhiC Peon

    Messages:
    2,594
    Likes Received:
    61
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Install DDoS Deflate and have a good fire wall.

    Run this in ssh as root

    netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n

    see if you have any ips excessively connecting to your server and block them
     
    IwhiC, Oct 1, 2008 IP
  10. maar3amt

    maar3amt Active Member

    Messages:
    34
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    71
    #10
    But they have dynamic ip's i block one and them get a new one. :(
    I think i can't block them just with sofware based firewalls.
    I have already installed ddos-deflate (ban by iptables not apf)
    I have mod_deflate
    I have csf firewall
    But i can´t stio them.
     
    maar3amt, Oct 1, 2008 IP
  11. maar3amt

    maar3amt Active Member

    Messages:
    34
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    71
    #11
    Well another question.

    From netstat i got 123 connections from my server ip adress it's normal?
     
    maar3amt, Oct 1, 2008 IP
  12. sadbuttrue

    sadbuttrue Member

    Messages:
    46
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #12
    Yes, it's normal. If you are under attack with 123 connections, you are getting big packets (same as cyclone).
     
    sadbuttrue, Oct 7, 2008 IP
  13. Pathan

    Pathan Well-Known Member

    Messages:
    2,196
    Likes Received:
    218
    Best Answers:
    0
    Trophy Points:
    165
    #13
    I would recommend DDoS Deflate and APF.
     
    Pathan, Oct 7, 2008 IP
  14. Shazz

    Shazz Prominent Member

    Messages:
    8,395
    Likes Received:
    453
    Best Answers:
    0
    Trophy Points:
    330
    #14
    I know the perfect host, they have spcecial plans to meet your sites needs. If your interested shoot me a PM and I will send you to the right person
     
    Shazz, Oct 7, 2008 IP