1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Hacked - DDos attacked, Downtime 1 week...

Discussion in 'Security' started by Shazz, Aug 23, 2008.

  1. #1
    Message from Host:
    I was on a shared plan and they moved me to a VPS same problem
    Host: http://www.urljet.com

    I have had one host representative thats said "I think we could take care of you but you would have to use this plan with the firewalls"

    https://www.liquidweb.com/cart/content/dedicated/Webmaster/Plan1
     
    Shazz, Aug 23, 2008 IP
  2. liquidwebBret

    liquidwebBret Greenhorn

    Messages:
    98
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    18
    #2
    liquidwebBret, Aug 25, 2008 IP
  3. Shazz

    Shazz Prominent Member

    Messages:
    8,395
    Likes Received:
    453
    Best Answers:
    0
    Trophy Points:
    330
    #3
    Bret, I was in a live chat on liquidweb 2-3 times with different sales people and they all say different things. First one said only the $180 plan would cover it, now your saying this $50 plan will do it.

    And there is no money back if you can't prevent it?
     
    Shazz, Aug 25, 2008 IP
  4. The Universes

    The Universes Peon

    Messages:
    187
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Is this a DDOS attack in that your pipe is flooded or just making so many requests the server is crumbling?
    Have you tried using software firewalls and blocking the offending IPs?
     
    The Universes, Aug 26, 2008 IP
  5. Shazz

    Shazz Prominent Member

    Messages:
    8,395
    Likes Received:
    453
    Best Answers:
    0
    Trophy Points:
    330
    #5
    Yes... Its not that simple :rolleyes:
    Its pretty hard going against botnet
     
    Shazz, Aug 26, 2008 IP
  6. Dollar

    Dollar Active Member

    Messages:
    2,598
    Likes Received:
    82
    Best Answers:
    0
    Trophy Points:
    90
    #6
    Its also hard when the IPs in the packet are spoofed, so they can just make them up as the go.
    Its really a wonder how to defend against that.
     
    Dollar, Aug 26, 2008 IP
  7. liquidwebBret

    liquidwebBret Greenhorn

    Messages:
    98
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    18
    #7
    Right. Regardless of what sales people may say on our chat. The logic holds that for serious DDOS attacks you're going to need serious appliances dedicated to your system. Those can cost many thousands a month. I'm not sure why someone would say moving from a shared account to the VPS would add security because it doesn't.
     
    liquidwebBret, Aug 26, 2008 IP
  8. The Universes

    The Universes Peon

    Messages:
    187
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #8
    You cant spoof a TCP connection, due to the handshake that has to happen.
    Sure you can do a SYN flood with spoofed IPs, but theres ways of protecting against that.
     
    The Universes, Aug 26, 2008 IP
  9. nimhost

    nimhost Active Member

    Messages:
    235
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    58
    #9
    from what i know iptables on linux only can handling 100 ip address listed
    if the DDOS source was come from thousand of ip address you need to ask your upstream to check out the connections to your server :)
     
    nimhost, Aug 26, 2008 IP
  10. Shazz

    Shazz Prominent Member

    Messages:
    8,395
    Likes Received:
    453
    Best Answers:
    0
    Trophy Points:
    330
    #10
    Bret can I get a money back garauntee if you guys can't prevent this Ddos attack, Ive moved from 4 different hosts so far. They all said they could.
     
    Shazz, Aug 26, 2008 IP
  11. liquidwebBret

    liquidwebBret Greenhorn

    Messages:
    98
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    18
    #11
    No we don't offer money back guarantee's specially for a DOS attack. The cost on our side wouldn't justify that. DOS attacks are harmful to data centers so inviting people to come over with current DOS attacks in place isn't vary appealing.
     
    liquidwebBret, Aug 27, 2008 IP
  12. Shazz

    Shazz Prominent Member

    Messages:
    8,395
    Likes Received:
    453
    Best Answers:
    0
    Trophy Points:
    330
    #12
    Then it would be 100% money wasted, I would pay for it then it wouldn't work and I would waste not only money but alot of time trying to get it back up. This attacker dosen't stop, has thousands of IP's a day comming in. I have been on every firewall for Ddos
     
    Shazz, Aug 27, 2008 IP
  13. Shazz

    Shazz Prominent Member

    Messages:
    8,395
    Likes Received:
    453
    Best Answers:
    0
    Trophy Points:
    330
    #13
    Update... This attacker is using a botnet its been confirmed by a few people that have monitored each attack. What are my next steps :eek:
     
    Shazz, Aug 27, 2008 IP
    Crazy_Rob likes this.
  14. nimhost

    nimhost Active Member

    Messages:
    235
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    58
    #14
    blocking the IP on your upstream side :)
     
    nimhost, Aug 28, 2008 IP
  15. LH-Danny

    LH-Danny Guest

    Best Answers:
    0
    #15
    It's not that easy because the flood is coming from thousands of IP's a day.
     
    LH-Danny, Aug 28, 2008 IP
  16. nimhost

    nimhost Active Member

    Messages:
    235
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    58
    #16
    well i got the same situation with the thread starter couple of weeks ago

    i had hardening my server using iptables firewall and can block 100 ips automatically but the attacks has come more bigger then what i had expected then i contacting my dedicated server provider

    they scanning the ip which had come and banning thousand of ips in a day on their upstream side and till now the ip that already listed on their list is not opened until my instruction is given to them :)

    and till now my server is safe :)
     
    nimhost, Aug 28, 2008 IP
  17. Dollar

    Dollar Active Member

    Messages:
    2,598
    Likes Received:
    82
    Best Answers:
    0
    Trophy Points:
    90
    #17
    Glad to hear its not easy I first suspected.
     
    Dollar, Aug 28, 2008 IP
  18. Shazz

    Shazz Prominent Member

    Messages:
    8,395
    Likes Received:
    453
    Best Answers:
    0
    Trophy Points:
    330
    #18
    Really, no one knows about botnet here? I have tried every security forum....
     
    Shazz, Aug 28, 2008 IP
  19. Shazz

    Shazz Prominent Member

    Messages:
    8,395
    Likes Received:
    453
    Best Answers:
    0
    Trophy Points:
    330
    #19
    Update - I am now going with Danny's hosting site lenohost. Will see how long I stay with them :eek:
     
    Shazz, Aug 28, 2008 IP
  20. Shazz

    Shazz Prominent Member

    Messages:
    8,395
    Likes Received:
    453
    Best Answers:
    0
    Trophy Points:
    330
    #20
    Danny hosting didn't last me more then 2 hours, I got my refund.
     
    Shazz, Aug 30, 2008 IP