1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Second DDOS Attack... this guy has no life

Discussion in 'Security' started by hotnoob, Oct 19, 2011.

  1. #1
    Just got DDOSed again, took me a little while to block this one, because i blocked myself by mistake lol :p

    anyways...

    last ddos attack i reported it to the FBI, which i really doubt they will do anything...

    so who else can i report it to?

    here is a list of the ips of the attackers, if you are interested: http://hotnoob.com/share/ddos_ips_oct19-2011.txt
    ---

    this attack was much different, from the looks of it, the attacker(same as before), tried to brute force into my mail system, so i had to disable that.
    fail2ban wasn't seeming to work; if it were working, my server would have never had 67 of the cpu cores running full blast.


    at the same time there was a brute force attack at the lpad, and AGAIN a 3 combo ddos attack was hitting(because of my current security, the combo ddos basically did nothing). seemed to be a mixture of a java based ddos program, and possibly LOIC (really pathetic that they used it lol); i'm not sure if it was a stupid skid group or a botnet who did this; seems to be a botnet due to how organized it is, but there is a lot of evidence that its not.
    also like before, shortly after i blocked it all, the attack stopped; does this loser have no life?

    also, this is a real issue with my bandwidth, i'm already at 2.3TB for this month, and its only half way through.

    any ideas on what i should do?
     
    Last edited: Oct 19, 2011
    hotnoob, Oct 19, 2011 IP
  2. vpslist

    vpslist Peon

    Messages:
    88
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #2
    FBI won't do anything unless you can prove over $5000 in damages.

    Is this a webserver or do you run multiple services on this?
     
    vpslist, Oct 19, 2011 IP
  3. supportex

    supportex Peon

    Messages:
    66
    Likes Received:
    0
    Best Answers:
    1
    Trophy Points:
    0
    #3
    More effectively write abuses to ISP. If you can not cope with DDoS attacks alone, you'd better use the services of companies providing DDoS protection.
     
    supportex, Oct 20, 2011 IP
  4. vpslist

    vpslist Peon

    Messages:
    88
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #4
    This guy doesn't listen.

    I looked and I gave him advice to fix this almost 2 weeks ago. He seems to prefer to insult the people who are ruining him in posts like this and probably will post something in two weeks saying that it has gotten worse.
     
    vpslist, Oct 20, 2011 IP
  5. hotnoob

    hotnoob Member

    Messages:
    96
    Likes Received:
    2
    Best Answers:
    1
    Trophy Points:
    28
    #5
    cloudflare does not work for video streaming.
     
    hotnoob, Oct 21, 2011 IP
  6. Jay-S

    Jay-S Member

    Messages:
    201
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    36
    #6
    I would recommend buying a hardware based firewall for your server or moving to a host that offers DDoS protection.

    Also, write a script to send abuse emails to the ISPs of all those IP addresses.
     
    Jay-S, Oct 22, 2011 IP
  7. raffo77

    raffo77 Active Member

    Messages:
    234
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #7
    You can setup a server firewall based on FreeBSD + Nginx + PF
    If you want to learn more i can teach you for free.

    Don't buy expensive DDoS protection ;)
     
    raffo77, Nov 13, 2011 IP
  8. 7h3 Wh173 R4bb17

    7h3 Wh173 R4bb17 Peon

    Messages:
    19
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    I was under the impression that DDOS was almost impossible to protect against due to the attacker changing their IP address at certain intervals to avert the IP blocking?
     
    7h3 Wh173 R4bb17, Nov 22, 2011 IP
  9. Qarizma

    Qarizma Member

    Messages:
    55
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    45
    #9
    Since when you can report to the FBI?

    But may I ask what are you hosting?
     
    Qarizma, Nov 23, 2011 IP
  10. blockdos

    blockdos Active Member

    Messages:
    96
    Likes Received:
    0
    Best Answers:
    3
    Trophy Points:
    71
    #10
    Depends on the budget you have and size of attack whether you can fight it or not. If it is not consuming your port and you have enough processing power on the box you have a fighting chance. If it is consuming port there is a number of things you can do from setting up failover clusters to getting more bandwidth/ram and such.

    And yes you can do nearly all this for a fraction of the cost of these expensive ddos protection services.
     
    blockdos, Nov 29, 2011 IP
  11. JamesZach

    JamesZach Peon

    Messages:
    12
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    67 cpu cores?? What kinda server is that? Also what was the traffic that you encountered in PPS?
     
    JamesZach, Dec 5, 2011 IP
  12. gohighvoltage

    gohighvoltage Greenhorn

    Messages:
    14
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    13
    #12
    CSF + LFD works awesome and it is free. I use it and it offers great protection.
     
    gohighvoltage, Dec 16, 2011 IP
  13. amigoserv.com

    amigoserv.com Peon

    Messages:
    35
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #13
    with some specific rules or use as it is if you have no experience

    Note: The Node must support iptables modules for runnig CSF
     
    amigoserv.com, Jan 4, 2012 IP