1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Wich are the best protection software and hardware against DDOS attacks any suggestio

Discussion in 'Security' started by Truth777, Oct 13, 2007.

  1. #1
    Wich are the best protection software and hardware against DDOS attacks, any suggestions?
    Thanks
     
    Truth777, Oct 13, 2007 IP
    Briant likes this.
  2. hostparlor

    hostparlor Peon

    Messages:
    521
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #2
    mod_evasive be careful with how tightly you set the settings though it can cause real problems with high imaged sites. Install csf and lfd on your server and advanced mod_security filters.
     
    hostparlor, Oct 13, 2007 IP
  3. Truth777

    Truth777 Peon

    Messages:
    519
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #3
    I've heard that DP was under DDOS attack.
    How did they manage to block it?
     
    Truth777, Oct 13, 2007 IP
  4. Ladadadada

    Ladadadada Peon

    Messages:
    382
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    0
    #4
    There's a company called prolexic that specialises in helping you survive DDoS attacks.

    Basically, the guy who started it had an idea that he could buy up loads of bandwidth, transfer the target's IP address to his servers, filter out the DDoS and pass the normal traffic on to the original site.

    It worked really well so he started an entire company based around that premise.

    Generally, the way a DDoS (as opposed to a DoS) works is that they flood you with so many requests that the 1% of your traffic that are legitimate users are unlikely to get the website they want. If you can identify the offending packets cheaply, and drop them then you might be able to survive but it's usually quite difficult to identify them as they often look like normal traffic and come from a large range of IP addresses.

    Sometimes they will try to keep the TCP connection open so that no-one else can connect on that port for a few minutes until the connection times out. Lowering your tcp connection timeout value can help with this sort of attack.

    Most likely, however, is that you won't have the processing power or bandwidth to deal with the problem yourself, and often the problem is not with your server but with the router just upstream from you.

    Most people, when confronted with a DDoS, call up their upstream provider and ask them to block the offending packets.
     
    Ladadadada, Oct 14, 2007 IP