
12-05-2011, 09:24 AM
|
|
Web Hosting Master
|
|
Join Date: Jan 2011
Posts: 552
|
|
How to permanently stop DOS attacks?
My cPanel server has recently been bombarded by romanians and people from hungary.
I've used country block in CSF, and that seems to have done the trick, but how can I stop this from happening again without blocking an entire country?
|

12-05-2011, 11:11 AM
|
|
Web Hosting Master
|
|
Join Date: Feb 2004
Location: UK
Posts: 1,429
|
|
Hi
You cant stop this from happening. Do you know who they are targetting on your server ?
Thanks
__________________
Relichost Budget Hosting Cpanel-14 Days R1soft-Weekly Monthly Cpanel Backups (off site)
VPS Servers / Dedi's on request.
|

12-05-2011, 11:14 AM
|
|
Urban Legend
|
|
Join Date: Feb 2006
Location: Global
Posts: 1,287
|
|
As said above, a DDoS can't be properly avoided, network level DDoS protection would help you though.
And finding who the attacks are being aimed at and looking at what's being targeted is a must.
__________________
High Performance, Super Fast 100% SSD Hosting, Resellers & VPS...
|

12-05-2011, 11:22 AM
|
|
Junior Guru
|
|
Join Date: Jun 2008
Location: South West, UK
Posts: 184
|
|
I'd recommend in getting a hardware firewall to start with, then its a long and winded process of tracing the IP's and blocking them.
However what exerox said is correct too you want to find out who they're attacking
__________________
James Little Operations Director Dream Servers Ltd
Dedicated Servers - Colocation - IP Transit - Data Storage - Managed Services - Cloud Web Hosting - Cloud vServers
|

12-06-2011, 04:36 PM
|
|
Web Hosting Master
|
|
Join Date: Jan 2011
Posts: 552
|
|
I'm still constantly being attacked from Romania and Hungary..
Any ideas how I can put a stop to this without blocking an entire country in CSF? They seem to constantly flood port 80, rather than attack a specific site on the server, and I've using CT_Limit = 100.
|

12-06-2011, 04:57 PM
|
|
Community Guide
|
|
Join Date: Jan 2006
Location: Athens, Greece
Posts: 1,479
|
|
|

12-06-2011, 09:13 PM
|
|
Web Hosting Master
|
|
Join Date: Nov 2004
Location: Australia
Posts: 1,440
|
|
CSF has some auto-blocking settings which could be worth experimenting with. If they persist they get permanently blocked, and if a number of IPs in a range get blocked CSF can be setup to block the entire range. If you play with the related settings for a while, along with some of the rate limiting stuff you may be able to get it going well enough to manage the blocking without your help. It may not be good enough to solve the problem, but it might be enough and it's definitely worth a shot.
Would be nice if you could update the thread and let us know how you went.
|

12-07-2011, 02:02 AM
|
|
Web Hosting Master
|
|
Join Date: Jan 2011
Posts: 552
|
|
Thanks for the replies guys...
I've tweaked CSF, and for the time being it seems that the attack is either getting smaller or the setting is quite strict so its blocking alot of traffic.
I'm using CT_LIMIT = 60, so I believe its blocking everyone who has more than 60 open connections on port 80 at the same time. I've also disabled Synflood feature in CSF as I dont think it has any benefit when used with CONNLIIMT. Let me know if I am wrong?
Can someone let me know where I can find Syn Deflate, I've installed DDos Deflate, but would like some protection against synflood attacks as well, and I think the synflood feature is not very good in CSF. All the download links I've seen for syn-deflate are broken.
Last edited by kshazad86; 12-07-2011 at 02:11 AM.
|

12-07-2011, 02:25 AM
|
|
Web Hosting Master
|
|
Join Date: Jan 2011
Posts: 552
|
|
Also, can someone let me know more about this IP range blocking.. I have it enabled on a setting of:
LS_DSHIELD = 86400
LF_SPAMHAUS =86400
But it would be nice to know exactly how this works? Thanks.
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
| Postbit Selector |
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|
| Login: |
|
|
| Advertisement: |
|
|
| Web Hosting News: |
|
|
|