hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Web Hosting : Question on "DDOS" attacks
Reply

Web Hosting Discussions on all aspects of web hosting including past experiences (both negative and positive), choosing a host, questions and answers, and other related subjects. If your service is unavailable, please click here.
Forum Jump

Question on "DDOS" attacks

Reply Post New Thread In Web Hosting Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 01-08-2004, 04:05 PM
dgessler dgessler is offline
Web Hosting Master
 
Join Date: Dec 2000
Location: Chicago, IL
Posts: 565

Question on "DDOS" attacks


Someone has done another "DDOS" attack on my hosts server (the attacker was targetting my website), bringing all the sites down for about a day, and my sites are still down apparently because he had to disable the IP. This is the 2nd time in about 5 months this has happened. Is there really no way to prevent these attacks from destroying the server? It seems pretty disturbing someone can just do this to any website, really.. Just curious. I feel bad for my host, for the second time he's had to deal with this.. Any info on this subject would be appreciated, thanks.

Reply With Quote


Sponsored Links
  #2  
Old 01-08-2004, 05:20 PM
Amish_Geek Amish_Geek is offline
Web Hosting Master
 
Join Date: Mar 2003
Location: Duluth MN
Posts: 3,865
It depends on the security of your hosts server. If they have their server secured and properly monitored, they can set their firewall to drop all packets coming from the ddosser's IP(s)

__________________
http://www.amishgeek.com

Reply With Quote
  #3  
Old 01-08-2004, 05:23 PM
jackpot101 jackpot101 is offline
Junior Guru
 
Join Date: Jul 2003
Location: Florida
Posts: 221
Well DDOS are quiet hard to avoid..Unless you are on a network firewall that filters from the router before it even enters..Try one of the SM server with the firewall management system.

Reply With Quote
Sponsored Links
  #4  
Old 01-08-2004, 07:35 PM
dgessler dgessler is offline
Web Hosting Master
 
Join Date: Dec 2000
Location: Chicago, IL
Posts: 565
So it's really this easy to ruin someone's site? I'm surprised it doesn't happen as often? *sigh*

So most normal hosts won't have protection against this, will they?

Thanks for the info guys.

Reply With Quote
  #5  
Old 01-08-2004, 08:33 PM
2Grumpy 2Grumpy is offline
Grumpy Redneck
 
Join Date: Nov 2001
Location: The South
Posts: 5,405
Quote:
Originally posted by amish_geek
It depends on the security of your hosts server. If they have their server secured and properly monitored, they can set their firewall to drop all packets coming from the ddosser's IP(s)
Dropped or not, those packets are still coming in and can bring the network to a standstill.

In a bad DDOS you have to get with your upstream (and often upstream's upstream) to block the traffic.

__________________
Gary Harris - the artist formerly known as Dixiesys
resident grumpy redneck

Reply With Quote
  #6  
Old 01-08-2004, 08:55 PM
NexDog NexDog is offline
Web Hosting God
 
Join Date: Dec 2001
Location: Above The Clouds
Posts: 6,651
Gary is absolutely correct. In small DoS or SYN flood cases, the server can just ignore all the packets but in a hard attack, those packets are just going to flood the network so the data center has to filter at the router.

__________________
- Laurence Flynn - atOmicVPS LTD (Post Launch Craziness!)
- OnApp Powered Linux & Windows Cloud Hosting [Shared] [Reseller] [Cloud VPS]
- We are LIVE - find out what we are doing for our Post Launch phase!
- Featuring the atOmicSTACK - Speed ● Performance ● Stability ●


Reply With Quote
  #7  
Old 01-08-2004, 10:45 PM
Kerry Jones Kerry Jones is offline
Web Hosting Master
 
Join Date: Jun 2003
Location: FT Worth, TX
Posts: 5,098
I'm usually in SSH when a attack happens. I've stopped two DDOS Attacks in the last 2 weeks. Its actually a simple command to run. The following commands are the 3 most important commands you will need to know.

netstat
ip route add to unreachable [ip u wanna add]
ip route delete to [ip u blocked]

__________________
Kerry Jones

Reply With Quote
  #8  
Old 01-08-2004, 11:14 PM
TomK TomK is offline
Aspiring Evangelist
 
Join Date: Jul 2001
Location: Northern VA
Posts: 397
Kerry, this works in low-traffic DoS attacks, if anything major hits, 100mbs - Gb's of traffic, that won't do anything.

Tom

Reply With Quote
  #9  
Old 01-08-2004, 11:29 PM
dbbrock1 dbbrock1 is offline
Web Hosting Master
 
Join Date: Jul 2002
Posts: 2,240
And both those suggestions will work 10% of the time. Most attacks are from hundreds and hundreds and hundreds of different IPs.

__________________
Download my eBook + Videos: Starting your own successful web hosting company.
Learn from a web host with 7 years of experience.


Reply With Quote
  #10  
Old 01-08-2004, 11:30 PM
dgessler dgessler is offline
Web Hosting Master
 
Join Date: Dec 2000
Location: Chicago, IL
Posts: 565
And it was a pretty major hit I believe, my sites just came back online after my host blocking the IP's or whatever. Attack seems to be over. I guess this is what I get for running a site where literally the entire visitor population is comprised of kids, and some "wannabe" hackers.

Reply With Quote
  #11  
Old 01-09-2004, 12:19 AM
idologicJeff idologicJeff is offline
Web Hosting Master
 
Join Date: Mar 2003
Location: London Ontario, Canada
Posts: 984
Ok, lets say I had the skills to write software to conduct a DDOS - how would I do it?


CLIENT

I would start with virus software that exploits Microsoft's Distrubuted Object model. This gives the virus the ability to replicate itself and spread.

I now have a platform for conducting the DDOS. What then?

I write into the virus the ability to "call home". The virii contact an IRC server that I have set up to sit and listen, and they securely identify themselves to the IRCBOT seeking either instructions or a target.


IRCBOT

Of course the coder has no control of the spread of the virii, but the fact that they contact an IRCBOT (seeking instructions) means it doesn't matter.

The IRCBOT then feeds the IP address of a potential target to the clients calling home. When the virii phone in, they are given the IP, or instructions.

If the coder is stupid and without stealth - the virii commence sending malformed packets directly to the IP and they target a specific port.

If the coder has a bit more skill, they bounce the malformed packets of a middleman host (like an ftp server or something) so the packet appears to come from random IPS. Also, the malformed packets can't be traced back to the infected client. Also, target ports are randomly choosen and spread out (i.e. not in a narrow range)


DEFENSE

Now the first senario can be guarded against at the firewall layer through stateful packet inspection, because it targets a specific port, or narrow range of ports, and the IP's are not completely random.

If the second senario takes place - God help the victim! Not only are the source IP's forged, they are completely random (due to the packets being bounced off secondary (innocent) hosts) and they target random ports in wide ranges. Its extremeley difficult to guard against that.

Hope this helps you understand the problem. Good thing I don't have the skills (or inclination) or knowledge to write such beasts.

I only present this hypothetical senario to illustrate why DDOS can be real beasts.

Cheers
Jeff

__________________
www.idologic.com
www.demologic.com
A company committed to people serious about their websites - If you don't DO LOGIC - what do you do?Check Us Out



Last edited by idologicJeff; 01-09-2004 at 12:26 AM.
Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Three DNS Hosting Providers Report Possibly Linked DDoS Attacks Web Hosting News 2013-06-05 16:50:15
DDoS Mitigation Provider Prolexic Blocks Extended DDoS Attack Against Ecommerce Website Parts Geek Web Hosting News 2012-11-07 10:57:01
Web Host Tenzing Launches DDoS, DoS Mitigation Service Web Hosting News 2012-10-11 17:35:53
Web Host Yola Uses DDoS Mitigation Service Prolexic Web Hosting News 2011-12-07 20:42:42
WHIR TV - Rick from Neustar Discusses DDOS Threats and Defense Blog 2011-09-23 13:52:45


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?