hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : DDOS potection. Does it exist?
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

DDOS potection. Does it exist?

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 11-15-2006, 06:12 PM
|venom| |venom| is offline
New Member
 
Join Date: Nov 2006
Posts: 2

DDOS potection. Does it exist?


I have just opened a site that got very popular within the first week and I made alot of webmasters unhappy since all their members are coming to my site. They are now ddosing the socks off of me. I purchased an "anti-ddos server but that only helped a little. If I only keep the main page up everything works fine but when I enable the forum the site completly shuts down due to the extreme ddosing.
So is there anyway to protect myself effectively? or should I just give in to the other webmasters and delete my site?

Reply With Quote


Sponsored Links
  #2  
Old 11-15-2006, 06:14 PM
Steven Steven is offline
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,625
what provider are you using?

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #3  
Old 11-15-2006, 06:17 PM
|venom| |venom| is offline
New Member
 
Join Date: Nov 2006
Posts: 2
blacklotus.com

Reply With Quote
Sponsored Links
  #4  
Old 11-15-2006, 06:54 PM
Steven Steven is offline
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,625
Contact http://awknet.com/ and explain the issue you are having.

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #5  
Old 11-15-2006, 09:35 PM
linux-tech linux-tech is offline
<?require_once("life")?>
 
Join Date: Sep 2002
Location: inside your network
Posts: 9,548
Quote:
when I enable the forum the site completly shuts down due to the extreme ddosing.
This doesn't sound like something that's a DDOS issue, more like a poor programming issue. If it was truly a DDOS issue, they would be trying to take your site down completely, not just parts of it.

Go through your system, make sure that the forums are configured properly, and that you have no redirects, because it really sounds like something is wrong, not with a DDOS attack, but with your forums and the configuration thereof.

__________________
Linux Tech Networks Reliable, Affordable Linux administration and monitoring since 2002

Reply With Quote
  #6  
Old 11-16-2006, 02:10 AM
packetm0nkey packetm0nkey is offline
WHT Addict
 
Join Date: Oct 2004
Posts: 150
Quote:
Originally Posted by linux-tech
This doesn't sound like something that's a DDOS issue, more like a poor programming issue. If it was truly a DDOS issue, they would be trying to take your site down completely, not just parts of it.

Go through your system, make sure that the forums are configured properly, and that you have no redirects, because it really sounds like something is wrong, not with a DDOS attack, but with your forums and the configuration thereof.
? Well serving a likely static index page vs a DB driven forum is completely different. The attack he could be experiencing is likely a resource starvation attack aimed at overload the server by way of excessive form/DB load. Not all attacks are created equal...

Reply With Quote
  #7  
Old 11-16-2006, 06:22 AM
eymbo eymbo is offline
Junior Guru Wannabe
 
Join Date: Jun 2006
Posts: 57
Quote:
Originally Posted by packetm0nkey
? Well serving a likely static index page vs a DB driven forum is completely different. The attack he could be experiencing is likely a resource starvation attack aimed at overload the server by way of excessive form/DB load. Not all attacks are created equal...
It depends, from what I see linux-tech is correct. His services doesn't sound like it's distributed throughout many servers so if the forum goes down the static files and site's should also go down if it was a ddos attack. But in his case, the static files continue serving even if the forum is down.

If you are being ddosed, I'd suggest you to install or enable mod_status and find out which IP keeps ddosing you. Then use iptables to block off the IP.

Reply With Quote
  #8  
Old 11-16-2006, 06:25 AM
bqinternet bqinternet is offline
Backup Guru
 
Join Date: Feb 2002
Location: New York, NY
Posts: 4,444
It sounds to me like your site is just a victim of its own popularity, and can no longer handle the load. Forum software generates quite a bit of load, so a server can become inaccessible even with modest traffic to a forum.

__________________
Scott Burns, President
BQ Internet Corporation
Remote Rsync and FTP backup solutions
*** http://www.bqbackup.com/ ***

Reply With Quote
  #9  
Old 11-17-2006, 02:32 PM
IRCCo Jeff IRCCo Jeff is online now
CISSP, CISA
 
Join Date: Aug 2002
Location: Los Angeles, CA
Posts: 5,038
Quote:
Originally Posted by |venom|
blacklotus.com
Which product did you purchase? We have four diffrent DDoS solutions and it is critical that you be outfitted with the one that best meets your needs.

Dollar for dollar the DDoS protection you would purchase elsewhere would be equal or less to what you're getting now unless you're able to adjust your budget and purchase the correct solution.

Submit a ticket at https://support.blacklotus.net with your exact concern and we will look into the situation. If you already have a ticket number, please PM it to me.

__________________
Black Lotus - Carrier Neutral Datacenter & DDoS Mitigation Solutions
Access to over 200 carriers | 60A per cabinet | Local, remote, proxy, and BGP GRE DDoS protection

>>> Take a virtual tour of the Black Lotus LA2 datacenter, our own Tier III facility


Reply With Quote
  #10  
Old 11-17-2006, 02:36 PM
IRCCo Jeff IRCCo Jeff is online now
CISSP, CISA
 
Join Date: Aug 2002
Location: Los Angeles, CA
Posts: 5,038
|venom|,

I just spoke with my technical support. Is this a shared account? Please feel free to contact me off board if you're not comfortable providing specifics.

__________________
Black Lotus - Carrier Neutral Datacenter & DDoS Mitigation Solutions
Access to over 200 carriers | 60A per cabinet | Local, remote, proxy, and BGP GRE DDoS protection

>>> Take a virtual tour of the Black Lotus LA2 datacenter, our own Tier III facility


Reply With Quote
  #11  
Old 11-17-2006, 02:38 PM
DiverGuy DiverGuy is offline
Junior Guru Wannabe
 
Join Date: May 2005
Posts: 55
I, too, am rather suprised at this posting.

The only customer I know of, who is having ddos isues, related to a website, is one of our shared hosting customers.

I have personally worked hand in hand with that customer and have even been on the phone with them.

Their site is coded in php and someone is hitting them with a botnet attack. It is a slow steady attack with about 100 VALID connections every second. Their site was coded in php and the P4 2.8ghz cpu jumps to 70% load when their IP was opened to public.

Once they coded their front page with an access key, to avoid the botnet, their site stabilized.

I'm very curious who this mysterious customer is and why they have not opened a support ticket with us to look into solving the problem.

__________________
Abuse Department & Customer Service

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
DDoS Mitigation Provider Prolexic Blocks Extended DDoS Attack Against Ecommerce Website Parts Geek Web Hosting News 2012-11-07 10:57:01
Security Firm Prolexic Launches Online Resource Portal for DDoS Mitigation Web Hosting News 2012-01-19 12:55:48
Web Host Yola Uses DDoS Mitigation Service Prolexic Web Hosting News 2011-12-07 20:42:42
New on WHIR TV: Kevin Hatfield of ServerOrigin Talks DDoS Protection Blog 2011-11-10 15:19:09
WHIR TV - Rick from Neustar Discusses DDOS Threats and Defense Blog 2011-09-23 13:52:45


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?