
12-25-2009, 02:03 AM
|
|
Junior Guru Wannabe
|
|
Join Date: May 2005
Posts: 52
|
|
DDOS attacks for 24 hours. Nothing can do but wait?!
My server has been under DDOS attacks for 24 hours.
I reported to the hosting company's technical support.
They blocked a few IP addresses, but the situation was also not improved at all.
Latter they told me that all I can do is to wait till the DDOS attacks come to an end on their own.
Is there anything I can do besides wait? My server has been unable to access for 24 hours, and I simply have to blow a gasket.
|

12-25-2009, 02:34 AM
|
|
Web Hosting Evangelist
|
|
Join Date: Oct 2007
Posts: 537
|
|
The Type of DDOS attack should be recoginzed. I am sure the server needs some fine tuning to reduce the amount of attack.
|

12-25-2009, 02:37 AM
|
|
Junior Guru Wannabe
|
|
Join Date: May 2005
Posts: 52
|
|
Quote:
Originally Posted by Srv24x7
The Type of DDOS attack should be recoginzed. I am sure the server needs some fine tuning to reduce the amount of attack.
|
How? which aspects shall I focus on?
|

12-25-2009, 02:40 AM
|
|
Web Hosting Evangelist
|
|
Join Date: Oct 2007
Posts: 537
|
|
Is the attack on port 80 ? Have you installed a firewall ? Your kernel should handle syncookies packet if they are flooding on port 80.
|

12-25-2009, 04:23 AM
|
|
I like ice cream
|
|
Join Date: Mar 2003
Location: California USA
Posts: 11,589
|
|
We really need to know the type of attack before members can offer solutions or suggestions.
|

12-25-2009, 04:40 AM
|
|
Junior Guru Wannabe
|
|
Join Date: May 2005
Posts: 52
|
|
Quote:
|
We really need to know the type of attack before members can offer solutions or suggestions.
|
It's kind of sync flooding...
|

12-25-2009, 04:54 AM
|
|
Web Hosting Master
|
|
Join Date: Jul 2009
Posts: 1,492
|
|
Quote:
Originally Posted by wula
It's kind of sync flooding...
|
Right, but what is the density of the attack is. If it's a light weight SYN attack, you can configure CSF firewall and use the SYN FLOOD option to mitigate it.
You can enable syncookies and increase backlog queue using /etc/sysctl.conf. Backlog queue is used to support more connections in the half-open state but it reserves additional memory resources so you have to make sure your server have enough memory else it will impact on system performance.
If the attack is too heavy, CSF OR APF won't help and you will have to look for a Hardware firewall.
|

12-25-2009, 05:06 AM
|
|
Junior Guru Wannabe
|
|
Join Date: May 2005
Posts: 52
|
|
Quote:
|
If the attack is too heavy, CSF OR APF won't help and you will have to look for a Hardware firewall.
|
According to tech support, the attack is VERY heavy. So shall I buy a hardware firewall or the hosting company will do some settings?
|

12-25-2009, 05:13 AM
|
|
Web Hosting Master
|
|
Join Date: Jul 2009
Posts: 1,492
|
|
Quote:
Originally Posted by wula
According to tech support, the attack is VERY heavy. So shall I buy a hardware firewall or the hosting company will do some settings?
|
If the attack is too heavy CSF or APF can't do anything. "Proxy Sheild" firewall offered by Gigenet is very effective in such situations but it's too costly. Check what your hosting company has to say as they are the one who are investigating and knows better.
|

12-25-2009, 08:06 AM
|
|
Support Facility
|
|
Join Date: Jun 2009
Posts: 2,318
|
|
The doss attack normally targets HTTP. Its always good to have filtering system for apache. So get installed mod_security it work. Update Apache to the latest version.
|

12-25-2009, 08:21 AM
|
|
Web Hosting Master
|
|
Join Date: Jul 2009
Posts: 1,492
|
|
mod_security? Are you sure? Mod Security only comes in to play once the 3 way handshake is completed...
|

12-25-2009, 09:51 AM
|
|
[ VPS Enthusiast ]
|
|
Join Date: Nov 2009
Location: Cheltenham, UK
Posts: 1,323
|
|
Christmas is obviously a prime time for DoS/DDoS attacks - maybe because people assume there will not be anyone about to do something about it?
We've just had a DoS attack too - luckily just a small scale one from one IP and CSF took care of it temporarily, then I just permanently banned the IP.
CSF is great for fending off small attacks, though as others have said unfortunately it can not do much for large scale ones.
Hope yours ends soon!
__________________
█ Ben Thomas, Director - BTCentral Web Development Services
█ http://www.btcentral.org.uk - Need a custom Web App? Visit us online.
Last edited by BTCentral - Ben; 12-25-2009 at 10:04 AM.
Reason: typo
|

12-25-2009, 09:55 AM
|
|
Junior Guru Wannabe
|
|
Join Date: May 2005
Posts: 52
|
|
Quote:
Christmas is obviously a prime time for DoS/DDoS attacks - maybe because people assume there will not be anyone about to do something about it?
We've just had a DoS attack too - luckily just a small scale one from one IP and CSF took care of temporarily, then I just permanently banned the IP.
CSF is great for fending off small attacks, though as others have said unfortunately it can not do much for large scale ones.
Hope yours ends soon!
|
You're lucky. The attack flood here suspends for a few hours. But not sure whether it comes back again.
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
| Postbit Selector |
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|
| Login: |
|
|
| Advertisement: |
|
|
| Web Hosting News: |
|
|
|