View Full Version : Hammered by DDos
Hello all vb masters,
I've a forum (vb/3.5.4) with more than 2.6K members, and its
unders ddos (2 GB/s) attacks most of the time, we managed to hire a security company
in the US called prolexic.com to help us in mitigating the attacks by routing any request to the forum to them and then back to us (after/cleaning) and its working great.
The problem is that the server IP should be hidden & nobody should know about it.
>> I disabled sending/reciving any email from server to members
or the forum real IP will be exposed to direct attacks.
we are already paying USD5,000/month for the security company!
-- meaning
http://meemra.googlepages.com/emails-options-vb.JPG
is there a way to enable only
- Report bad post.
- contact us link.
and disable the rest
- email a member
- email this page a friend
- new post notifications to members
amykhar
05-22-2006, 06:07 PM
one suggestion - us a modification to report bad posts as either a pm or a post to a private forum. No need for email then.
Regarding the contact us form, Perhaps the check just needs to be removed for if email is enabled.
amykhar pls help. im waiting for answer for 3 weeks
in vbulletin.com they advised me to edit a template, put i dont know how and which one to edit.
stonyarc
05-22-2006, 06:14 PM
amykhar pls help. im waiting for answer for 3 weeks
ddos shouldn't be handled on your server alone but on the network layer on top.
Are you really paying 5000 to have them secure your server for a thing that should be handled on the core and underprinning routers??????
That doesn't seem real.
Have you contacted your Provider to have them block the trafic on a higher level. It's just a question of them uploading the correct firmwares and config files.
amykhar
05-22-2006, 06:16 PM
I'm at work right now and unable to help with the contact us form. But, look for Paul_M's reported post as a thread modification. Amy
beacuse of this ddos we move from one host to another (4)
rackspace they said we cant hadle these attacks,
also telecity ,
there was no option but go with prolexic
stonyarc
05-22-2006, 07:01 PM
beacuse of this ddos we move from one host to another (4)
rackspace they said we cant hadle these attacks,
also telecity ,
there was no option but go with prolexic
Very strange as normally every ddos is based on an exploit of some sort be it from the server or the network equipment.
Even so they must be able to trace the origin or the port of the attack. That should stop it cold with a little help from the supplier. Drop the trafic at the gates.
if you can trace the attacker origin , that would be just great ;)
can we discuss this ?
lets be realistic , they live on their mitigation solution.
we are now in another subject , is it possible to modify a template so that i can be able to recieve bad post and contact us only.
all my thanks to all
stonyarc
05-22-2006, 07:43 PM
if you can trace the attacker origin , that would be just great ;)
can we discuss this ?
lets be realistic , they live on their mitigation solution.
we are now in another subject , is it possible to modify a template so that i can be able to recieve bad post and contact us only.
all my thanks to all
If they live on the mitigation solution they sure must be able to log what exactly the ddos is targetting. Once you know the target you can start blocking it one hop each time (server/switch/router).
In principle you only need to block at the highest level to make it stop, then you can start on securing the layers below that.
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.