vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Forum and Server Management (https://vborg.vbsupport.ru/forumdisplay.php?f=232)
-   -   Massive DDos Attack. (https://vborg.vbsupport.ru/showthread.php?t=213692)

bigcurt 05-14-2009 04:12 PM

Massive DDos Attack.
 
Well, for the past going on 2 days now I have a received a massive DDos attack on my server from an unclaimed source. This is my first DDos attack ever, and hopefully my last. My server company ( URLJet ) has been great to try and help me, but they have given up hope as they have worked for the past day and the attack still persists. Do any of you guys have any suggestions to help me out? No idea why this is happening, considering this is our first ever attack..especially on this scale.


Thanks,
Curt

Lynne 05-14-2009 04:56 PM

Moved out of the Community Lounge.

We've gone through these and just had to basically wait it out (onec for four or so days). My server guy did write me a script which I turn on when we go through this and it will ban an ip when it pounds the server too much. Our iptables get filled, and the site will be slow, but at least the users can get on and see my message about us being under attack.

bigcurt 05-14-2009 05:00 PM

Quote:

Originally Posted by Lynne (Post 1810778)
Moved out of the Community Lounge.


We've gone through these and just had to basically wait it out (onec for four or so days). My server guy did write me a script which I turn on when we go through this and it will ban an ip when it pounds the server too much. Our iptables get filled, and the site will be slow, but at least the users can get on and see my message about us being under attack.

That must be a nice thing to have. So far, we have banned like 20 IP's..and they keep coming. I wish there was just some way I could get a message out to everyone saying we are under attack..but the site doesn't even come up :(.

motowebmaster 05-15-2009 01:38 AM

Banning an IP won't stop it from executing a DDOS attack. Are you running your own server, or a shared host?

bigcurt 05-15-2009 03:24 AM

It is a VPS plan with URLJet.

Dismounted 05-15-2009 06:54 AM

Depending on what they are pounding, you can try placing basic HTTP authentication in .htaccess (with user/pass displayed in the description). This is somewhat effective if they are attacking HTTP.

bigcurt 05-15-2009 12:01 PM

Quote:

Originally Posted by Dismounted (Post 1811063)
Depending on what they are pounding, you can try placing basic HTTP authentication in .htaccess (with user/pass displayed in the description). This is somewhat effective if they are attacking HTTP.

I am fairly sure the host has already tried that. I figured out that this is a "100mps UDP Attack". They are also using stolen EU dedicated servers to do it.

Brandon Sheley 05-15-2009 01:21 PM

If your with a decent host, they should be able to help you out
I know when I've been under attack, my host has added some lines to the htaccess to help with the attacks

Wayne Luke 05-15-2009 01:36 PM

A good host can redirect these attacking IP addresses at the primary router level where the bandwidth is in the hundreds of gigabytes per second and not let them into their own network where it will cause problems for all their customers as the bottlenecks get smaller and smaller. With a DDOS, once the IP addresses have gotten to the server level, you've pretty much lost. Especially when the attacking addresses number in the thousands.

When vBulletin.com was DDOSed once we had to block of entire continents worth of IP addresses and then slowly open them up later.

royo 05-15-2009 01:39 PM

No company has hundreds of gigabytes per second, maybe gigabits, and you can't simply redirect an attack by flipping a switch. The company will need to work with their upstream providers to resolve the issue most of the time, it's either that or absorbing the attack.


All times are GMT. The time now is 10:00 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01198 seconds
  • Memory Usage 1,737KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete