Quote:
Originally Posted by Lynne
You are making the assumption that a user will first login to the forums prior to the game server? Is that always true? Personally, I'd do something with the server iptables to block ips that pound the server. Or, I'd talk to the host about different methods available to combat a dos attack.
|
After 3 days of being constantly DDOS'd we've tried those.
Our host will provide DDOS protection.... for $1,000 a month - so thats a non starter
We frequently run a PHP script to scan the apache access_log, find anything that has requested the same "GET" in a short time then add it to the IPTABLES list - this is working and catching about 80-90% of the ddos but its a task we have to run every few hours as and when new zombies power up
All players have been told if they are on DHCP they will need to browse the forums before they can loginto the game to ensure their IP is authorised, and they are happy with this if it will reduce the LAG of the current packet filter