Go Back   vb.org Archive > Community Discussions > Forum and Server Management
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 05-14-2009, 04:12 PM
bigcurt's Avatar
bigcurt bigcurt is offline
 
Join Date: Nov 2004
Location: KierDarby.php
Posts: 1,009
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Massive DDos Attack.

Well, for the past going on 2 days now I have a received a massive DDos attack on my server from an unclaimed source. This is my first DDos attack ever, and hopefully my last. My server company ( URLJet ) has been great to try and help me, but they have given up hope as they have worked for the past day and the attack still persists. Do any of you guys have any suggestions to help me out? No idea why this is happening, considering this is our first ever attack..especially on this scale.


Thanks,
Curt
Reply With Quote
  #2  
Old 05-14-2009, 04:56 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Moved out of the Community Lounge.

We've gone through these and just had to basically wait it out (onec for four or so days). My server guy did write me a script which I turn on when we go through this and it will ban an ip when it pounds the server too much. Our iptables get filled, and the site will be slow, but at least the users can get on and see my message about us being under attack.
Reply With Quote
  #3  
Old 05-14-2009, 05:00 PM
bigcurt's Avatar
bigcurt bigcurt is offline
 
Join Date: Nov 2004
Location: KierDarby.php
Posts: 1,009
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Lynne View Post
Moved out of the Community Lounge.


We've gone through these and just had to basically wait it out (onec for four or so days). My server guy did write me a script which I turn on when we go through this and it will ban an ip when it pounds the server too much. Our iptables get filled, and the site will be slow, but at least the users can get on and see my message about us being under attack.
That must be a nice thing to have. So far, we have banned like 20 IP's..and they keep coming. I wish there was just some way I could get a message out to everyone saying we are under attack..but the site doesn't even come up .
Reply With Quote
  #4  
Old 05-15-2009, 01:38 AM
motowebmaster motowebmaster is offline
 
Join Date: Feb 2006
Posts: 62
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Banning an IP won't stop it from executing a DDOS attack. Are you running your own server, or a shared host?
Reply With Quote
  #5  
Old 05-15-2009, 03:24 AM
bigcurt's Avatar
bigcurt bigcurt is offline
 
Join Date: Nov 2004
Location: KierDarby.php
Posts: 1,009
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It is a VPS plan with URLJet.
Reply With Quote
  #6  
Old 05-15-2009, 06:54 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Depending on what they are pounding, you can try placing basic HTTP authentication in .htaccess (with user/pass displayed in the description). This is somewhat effective if they are attacking HTTP.
Reply With Quote
  #7  
Old 05-15-2009, 12:01 PM
bigcurt's Avatar
bigcurt bigcurt is offline
 
Join Date: Nov 2004
Location: KierDarby.php
Posts: 1,009
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Dismounted View Post
Depending on what they are pounding, you can try placing basic HTTP authentication in .htaccess (with user/pass displayed in the description). This is somewhat effective if they are attacking HTTP.
I am fairly sure the host has already tried that. I figured out that this is a "100mps UDP Attack". They are also using stolen EU dedicated servers to do it.
Reply With Quote
  #8  
Old 05-15-2009, 01:21 PM
Brandon Sheley's Avatar
Brandon Sheley Brandon Sheley is offline
 
Join Date: Mar 2005
Location: Google Kansas
Posts: 4,678
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

If your with a decent host, they should be able to help you out
I know when I've been under attack, my host has added some lines to the htaccess to help with the attacks
Reply With Quote
  #9  
Old 05-15-2009, 01:36 PM
Wayne Luke's Avatar
Wayne Luke Wayne Luke is offline
Senior Member
 
Join Date: Jan 2002
Location: Southern California
Posts: 1,694
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

A good host can redirect these attacking IP addresses at the primary router level where the bandwidth is in the hundreds of gigabytes per second and not let them into their own network where it will cause problems for all their customers as the bottlenecks get smaller and smaller. With a DDOS, once the IP addresses have gotten to the server level, you've pretty much lost. Especially when the attacking addresses number in the thousands.

When vBulletin.com was DDOSed once we had to block of entire continents worth of IP addresses and then slowly open them up later.
Reply With Quote
  #10  
Old 05-15-2009, 01:39 PM
royo royo is offline
 
Join Date: Jan 2005
Posts: 80
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

No company has hundreds of gigabytes per second, maybe gigabits, and you can't simply redirect an attack by flipping a switch. The company will need to work with their upstream providers to resolve the issue most of the time, it's either that or absorbing the attack.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:16 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04333 seconds
  • Memory Usage 2,247KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete