Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 05-22-2006, 05:58 PM
Zolo Zolo is offline
 
Join Date: May 2006
Posts: 15
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Hammered by DDos

Hello all vb masters,

I've a forum (vb/3.5.4) with more than 2.6K members, and its
unders ddos (2 GB/s) attacks most of the time, we managed to hire a security company
in the US called prolexic.com to help us in mitigating the attacks by routing any request to the forum to them and then back to us (after/cleaning) and its working great.

The problem is that the server IP should be hidden & nobody should know about it.

>> I disabled sending/reciving any email from server to members
or the forum real IP will be exposed to direct attacks.

we are already paying USD5,000/month for the security company!

-- meaning


http://meemra.googlepages.com/emails-options-vb.JPG

is there a way to enable only
- Report bad post.
- contact us link.


and disable the rest
- email a member
- email this page a friend
- new post notifications to members
Reply With Quote
  #2  
Old 05-22-2006, 06:07 PM
amykhar's Avatar
amykhar amykhar is offline
 
Join Date: Oct 2001
Location: PA
Posts: 4,438
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

one suggestion - us a modification to report bad posts as either a pm or a post to a private forum. No need for email then.

Regarding the contact us form, Perhaps the check just needs to be removed for if email is enabled.
Reply With Quote
  #3  
Old 05-22-2006, 06:08 PM
Zolo Zolo is offline
 
Join Date: May 2006
Posts: 15
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

amykhar pls help. im waiting for answer for 3 weeks

in vbulletin.com they advised me to edit a template, put i dont know how and which one to edit.
Reply With Quote
  #4  
Old 05-22-2006, 06:14 PM
stonyarc stonyarc is offline
 
Join Date: Aug 2005
Location: Leuven (Belgium)
Posts: 930
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zolo
amykhar pls help. im waiting for answer for 3 weeks
ddos shouldn't be handled on your server alone but on the network layer on top.

Are you really paying 5000 to have them secure your server for a thing that should be handled on the core and underprinning routers??????

That doesn't seem real.

Have you contacted your Provider to have them block the trafic on a higher level. It's just a question of them uploading the correct firmwares and config files.
Reply With Quote
  #5  
Old 05-22-2006, 06:16 PM
amykhar's Avatar
amykhar amykhar is offline
 
Join Date: Oct 2001
Location: PA
Posts: 4,438
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I'm at work right now and unable to help with the contact us form. But, look for Paul_M's reported post as a thread modification. Amy
Reply With Quote
  #6  
Old 05-22-2006, 06:25 PM
Zolo Zolo is offline
 
Join Date: May 2006
Posts: 15
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

beacuse of this ddos we move from one host to another (4)
rackspace they said we cant hadle these attacks,
also telecity ,

there was no option but go with prolexic
Reply With Quote
  #7  
Old 05-22-2006, 07:01 PM
stonyarc stonyarc is offline
 
Join Date: Aug 2005
Location: Leuven (Belgium)
Posts: 930
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zolo
beacuse of this ddos we move from one host to another (4)
rackspace they said we cant hadle these attacks,
also telecity ,


there was no option but go with prolexic
Very strange as normally every ddos is based on an exploit of some sort be it from the server or the network equipment.

Even so they must be able to trace the origin or the port of the attack. That should stop it cold with a little help from the supplier. Drop the trafic at the gates.
Reply With Quote
  #8  
Old 05-22-2006, 07:22 PM
Zolo Zolo is offline
 
Join Date: May 2006
Posts: 15
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

if you can trace the attacker origin , that would be just great
can we discuss this ?

lets be realistic , they live on their mitigation solution.


we are now in another subject , is it possible to modify a template so that i can be able to recieve bad post and contact us only.


all my thanks to all
Reply With Quote
  #9  
Old 05-22-2006, 07:43 PM
stonyarc stonyarc is offline
 
Join Date: Aug 2005
Location: Leuven (Belgium)
Posts: 930
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zolo
if you can trace the attacker origin , that would be just great
can we discuss this ?

lets be realistic , they live on their mitigation solution.


we are now in another subject , is it possible to modify a template so that i can be able to recieve bad post and contact us only.


all my thanks to all
If they live on the mitigation solution they sure must be able to log what exactly the ddos is targetting. Once you know the target you can start blocking it one hop each time (server/switch/router).

In principle you only need to block at the highest level to make it stop, then you can start on securing the layers below that.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:31 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.11599 seconds
  • Memory Usage 2,238KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (9)post_thanks_box
  • (9)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (9)post_thanks_postbit_info
  • (9)postbit
  • (9)postbit_onlinestatus
  • (9)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete