The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
Attacks
DDoS attacks, Botnet attacks, or any other http flood attacks on forums that we all own.
Is it possible to create a scripting of any language to block that such stuff? |
#2
|
||||
|
||||
Such attacks cannot be effectively "fought" at the server level. They are best dealt with at the router, or with the upstream provider. These are things you cannot do yourself, and are best dealt with by consulting your host.
Also see the other threads in this section. |
#3
|
||||
|
||||
Alright ill read them, but there has to be a way in the software that you can manually plug in the scripting to block all connections over 1000+ from the same ip in 10 seconds or less.
|
#4
|
||||
|
||||
Imagine a pipe to your server. This pipe carries data. If this pipe is full of data, nothing else can get through. Even if you "block" packets at the server level, the pipe is still full...
I'm not saying you can't use software to block incoming connections, I'm just saying it is ineffective for all but the weakest of attacks. |
#5
|
||||
|
||||
I understand that but what are ways you can? like whats been discovered?
|
#6
|
||||
|
||||
You can use an Apache module, such as mod_evasive.
|
#7
|
||||
|
||||
Alright ill look into it. I just need ideas of what to add to my site as well. =X oh well thanks for the help.
|
#8
|
||||
|
||||
There are also scripts, and command lines, you can use along with the iptables to grab 'bad' ips and block them (google is your friend to find them). Again, this is at the server level and not effective against someone who is determined to cause you problems.
|
#9
|
||||
|
||||
Quote:
"One common method of attack involves saturating the target (victim) machine with external communications requests, such that it cannot respond to legitimate traffic, or responds so slowly as to be rendered effectively unavailable." US-Certs confirms it also: "Unfortunately, there are no effective ways to prevent being the victim of a DoS or DDoS attack, but there are steps you can take to reduce the likelihood that an attacker will use your computer to attack other computers." Whoever tells you they can stop a DDoS attack, they are telling you big red lies. There is no way in the world you will stop (for example) a russian hacker who wants to keep your site down for a month. |
#10
|
||||
|
||||
CSF&LFD will do this, but again it won't give you full protection.
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|