APF And AntiDOS

Mar 24, 2007

I have installed APF. I also activated AntiDos that is part of APF.

I have changed the following in the config file:

Quote:

# Try to detect syn-flood attacks [0=off,1=on]
DET_SF="1"

The rest of settings are default. I have Intel Xeon-Woodcrest 5148-DualCore-LV [2.33GHz] server with 4 gigs of RAM. My web server is extremely slow.
I run commands, such as:

Quote:

netstat -pan | sort +4 |awk '{print$5}'| sed -e s/':.*'/''/g | sort | uniq -c | sort -k1 -nr | head -n 20
netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
netstat -plan|grep :80|awk {'print $5'}|cut -d: -f 1|sort|uniq -c|sort -nk 1
netstat -plan|grep :25|awk {'print $5'}|cut -d: -f 1|sort|uniq -c|sort -nk 1
netstat -nap | grep SYN | awk '{print $5}' | awk -F ":" '{print $1}' | sort | uniq -c | sort -n
netstat -n | grep SYN

Sometimes I see entries that indicate possible attack, such as:
Quote:

63 80.191.210.252

, but most of times, there are many IPs, example:

Quote:

24 85.133.177.70
20 89.178.184.215
18 83.11.216.179
15 84.234.0.183
7 87.228.120.88
7 172.188.3.203
6 202.84.43.178
5 89.178.45.124
4 85.117.72.151
2 202.40.181.72
2 217.172.29.7

Here are my questions: what is going on? I understand that apache is getting flooded, but any way to adjust APF's antidos to block those attacks?

ANy better solution? Does AntiDos feature of APF really work?

I've read about mod_evasive addon. Shall I install it, too?

Will there be a conflict between APF's AntiDos and mod_evasive running together?

My users are tired of waiting for forum to load.

View 14 Replies


ADVERTISEMENT

Antidos Setting

May 29, 2008

Can someone tell me the difference?

This comes from the antidos config.

# Trigger value before we drop an event SRC
TRIG="75"

# Trigger value before we drop syn-floods for SRC
SF_TRIG="75"

View 1 Replies View Related

Can't Remove The Ip Blocked By APF Antidos

Mar 2, 2007

APF Antidos blacklisted a number of ips that seem to be okay to me
I have tried to delete them with /etc/apf/apf -l , /etc/apf/apf --unban xxx.xx..,
and even iptables --flush no avail ! Where does apf store its ip rules. I guess that is /etc/apf/.ipt.chains but not found ..

looks like there was no command line option allowing to remove IPs from apf backlist

View 7 Replies View Related

How To Get BFD Or Antidos To Work On Ubuntu 5.10 / 6.06 --- Plesk 8?

Sep 18, 2006

Have been trying to get BFD and APF Antidos (not at same time) to work on Ubuntu 5.10 / Plesk and 6.06 (No Plesk yet) servers. APF appears to work fine after checking /sbin/iptables -L -n

Both cronjobs run but getting a lot of brute force attacks to ssh and Plesk but no offending IP's are being blocked and no e-mails reporting that they are being blocked. Log files for BFD and Antidos are always "0". Everything setup and configured the same as on my previous CentOS servers.

Can't find much on the net with this newer OS. Can anyone point me in the right direction to get one of these to work on the systems above? Thought it might be a path error referencing rc.d but put a symlink in for that and no change.

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved