How To Secure Your Web From FLOOD ; Ddos ; Etc
			Jun 20, 2007
				some of my friend website is under attack by Ddos ; FLOOD ; and other way to down his site !
how can we save him from these attacks? 
else the firewall!
1- is there any program or script to prevent these attacks! 
2- is there any rules or script's for Firewall to prevent it!
	
	View 4 Replies
  
    
		
ADVERTISEMENT
    	
    	
        Jun 25, 2008
        one of my costumers server is getting ddos attacks. I solved syn and get attacks with litespeed web server but I have another problem. They started to do udp flood. I m losing connection to my server. I bought new server with 1 gbit port for solving it.
	View 3 Replies
    View Related
  
    
	
    	
    	
        May 17, 2009
        way to secure apache from ddos attack's on centos 5.3.
	View 7 Replies
    View Related
  
    
	
    	
    	
        May 11, 2009
        I've been getting a syn flood for the last week or so. 
I've pretty much tried everything I could online but have been unsuccessful in stopping them. 
I talked to the data center techs and they basically can't put a stop to it either. 
Here's a very small portion of my netstat
tcp        0      0 xxx.xxx.xxx.xxx:80          86.50.121.144:8540          SYN_RECV    -
tcp        0      0 xxx.xxx.xxx.xxx:80          41.100.16.152:7824          SYN_RECV    -
tcp        0      0 xxx.xxx.xxx.xxx:80          52.53.22.7:3146             SYN_RECV    -
tcp        0      0 xxx.xxx.xxx.xxx:80          77.217.49.124:1659          SYN_RECV    -
tcp        0      0 xxx.xxx.xxx.xxx:80          75.162.93.151:3230          SYN_RECV    -
tcp        0      0 xxx.xxx.xxx.xxx:80          113.85.63.249:1656          SYN_RECV    -
tcp        0      0 xxx.xxx.xxx.xxx:80          15.253.35.29:8849           SYN_RECV    -
tcp        0      0 xxx.xxx.xxx.xxx:80          24.56.59.180:6911           SYN_RECV    -
tcp        0      0 xxx.xxx.xxx.xxx:80          33.185.99.83:1917           SYN_RECV    -
tcp        0      0 xxx.xxx.xxx.xxx:80          103.5.8.249:4782            SYN_RECV    -
root@xxx [/]# netstat -nap |grep SYN |wc -l
2008
The IP's change often and it's not possible to narrow it down. 
So far the things I have done;
syn cookies enabled
reduced time out
echo "1" > /proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_syn_recv
increased 
echo "150000" > /proc/sys/net/ipv4/ip_conntrack_max
installed apf but it slowed down the server to a crawl which made my clients really unhappy so had to remove it. 
The bandwidth is constantly staying at 30Mbps with slight bumps here and there but every day around 7pm it drops completely to normal levels and the flood stops. It starts back up around 7 in the morning. 
	View 6 Replies
    View Related
  
    
	
    	
    	
        Jul 28, 2009
        We are currently experiencing an SYN Flood attack on our primary production server and are looking for some help in resolving the issue.
Running:
Novell SUSE Linux Enterprise Server 10.2-64
SuperMicro X7DBR-E Intel Xeon QuadCore DualProc SATA [2Proc]
Processor Intel Xeon-Clovertown 5320L-QuadCore [1.86GHz]
8GB Memory
@ Softlayer DC in Texas.
Need help within the next hour or two. Please ask any necessary follow up questions and how you might go about resolving the issue (i.e. SYN Cookies, etc.) 
	View 5 Replies
    View Related
  
    
	
    	
    	
        May 3, 2009
        someone decided to attack my webserver and I can't figure out how to block it.
tcp        0      0 localhost:80             207.44.129.88:2138          SYN_RECV
tcp        0      0 localhost:80             207.44.129.88:2243          SYN_RECV
tcp        0      0 localhost:80             213.66.121.211:63372        SYN_RECV
It's literally thousands of those requests overloading apache. The server is fine, the load average is like .8. But none of the website are loading.
We're hosting with ThePlanet, and they're doing a great job at blocking a huge portion of the attack. But we're still getting hit pretty hard. I've got APF installed, and 3 or 4 anti-dos scripts.
Every once in a while a page will load for the websites, I think we've got just under 50 legit connections.
	View 14 Replies
    View Related
  
    
	
    	
    	
        Jun 11, 2008
        How can I best work with a syn flood?  I've tried the apf, deflate-ddos etc.... and don't work. Even tried litespeed etc but doesn't work against a 90mbps attack.
If I get a few servers, how would I have it setup to best defend?
	View 6 Replies
    View Related
  
    
	
    	
    	
        Jul 25, 2008
        one of my server were hit by massive ddos syn atack. target was port 80-apache
i am running centos 5 in xen vps iptables were strong with syn filtering and limit
but...what can do?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Mar 8, 2008
        I don't know it anymore. Tried everything. I can not reach my server properly. A lot of time time out.
netstat -anp |grep 'tcp|udp' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
1 127.0.0.1
1 38.99.44.101
1 64.131.90.38
1 78.176.158.75
1 78.179.73.135
1 88.229.70.143
1 88.242.97.204
1 88.247.87.58
1 92.112.211.223
3 78.176.175.136
3 88.229.40.142
3 88.231.180.181
4 78.183.227.146
18 0.0.0.0
348
348 connections from an empty IP? i have tried syn cookies, let the firewall block all ports without results. 
	View 10 Replies
    View Related
  
    
	
    	
    	
        May 28, 2008
        Can anyone share tips how to prevent DNS flood on a cPanel and Directadmin server platform on Centos?
	View 7 Replies
    View Related
  
    
	
    	
    	
        May 29, 2008
        Does keepalive off help in syn flood?
	View 6 Replies
    View Related
  
    
	
    	
    	
        May 4, 2008
        My server run after 10h sevices ftp is down (network error: connection timed out). may be flood ftp.
how to Detect flood ftp.
	View 4 Replies
    View Related
  
    
	
    	
    	
        Apr 4, 2008
        We got hit with a huge bandwidth bill for last month.  It was 4X our usual bill.  The ISP said that we were the victim of UDP flood attacks from an outside server.  We have a sonicwall router and the firewall seems to be blocking the port that the ISP claims the attacks can from.  Is it possible that the attacks would still count towards our bandwidth usage even if the connection is refused by our firewall?  Our ISP uses 95th percentile billing.
	View 6 Replies
    View Related
  
    
	
    	
    	
        Oct 30, 2007
        One of the servers have 1 account on, but seems like its extremely attacked. I cannot SSH and many packet loss. so I asked softlayer and they access it and said its a SYN Flood as from the /var/log/messages (I cannot see it as the server is not accessable) they put the main public ip under Cisco guard but still didn't help. when I asked for any solution, unfortunaly I were told there isn't and have to wait the attackers to stop as it comes from MANY addresses that iptables even won't help.
Isn't there any solution (software-hardware) to stop that ?
	View 14 Replies
    View Related
  
    
	
    	
    	
        Oct 27, 2008
        flood in FTP and brute force
all day i receved msgs of BFD someone trying acess server, how to stop it, exemple:
Executed ban command:
/etc/apf/apf -d 221.186.164.233 {bfd.pure-ftpd}
The following are event logs from 221.186.164.233 on service pure-ftpd (all time stamps are GMT -0500):
Oct 25 13:52:37 svr1 pure-ftpd: (?@221.186.164.233) [INFO] New connection from 221.186.164.233
Oct 25 13:52:37 svr1 pure-ftpd: (?@221.186.164.233) [INFO] New connection from 221.186.164.233
Oct 25 13:52:38 svr1 pure-ftpd: (?@221.186.164.233) [WARNING] Authentication failed for user [router] ....
	View 0 Replies
    View Related
  
    
	
    	
    	
        Jul 26, 2009
        I use Outpost Firewall to view active connections to my server. If I don't restart the httpd service on a regular basis my server will grind to a halt from being flooded by robots. 
I currently have the service set up to restart at Midnight and Noon every day. Sometimes that's enough, lately it's not. For example, I checked an hour ago and I had 385 connections to httpd. At least 50% of the connections were robots - tons of the same IP addresses and they're just crawling the site.
Almost all of the connections show up as less than 1kb bytes received and 0 bytes sent per connection. 
I already have a good 20 connections by these robots and the connection time shows as 11 minutes... I just browsed to a web gallery page on my site figuring that'd be mildly "intensive" on connections with all the thumbnails and my connections aren't lasting more than one minute.
So, what's with all these connections that are lasting 10+ minutes? I've even got one connection that has an Uptime of 30 minutes, bytes sent 65811, bytes received 180. It seems like something with these robots doesn't terminate correctly...
what to do so these connections quit jamming my server up? It's like a very very slow DOS...
	View 3 Replies
    View Related
  
    
	
    	
    	
        Aug 1, 2007
        When I check on port 80 connections, I get a list of few IPs with more than 100 connections.
I need to know which website / specific file being downloaded / URL is the IP accessing to? How can I do that?
	View 3 Replies
    View Related
  
    
	
    	
    	
        Jan 11, 2007
        my server under attack with syn flood and i attach the active connection during attack
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jun 5, 2015
        I serve large professional documents, and sometimes links to them end up on social media. No big deal, but I think people clicking on them from tose social media sites don't have a clue. They think they're being directed to small page, when in fact they are downloading megabytes of pdf -- myfile.pdf. So what I've started to do is to redirect requests from social media to an archive page, where they can see specifically what document they are trying to get, and recognize its size before they ask for it. No problem, right? I just do
	View 10 Replies
    View Related
  
    
	
    	
    	
        Nov 7, 2008
        it's come under my attention that dragonara.net has been ddosing me today since morning from the ip:
194.8.75.229
What's so ironic about it is that the ip is from a UK DDOS protection site so i'm expecting some email with their services in the next hour or so. Stay clear of them they are fakes and e-terrorists.
	View 14 Replies
    View Related
  
    
	
    	
    	
        Oct 8, 2009
        I am looking for some good ddos protection providers, via protected dns. I've searched on internet, but most of them are really expensive.
Please tell me some ddos protection providers what could help me.(gige is too expensive btw).
And I found some ddos protection scripts. How can a script protected a server from ddos? A sript like CSF or DDoS deflate?
	View 12 Replies
    View Related
  
    
	
    	
    	
        Jul 26, 2009
        how can i secure my tmp on vps?
mount -o loop,noexec,nosuid,rw /dev/tmpMnt /tmp
it isnt work on vps and i have this error:
[root@ dev]# mount -o loop,noexec,nosuid,rw /dev/tmpMnt /tmp
mount: could not find any device /dev/loop#
	View 4 Replies
    View Related
  
    
	
    	
    	
        May 5, 2009
        i want to secure my /tmp and do this:
so i try this link
[url]
so:
cd /dev
dd if=/dev/zero of=tmpMnt bs=1024 count=150000
/sbin/mke2fs /dev/tmpMnt
cd /
cp -R /tmp /tmp_backup
mount -o loop,noexec,nosuid,rw /dev/tmpMnt /tmp
but i have this error:
root@server [/]# mount -o loop,noexec,nosuid,rw /dev/tmpMnt /tmp
mount: no permission to look at /dev/loop#
	View 4 Replies
    View Related
  
    
	
    	
    	
        May 13, 2009
        when I get a dedi server for shared hosting. I secure it as much as i can and then just incase I miss stuff etc I hire 2 other companys to check over everything. Since I bought a vps from fsckvps are there any guides to secure and optimize a vps other then the one located in the vps section? thanks. I Dont feel like spending 50+ dollars on securing a vps that costs less then 15 a month.
	View 14 Replies
    View Related
  
    
	
    	
    	
        Aug 7, 2008
        vbulletin.com/forum/showthread.php?t=281011
How secure is my VPS? Anyone who has some free time and is reading this thread could please try to do some penetration-testing or something related (I really do not know much about network security) in order to know if my server configuration could be the problem?
Do you find any way to download the full database without login on the system (cPanel or phpMyAdmin)?
	View 3 Replies
    View Related
  
    
	
    	
    	
        Sep 8, 2008
        i'v been Installed all these In my VPS server 
1)Disable Functions:
system,system_exec,shell,shell_exec,exec,passthru,escapeshellarg, escapeshellcmd,proc_close,proc_open,ini_alter,dl, popen,parse_ini_file,show_source
and Enable The Safe_Mode.
---------------------------------------
2)Hide_your_apache_Version
---------------------------------------
3)Install LogWatch in a Server
---------------------------------------
4)Mod-Security-Install
---------------------------------------
5)Root-Login (IP Sent).
---------------------------------------
6)Disable Login Root and Change SSH Port .
---------------------------------------
7)Installing eAccelerator .
---------------------------------------
8)Install Nobody Check 
---------------------------------------
9)Updateing All of 
/scripts/upcp 
/scripts/updatenow 
/scripts/sysup 
/scripts/fixeverything 
/scripts/exim4 
/scripts/easyapache 
/scripts/securetmp
----------------------------------------
but doesnt know yet what the better to secure my vps ..
and about Firewall two .. wich firewall better 
CSF or APF+BFD ..
	View 4 Replies
    View Related
  
    
	
    	
    	
        Mar 27, 2008
        I have an application that requires a Secure FTP connection to a server to work.  I am having trouble connecting to one server, a windows based server, while the CentOS Linux server is working fine.
Does anyone know where I can find test Secure FTP locations so I can determine if the issue is with misconfiguration or with an incompatibility of the program with windows Secure FTP sites?
I am able to connect to both sites using WinSCP and choosing Secure FTP.
	View 1 Replies
    View Related
  
    
	
    	
    	
        Aug 30, 2007
        Check out this blog and suggest what thing more can be added to secure the vps and i think this information database can be helpful for newbies and intermediate users which like to secure the VPS.. which sometimes exploited due to bad scripts.
[url]
	View 2 Replies
    View Related
  
    
	
    	
    	
        Nov 11, 2007
        Ive been using Dreamhost for years and there great however, One of my clients needs has drastically changed and they are now required to comply with the Data Protection Act. 
In particular this bit make Dreamhost a bit of a no go due to them being in California:
"Personal information may not be transmitted outside the EEA unless the individual whom it is about has consented or adequate protection is in place, for example by the use of a prescribed form of contract to govern the transmission of the data."
Unless my client goes and asks all 1000+ customers they are kinda in a bit of a quandary. So here's what im looking for:
Secure UK Datacenter, eg Easynet, Blue Square etc
128mb RAM, 256mb Burstable, 20GB storage, 500GB transfer
LAMP Environment
Support within Business Hours
Control Panel
	View 6 Replies
    View Related