Thread Rating:
  • 3 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Breakdown of DDOS Attack Prevention
#13
(08-25-2010, 11:16 PM)Omniscient Wrote: Slowloris is more complicated than simple get commands. It opens the HTTP connection but doesn't ever close it. What you describe is simple httpd flood which is easily blocked mostly.

Syn floods are normally easy to stop too if you have a capable sys admin. 99% of attacks I have seen had a pattern that was recognizable enough for me to block them at server level.

UDP/Ping are funny since these are services you can normally just turn off or reroute. You can just do DNS mirrors or round-robin DNS to avoid large botnet attacks. DNS service can easily be moved to a host offering good DDOS protection at a fairly reasonable price too.

Ping flood is a just. Complete waste of everyones time.

Everything can be stopped at router level but the risk of false positives grows. Best to use all 3 protection layers appropriately.
Yeah, a few datacenters have Cisco's and other HWFW routers You have to pay loads but i did once and it was worth having the access ^^.

my site mainly gets hit by Get floods on heavier pages. (the occasional slowloris) httpflood i just block with a php script to add "spamming" Ip's to the htaccess block list. Slowloris i haven't figured yet, buy instead of spamming it holding connections i can't find a rule to detect it. Surprised apache haven't done something about it yet.
Reply


Messages In This Thread
RE: Breakdown of DDOS Attack Prevention - by Eve - 06-13-2010, 11:16 AM
RE: Breakdown of DDOS Attack Prevention - by Sam - 06-26-2010, 03:07 PM
RE: Breakdown of DDOS Attack Prevention - by Iarkey - 08-26-2010, 06:22 AM
RE: Breakdown of DDOS Attack Prevention - by Tobe - 04-19-2011, 06:53 AM
RE: Breakdown of DDOS Attack Prevention - by !LoL - 06-01-2011, 03:55 AM
RE: Breakdown of DDOS Attack Prevention - by 0xE9 - 06-09-2011, 01:34 AM
RE: Breakdown of DDOS Attack Prevention - by 0xE9 - 06-09-2011, 02:12 AM
RE: Breakdown of DDOS Attack Prevention - by 0xE9 - 06-09-2011, 08:54 PM
RE: Breakdown of DDOS Attack Prevention - by H-Q - 06-28-2011, 11:42 AM
RE: Breakdown of DDOS Attack Prevention - by Link - 07-04-2011, 09:09 AM
RE: Breakdown of DDOS Attack Prevention - by FISH - 08-12-2011, 06:25 PM

Possibly Related Threads…
Thread Author Replies Views Last Post
  DDOS Prevention mcdl 42 14,718 10-17-2011, 08:37 AM
Last Post: ZooT ツ

Forum Jump:


Users browsing this thread: 18 Guest(s)