LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 03-20-2010, 05:07 AM   #31
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,610
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413

Quote:
Originally Posted by konsolebox View Post
Still it sounds like you made an assumption on your last post. Also with regards to reconsidering your first post, it seems that it just makes the difference between your persuasions and/or concepts compared to mine just vague or unclear.
Your choice of words makes it look like your part of the discussion is determined by other things than is worth discussing here. With all due respect of course.
 
Old 03-20-2010, 02:16 PM   #32
bendib
Member
 
Registered: Feb 2009
Location: I'm the black rat in your couch.
Distribution: Some version of Fedora on most PCs. Others include CentOS, SliTaz, Pipsqueak, Mint.
Posts: 166

Rep: Reputation: 35
Quote:
Originally Posted by Web31337 View Post
And how on earth you're going to find a central IP of b-net? If it's run by evilcrackers, their net is probably built the way you won't find which IP is main. Most commonly that is impossible.
And well, domain is needed to host something. Not to host cracker servers.
Like I said, if it's a botnet, my idea is retarded. If it's just one little client slowing you down, then my idea is still good.
 
Old 03-20-2010, 03:45 PM   #33
Goni
LQ Newbie
 
Registered: Sep 2005
Posts: 26

Original Poster
Rep: Reputation: 15
Hello Guys, I have been real busy trying to mitigate the situation I was in and was not able to concentrate on this thread.

I found a solution to host the domain to a different provider who actually offers different DDoS mitigation strategies. They are filtering traffic on their border routers thus not letting them pass through. SYN and HTTP flood in my case, easy to identify and mitigate. They were able to stop some of the traffic, let's say 70% and rest of the scrubbing was done by ipfilter.

I have DNS TTL set to 10 minutes, so changing the IP did not helped. Whenever I changed, I was always welcomed at the new IP with the shear traffic.

Yes, netfilter will eat up the RAM in case of a well tuned DDoS attack. I tried, csf, apf and shorewall but they all ended up doing nothing. The amount of data was not that much, it varies from 18 to 30 Mbps and once I measured it around 185 Mbps. Lucky did not see those G attacks

Number of PPS were though the main concern. I got an easy 25K PPS which actually nailed down my good old cisco 5505 and Firebox 500.

Now that the DDoS has stopped, and the ISP is also taking care of it for me, I am concentrate of developing a solution which can actually help me to slow down an attack. I have been reading about pf (openbsd/freebsd) and the synproxy. It sounds compelling. But in case say, 25,000 Packets Per second, I think I would have to really really fine tune the OS to take such load? I have seen ppl deploying firewall running with freebsd using pf on their border routers to mitigate DDoS.

Would like to thank again for everyone who posted such good info. I'll try to setup a local domain with pf and see what load it can go through. Will keep ya guys posted
 
Old 03-25-2010, 08:31 AM   #34
konsolebox
Senior Member
 
Registered: Oct 2005
Location: Philippines
Distribution: Gentoo, Slackware, LFS
Posts: 1,526
Blog Entries: 5

Rep: Reputation: 98
Quote:
Originally Posted by unSpawn View Post
Your choice of words makes it look like your part of the discussion is determined by other things than is worth discussing here. With all due respect of course.
Sorry if I go far. Sometimes I really just can't recall a word that I know best fits my descriptions that sometimes I am forced to use "and/or" to two or more words.

Regarding what you think I may be determined at, maybe I'm just getting over-defensive or frank that's why I make tended although not intended uneasy responses as with respect to my first and later posts. Sharing what I thought was a good idea, amplified with little excitement was what I intended most in my first post. I think it's just a common manner. The latter posts, I don't know,.. it may be no longer of respect but shouldn't we also consider other factors or catalysts in the following posts? I hope you acknowledge my message openly. Anyway, for anything I guess it's better if I go off this thread. Peace.
 
  


Reply

Tags
nginx


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Hello / DDoS attacks cybernet2u Linux - Security 7 11-21-2009 09:30 PM
DDOS attack help me dheeraj4uuu Linux - Security 9 05-31-2009 03:07 PM
Concerning DDoS attacks joji_in_changwon Linux - Security 13 11-27-2007 11:12 AM
DDOS Attack studiofos Linux - Security 3 09-12-2006 03:42 AM
Ddos Mag|c Linux - Security 2 08-16-2003 09:41 PM


All times are GMT -5. The time now is 04:26 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration