LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   DDoS Attacks - Something to do with my linux server - suggestions (https://www.linuxquestions.org/questions/linux-security-4/ddos-attacks-something-to-do-with-my-linux-server-suggestions-4175423711/)

xlcor 08-23-2012 09:58 PM

DDoS Attacks - Something to do with my linux server - suggestions
 
Hello,

I have a CentOS 6.3 dedicated server (unmanaged).

I would like to have an anti-DDoS software or something that helps me with these attacks.

Do you have any ideas ?
Please suggest me.

abrinister 08-23-2012 10:02 PM

Here is a good start.

Alex Brinister

xlcor 08-23-2012 10:17 PM

thank you very much abrinister !

Quantumstate 08-24-2012 12:03 AM

Quote:

Originally Posted by abrinister (Post 4762720)
Here is a good start.

Well that does not address UDP DOS attacks, which can have unlimited IPs.

Come back if they have that problem.

xlcor 08-24-2012 04:13 AM

Is there any better software for ddos protection ?

Quantumstate 08-24-2012 08:27 AM

No, only technique. The worse it is, the worse it gets.

theserverteam 08-24-2012 09:53 AM

Quote:

Originally Posted by xlcor (Post 4762939)
Is there any better software for ddos protection ?

There are different options you can try:
- csf/lfd (firewall)
- apf (firewall)
- mod_evasive for apache
- mod_security for apache

Quantumstate 08-24-2012 11:38 AM

Please let us know how those work out in a DDoS with unlimited IPs. UDP source IP can be forged. Hell, even fail2ban is ineffective; ban a million IPs and they still keep coming...

Of course you should have a firewall, such as Shorewall. But you need to either not piss these guys off, or do more research in the case of the LOIC, et al.

Noway2 08-24-2012 04:03 PM

Quote:

Originally Posted by xlcor (Post 4762716)
I would like to have an anti-DDoS software or something that helps me with these attacks.

Are you having a problem or just trying to take action against .... ?
Typically, if you are having a true DDOS, it is going to require help beyond what you can achieve with your server (e.g.) firewall. Also, as with most things security related, security is not an application you can install, or a set of firewall rules, but a continual process of monitoring your system and then analyzing and responding to events. Using applications like the ones mentioned in this thread, when properly understood and utilized, can help increase your overall security posture, but in and of themselves do not provide security.

xlcor 08-24-2012 07:16 PM

I had some attacks to my previous server.
That's why I am asking for a script or something.

NyteOwl 08-28-2012 04:59 PM

You can only do so much against a DoS at the server level. After a certain point it needs to be addressed upstream at the network routers.

unSpawn 08-29-2012 05:13 AM

That's what fukawi2 already said in the thread abrinister linked to in his first reply and it's what Noway2 said in the 9th reply. Please read before posting.


All times are GMT -5. The time now is 03:13 PM.