LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-23-2012, 09:58 PM   #1
xlcor
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Rep: Reputation: Disabled
DDoS Attacks - Something to do with my linux server - suggestions


Hello,

I have a CentOS 6.3 dedicated server (unmanaged).

I would like to have an anti-DDoS software or something that helps me with these attacks.

Do you have any ideas ?
Please suggest me.
 
Old 08-23-2012, 10:02 PM   #2
abrinister
Member
 
Registered: Dec 2010
Location: Boston, MA, USA
Distribution: Arch Linux
Posts: 460

Rep: Reputation: 38
Here is a good start.

Alex Brinister
 
Old 08-23-2012, 10:17 PM   #3
xlcor
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
thank you very much abrinister !
 
Old 08-24-2012, 12:03 AM   #4
Quantumstate
Member
 
Registered: Jun 2005
Location: Seattle, Ecotopia
Distribution: CentOS 7.4 with KDE
Posts: 262

Rep: Reputation: 22
Quote:
Originally Posted by abrinister View Post
Here is a good start.
Well that does not address UDP DOS attacks, which can have unlimited IPs.

Come back if they have that problem.
 
Old 08-24-2012, 04:13 AM   #5
xlcor
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
Is there any better software for ddos protection ?
 
Old 08-24-2012, 08:27 AM   #6
Quantumstate
Member
 
Registered: Jun 2005
Location: Seattle, Ecotopia
Distribution: CentOS 7.4 with KDE
Posts: 262

Rep: Reputation: 22
No, only technique. The worse it is, the worse it gets.
 
Old 08-24-2012, 09:53 AM   #7
theserverteam
LQ Newbie
 
Registered: Aug 2012
Posts: 8

Rep: Reputation: Disabled
Quote:
Originally Posted by xlcor View Post
Is there any better software for ddos protection ?
There are different options you can try:
- csf/lfd (firewall)
- apf (firewall)
- mod_evasive for apache
- mod_security for apache
 
Old 08-24-2012, 11:38 AM   #8
Quantumstate
Member
 
Registered: Jun 2005
Location: Seattle, Ecotopia
Distribution: CentOS 7.4 with KDE
Posts: 262

Rep: Reputation: 22
Please let us know how those work out in a DDoS with unlimited IPs. UDP source IP can be forged. Hell, even fail2ban is ineffective; ban a million IPs and they still keep coming...

Of course you should have a firewall, such as Shorewall. But you need to either not piss these guys off, or do more research in the case of the LOIC, et al.

Last edited by Quantumstate; 08-24-2012 at 11:46 AM.
 
Old 08-24-2012, 04:03 PM   #9
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Quote:
Originally Posted by xlcor View Post
I would like to have an anti-DDoS software or something that helps me with these attacks.
Are you having a problem or just trying to take action against .... ?
Typically, if you are having a true DDOS, it is going to require help beyond what you can achieve with your server (e.g.) firewall. Also, as with most things security related, security is not an application you can install, or a set of firewall rules, but a continual process of monitoring your system and then analyzing and responding to events. Using applications like the ones mentioned in this thread, when properly understood and utilized, can help increase your overall security posture, but in and of themselves do not provide security.
 
Old 08-24-2012, 07:16 PM   #10
xlcor
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
I had some attacks to my previous server.
That's why I am asking for a script or something.
 
Old 08-28-2012, 04:59 PM   #11
NyteOwl
Member
 
Registered: Aug 2008
Location: Nova Scotia, Canada
Distribution: Slackware, OpenBSD, others periodically
Posts: 512

Rep: Reputation: 139Reputation: 139
You can only do so much against a DoS at the server level. After a certain point it needs to be addressed upstream at the network routers.
 
Old 08-29-2012, 05:13 AM   #12
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
That's what fukawi2 already said in the thread abrinister linked to in his first reply and it's what Noway2 said in the 9th reply. Please read before posting.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to prevent ddos apache attacks skoinga Linux - Security 2 01-27-2011 06:45 PM
Hello / DDoS attacks cybernet2u Linux - Security 7 11-21-2009 09:30 PM
Help Me stop Botnet ddos attacks Drutten Linux - Security 6 08-18-2008 11:56 AM
DDOS attacks Challengers alamlinux Linux - Security 2 03-23-2008 01:12 PM
Concerning DDoS attacks joji_in_changwon Linux - Security 13 11-27-2007 11:12 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration