LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-06-2014, 12:50 AM   #1
Yazeed98
LQ Newbie
 
Registered: May 2014
Posts: 29

Rep: Reputation: Disabled
firewall to stop ddos or paid to someone to setup firwall


Hello,

Is there firewall or firewall device from amazon or ebay that can stop ddos attack or paid to someone to setup firewall , is there way to stop ddos attackinh?
Note : ports are udp (home connection)
Thanks
 
Old 07-06-2014, 06:59 PM   #2
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,976

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
Yes, hundreds of devices are for sale.

It is possible to get a firewall/security virtual machine appliance and run it possibly for no cost.

You should be able to have some control over your access to the web. I'd look to the router/modem and close all ports except ones that you must have open. And that is only a few for most people.

If someone knows your ip address it may be that no amount of your work can stop a ddos attack. You may have to have your isp block the attack.
 
Old 07-06-2014, 09:02 PM   #3
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,317
Blog Entries: 28

Rep: Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140
I don't think you can "stop" a DDoS attack.

The point of a DDoS attack is to overwhelm a server/site with repeated calls, not to gain access to it. The persons who start a DDoS attack don't care whether they ever get past the firewall; their goal is to deny others access to the site.

The only way to stop a DDoS attack is to alter the target's ip address and, once the new ip address propagates across DNS servers, the attack can be resumed if the perpetrators wish.

Wikipedia has a pretty good article about this. https://en.wikipedia.org/wiki/Denial-of-service_attack

Intrusion is a whole nother story. Everyone, whether home network or a huge ISP, should make intrusion as difficult as possible.

Last edited by frankbell; 07-06-2014 at 09:06 PM.
 
Old 07-10-2014, 11:14 AM   #4
Yazeed98
LQ Newbie
 
Registered: May 2014
Posts: 29

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by jefro View Post
Yes, hundreds of devices are for sale.

It is possible to get a firewall/security virtual machine appliance and run it possibly for no cost.

You should be able to have some control over your access to the web. I'd look to the router/modem and close all ports except ones that you must have open. And that is only a few for most people.

If someone knows your ip address it may be that no amount of your work can stop a ddos attack. You may have to have your isp block the attack.
Well everyone know my ip+port
 
Old 07-10-2014, 11:15 AM   #5
Yazeed98
LQ Newbie
 
Registered: May 2014
Posts: 29

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by frankbell View Post
I don't think you can "stop" a DDoS attack.

The point of a DDoS attack is to overwhelm a server/site with repeated calls, not to gain access to it. The persons who start a DDoS attack don't care whether they ever get past the firewall; their goal is to deny others access to the site.

The only way to stop a DDoS attack is to alter the target's ip address and, once the new ip address propagates across DNS servers, the attack can be resumed if the perpetrators wish.

Wikipedia has a pretty good article about this. https://en.wikipedia.org/wiki/Denial-of-service_attack

Intrusion is a whole nother story. Everyone, whether home network or a huge ISP, should make intrusion as difficult as possible.
"The only way to stop a DDoS attack is to alter the target's ip address and, once the new ip address propagates across DNS servers, the attack can be resumed if the perpetrators wish"

how i can do that

thanks
 
Old 07-10-2014, 11:18 AM   #6
Yazeed98
LQ Newbie
 
Registered: May 2014
Posts: 29

Original Poster
Rep: Reputation: Disabled
Can this stop the attacks ?
http://www.amazon.com/ZYXEL-Unified-...ords=anti+ddos

or this
http://www.newegg.com/Product/Produc...82E16833120135

Last edited by Yazeed98; 07-10-2014 at 11:24 AM.
 
Old 07-10-2014, 01:02 PM   #7
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
You cannot stop a DDoS attack. To make it more simple you are asking "how can I confirm that every person visiting my shop wants to buy something". It's a bad analogy but roughly how things stand
 
Old 07-10-2014, 01:36 PM   #8
Yazeed98
LQ Newbie
 
Registered: May 2014
Posts: 29

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by 273 View Post
You cannot stop a DDoS attack. To make it more simple you are asking "how can I confirm that every person visiting my shop wants to buy something". It's a bad analogy but roughly how things stand
I don't want to stop ddos attack all i want that every person protected to disconnect from the server

when i have ddos attack my network disconnect i had to restart it
 
Old 07-10-2014, 02:43 PM   #9
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
Quote:
Originally Posted by Yazeed98 View Post
Hello,

Is there firewall or firewall device from amazon or ebay that can stop ddos attack or paid to someone to setup firewall , is there way to stop ddos attackinh?
You are asking about stopping DDoS attacks? If they are true DDoS attacks (and you should keep in mind that most of the questions on here about DDoS attacks turn out to be about something else, such as plain DoS attacks, and the answers for other attacks can be very different), it is difficult to stop them, although there may be palliative measures (which you aren't asking about).

In any case, as DDoS attacks cost money to mount, what has made it worthwhile for someone to do this?

@273
Quote:
You cannot stop a DDoS attack. To make it more simple you are asking "how can I confirm that every person visiting my shop wants to buy something". It's a bad analogy but roughly how things stand
I think a slightly better analogy (and it is only an analogy - you can get into trouble by pushing analogies too far) would be to ask "How do I stop people knocking on my front door; I can't tell when a serious caller is knocking because of all of these nonsense people knocking on the door?"

Well, if the 'bad' requests are doing something different from the 'good' requests, then you could, potentially, do something based on that difference. If you have a fairly limited list of 'good' users, perhaps you could whitelist based on that (but the 'bad' requests are still made, you just drop them fairly efficiently). If there is only a fairly limited list of 'bad' accessors (in which case, it isn't much of a DDoS) then you might get somewhere with something like fail2ban, or manually blacklisting the worst offenders. But, ultimately, if it really is a full blown DDoS, you'll have to get co-operation from upstream.

Quote:
I don't want to stop ddos attack all i want that every person protected to disconnect from the server
That sounds rather different from the earlier statements; it sounds now as if you have people who are authorised to the server (is that correct??? maybe that's not what you mean by some people being 'protected') and you want the others to disconnect. If that is true, then it might be more possible; can you clarify, please?
 
Old 07-10-2014, 02:48 PM   #10
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
Quote:
Originally Posted by salasi View Post
@273
I think a slightly better analogy (and it is only an analogy - you can get into trouble by pushing analogies too far) would be to ask "How do I stop people knocking on my front door; I can't tell when a serious caller is knocking because of all of these nonsense people knocking on the door?"
I defer to your better analogy -- I seem to be out of good analogies.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
CentOS - Firewall - Preserving Source IP Address (DDoS) surgeon Linux - Security 4 08-05-2011 02:31 PM
what is the best program to stop DDOS Attack? Eng_Designer Linux - Security 26 06-04-2011 09:17 PM
Need to setup Linux Router/Firwall Server to log employee web activity. chopinpatel Linux - Server 2 11-10-2010 11:35 PM
What is the best way to stop this DDoS attack? abefroman Linux - Security 9 04-22-2009 11:25 AM
Help Me stop Botnet ddos attacks Drutten Linux - Security 6 08-18-2008 11:56 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration