LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-30-2011, 09:47 PM   #1
Eng_Designer
LQ Newbie
 
Registered: May 2011
Posts: 23

Rep: Reputation: Disabled
what is the best program to stop DDOS Attack?


Good Morning.
i have 1 question no more because i got many ddos attack and my load is 95++
what is the best program to stop DDOS Attack ???

Thanks
Abdelrahman

Last edited by Eng_Designer; 05-30-2011 at 09:50 PM.
 
Old 05-30-2011, 10:04 PM   #2
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,602

Rep: Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648
turn off the server .
 
0 members found this post helpful.
Old 05-30-2011, 10:11 PM   #3
Eng_Designer
LQ Newbie
 
Registered: May 2011
Posts: 23

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by John VV View Post
turn off the server .
and then?

i get ddos attack from 5 days
i had ban alot of them
and load become 1
but they are back again so i wana stop them

Thanks
 
Old 05-31-2011, 01:41 AM   #4
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,602

Rep: Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648Reputation: 2648
there is not much that can be done

is "fail2ban" installed and configured in Apache ?
http://www.fail2ban.org/wiki/index.php/HOWTOs

or have you blocked the ip's ?

what have you done ?

are you sure it is a "Distributed Denial of service "
and not a misconfiguration server just tiring to access

i once had "The University of Chicago" try to dl my ENTIRE site( html,php,ssc's ,png's ,jpg's everything) over and over and over .To the tune of 4 to 6 gig per day .
 
Old 05-31-2011, 04:40 AM   #5
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Eng_Designer, please spell out your words and avoid using 'texting' slang, short lines, and abbreviations because it makes your question very hard to read.

As far as your concerns about a DDOS attack, the best thing you can do is contact your ISP. If you really are facing a DDOS, the help of your ISP will be required to stop it. The chances that you are actually getting such an attack are very small, unless you have done something to anger the wrong group of people. This is not to say that you aren't have a problem with rogue connections, just that it isn't likely to be a true DDOS scenario.

Rather than speculate on what may, or may not be happening, would you please post some examples of the troublesome log entries. Also describe exactly what you are trying to do and what type of service / server you are running. Also look at your logs for signs of a problem other than connections as this can cause a very high system load.
 
3 members found this post helpful.
Old 06-01-2011, 10:57 PM   #6
Eng_Designer
LQ Newbie
 
Registered: May 2011
Posts: 23

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by John VV View Post
there is not much that can be done

is "fail2ban" installed and configured in Apache ?
http://www.fail2ban.org/wiki/index.php/HOWTOs

or have you blocked the ip's ?

what have you done ?

are you sure it is a "Distributed Denial of service "
and not a misconfiguration server just tiring to access

i once had "The University of Chicago" try to dl my ENTIRE site( html,php,ssc's ,png's ,jpg's everything) over and over and over .To the tune of 4 to 6 gig per day .
i solve it
thanks alot

---------- Post added 06-01-11 at 10:58 PM ----------

Quote:
Originally Posted by Noway2 View Post
Eng_Designer, please spell out your words and avoid using 'texting' slang, short lines, and abbreviations because it makes your question very hard to read.

As far as your concerns about a DDOS attack, the best thing you can do is contact your ISP. If you really are facing a DDOS, the help of your ISP will be required to stop it. The chances that you are actually getting such an attack are very small, unless you have done something to anger the wrong group of people. This is not to say that you aren't have a problem with rogue connections, just that it isn't likely to be a true DDOS scenario.

Rather than speculate on what may, or may not be happening, would you please post some examples of the troublesome log entries. Also describe exactly what you are trying to do and what type of service / server you are running. Also look at your logs for signs of a problem other than connections as this can cause a very high system load.
i'm sorry for my bad language but i was write fast ,
anyway, i solve it
thanks alot
 
0 members found this post helpful.
Old 06-01-2011, 11:19 PM   #7
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 10,963

Rep: Reputation: 5216Reputation: 5216Reputation: 5216Reputation: 5216Reputation: 5216Reputation: 5216Reputation: 5216Reputation: 5216Reputation: 5216Reputation: 5216Reputation: 5216
How did you solve it?
 
Old 06-01-2011, 11:24 PM   #8
Nylex
LQ Addict
 
Registered: Jul 2003
Location: London, UK
Distribution: Slackware
Posts: 7,464

Rep: Reputation: Disabled
Quote:
Originally Posted by Eng_Designer View Post
Good Morning.
i have 1 question no more because i got many ddos attack and my load is 95++
what is the best program to stop DDOS Attack ???

Thanks
Abdelrahman
Are you actually running Linux?

Since no-one has mentioned this, please don't put "urgent" in your thread titles. This is a volunteer site and no threads are any more urgent than any other.

Also, "alot" is incorrect - it should be two words (see the link in my signature).
 
Old 06-02-2011, 12:16 AM   #9
Eng_Designer
LQ Newbie
 
Registered: May 2011
Posts: 23

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by dugan View Post
How did you solve it?
i make a bash script that's block's ip's make syn attack
 
Old 06-02-2011, 12:20 AM   #10
Eng_Designer
LQ Newbie
 
Registered: May 2011
Posts: 23

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by Nylex View Post
Are you actually running Linux?

Since no-one has mentioned this, please don't put "urgent" in your thread titles. This is a volunteer site and no threads are any more urgent than any other.

Also, "alot" is incorrect - it should be two words (see the link in my signature).
so?
we will forget problem and debate what should i write alot or a lot?
thanks for reply and your solve !!
 
Old 06-02-2011, 12:22 AM   #11
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by Eng_Designer View Post
i make a bash script that's block's ip's make syn attack
Huh? The "DDoS" you were referring to was a SYN flood? How did you conclude it was DDoS? I mean, a SYN flood can be done from a single IP-spoofing host (no DDoS necessary). What does your script look like? Why didn't you just enable SYN cookies?

Last edited by win32sux; 06-02-2011 at 12:24 AM.
 
1 members found this post helpful.
Old 06-02-2011, 12:30 AM   #12
Eng_Designer
LQ Newbie
 
Registered: May 2011
Posts: 23

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by win32sux View Post
Huh? The "DDoS" you were referring to was a SYN flood? How did you conclude it was DDoS? I mean, a SYN flood can be done from a single IP-spoofing host (no DDoS necessary). What does your script look like? Why didn't you just enable SYN cookies?
and SYN attack also not only DDoS


#!/bin/bash

netstat -na | grep -i SYN_RECV |cut -d: -f2 |awk '{print $2}' > /tmp/ip
for i in `cat /tmp/ip`
do
iptables -v -A INPUT -s ${i} -j DROP
iptables -v -D INPUT -s ${i} -j DROP
iptables -v -A OUTPUT -d ${i} -j DROP
iptables -v -I INPUT -s ${i} -j DROP
done
service iptables save
 
Old 06-02-2011, 12:32 AM   #13
Eng_Designer
LQ Newbie
 
Registered: May 2011
Posts: 23

Original Poster
Rep: Reputation: Disabled
i forget check SYN cookies, i will check it
 
Old 06-02-2011, 12:45 AM   #14
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by Eng_Designer View Post
and SYN attack also not only DDoS


#!/bin/bash

netstat -na | grep -i SYN_RECV |cut -d: -f2 |awk '{print $2}' > /tmp/ip
for i in `cat /tmp/ip`
do
iptables -v -A INPUT -s ${i} -j DROP
iptables -v -D INPUT -s ${i} -j DROP
iptables -v -A OUTPUT -d ${i} -j DROP
iptables -v -I INPUT -s ${i} -j DROP
done
service iptables save
So basically you're using netstat to look for half-open connections, then using iptables to filter packets from the relevant source addresses? What you've done is essentially created a giant denial-of-service vulnerability. Now all a bad guy has to do is spoof a packet with the source IP of any host he wishes to block to/from your server (which may include critical things such as security update package repositories). Not to mention that since in most SYN floods the spoofed IPs are random, these iptables rules are potentially useless. So yeah, use SYN cookies instead (it's what they're designed for). Getting back to the DDoS (separate issue): How did you solve that? Did your ISP jump in? You never even showed us or described what it looked like, AFAICT.

Last edited by win32sux; 06-02-2011 at 12:52 AM.
 
3 members found this post helpful.
Old 06-02-2011, 09:47 AM   #15
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,253
Blog Entries: 4

Rep: Reputation: 3777Reputation: 3777Reputation: 3777Reputation: 3777Reputation: 3777Reputation: 3777Reputation: 3777Reputation: 3777Reputation: 3777Reputation: 3777Reputation: 3777
There is a compelling reason to use tools like "Shorewall" to manage your iptables entries. (P.S. it's free, FOSS.)

When you simply try to "roll your own" commands, you're very likely to make some mistake ... even to create some vulnerability ... just because you really didn't know what you are doing. Whereas the authors of Shorewall have dealt with the same problems very deeply for a long time and have developed software to do the right thing.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
DDOS attack help me dheeraj4uuu Linux - Security 9 05-31-2009 03:07 PM
DDos attack - prevention dheeraj4uuu Linux - Security 3 05-28-2009 07:41 AM
What is the best way to stop this DDoS attack? abefroman Linux - Security 9 04-22-2009 11:25 AM
DDOS Attack studiofos Linux - Security 3 09-12-2006 03:42 AM
ddos attack ashis Linux - Security 1 06-14-2001 02:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:30 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration