LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-02-2006, 08:49 AM   #1
UberNewb
LQ Newbie
 
Registered: Nov 2006
Posts: 3

Rep: Reputation: 0
Fisher Price Answers For UberNewb Please


Hello everyone, im new here...

Just bought my first ever dedicated server. Bought it because my website melted all the inodes on my VPS.

Now, I have a question for all you experts out there - if anyone could take the time to help..

My site I have concerns about is a Domain parking website - that allows registered users to park their domains with me.

However, my VPS was constantly down because of stupid users sending tonnes of autohit/BS traffic to their domains.

I am told of something called IPtables that will block this stuff before it reaches my server.... Hey forget that, my question is simple.

If you provided hosted automated mini sites (aka a parking pages) for other peoples domains and didnt want any visitors, except real people and indexing bots from reaching your server, how would you do it? Please bear in mind that we use a DNS catchall script instead of physically parking each domain on the server...

Thankyou ever so much in advance

Last edited by UberNewb; 11-02-2006 at 08:51 AM.
 
Old 11-02-2006, 10:23 AM   #2
Draciron
Member
 
Registered: Jul 2006
Posts: 44

Rep: Reputation: 16
IPtables is your firewall. Yes you can block certain traffic. You can do this by IP, domain, protocol/port. There are scripts you could easily modify that watch your logs for failed logins and automatically add rules to your firewall to block IPs which have too many failed login attempts. If you took one of those scripts and modified it to watch your http logs instead and by keyword block the IPs of unwanted traffic such as bots. Be carefull or you might block legit traffic also.

Another way is to block bots and spyders up at the document root.

With Apache instead of catch all you can do virtual domains. That way the message can be customized for the domain, different actions can be performed so that you can offer different levels of parking.

Just some ideas.
 
Old 11-02-2006, 02:59 PM   #3
UberNewb
LQ Newbie
 
Registered: Nov 2006
Posts: 3

Original Poster
Rep: Reputation: 0
Thanks Drac..

It appears we are under some sort of flood attack or Ddos by a chinese site zvmv.com - however, this might be one of our stupid users buying up an horrendous amount of automated traffic...

This domain (and others) are now blocked, but obviously the traffic is still reaching our server... Did you say you could deny referrers at the firewall? We were under the impression you could only block domains through a mod_rewrite on the server ??
 
Old 11-02-2006, 11:27 PM   #4
Draciron
Member
 
Registered: Jul 2006
Posts: 44

Rep: Reputation: 16
You'll be blocking the IP. You read the http logs for IPs or a domain you don't like. Then a firewall rule is automatically added to block all traffic from that IP/domain. So the question is do you also have legit traffic from that same domain or is it all junk? If it's all junk it'd be trivial to scan the http for the types of hits you don't want and block that IP and or even the whole domain at the firewall.
 
Old 11-03-2006, 01:51 AM   #5
UberNewb
LQ Newbie
 
Registered: Nov 2006
Posts: 3

Original Poster
Rep: Reputation: 0
Hits are all total garbage and coming in at the rate of 4000 a second.

We have iptables in place and a log file but we cant ban by domain using IPtables. Unless you can tell me how??

Weve simply had to revert to banning all users from certain countries using an IP Range.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Processor Upgrade (Pentium M) VS. Price: Which has the best price/tech ratio? hanzj Linux - Laptop and Netbook 8 03-22-2005 06:18 PM
Processor Upgrade (Pentium M) VS. Price: Which has the best price/tech ratio? hanzj General 3 03-21-2005 01:10 AM
Searching For Bobby Fisher jaz General 2 10-24-2004 04:04 AM
Windows User/Linux ubernewb seeking to convert B4UTRUST Linux - Distributions 12 01-23-2004 01:30 AM
RH Fisher versus 7.0 problems vlgligor Linux - Software 0 03-02-2001 07:57 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 04:31 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration