Bài đăng

Hiển thị các bài đăng có nhãn DDOS

How to install (D)DoS Deflate and APF (Advanced Policy Firewall) to block bad IPs

Hello. You could probably find tutorials using google, but here it is, at one place.  Before few days I had problems with one of the servers I administrate and situation on the server was as follows: - totally slow network, websites loading was 10-20sec (30) - at first I though, ok, slow loading, server load is high and some client is doing problems - after connecting to the server and checking statistics - server CPU was all the time on 20-30%, memory was fine, all services were up-and-running so where is the problem? - server wasn't on latest #MU, it was just missing 2-3 updates (I'm talking about plesk 11.5) and I could saw in history of changes no security updates whatsoever, but what ever, lets give it a try - nothing, didn't helped - i did apt-get update && upgrade - still nothing - current status was that everything is up-to-date, however there are still problems - listing connections on the server with command: netstat -ntu | awk '{print $5}' | c...

Phát hiện và chống tấn công ddos

DDOS là một vấn đề nan giải cho các webmaster hoặc admin. Sau đây mình xin giới thiệu một vài thủ thuật để nhận biết DDOS và một số biện pháp đối phó khi server bị DDOS. Khi server đột ngột chậm như rùa, mọi xử lý của server đều rất nặng nề, thì nhiều khả năng do một trong hoặc những nguyên nhân sau: 1. Server bị DDOS 2. Server bị quá tải do thiếu RAM 3. Server bị quá tải do tốc độ xử lý của CPU không đảm bảo 4. Tốc độ truy xuất dữ liệu của HDD không đáp ứng nhu cầu read/write của data. (Thông thường xảy ra trên các ổ SATA 72krpm hoặc HDD sắp hỏng) Trong bài viết này chúng ta đi vào vấn đề thứ 1: server bị DDOS, các vấn đề 2,3,4 có thể khắc phục dễ dàng bằng cách nâng cấp phần cứng. Kiểm tra xem server có bị DDOS hay không: Từ command line Linux gõ: Mã: netstat -anp |grep 'tcp\|udp' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n Câu lện trên sẽ trả về hàng loạt IP chiếm nhiều connection nhất trên server. Cần lưu ý rằng DDOS có thể xuất phát từ một l...

(D)DoS Deflate

(D)DoS Deflate  is a lightweight bash shell script designed to assist in the process of blocking a denial of service attack. It utilizes the command below to create a list of IP addresses connected to the server, along with their total number of connections. It is one of the simplest and easiest to install solutions at the software level. netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n IP addresses with over a pre-configured number of connections are automatically blocked in the server's firewall, which can be direct iptables or Advanced Policy Firewall (APF). (We highly recommend that you use APF on your server in general, but deflate will work without it.) Notable Features It is possible to whitelist IP addresses, via /usr/local/ddos/ignore.ip.list. Simple configuration file: /usr/local/ddos/ddos.conf IP addresses are automatically unblocked after a preconfigured time limit (default: 600 seconds) The script can run at a chosen frequency via the...

Install and configure APF and (D)DOS-Deflate

A supported website has recently been under a distributed vulnerability scanning that has similarities to a DOS attack. Countermeasures had been taken and that leaded to this post, "A detailed tutorial on how to install and configure APF (Advanced Policy Firewall) and (D)DOS-Deflate" APF What is APF (Advanced Policy Firewall)? Advanced Policy Firewall (APF) is an iptables(netfilter) based firewall system designed around the essential needs of today’s Linux servers. The configuration is designed to be very informative and easy to follow. The management on a day-to-day basis is conducted from the command line with the ‘apf’ command, which includes detailed usage information on all the features. Requirements: - Root SSH access to your server Install Login to your server through SSH and su to the root user.   cd /root/downloads or another temporary folder where you store your files.   wget  http://www.rfxnetworks.com/downloads/apf-current.tar.gz   tar -xvz...

Ba cách phòng chống DDOS cơ bản cho website của bạn

Tấn công DDOS hay còn được gọi tấn công từ chối dịch vụ đơn giản được hiểu là tạo ra 1 lượt truy cập ảo ồ ạt vào một địa chỉ website tại cùng một thời điểm nào đó đã định sẵn nhằm “đánh sập” máy chủ lưu trữ khiến nó chạy chậm hoặc không thể chạy được nữa. Thật sự thì không có phương pháp chống DDOS hiệu quả nhất nhưng nếu với mức độ nhỏ và mang tính không chuyên khi sử dụng các phần mềm được lập trình sẵn ở quy mô nhỏ lẻ thì ta hoàn toàn có thể chủ động phòng chống. Cách 1: Chống iframe Đây là phương pháp được xem là thô sơ nhất. Kẻ tấn công sẽ mượn 1 website có lượt truy cập lớn nào đó chèn các iframe hướng về website cần đánh rồi cho chạy lệnh refresh (tải lại) nhiều lần hoặc họ viết sẵn 1 tập tin flash với công dụng tương tự rồi đặt lên website và khi người dùng truy cập vào website này thì họ vô tình bất đắc dĩ trở thành người tấn công website kia. Với hình thức tấn công kiểu như thế này bạn hoàn toàn có thể chống lại bằng cách chèn 1 đoạn mã Javascript chống chèn iframe t...