Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-18-2002, 06:33 AM   #1
RMG
Confirmed User
 
Join Date: Apr 2002
Posts: 542
If you're site was ddos'd...........

Ok, my sites have been down for 17 hour now. Is there ANYTHING that can be done against this? Are large sites like hun, al4a, etc protected against these kind of attacks? or are they just as vunerable as everyone else?
RMG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 06:46 AM   #2
hjnet
Confirmed User
 
Join Date: May 2002
Location: European Union
Posts: 3,815
Take a look at this threat I guess they´ve found a solution.
hjnet is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 06:49 AM   #3
Juge
Confirmed User
 
Join Date: Feb 2001
Posts: 1,917
Go to grc.com and read up about what they did. There's not much you can do, except contact your host and hope they know what they are doing.
Juge is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 07:10 AM   #4
extreme
Confirmed User
 
Industry Role:
Join Date: Oct 2002
Location: lalaland
Posts: 2,120
Depends on what kind of attack that is launched against you. If the attackers does it right a DDOS attack is nearly impossible to stop.

Anyway, if the attack isn't using spoofing (the source ip of the attack is random/forged/faked) + you're running linux and got root you could just block the offending ip with the builtin linux firewall:

ipchains -A input -j DENY -p all -l -s 1.1.1.1/32 -d 0.0.0.0/0

Would stop all traffic from IP 1.1.1.1.

Another example:

ipchains -A input -j DENY -p all -l -s 1.1.1.1/24 -d 0.0.0.0/0

Would stop all traffic comming from 1.1.1.* (1.1.1.1 - 1.1.1.255)

This is usefull for totally blocking all traffic from a certain ip ... your box will seem totaly nonexistant to the blocked ip.

If you're getting attacked with a PINGflood from many diff IPs You can block it with (again, for linux roots):

echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all

(any fool with linuxroot could easily launch an pingattack with "ping -f <your ip>". Ping wont fake the sourceIP though so You can easily see where the attack is comming from).

If You're attacked with the classic synflood (eating CPU with halfopen TCP connections) enabling syncookies could help:

echo 1 > /proc/sys/net/ipv4/tcp_syncookies

The good thing with the above methods is that they are fairly easy to take. The bad thing is that they will only stop the traffic Out from your box .. . the bandwdith the DOSattack eats going Into your Networkcard/Box cant be stopped this way. For that you have to contact your ISP and tell them a DDOS attack is going on... maybe they can filter the attack in their routers. So, always contact your uplink/isp.

Hope some of this helps..
extreme is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 07:10 AM   #5
RMG
Confirmed User
 
Join Date: Apr 2002
Posts: 542
seems there is nothing that can be done....I could essentially begin an attack on any site I please. They could try and stop it on a router level, but then there is always a back door.
RMG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 07:21 AM   #6
RMG
Confirmed User
 
Join Date: Apr 2002
Posts: 542
Quote:
Originally posted by extreme
Depends on what kind of attack that is launched against you. If the attackers does it right a DDOS attack is nearly impossible to stop.

Thats what I figured...so if I wanted to i could knock the biggest sites in the adult industry completely off the net and there is nothign that can be done. Talk about fucking power.
RMG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 07:37 AM   #7
extreme
Confirmed User
 
Industry Role:
Join Date: Oct 2002
Location: lalaland
Posts: 2,120
Ye.. mostly that's exactly what it is to the attacker too, a powertrip :/. DDoS is a big problem in todays internetinfrastructure, everybody is so vulnerable. the new generation of the Internet Protocol (IPv6) will address some of the problems with IPv4 (the IP version that's mostly used on internet today) but it will take a long time before IPv6 is more deployd/used then IPv4.

Its mostly just a matter of bandwidth though.. if the attacker can bring up more "bandwidthpower" then you can... he can make your site appear dead. And if he's a scriptkiddie masshacking with the newest remote root sploits found on packetstorm its very likely that he has just that...

Even if he has less bandwidth then you an attacker can use certain tricks like synflood etc, to kill your sites anyway. Read my previous post for possible protection against that.

good luck
extreme is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 07:48 AM   #8
RMG
Confirmed User
 
Join Date: Apr 2002
Posts: 542
fucking gay
RMG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 07:55 AM   #9
DarkJedi
No Refunds Issued.
 
DarkJedi's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: GFY
Posts: 28,300
jesus, just don't fuck with the hackers an no one will be DDoS ing your ass
DarkJedi is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 08:05 AM   #10
RMG
Confirmed User
 
Join Date: Apr 2002
Posts: 542
It wasn't me....one of the clients of my host who shares with me pissed someone off.
RMG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 08:06 AM   #11
RMG
Confirmed User
 
Join Date: Apr 2002
Posts: 542
In any case, my site has been down for nearly 20 hours, time to move
RMG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 08:08 AM   #12
DarkJedi
No Refunds Issued.
 
DarkJedi's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: GFY
Posts: 28,300
dude, i'm on the same host - its already up
DarkJedi is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2002, 08:10 AM   #13
RMG
Confirmed User
 
Join Date: Apr 2002
Posts: 542
hmmm I cant access any of my pages.

Btw...this mostly me just letting of steam.
RMG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.