![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
DDOS Attack
One of my sites is undergoing a DDOS attack that is coming in at around 40-50mbps. The traffic is all coming from Russia and I've tried blocking Russian traffic through a firewall but my host is telling me all they can do now is null the IP that the site is on. I'm not too worried as the site doesn't make me money but as a matter of principle I'd like to be able to keep the site up.
Are there any hosts out there that I could get a server with that would be able to mitigate these attacks? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Registered User
Industry Role:
Join Date: Jul 2003
Location: Encrypted. Access denied.
Posts: 31,779
|
Back when Russians were DESTROYING all the ladyboy sites, isprime was the only company who took a licking and kept on ticking. Everyone else fell to shit and couldn't handle it very well.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
![]() Contact Fortress and ask for their "special sauce". That will take care of it for you.
I think it runs around $2500.00 a month. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
myadultdesign.com
Industry Role:
Join Date: May 2004
Location: Europe
Posts: 12,557
|
It happens to me too, every couple of months or so. I just take the targeted sites down for 3-4 days and that's it. I swallow it with pride, lol.
__________________
Banners, logos, headers, peels, FHGs, ads, paysites, photo retouching etc: my adult design portfolio
My logo portfolio: PornLogos.com ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
lol so all I need to take down any site is some little script kiddy bs script and some russian server and that's it? there's gotta be a company that can deal with this thats not going to cost a fortune
edit: ive tried taking the site down for months and brought it back up just for the attack to resume |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 | |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
![]() Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
. . .
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,391
|
I'd say bluegravity but they just sold themselves to someone else.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
no clue what it is about the site, i think its just some copycat guy wanting my site to fail
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
barefootsies you seem to advertise ddos mitigation with your servers, do you guys actually provide that or are you just saying that?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
Quote:
If you are determined to keep your site up, despite it not making you a lot of money, going the null routing would be your best option to be frank. Since yours is a sustained, months on end, attack any other option is going to cost you more than you, apparently, want to spend. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
Quote:
Shouldn't advertise DDOS mitigation if you can't really provide it Barefootsies. SEMI MANAGED SUPPORT: 24/7/365 Tech Support Available Free Reboot Control Panel installation and Configuration DDOS Mitigation Resource Monitoring Free Migration So all I need to bring 95% of websites down is just a server with this company in Russia and a little script kiddie DOS script? Hard to believe! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
Quote:
![]() We have a DC that we use for JUST DDoS attacked clients (as it typically happens for a client at any host). We have two or three clients in there right now as a matter of fact. Although their attacks come and go. They have to pay more for that since it is repeated every few weeks. That said, you forget I do not like you champ. So realistically, I would never host you, or help you one way or the other. Although I appreciate the free advertising. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
Quote:
![]() Picture is right. Nigga please, you can't do shit when it comes to DDOS attacks. You pretend like you can but really it's just a scam like when you sold stolen celebrity photos you didn't own. So yes, nigga please, don't pretend like you're not the one trying to cheat noobs like you did when you were selling your 'start a business packages' that failed miserably. As I recall you're the one who is scared shitless to share what sites he has because of a DDOS attack that you were crying about a while back. Stop lying and doing false advertising Barefootsies. You might not want to sell me something but I'm sure as hell that money talks and little bitches like you walk, I can always go to whoever you resell for and get whatever I want without being lied to and cheated by a punk dumbass like you. That said, anyone that isn't all talk that can help out? |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
![]() Quote:
![]() Yep. Money talks. You don't have it. So keep walking to the next host. Keep the bumps a rockin toots. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
Quote:
Barefootsies why don't you go back to spamming the forums with your multiple failed business ventures so the rest of the people here can continue watching your tragic/comical failures pile up. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Junior Achiever
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
|
Whats the site?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
Just a dinky little forum for dudes to wank off on pictures LOL
I wasn't even making any money on it or flying ads on it was just building it for the member base and it had about 8500 a while ago when I shut it down. Like I said it doesn't really matter if it goes up or not since it wasn't making money but as a matter of principle id really like to be able to keep it up in the face of the attacks especially since the attacks aren't even that big. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
Quote:
[Tutorial] Celebrity Membership Pay Site, Blog, Fan Site Sin2.0 Interview - Modern Consumer Marketing Methods Sin2.0 Interview - Niche Pay Sites 101 Will do. Thanks for the permission chief. ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
Ok byeeee
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Industry Role:
Join Date: Aug 2002
Posts: 9,752
|
Wow sorry man, it happens to everyone. Even Google has been dossed and offline for hours. Just be patience it costs them a lot of money or reputations to do it so they will run out of funds or people soon.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
Maybe someone can recommend a DDOS protection service that isn't too expensive? Lets say 200-300 a month type thing.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Industry Role:
Join Date: Apr 2009
Posts: 1,313
|
We've had Ddos attacks as high as 13GB... enough to take down multiple DCs. There's no service out there that can totally mitigate DDos, SynRecv, etc. Just null route the IP.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
That's what I've been doing for the past little bit but I just want to say fuck it and see what I can do to keep the site up. I don't think it's that big of an attack 40-50mbps type thing and I really doubt it's anyone that really wants to put any resources towards it.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Confirmed User
Industry Role:
Join Date: Apr 2009
Posts: 1,313
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
What if i hosted it at dreamhost.com or something, they have ddos protection I'm sure and would they really be able to tell that it's an attack on me and not just another site on the server? Can't that be a sneaky way out at least for a couple of weeks until the attack stops and I can move it back to something reasonable?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
Confirmed User
Industry Role:
Join Date: Apr 2009
Posts: 1,313
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 | |
. . .
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Registered User
Industry Role:
Join Date: Dec 2007
Location: Ireland
Posts: 54
|
Is your forum on shared hosting or a dedicated box?
__________________
Server Optimisation - Pentesting - Secure WP Installs. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Icq: 14420613
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
|
yes they can tell unless they are idots in that case the whole server will just go down.
if its only a 40-50mbps attack you might be able to stop it on the server with a firewall if your not using a good managed host i would start with hiring someone that knows what they are doing to try that.
__________________
Need WebHosting ? Email me for some great deals [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Registered User
Industry Role:
Join Date: Dec 2007
Location: Ireland
Posts: 54
|
I asked that as it seems weird to me that someone would sustain (while small) a 50mbps DDoS on a forum/site of no value. If it was VPS/shared/etc hosting I would of put it down to just being caught in the crossfire as such, but it seems very weird to me that it returns time and again after being null routed (btw a firewall wont even cause the DDoS to slow down). Best I would suggest would be simply to rehost with another host, ask them how they deal with DDoS attacks, if they just say "null route" move on to the next one.
It doesn't matter which host you choose tho (exception being something like Prolexic, they charge a LOT but can handle multi-gigabit DDoS without breaking sweat, allegedly.), a DDoS attack can't be prevented, it can only ever be mitigated once it has begun so in Foots' defense his ads are 100% truthful, so you should base your choice of new host on their answers to your DDoS questions. ![]()
__________________
Server Optimisation - Pentesting - Secure WP Installs. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
I just don't get how some kid with a server that isn't really pumping much bandwidth at all is taking down a website like that. Is it really that easy that it just takes 1 person and most of the websites out there would go down?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 |
Confirmed User
Industry Role:
Join Date: Aug 2007
Posts: 6,697
|
You have to realize that many people have connections which are capable of 50 Mbps alone. Get 1000 of these in a bot net and it can be tough for anything to stay up. There are things you could do but they have to be done at the host or in some cases the backbone. Most aren't going to want to bother. For small unsophisticated attacks which are only meant to overload one server you sometimes can change things around at the server (IPtables and kernel buffer) but often the attacks are way more than this method can handle.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 | |
Confirmed User
Industry Role:
Join Date: Aug 2001
Posts: 832
|
Quote:
It sounds like your enemy has made a script which always monitors which IP your domain is hosted at, and then he either automatically or manually enters that IP into some botnet command tool which he has access to. You should probably identify which hostname he is monitoring, and then move that problematic hostname away from your main server. Isolate the troubled hostname, move it far away from your important stuff. Now you have "mitigated" the DDOS to somewhere else. Not a perfect solution, but better than nothing? |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 |
Registered User
Industry Role:
Join Date: Dec 2007
Location: Ireland
Posts: 54
|
DDoS'ing capabilities are only limited by the size of the botnet. A single person with just their home connection and a copy of some skiddie tool like LoIC would be like firing a peashooter at a batteship these days. But get a group of 20+ using it and your site will be effected (not Google etc obviously, 99% of VPS/shared sites). Next level, someone creates their own botnet (easy to do), or someone who pays to use one of the big botnets would be like Godzilla (them) Vs Japan (your server). You'd be walking funny for weeks after.
DDoS is so effective simply due to its packet structure, not necessarily it's mbps/gbps size (tho obviously the more the merrier). So, for example, the BredoLab/Oficla botnet had, at it's peak last year, close to 30,000,000 bots at it's disposal. While it was mostly used for email spam if it had of been used for DDoS'ing it would have.. well.. it would have fucked any site up it targeted. Google included. Easily.
__________________
Server Optimisation - Pentesting - Secure WP Installs. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#40 | |
Confirmed User
Industry Role:
Join Date: Apr 2009
Posts: 1,313
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#41 |
Confirmed User
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
|
So what is the site really? BS it's just a nothing forum.
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#42 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#43 |
Confirmed User
Industry Role:
Join Date: Feb 2002
Location: NYC, NY
Posts: 8,531
|
40+ GIG protect
![]() WEBAIR.COM
__________________
![]() ~ Webair Dedicated Cloud Servers™ ~ WEBAIR VSYS™ Virtual Hosting Platform ~ Superior CDN Network ~ ~ Managed Dedicated hosting Specialists ~ DISCOUNT DOMAIN NAMES! ~ WEBAIR FUSION IO MANAGED CLOUD SERVERS! ~ ICQ: 243116321 - TWITTER - @WEBAIRINC - E-Mail: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#44 |
Confirmed User
Industry Role:
Join Date: Dec 2007
Location: Ontario
Posts: 4,235
|
I have a server at webair too, if I got a second one there you guys could help me through this you think?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#45 | |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2002
Location: Punta Cana, DR
Posts: 29,585
|
Quote:
But most who answered here are right : it cost way too much for a nothing site ...
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT ! But I can't figure out how he can breathe or type , at the same time .... |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#46 |
Registered User
Industry Role:
Join Date: Jan 2011
Posts: 40
|
don't worry 40-50 mbps is nothing as long they dont open massive number of connections per second.
as I already write here: gofuckyourself / showthread.php?t=1006103 how much connections/sec they open? what kind of attack? proably you can handle this scriptkiddy ddos attack with server hardening only... give them a try, google for: inetbase ddos script If your forum is for small set of countries only, move to a DNS Service with Geo split service. Install GeoIP on your server and do the same there, you can put this rules inside .htaccess. Such small attack is not hard to fight server based as long the connections/sec are not too high. A real hard fighting begins above 20 gbps and above 1 mio new connections per second :-) --- regarding Geo DNS / local GeoIP Routing -> sent all requests that you don't need back to 127.0.0.1
__________________
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ WTB: Video Dating Profiles ICQ: 8.21 / 000 (digits only) ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#47 |
Confirmed User
Join Date: Feb 2005
Location: Montreal
Posts: 3,018
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#48 |
Confirmed User
Join Date: Mar 2007
Posts: 118
|
hit me up 349588486 I might be able to help you where you are. If not I have a solution for you which doesnt cost 2500 a month.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#49 |
Confirmed User
Join Date: Feb 2005
Location: Montreal
Posts: 3,018
|
Here's the thing .... a managed host may be able to lighten the blow somewhat using DDoS Deflate, tightening up some firewall rules, temporarily reconfiguring your php.ini, etc., etc ... but if the attacker is stubborn enough, what's going to happen is that your site will stay "up", but it will be severely bottlenecked, as your load balances go up into the double (or even triple) digits ... which will mean half of your legit traffic is going to back out of your page before it even loads anyways!!!
Between the added expense of DDoS mitigation, and the loss of legit traffic, I would say this endeavor is a bad one before it even begins ... For a site that is not making you any money, I have to wonder why you want to keep it up so badly? ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#50 |
Confirmed User
Industry Role:
Join Date: Apr 2009
Posts: 1,313
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |