Help DDos Attack On My Offer...

ipark

New member
Dec 23, 2010
25
1
0
What is the best solution or service provider? Help me and I'll pay you.

PM Me


Thanks
 


sys admin

nah, just kidding, but a competant sys admin will deal with it pretty easily.

you can check if the attacker is smart or a dumb ass with cloudflare or reverse proxy.

otherwise, there are lots of option around the thousand dollars price range.

and another option is a firewall hardware, which is really expensive.
 
No everyone's paid. Competitor in my space most likely. Have paid out
3-million plus to affiliates.
 
No everyone's paid. Competitor in my space most likely. Have paid out
3-million plus to affiliates.

a.baa-This-seems-legit.jpg
 
Check your logs for the IP's hitting your site, then do a geo IP lookup to see what country/countries it is coming from, then create an .htaccess file to block those countries.

Use this site to help you: Block Visitors by Country | IP2Location.com

useless tip, cause the ips still hitting your server, and causing load. It could be also that they dont try to access port 80 (webserver) maybe some other port service. try netstat -anpenl check on what port and ips etc its coming (monitor for some mins), and check if its coming from small group ips, if small group ip, you could message your hoster, to ban them on router level, before they hit your server. As you said you make serious money, i would move to a ddos protection hoster, but dont ask me which never used. Or cloudflare but you will need a new IP cause the attackers know it now, so they could just ddos the ip instread of the domain ;)
 
Its a syn flood DDoS attack which spoofs the IP's and makes blocking difficult. It's hitting me at 600K requests minute. So I'm babysitting bandwidth and toggling domains and IP's for the short term to keep it at bay.
 
Its a syn flood DDoS attack which spoofs the IP's and makes blocking difficult. It's hitting me at 600K requests minute. So I'm babysitting bandwidth and toggling domains and IP's for the short term to keep it at bay.

You can setup the input chain on iptables to drop all icmp/syn request.
 
If you know the culprit, 301 the attacked domain to one of his domains for a while.

Change the domains for your setups and start another domain replacing it in google webmaster tools but not setting the 301 for all of your content. Not the perfect solution, but hitting the culprits money site with his own ddos might hurt him at least a little.

Forget about that shit 301'ing to fbi and stuff idiots will tell you.