Server rentals :: NFOservers.com

Forums

All times are UTC - 8 hours



Author Message
 Post subject: DDos Attack Prevention
PostPosted: Sat Feb 11, 2012 6:13 pm 
Offline
New to forums
New to forums

Joined: Sat Feb 11, 2012 6:10 pm
Posts: 10
Ok so John transfered me here -.-, He told me he would advise me on how to determine the type of attack in order to be able to block it or to help us block it on my behalf. This will involve
troubleshooting it with utilities such as wireshark/windump, process monitor, or
the application and its logs itself.


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 7:01 pm 
Offline
This is my homepage
This is my homepage

Joined: Thu Aug 10, 2006 9:41 pm
Posts: 966
Do you have a firewall installed on your server?

Question, do you plan on hosting websites or game servers on this machine?

Either way I am sure NFo/Internap has some type of security option that can help against DDOS attacks.

Generally speaking you can't really stop all DDOS attacks.

_________________
Image
Image

http://www.47r-squad.com


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 7:10 pm 
Offline
New to forums
New to forums

Joined: Sat Feb 11, 2012 6:10 pm
Posts: 10
i host a small, 2d pvp game run through a system by Byond.com called dream maker and hosted through dream daemon. Currently i have hackers ddosing my game and nfo cant do anything about it, because they have no clue about what is happening, The Hackers are flooding my game with thousands of fake players causing HUGE lag surges and blocking my players from playing my game. Im extremly pissed off about it and i have NO clue what the hell to do. I Have to stop them they are ruining my game


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 7:11 pm 
Offline
New to forums
New to forums

Joined: Sat Feb 11, 2012 6:10 pm
Posts: 10
if this keeps up the only thing i can think of is transfering servers or serer companys because no one can keep them out


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 7:13 pm 
Offline
This is my homepage
This is my homepage

Joined: Thu Aug 10, 2006 9:41 pm
Posts: 966
This can happen to any providers.

I'd probably suggest looking for which ports they are spamming.

Also do you have any anti DDOS scripts installed?

_________________
Image
Image

http://www.47r-squad.com


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 7:19 pm 
Offline
This is my homepage
This is my homepage

Joined: Thu Aug 10, 2006 9:41 pm
Posts: 966
I'd suggest giving this a try (if you are using windows):
http://wipfw.sourceforge.net/
http://wipfw.sourceforge.net/doc.html

_________________
Image
Image

http://www.47r-squad.com


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 7:38 pm 
Offline
New to forums
New to forums

Joined: Sat Feb 11, 2012 6:10 pm
Posts: 10
it doesnt work it wont let me install it


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 7:55 pm 
Offline
This is my homepage
This is my homepage

Joined: Thu Aug 10, 2006 9:41 pm
Posts: 966
linkinparksf wrote:
it doesnt work it wont let me install it


What server do you run?
Win 2003?

_________________
Image
Image

http://www.47r-squad.com


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 8:07 pm 
Offline
New to forums
New to forums

Joined: Sat Feb 11, 2012 6:10 pm
Posts: 10
2008 server


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 8:07 pm 
Offline
New to forums
New to forums

Joined: Sat Feb 11, 2012 6:10 pm
Posts: 10
and indows 7 on my laptop and it failed there too


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 10:12 pm 
Online
Founder
Founder
User avatar

Joined: Thu Apr 18, 2002 11:04 pm
Posts: 9223
Location: Seattle
To clarify, what is happening against linkinparksf is not a DDoS, but an application-specific/OS-specific DoS of some sort. It is not large enough to make a blip in bandwidth graphs and I have not been able to capture it on this end. This does not mean that it can't be filtered; likely, the opposite is true. But, linkinparksf, through his unmanaged single-core VDS, needs to collect further information on what is happening, for us to understand the attack and suggest a course of action. Fundamentally, this is a software question, and one that other customers can benefit from the answer to, which is why I advised him to post here.

The first step here will be to run Wireshark or windump while the attack is in progress, looking for anything that stands out. For instance:

* Many connections from a single IP
* Packets that are all the same size
* Many ICMP messages
* Packets sent to an invalid port
* Anything that does not fit in with the normal game traffic flows

With an application-specific attack, it does not usually require much traffic to take the target service down, typically because the attack exploits a weakness in the code that causes all CPU or memory resources to be exhausted (something that should also be visible through the task manager). Generally these types of attacks use specially-crafted identical packets that come either from a large set of spoofed IPs or from a single attacking IP.


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 10:38 pm 
Offline
New to forums
New to forums

Joined: Sat Feb 11, 2012 6:10 pm
Posts: 10
So John ive got further questions for you , There are black highlited items packets i guess you call them, what are they , their are several black ones all from the same ip


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 10:44 pm 
Online
Founder
Founder
User avatar

Joined: Thu Apr 18, 2002 11:04 pm
Posts: 9223
Location: Seattle
If those lines are labelled with things like "length", "source", and "dest", then those are the packets that you are looking for.


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 11:11 pm 
Offline
New to forums
New to forums

Joined: Sat Feb 11, 2012 6:10 pm
Posts: 10
yea i get that but normally when ppl log in its red these are black


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 11:17 pm 
Online
Founder
Founder
User avatar

Joined: Thu Apr 18, 2002 11:04 pm
Posts: 9223
Location: Seattle
I'm not very familiar with the color-coding in Wireshark, but that likely means that something about the properties on the packets is different.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 18 posts ]  Go to page 1, 2  Next

All times are UTC - 8 hours


Who is online

Users browsing this forum: Edge100x, Google [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
It is currently Sun May 19, 2013 3:17 pm
Powered by phpBB® Forum Software © phpBB Group