Page 1 of 1

DDoS Attacks

PostPosted: Fri Apr 13, 2007 12:24 am
Author: Southern Man
Your phpBB Version: 2.0.19
phpBB Type: Integramod 140
MODs: Yes
Your knowledge: Basic Knowledge
Board URL: http://www.newchatterbox.co.uk

PHP Version:
MySQL Version:


What was done before the problem appeared?



What was done to try to solve the problem?




De.scription and Message

I am getting a lot of DDos attacks at the moment. Thankfully the board sems to be coping with them and the IPs are getting banned.

The attacking IPs are largely from Brasil and South Africa and are using a cmd.txt file hosted on several other websites.

The attacks seem mainly directed at profile.php.

I have emailed one of the ISPs involved at thier abuse address but guess what.. no reply <img>

I guess im just looking for some reassurance that the site will hold up and if there is anything more i can do to protect it.

Upgrade to 1.4.1 is planned but I have quite a few mods which I am going through before I bite the bullet.

cheers

PostPosted: Fri Apr 13, 2007 10:07 am
Author: ZacFields
DDos attacks are largely harmless. Just some punk trying to eat up your bandwidth or your CPU and get your site shut down.

As long as phpbb security is catching them and banning them then I wouldn't worry about it. Your site should handle it just fine.

However just to be on the *safe* side if you are getting an overload of attacks I would go ahead and make a backup of your SQL databases and your files just to be on the safe side, in case the attackers actually have some wits and could try something else.

Zac

Re: DDoS Attacks

PostPosted: Wed Apr 18, 2007 2:51 pm
Author: Southern Man
Ok thanks, I do regular backups and the hosts guarentee to have one no more than a week old which is good as well.

Its still continuing but there is nothing new happening so fingers crossed it will be ok <img>

Re: DDoS Attacks

PostPosted: Thu Apr 19, 2007 5:43 am
Author: Southern Man
I have spoken to my host about this as well and they can ban IPs at thier router, when I look in the banlist table all the IPs are encrypted.

Does anyone have a way to extract banned IPs to a table please?

Re: DDoS Attacks

PostPosted: Thu Apr 19, 2007 7:15 am
Author: Frost
[Related] If everyone used a cisco router when hosting and disabled port forwarding, we wouldn't have this problem <img>

PostPosted: Fri Apr 20, 2007 7:58 am
Author: Dioncecht
Yeah, but Cisco's not exactly cheap equipment and setting up a config on a Cisco router can be a bit over some folks heads.

Re: DDoS Attacks

PostPosted: Fri Apr 20, 2007 6:59 pm
Author: Helter
[quote=""Frost";p="24188""][Related] If everyone used a cisco router when hosting and disabled port forwarding, we wouldn't have this problem :)

Re: DDoS Attacks

PostPosted: Fri Apr 20, 2007 9:07 pm
Author: Frost
Yep, so I guess it is worth it to people like you and me who can look past a few minutes of denial of service because we aren't paying that much anyway (I don't pay a dime anyway :) His name was "NoTo" if anyone knows him.