Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

 

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
New Webmasters ask "How-To" questions here. This is where other fucking Webmasters help.

 
Thread Tools
Old 06-30-2015, 02:24 AM   #1
RachelBlackG
Elysium
 
RachelBlackG's Avatar
 
Industry Role:
Join Date: Feb 2011
Location: Prague
Posts: 1,037
How to protect against DDoS?

Hello,

do you guys have any experience with DDoS attacks? Are there any ways how to protect my VPS? I know about Anti-DDoS service, but its expensive for me. ATM I just manually ban suspicious IP's. But that's not enough.

Thanks
RachelBlackG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-30-2015, 04:50 AM   #2
dirtymind
Confirmed User
 
Join Date: May 2008
Posts: 2,348
You can use several things to protect your vps, but it is best to have your hosting company do this. We do this all the time for our clients and we also monthly scan their servers to make sure nothing happens to it. If you have a good host, than they will do this for you or help you with it.

If your host sucks, come talk to us
__________________
skype: codercarlos
dirtymind is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-30-2015, 06:23 AM   #3
RachelBlackG
Elysium
 
RachelBlackG's Avatar
 
Industry Role:
Join Date: Feb 2011
Location: Prague
Posts: 1,037
I am with WebAir and have unmanaged VPS. They charge extra $ for managed servers which I can't afford at this moment. You have better prices and plans as I can see. Looks very interesting for me.

Anyway I have my contract for another 9 months so I need to fix it. There's a lot of tutorials about firewalls, mod_security and other mod_'s. So I am trying to find as much useful info as I can see and give it to my developer.
RachelBlackG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-30-2015, 09:26 AM   #4
CPA-Rush
small trip to underworld
 
Industry Role:
Join Date: Mar 2012
Location: first gen intel 80386/nintendo-gb/arcade/ps1/internet person
Posts: 4,927
u are under attack ? or maybe just trying to protect yourself from possible ddos?
regularly people use cloudflare ... for vps i didn't research .


yes banning ips is not low level solution
__________________

automatic exchange - paxum , bitcoin,pm, payza

. daizzzy signbucks caution will black-hat black-hat your traffic

ignored forever :zuzana designs
CPA-Rush is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-30-2015, 09:39 AM   #5
RachelBlackG
Elysium
 
RachelBlackG's Avatar
 
Industry Role:
Join Date: Feb 2011
Location: Prague
Posts: 1,037
I am under every-day attack. Sometimes it's so strong that I can't even believe it.

Yes, I know about Cloudflare and other similar services. I am not in position to afford it right now. I have banned many IP's, but it always come from different one. So this doesn't help at all.
RachelBlackG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-30-2015, 10:09 AM   #6
CPA-Rush
small trip to underworld
 
Industry Role:
Join Date: Mar 2012
Location: first gen intel 80386/nintendo-gb/arcade/ps1/internet person
Posts: 4,927
Quote:
Originally Posted by RachelBlackG View Post
I am under every-day attack. Sometimes it's so strong that I can't even believe it.
wow that's ridiculous


Quote:
Yes, I know about Cloudflare and other similar services. I am not in position to afford it right now. I have banned many IP's, but it always come from different one. So this doesn't help at all.
i see...maybe there are codes online that could help u out i'm pretty sure some are available for free
__________________

automatic exchange - paxum , bitcoin,pm, payza

. daizzzy signbucks caution will black-hat black-hat your traffic

ignored forever :zuzana designs
CPA-Rush is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-30-2015, 10:14 AM   #7
CPA-Rush
small trip to underworld
 
Industry Role:
Join Date: Mar 2012
Location: first gen intel 80386/nintendo-gb/arcade/ps1/internet person
Posts: 4,927
moving to another vps is smart choice too... seems ur vps is known to those attackers-network
__________________

automatic exchange - paxum , bitcoin,pm, payza

. daizzzy signbucks caution will black-hat black-hat your traffic

ignored forever :zuzana designs
CPA-Rush is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-30-2015, 10:26 AM   #8
RachelBlackG
Elysium
 
RachelBlackG's Avatar
 
Industry Role:
Join Date: Feb 2011
Location: Prague
Posts: 1,037
Quote:
Originally Posted by CPA-Rush View Post
moving to another vps is smart choice too... seems ur vps is known to those attackers-network
I think the same. I have another mainstream project coming, so it will be hosted somewhere else and I will close this one when contract ends. Anyway until then I want to try as much as I can to deny access to my server for these fuckers.
RachelBlackG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-30-2015, 10:50 AM   #9
CPA-Rush
small trip to underworld
 
Industry Role:
Join Date: Mar 2012
Location: first gen intel 80386/nintendo-gb/arcade/ps1/internet person
Posts: 4,927
Quote:
Originally Posted by RachelBlackG View Post
I think the same. I have another mainstream project coming, so it will be hosted somewhere else and I will close this one when contract ends. Anyway until then I want to try as much as I can to deny access to my server for these fuckers.
find one with ddos protection ,sure depends how extensive are the attacks
those links provide some good info ...

cloudflare Free plan can be good for save ddos attack? | Web Hosting Talk

virtual machine - VPS hosting and DDoS attacks prevention - Super User

webserver - What methods are there of protecting a VPS from DDOS attacks? - Information Security Stack Exchange
__________________

automatic exchange - paxum , bitcoin,pm, payza

. daizzzy signbucks caution will black-hat black-hat your traffic

ignored forever :zuzana designs
CPA-Rush is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-30-2015, 11:42 AM   #10
DonJon69
Confirmed User
 
DonJon69's Avatar
 
Industry Role:
Join Date: Nov 2014
Location: NJ
Posts: 475
I thought cloud flare was free.
__________________
Make Money With Adult Websites - Free Step by Step Guide!
DonJon69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-30-2015, 11:47 AM   #11
RachelBlackG
Elysium
 
RachelBlackG's Avatar
 
Industry Role:
Join Date: Feb 2011
Location: Prague
Posts: 1,037
Thanks for links. :-)

Cloudflare is free in the very basic plan.
RachelBlackG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 07-01-2015, 11:16 PM   #12
brandonstills
Confirmed User
 
brandonstills's Avatar
 
Join Date: Dec 2007
Location: Chatsworth, CA
Posts: 1,964
Go with a hosting company that has DDOS protection. Ultimately though if it looks like legit traffic there is no way to block it without blocking legitimate traffic. You can mitigate it by making your site resilient and scalable.
brandonstills is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 07-03-2015, 03:44 PM   #13
jimmycastor
So Fucking Banned
 
Join Date: Jul 2006
Posts: 342
u running wordpress ?
wordpress is vulnerable and a simple script kiddie can be pain in the ass and eat up your server ressources, if u dont have basic protections like firewall, slowloris protection etc,
doesnt even have to be a ddos attack,


just dig into some good firewall settings, .htacces protection and go further from there
check your logs for malicious behaviour and post request and ban ips handish on cloudflare, that can help , is free and doesnt eat up to much time

big ddos attacks with thousands of ips do cost and eat up ressources, ask yourself why someone would invest time , money to attack just you, its maybe just a couple of script kiddies checking your machine for vulnerablity and some unexperienced webmaster might thing ouch this is a huge ddos attack

you dont need an atomic bomb to kill some insects
jimmycastor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 07-04-2015, 03:23 AM   #14
RachelBlackG
Elysium
 
RachelBlackG's Avatar
 
Industry Role:
Join Date: Feb 2011
Location: Prague
Posts: 1,037
I have WP and custom made sites. I ban IP's from logs on regular basis. Sometimes it can go up to 500 MB per second (it decreased since I started with IP ban...mostly it's about 10-50MB/sec). I don't have big sites or something that would compete with someone. It's weird.

Thanks for another useful info.

I'd rather have that A-Bomb for them
RachelBlackG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 07-04-2015, 12:45 PM   #15
Barry-xlovecam
It's 42
 
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
Change your DNS to your registrar's DNS server with the registrar's default page.Take the site down for a day.

If it doesn't stop: copy with new names and remove the files they are requesting so fast causing the ddos ...
Barry-xlovecam is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 07-04-2015, 10:37 PM   #16
supperball
Registered User
 
supperball's Avatar
 
Industry Role:
Join Date: Jul 2015
Posts: 3
Quote:
Originally Posted by DonJon69 View Post
I thought cloud flare was free.
Me too :D:D
__________________
Best Porn 69
supperball is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 07-05-2015, 04:59 AM   #17
dirtymind
Confirmed User
 
Join Date: May 2008
Posts: 2,348
you should have a look at csf firewall and fail2ban to start with, then make sure yuo ssh port is update, lockout the root and use a custom user. vclam to scan your server on mailware. If you know where your traffic is coming from you can lock out ips from certain countries.

There is a lot of free stuff you can do.
__________________
skype: codercarlos
dirtymind is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 07-06-2015, 05:47 PM   #18
NameName
Registered User
 
Industry Role:
Join Date: Apr 2014
Posts: 25
I'm using Cloudflare. I also installed csf firewall on my vps, enable some function then it can block suspicious ip.
NameName is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 07-07-2015, 07:50 AM   #19
jimmycastor
So Fucking Banned
 
Join Date: Jul 2006
Posts: 342
most suspcious script kiddies , scrapers and other malicious behaviour are hiding behind cloudflare, while normal users with their assigned ips from their networks wont use cloudflare, so its sometime helpful , if your box is under stress, to ban cloudflare subnetranges and you see your box
taking a breath instantly
its more like a antibiotic method, not really surgical but if your mysql dropsout all the time due to heavy load and you want to keep your site up it might help
jimmycastor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 07-07-2015, 09:08 AM   #20
RachelBlackG
Elysium
 
RachelBlackG's Avatar
 
Industry Role:
Join Date: Feb 2011
Location: Prague
Posts: 1,037
Thanks guys for more info. Cloudflare seems to help. I haven't had any spike for a few days. Like wow! But it's true that I search logs every day and ban all suspicious IP's. That must have some positive effect. I can also confirm that majority of such attempts are made from China. Next is csf firewall and some modules.
RachelBlackG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 07-07-2015, 05:28 PM   #21
jscott
So Fucking Banned
 
Industry Role:
Join Date: Feb 2001
Location: Taipei
Posts: 25,198
Hate to say but i was pretty much told that there is no affordable protection from ddos..... not is there any way to find/prosecute the attacker

This was years ago.... i hope things have gotten better
jscott is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 09-04-2015, 05:41 PM   #22
anexsia
Confirmed User
 
anexsia's Avatar
 
Industry Role:
Join Date: May 2010
Posts: 5,735
Get a cheap DDOS protected VPS and then setup a GRE tunnel to your main server
anexsia is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 09-04-2015, 09:51 PM   #23
PornSEO
Confirmed User
 
Industry Role:
Join Date: Dec 2011
Posts: 396
Cloudflare can give u some basic protection if you are considering free options. Its also easy to configure and setup.
__________________
FREE SEO HELP DESK

If you have any questions or need any advice related to SEO of porn or mainstream websites, PM them to me. I will answer them in my spare time.
PornSEO is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 09-06-2016, 12:26 PM   #24
JayX
Confirmed User
 
JayX's Avatar
 
Industry Role:
Join Date: Dec 2015
Location: Montreal
Posts: 18
I'm under a massive DDOS attack and even with the paid version of cloudflare it isn't helping.... either I set their security level to highest (called under attack mode) and it cuts my seo traffic, or I lower it one notch and these hacker cunts max my CPU. There are over 340+ sites attacking, here are just a few:
paidverts.com
twodollarclick.com
clixsense.com
neobux.com
easyhits4u.com
mysteryptc.com
buxers.net
revenuesharefive.com


By the way I don't advertise for my site so these all look like legit referrals but they use all my server resources until it crashes.

Any REAL solutions to this BS would be very helpful.

Thanks
JayX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
 
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
ddos, protect, atm, expensive, manually, ips, ban, suspicious, service, experience, guys, attacks, vps, anti-ddos



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.