Linode.com Forum Forum Index Linode.com Forum
Linode Community Forums
 


Defending against Denial of Service attacks

Click here to go to the original topic

 
       Linode.com Forum Forum Index -> Linux Networking
Author Message
jsalloum



Joined: 01 Jun 2004
Posts: 15
Location: Toronto, Canada

Posted: Tue Jun 29, 2004 10:24 am    Post subject: Defending against Denial of Service attacks  

After last night's DDoS attack at the HE datacenter, I'm a bit curious about what I should install on my linode to protect against such an attack. I've been reading up on the packet flow rate options in iptables, but I wondered if anyone could recommend a really good tutorial/HOWTO/example of what an ideal iptables firewall setup to defend against DDoS would be. A lot of the documentation is very abstract--detailing every possible option you could implement with the software. Something that broke it down down more concretely for those of us that are learning about it would be ideal.

I've already got an iptablesrocks.org setup in place (that *seems* to be working nicely), but I need to pay attention to the DDoS side of things for those ports that are open...

Thanks in advance for your help! :D
j.
Back to top  
caker



Joined: 15 Apr 2003
Posts: 2392
Location: Galloway, NJ

Posted: Tue Jun 29, 2004 12:10 pm    Post subject:  

DoS attacks that don't fill our bandwidth capacity (at the switch) only render the Linode and the host that Linode is on inaccessible. A few things had to happen to affect everyone like it did last night. It has more to do with the networking hardware than your configuration. DoS attacks are best handled either on my end or upstream.

Of course, what you can do is not attrack DoS attacks in the first place, which I doubt you would :)

-Chris
Back to top  
You_Wish



Joined: 02 Nov 2003
Posts: 58

Posted: Tue Jun 29, 2004 7:31 pm    Post subject: Caker were these attacks coming from the linode or going to  

Caker were these attacks coming from the linode or going to it. If they were coming from is there any way to check if they are coming from ours. I love my linode and dont want to a part of that parade.
Back to top  
caker



Joined: 15 Apr 2003
Posts: 2392
Location: Galloway, NJ

Posted: Tue Jun 29, 2004 8:05 pm    Post subject:  

It was going TO a Linode (not yours). If it was coming FROM, that would be a clearer case of abuse.

-Chris
Back to top  
efc



Joined: 10 Jun 2004
Posts: 19
Location: Ireland

Posted: Thu Jul 01, 2004 3:43 am    Post subject:  

You could always install some additional apache modules to help - mod_dosevasive, mod_throttle, and mod_security. A few searches on WHT throws up some good info regarding these modules.

They are not a perfect solution, but may help somewhat against attacks.
Back to top  
 
       Linode.com Forum Forum Index -> Linux Networking
Page 1 of 1