Re: Block ddos steam Fail2Ban
I can't imagine this working. More professional DDoS attacks rely on sending the maximum amount of data on random UDP ports per packet. The idea is to overload the router with data. In this manner, there is no possible way to, with software, block a DDoS attack.
Mainly, underage script kiddies rely on ICMP packet flooding (Ping protocol) with a copious amount of ping.exe files running. The end result would the be the same (overloading the router) if the attacker's connection was strong enough to send that many packets. However, most likely it isn't, and results in lag instead of an actual denial of service. Edit: More recently, kids have been buying $10 VPS accounts and using them to run packet flooding scripts. In conclusion, your router would be overloaded before the packets had a chance to reach your server. Typically, this is what can bring down a network of datacenter servers that were attached to a single router. It is for this reason that DDoS attacks must be prevented at the hardware level, and this is actually done by some datacenters, which actually advertise their "DDoS protection." I have purchased one of those servers, and I have to say that it protected me from an attack that used hundreds of bots (each with at LEAST 10 mb/s) |
Re: Block ddos steam Fail2Ban
You guys should first know the difference between DoS and DDoS Attacks.
DDoS != DoS. And I think we are talking about DoS attacks here, which can be blocked by filters. DDoS can't be blocked by the system, if anything can block DDoS attacks then it would be load balancers... |
Re: Block ddos steam Fail2Ban
Quote:
|
Re: Block ddos steam Fail2Ban
Steven, I'm pretty sure I know what it is. I've had it done to me before on my home connection.
>:/ I may not know everything about it, but I know the symptoms. So if this won't work for DDoS then I should look somewhere else. |
Re: Block ddos steam Fail2Ban
Quote:
|
Re: Block ddos steam Fail2Ban
You should read, I never said I could stop it I just said i'd have to look somewhere else to try and fix the issue. It's a bit hard when the guy that did it to me keeps trying to find my new server. So i'm paranoid. Also, I know how the whole script things goes it's not like their aren't a gazillion people that are silly on hl1 mods spamming them to death :P
|
Re: Block ddos steam Fail2Ban
Group,
I'm trying to understand 1) how to implement this, 2) how this works. In the IP Tables rules, the following is presented, Code:
iptables -A INPUT -i eth0 -p udp --dport your_port -m length --length 28 -j REJECT_FLOOD28 Also, what part does the fail2ban program play in the equation? Much thanks in advance! Knight Knight Vision Systems http://www.knightvisionsystems.com |
Re: Block ddos steam Fail2Ban
Quote:
Yes, here is to monitorize the port, but I have removed the port, to monitorize all, even, in my server I have just 5060, and 443 open... But I did: Quote:
In the jail conf, I'm missing the action, dose the action should be to deliver back to the iptables?? I have did: Quote:
|
Re: Block ddos steam Fail2Ban
Quote:
Quote:
Bad idea. Upgrades overwrite jail.conf.:rtfm: Quote:
cstrike-planet.com disappeared 11 years ago. [counter-strike] has been default in fail2ban years before this thread was written. I see IP rules threads to offloading module threads while we have had one all along with fail2ban preconfigured. The logpath is out of date and needs to point to /var/log/messages in most instances. Code:
|
All times are GMT -4. The time now is 17:24. |
Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.