So sick! Posted October 7, 2010 Report Share Posted October 7, 2010 Kā uz lighttpd, kuru darbina linux gentoo, aizsargāties no DOS/DDOS? Ir kādi tutoriāļi? Quote Link to comment Share on other sites More sharing options...
marcis Posted October 7, 2010 Report Share Posted October 7, 2010 Atslēdzot internetu :> Quote Link to comment Share on other sites More sharing options...
EdgarsK Posted October 8, 2010 Report Share Posted October 8, 2010 tev vajag apacim dabut moduli mod_evasivear apache to varetu izdarit apt-get install libapache2-mod-evasive Quote Link to comment Share on other sites More sharing options...
EdgarsK Posted October 8, 2010 Report Share Posted October 8, 2010 varbut noder arii http://www.cyberciti.biz/tips/lighttpd-set-throughput-connections-per-ip.html Quote Link to comment Share on other sites More sharing options...
marcis Posted October 8, 2010 Report Share Posted October 8, 2010 Ja tev kāds uzlaidīs DDoS, tad neko tu tur nespēsi izfiltrēt. Quote Link to comment Share on other sites More sharing options...
So sick! Posted October 8, 2010 Author Report Share Posted October 8, 2010 Edgar, mani pārsteidz tava lasītprasme. Kā uz lighttpd Bet nu, visi mēdz neizlasīt līdz galam.. :D mārci, vismaz pret HTTP DOS man vajag zāles. :D Quote Link to comment Share on other sites More sharing options...
Klez Posted October 8, 2010 Report Share Posted October 8, 2010 rekur http://en.wikipedia.org/wiki/Denial-of-service_attack pastudē un tad sapratīsi ka ar programmatūru aizsardzība nebuus .. Quote Link to comment Share on other sites More sharing options...
marrtins Posted October 9, 2010 Report Share Posted October 9, 2010 (edited) Dzirdēju, ka lielie zēni izmanto freebsd+pfsense. Pats vēl neesmu liels, mēģinājis neesmu :) Pats izmantoju OSSEC un dažiem serveriem mod_evasivear Edit: un, ja kādiem lauzēj-bruteforcēj-dauņiem nepielec, tad ir nācies webu aizsargāt ar cat access* | grep "GET / " | awk '{print $1}' | sort | uniq -c | sort -rg > ip.ddos Pēc tam jau ip.ddos failā var redzēt kungus, kas smagi izceļas. iptables un miers mājās. Edited October 9, 2010 by marrtins Quote Link to comment Share on other sites More sharing options...
So sick! Posted October 9, 2010 Author Report Share Posted October 9, 2010 mod_evasive @ lighttpd.conf? vai mod_evasivear @ lighttpd.conf? Quote Link to comment Share on other sites More sharing options...
Klez Posted October 11, 2010 Report Share Posted October 11, 2010 marrtins, ja buus ddos, tad arī iptable nelīdzēs, jo pieprasījums uz tavu kasti atnāks. tikai vinsh netiks tālāk par atļauto robežu. ar to gribēju teikt, ka trafiku var noslogot, kā rezultātā kaste ir lēna. un iptablēm arī ir jāizdomā ko darīt ar ienākošo konekciju. Protams ka no maziem ddos tas paliidz. Quote Link to comment Share on other sites More sharing options...
marrtins Posted October 11, 2010 Report Share Posted October 11, 2010 Nu man jautrīši vienreiz aizsita visus 100mbit. Es pat nepamanīju uzreiz (pateicoties nginx), tik skatos, ka tīkls bremzē. grep pa logfailiem palīdzēja ļooooti labi :) Vispār vairāk jāsatraucas par lēniem skriptiem bez frontend servera, jo tie ddos ar 1b/sec, kas tur vaļā apaci, vai arī kustina lēnus-līkus skriptus, ir baisi kaitinoši - 1/2h un servers beigts ar oom_killeri. Quote Link to comment Share on other sites More sharing options...
Aleksejs Posted October 12, 2010 Report Share Posted October 12, 2010 Pret pilnvērtīgu DDoS var cīnīties tikai tad, ja ir pieklājīga infrastruktūra: http://blog.unixy.net/2010/08/the-penultimate-guide-to-stopping-a-ddos-attack-a-new-approach/ Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.