Portal Home > Knowledgebase > Articles Database > How to permanently stop DOS attacks?


How to permanently stop DOS attacks?




Posted by kshazad86, 12-05-2011, 09:24 AM
My cPanel server has recently been bombarded by romanians and people from hungary. I've used country block in CSF, and that seems to have done the trick, but how can I stop this from happening again without blocking an entire country?

Posted by relichost, 12-05-2011, 11:11 AM
Hi You cant stop this from happening. Do you know who they are targetting on your server ? Thanks

Posted by iexo, 12-05-2011, 11:14 AM
As said above, a DDoS can't be properly avoided, network level DDoS protection would help you though. And finding who the attacks are being aimed at and looking at what's being targeted is a must.

Posted by DreamServers, 12-05-2011, 11:22 AM
I'd recommend in getting a hardware firewall to start with, then its a long and winded process of tracing the IP's and blocking them. However what exerox said is correct too you want to find out who they're attacking

Posted by kshazad86, 12-06-2011, 04:36 PM
I'm still constantly being attacked from Romania and Hungary.. Any ideas how I can put a stop to this without blocking an entire country in CSF? They seem to constantly flood port 80, rather than attack a specific site on the server, and I've using CT_Limit = 100.

Posted by Steve_Arm, 12-06-2011, 04:57 PM
If it helps, take a look here: http://forums.cpanel.net/f34/first-a...0-a-66952.html

Posted by brianoz, 12-06-2011, 09:13 PM
CSF has some auto-blocking settings which could be worth experimenting with. If they persist they get permanently blocked, and if a number of IPs in a range get blocked CSF can be setup to block the entire range. If you play with the related settings for a while, along with some of the rate limiting stuff you may be able to get it going well enough to manage the blocking without your help. It may not be good enough to solve the problem, but it might be enough and it's definitely worth a shot. Would be nice if you could update the thread and let us know how you went.

Posted by kshazad86, 12-07-2011, 02:02 AM
Thanks for the replies guys... I've tweaked CSF, and for the time being it seems that the attack is either getting smaller or the setting is quite strict so its blocking alot of traffic. I'm using CT_LIMIT = 60, so I believe its blocking everyone who has more than 60 open connections on port 80 at the same time. I've also disabled Synflood feature in CSF as I dont think it has any benefit when used with CONNLIIMT. Let me know if I am wrong? Can someone let me know where I can find Syn Deflate, I've installed DDos Deflate, but would like some protection against synflood attacks as well, and I think the synflood feature is not very good in CSF. All the download links I've seen for syn-deflate are broken. Last edited by kshazad86; 12-07-2011 at 02:11 AM.

Posted by kshazad86, 12-07-2011, 02:25 AM
Also, can someone let me know more about this IP range blocking.. I have it enabled on a setting of: LS_DSHIELD = 86400 LF_SPAMHAUS =86400 But it would be nice to know exactly how this works? Thanks.



Was this answer helpful?

Add to Favourites Add to Favourites    Print this Article Print this Article

Also Read


Language:

LoadingRetrieving latest tweet...

Back to Top Copyright © 2018 DC International LLC. - All Rights Reserved.