Under DDOS Attack
Results 1 to 8 of 8

Thread: Under DDOS Attack

  1. #1
    Registered User L15ard's Avatar
    Join Date
    Apr 2001
    Location
    Newcastle, England
    Posts
    83

    Under DDOS Attack

    Our website is under DDOS attack, and whilst ZA pro is blocking all the requests for port 137, it still render the website inaccessable, we have a linksys router, is there any way to bounce these request at the router?

  2. #2
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    If you have proof then your isp should be able to block it at their routers.

  3. #3
    Registered User Gollo's Avatar
    Join Date
    Sep 2001
    Location
    Grand Rapids, Michigan US of A
    Posts
    2,383
    Gotta agree with noo on this one. If you had a decent router (not a home gateway like you have there) then you could block the ip or range of ip's (depends on the situation)

  4. #4
    Registered User L15ard's Avatar
    Join Date
    Apr 2001
    Location
    Newcastle, England
    Posts
    83
    We're gonna try a packet sniffer and get the true source of the attack and inform his/her isp, thanks for you input, BTW things seem to have calmed down now, maybe he/she know we're onto em???

  5. #5
    Registered User silencio's Avatar
    Join Date
    Sep 2000
    Location
    Savannah
    Posts
    3,960
    If you are indeed under a DDOS attack an IP will do zero good. The first D in DDOS is for Distributed. That means that the attacker is utilizing a number of zombies. That means you'd have to block hundreds or thousands of IPs or networks AT THE ISP. No ISP is going to do that. If it's just one dude attacking you it's simple to block the IP and if you keep your logs you can sue the bastage.

  6. #6
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    Originally posted by silencio
    If you are indeed under a DDOS attack an IP will do zero good. The first D in DDOS is for Distributed. That means that the attacker is utilizing a number of zombies. That means you'd have to block hundreds or thousands of IPs or networks AT THE ISP. No ISP is going to do that. If it's just one dude attacking you it's simple to block the IP and if you keep your logs you can sue the bastage.
    Indeed, but the ISP should be involved as its running up the bw for this site through no fault of their own.... I was thinking along the line of what Steve Gibson did when his site was attacked... www.grc.com

  7. #7
    Registered User L15ard's Avatar
    Join Date
    Apr 2001
    Location
    Newcastle, England
    Posts
    83
    And dis-assembling a packet and comparing the IPs is always a good thing to do, as like you say they do use zombies, but there maybe info in there that leads to the perp...

  8. #8
    Chat Operator Matridom's Avatar
    Join Date
    Jan 2002
    Location
    Ontario, Canada
    Posts
    3,778
    Originally posted by NooNoo
    Indeed, but the ISP should be involved as its running up the bw for this site through no fault of their own.... I was thinking along the line of what Steve Gibson did when his site was attacked... www.grc.com
    I believe Noo has it right here. He should call his OWN ISP and have those packets blocked, the ISP has a much broader trunk for internet access and is therefore much much more difficult to get knocked off by a DDOS attack. What you need to do is determine what type of packets are knocking you offline, findout what you want blocked and have and ACL put on the router to block that info (ACL, Access Control List)

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •