Home Client Area Affiliate Program Features Sign In
IPB

Welcome Guest ( Log In | Register )

Profile
Personal Photo
Rating
 
Options
Options
Personal Statement
emoney doesn't have a personal statement currently.
Personal Info
emoney
Newbie
Age Unknown
Gender Not Set
Location Unknown
Birthday Unknown
Interests
No Information
Statistics
Joined: 22-June 08
Profile Views: 167*
Last Seen: 23rd June 2008 - 07:53 AM
Local Time: Dec 5 2008, 11:20 AM
2 posts (0.01 per day)
Contact Information
AIM No Information
Yahoo No Information
ICQ No Information
MSN No Information
Contact Private
* Profile views updated each hour

emoney

Members

*


Topics
Posts
Files
Issues
Comments
Friends
My Content
22 Jun 2008
First off, we are under constant ddos attacks, not sure why, not sure who, but they are quite persistent. We've been running APF and even upped to a hardware firewall for $50/month from the host.

I asked around and most seem to think purchasing this script would help, considering the fact we have both a software and hardware FW already, but I just wanted to ask for another opinion.

Our main problem, is that somehow our members (including myself and my staff) can easily rack up a high number of connections (otherwise known as requests, right?) so many legit users get blocked from the script. So after a wave of ddos'ing, then we spend the next few days unblocking legit users, at least ones not on the white list. So my question is does your software handle this differently in any way? Would there be a way to decipher between legit high connection IPs and botnet high connection IPs?

And is there a way to block all traffic to a specific url, in case the botnets are hitting one url specifically?

And I guess a more general question, are there other users with this problem, or would you have an idea as to why its easy for our forum users to rack up such a high number of connections? Too many mods? 1 faulty mod? Ajax? Shoutbox? etc etc? It would make things a lot easier if we could lower that "baseline" connection number, so when we do block any IP with over 100 connections we can be more sure that it is in fact a botnet IP.

thanks for any help! and please link me to other threads if these questions have already been answered. smile.gif
Last Visitors
emoney has no visitors to display.

Comments
Other users have left no comments for emoney.

Friends
There are no friends to display.
Lo-Fi Version Time is now: 5th December 2008 - 11:20 AM