LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Bug Reports > Anti DDOS not working for proxy server

Reply
 
Thread Tools Display Modes
  #1  
Old 04-17-2012, 12:10 PM
freeballt freeballt is offline
Member
 
Join Date: Apr 2011
Posts: 38
Default Anti DDOS not working for proxy server

I'm using cloudflare with my litespeed installation and have been getting hit with a DDOS lately. I have the server setup so that it only allows 7 dynamic requests from a user per second. My logs show a number of ips requesting the same file several times a second (over 10). I suspect since I'm using cloudflare and have those IP's whitelisted, that the DDOS ips aren't being blocked.

In addition, is there a way to block IPs without going through the interface, such as using a ssh command?
Reply With Quote
  #2  
Old 04-18-2012, 12:04 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,390
http://www.litespeedtech.com/support...ead.php?t=5865
Reply With Quote
  #3  
Old 04-18-2012, 03:29 PM
damoncloudflare damoncloudflare is offline
New Member
 
Join Date: Apr 2012
Posts: 4
Post DDoS

Quote:
Originally Posted by freeballt View Post
I'm using cloudflare with my litespeed installation and have been getting hit with a DDOS lately. I have the server setup so that it only allows 7 dynamic requests from a user per second. My logs show a number of ips requesting the same file several times a second (over 10). I suspect since I'm using cloudflare and have those IP's whitelisted, that the DDOS ips aren't being blocked.

In addition, is there a way to block IPs without going through the interface, such as using a ssh command?
Just a quick note that you might want to consider using CloudFlare's DDoS mitigation feature as an option as well (don't know how the large the attack is you're trying to manage).
Reply With Quote
  #4  
Old 04-19-2012, 01:42 PM
freeballt freeballt is offline
Member
 
Join Date: Apr 2011
Posts: 38
Quote:
Originally Posted by damoncloudflare View Post
Just a quick note that you might want to consider using CloudFlare's DDoS mitigation feature as an option as well (don't know how the large the attack is you're trying to manage).
The 5s wait thing is annoying to my users. Ive had complaints about it.

I limited dynamic requests to 1 a second, and there are NO ips in the temporary ban list. There is obviously a problem with using cloudflare or some other proxy service and ip banning with litespeed.

Last edited by freeballt; 04-19-2012 at 01:49 PM..
Reply With Quote
  #5  
Old 04-19-2012, 01:59 PM
damoncloudflare damoncloudflare is offline
New Member
 
Join Date: Apr 2012
Posts: 4
Post Hi,

"The 5s wait thing is annoying to my users. Ive had complaints about it."

Do you think there is something we can do to improve the messaging?
Reply With Quote
  #6  
Old 04-19-2012, 02:05 PM
freeballt freeballt is offline
Member
 
Join Date: Apr 2011
Posts: 38
It's an issue with the message and having to wait 5 seconds. Obviously I don't know what you guys are doing behind the scenes during those 5 seconds, but it makes no sense why you guys would display that message or any prompt (seems unnecessary, or rather advertising).

Having said that, I think if you guys offered a service where we could skin our own captcha page that is well worth a premium subscription.
Reply With Quote
  #7  
Old 04-19-2012, 02:26 PM
damoncloudflare damoncloudflare is offline
New Member
 
Join Date: Apr 2012
Posts: 4
Post Hi,

"Having said that, I think if you guys offered a service where we could skin our own captcha page that is well worth a premium subscription."

Being worked on (don't know the account level type that will be offered with yet).

"It's an issue with the message and having to wait 5 seconds. Obviously I don't know what you guys are doing behind the scenes during those 5 seconds, but it makes no sense why you guys would display that message or any prompt (seems unnecessary, or rather advertising)."

Don't think there is an easy solution for the 5 seconds (will mention it). Basically, we're running some checks on the visitor to see if they exhibit behaviors of a botnet or other type of attack (generally have some specific signatures during a DDoS). I'm sure we'll figure out a way to speed it up.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 11:23 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.