LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Install/Configuration > Being attacked by DDos

Reply
 
Thread Tools Display Modes
  #1  
Old 11-04-2011, 11:48 AM
bigjl bigjl is offline
Member
 
Join Date: Nov 2011
Posts: 10
Default Being attacked by DDos

Hi there,
One of my website has been getting ddos attack for a couple of months. The site is hosted on my dedicated server which managed under WHM.
The site is getting around 36k-47k hits everyday and the bandwidth is around 3-4G per day.
I found that litespeed has build-in feature for anti-ddos-attach so I installed a trial version on WHM.
But there is no getting better. The hits still come along and the bandwidth still goes high. Here is my configuration on Per Client Throttling.

Static Requests/second: 0
Dynamic Requests/second: 2
Outbound Bandwidth (bytes/sec): 0
Inbound Bandwidth (bytes/sec): 0
Connection Soft Limit: 5
Connection Hard Limit: 20
Block Bad Request: Yes
Grace Period (sec): 15
Banned Period (sec): 300

Intel i5 2.99
16GB RAM
2TB HDD Raid10
cPanel/WHM

Any suggestions?
Many thanks!
Reply With Quote
  #2  
Old 11-04-2011, 12:04 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
Is the attack a GET flood? Can you tell which URL the botnet abuse?
For large scale attack, the built-in anti-DDoS may not able to stop, it is depends on the size of the botnet and how aggressive the robot behave.

Our antiDDoS proxy service will be live soon, maybe you can give it a try.
Reply With Quote
  #3  
Old 11-04-2011, 10:43 PM
anewday anewday is offline
Senior Member
 
Join Date: Nov 2007
Location: New York
Posts: 729
Set Static Requests/second to something around 5. 0 is unlimited.
Reply With Quote
  #4  
Old 11-05-2011, 04:09 AM
bigjl bigjl is offline
Member
 
Join Date: Nov 2011
Posts: 10
Quote:
Originally Posted by mistwang View Post
Is the attack a GET flood? Can you tell which URL the botnet abuse?
For large scale attack, the built-in anti-DDoS may not able to stop, it is depends on the size of the botnet and how aggressive the robot behave.

Our antiDDoS proxy service will be live soon, maybe you can give it a try.
Thnx mistwang,
I wonder how I know it is a GET flood?
There are huge amount of traffic going to the home page of the site "/"
The user agencies below had the most hits
check_http/v1.4.14 (nagios-plugins 1.4.14)
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.2
Reply With Quote
  #5  
Old 11-05-2011, 04:11 AM
bigjl bigjl is offline
Member
 
Join Date: Nov 2011
Posts: 10
Quote:
Originally Posted by anewday View Post
Set Static Requests/second to something around 5. 0 is unlimited.
Thnx anewday,
I have changed the setting and see if there is any improvement. Thank you.
Reply With Quote
  #6  
Old 11-06-2011, 07:34 AM
NeustarRick NeustarRick is offline
New Member
 
Join Date: Nov 2011
Posts: 1
Default DDoS Protection

Unfortunately there is no way to protect your bandwidth usage at the permiter. The only way to fully protect your systems and your bandwidth usage is with a cloud based DDoS service like the one from Neustar (http://www.ultradns.com/ddos-protect...is-siteprotect).

Another tool set which you may want to look at is UltraTools.com which is 100% free.

Full disclosure I work at Neustar.

Rick
Reply With Quote
  #7  
Old 11-06-2011, 11:08 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
Quote:
Originally Posted by bigjl View Post
Thnx mistwang,
I wonder how I know it is a GET flood?
There are huge amount of traffic going to the home page of the site "/"
The user agencies below had the most hits
check_http/v1.4.14 (nagios-plugins 1.4.14)
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.2
We have a solution to detect if the request is sent by botnet or a real user, if detected botnet, our service will block those IPs at firewall level.
I recommend you sign up with our anti-ddos proxy service when it become available (probably this coming Monday).
It is free during our trial period.
Reply With Quote
  #8  
Old 11-08-2011, 11:49 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
Our anti-DDoS proxy is up now, you can sign up at
https://store.litespeedtech.com/antiddos/cart.php
Reply With Quote
  #9  
Old 11-08-2011, 12:32 PM
bigjl bigjl is offline
Member
 
Join Date: Nov 2011
Posts: 10
Thanks mistwang for your reply.
My website is hosted in the UK and if I use your proxy does my website loading speed become slow?
Thanks
Reply With Quote
  #10  
Old 11-08-2011, 12:58 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
The global WAN speed should be very fast those days, you can give it a try from your location by update "/etc/hosts" by pointing your domain to our proxy server, see if the speed is good.
I think it should be better than being taken down by botnet even if it was indeed slightly slower.
Reply With Quote
Reply

Tags
ddos, ddos attack, per client throttling

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 09:48 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.