Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

attack

General questions about VestaCP
Post Reply
  • Print view
Advanced search
4 posts • Page 1 of 1
Teo
Posts: 97
Joined: Mon May 11, 2015 9:17 am

Os: CentOS 6x
Web: apache + nginx
attack
  • Quote

Post by Teo » Wed Nov 11, 2015 4:26 pm

Hello guys,

someone is attacking my SOF2.ORG website with something weird, the VPS where is running my webserver is DDoS protected and it works fine but this bastard is doing something against the 8080 port, during a recent attack i was able to get this from LOG:
http://paste.ubuntu.com/13211397/

he seems is attacking with something which generate a stress for the VPS
Image

untill the mysql server crash and it stops.

my action: i have VPS with OVH using their DDoS protection and i added Mod_Security and Mod_evasive in my webserver.

any idea on how to block this please?

thanks.
Top

ykpon
Posts: 56
Joined: Thu Jul 23, 2015 3:29 pm

Re: attack
  • Quote

Post by ykpon » Wed Nov 11, 2015 5:15 pm

https://github.com/kyprizel/testcookie-nginx-module
I think, that help you.
Top

Teo
Posts: 97
Joined: Mon May 11, 2015 9:17 am

Os: CentOS 6x
Web: apache + nginx
Re: attack
  • Quote

Post by Teo » Thu Nov 12, 2015 8:25 am

oh many thanks, but what it exactely do and what who is attacking is exactely doing please? Have you experienced the same issue yourself?
Top

DRS
Posts: 6
Joined: Wed Nov 11, 2015 9:54 pm

Re: attack
  • Quote

Post by DRS » Thu Nov 12, 2015 12:16 pm

Have you tested with the DDOS Deflate Script?

1º) Download:
wget http://www.inetbase.com/scripts/ddos/install.sh
2º) Grant permissions:
chmod 0700 install.sh
3º) Install:
./install.sh
4º) Settings:
nano /usr/local/ddos/ddos.conf

[Options]

FREQ=1 (Frequency of script in minutes)
NO_OF_CONNECTIONS=150 (Maximum connections before being banned)
APF_BAN=1 (1 to use APF, 0 to use IPTables)
BAN_PERIOD=600 (time ban)
EMAIL_TO=”root” (Send email whenever someone is bans)
KILL=1 (1 to unable anti-DDOS, 0 for disable anti-DDOS)


[Recommendation]

FREQ=1
NO_OF_CONNECTIONS=100
APF_BAN=0
BAN_PERIOD=10800
EMAIL_TO=”[email protected]”
KILL=1
Top


Post Reply
  • Print view

4 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password