my friend has a website. recently it has been D.o.S attack. anyone know to to prevent that? plz help. thankz alot
[help]how To Prevent D.o.s Attack?
Originally posted by Voodoo411@Sep 29 2003, 07:54 AMmy friend has a website. recently it has been D.o.S attack. anyone know to to prevent that? plz help. thankz alot
The key to fixing it isn't looking at it as a DoS attack but finding out what caused it. Once you find the cause you can fix it. There is so many things that can cause such an attack. Do you know any more information?
DoS means Denial of Service, it's just a term used to describe a type of attack, not the actual cause of the attack.
Hope that helps? ![]()
his website is a forum. someone came in, get banned, decided to shutdown his forum. this popup is what i got when access his forum

at first his forum is phpBB, now is vbulletin. both cant prevent that attack. not only the forum, the whole website is down
you aren't blocking cookies from his site, are you?
Originally posted by tek@Sep 29 2003, 09:33 AMyou aren't blocking cookies from his site, are you?
no. his website is down, not me blocking cookies, everyone got that popup (kind of flooding exeed or something?)
If he's flooding your forum. Then just ban his IP.
If you mean it's a ture DoS attack, there's really nothing you can do at your level.
A DoS is just someone sending large amounts of packets at your IP over and over. If it's a DDoS, it's a distributed attack, and the person has multiple machines packeting yoru server non-stop. It makes a bottleneck, and there's no room for any other data to go in or out.
Unless his backbone, or main provider buys extremely expensive routers, there's not much that can be done. You'd need a router a few steps above you that would filter malicious packets. The most he can try to do is ignore all ICMP packets.
If the attacker is using UDP packets at random ports it becomes alot more difficult. If it's a window's box, i'd say just the best firewall you can find. If it's on a linux box, get some good iptable rules in effect. You could search freshmeat.net for some software which would help create the rules, and advanced firewall's.
Like i said though, that's really not gonna help much. All that really does is stops your box from replying, but if enough data is coming down, it doesn't matter if your box drops all the replies, there's still thousands of requests coming in.
Oh, and along the lines of the windows firewall. You can try BlackIce or something, but if he's using a good DDoS and sending lots of little packets, you'll just end up using 100% CPU usage trying to drop the packets.
Track the IP, if it's not spoofed, start calling ISP's and sending out e-mails.
if your friend can compile and install his own apache I recommend this:
http://freshmeat.net/projects/mod_dosevasi...ve/?topic_id=43
Aqua-Soft Forums