Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.javascript > #16347
| From | "Mel Smith" <med_cutout_syntel@aol.com> |
|---|---|
| Newsgroups | comp.lang.javascript |
| Subject | Thwarting DoS attacks |
| Date | 2012-10-03 09:41 -0600 |
| Message-ID | <ad34l0Fka06U1@mid.individual.net> (permalink) |
Hi:
I have a download site for C/C++ programmers where they can download the
most current versions of our Harbour Language.
For the past many months I have been undergoing DoS attacks whereby a
person(s)
bypasses the 'manual' way of 'clicking' and downloading, and instead,
automates this
process with a program to begin many downloads simultaneously to attempt to
'drown'
my home office server (Apache 2.2.22). These downloads are aborted part way
thru and
more downloads are started up.
Of course, I can 'Deny' the IPs access, but this person just uses a
different client proxy.
I have approx 20 different anchors/links of the style below:
<a href="http://www.mysite.com/files/somefile.zip">Download Some
File</a>
JAVASCRIPT:
In the link statement above, and with javascript I regularly modify the
'files' word in the
above statement to a different sub-directory at my site -- when loading is
complete.
However, my 'attacker' has again outsmarted me, and uses source
investigation techniques
to determine the actual download sub-dir.
Examining my Apache logs I see the vast stream of aborted downloads
resulting in
'206' errors
Question:
Is there a different download technique whereby my 'script' (actually a
C-based executable)
could intercept the download request, investigate it, then (perhaps) refuse
the download request.
As it is now, my script doesn't even know that this attack is happening.
Thanks for any Javascript guidance offered.
-Mel Smith
Back to comp.lang.javascript | Previous | Next — Next in thread | Find similar | Unroll thread
Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 09:41 -0600
Re: Thwarting DoS attacks Dr.Kral@nyc.rr.com - 2012-10-03 14:29 -0400
Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 14:39 -0600
Re: Thwarting DoS attacks Daniel Pitts <newsgroup.nospam@virtualinfinity.net> - 2012-10-03 14:49 -0700
Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:15 -0600
Re: Thwarting DoS attacks Gene Wirchenko <genew@ocis.net> - 2012-10-03 17:26 -0700
Re: Thwarting DoS attacks Denis McMahon <denismfmcmahon@gmail.com> - 2012-10-03 22:13 +0000
Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:20 -0600
Re: Thwarting DoS attacks dann90038@gmail.com - 2012-10-03 15:45 -0700
Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:24 -0600
Re: Thwarting DoS attacks Stefan Weiss <krewecherl@gmail.com> - 2012-10-04 00:51 +0200
Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:28 -0600
csiph-web