Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #16347

Thwarting DoS attacks

From "Mel Smith" <med_cutout_syntel@aol.com>
Newsgroups comp.lang.javascript
Subject Thwarting DoS attacks
Date 2012-10-03 09:41 -0600
Message-ID <ad34l0Fka06U1@mid.individual.net> (permalink)

Show all headers | View raw


Hi:

   I have a download site for C/C++ programmers where they can download the
most current versions of our Harbour Language.

   For the past many months I have been undergoing DoS attacks whereby a 
person(s)
bypasses the 'manual' way of 'clicking' and downloading, and instead, 
automates this
process with a program to begin many downloads simultaneously to attempt to 
'drown'
my home office server (Apache 2.2.22). These downloads are aborted part way 
thru and
more downloads are started up.

   Of course, I can 'Deny' the IPs access, but this person just uses a 
different client proxy.

   I have approx 20 different anchors/links of the style below:

      <a  href="http://www.mysite.com/files/somefile.zip">Download Some 
File</a>

JAVASCRIPT:
   In the link statement above, and with javascript I regularly modify the 
'files' word in the
above statement to a different sub-directory at my site -- when loading is 
complete.

   However, my 'attacker' has again outsmarted me, and uses source 
investigation techniques
to determine the actual download sub-dir.

   Examining my Apache logs I see the vast stream of aborted downloads 
resulting in
'206' errors

Question:
   Is there a different download technique whereby my 'script'  (actually a 
C-based executable)
could intercept the download request, investigate it, then (perhaps) refuse 
the download request.

   As it is now, my script doesn't even know that this attack is happening.

Thanks for any Javascript guidance offered.

-Mel Smith

Back to comp.lang.javascript | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 09:41 -0600
  Re: Thwarting DoS attacks Dr.Kral@nyc.rr.com - 2012-10-03 14:29 -0400
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 14:39 -0600
  Re: Thwarting DoS attacks Daniel Pitts <newsgroup.nospam@virtualinfinity.net> - 2012-10-03 14:49 -0700
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:15 -0600
      Re: Thwarting DoS attacks Gene Wirchenko <genew@ocis.net> - 2012-10-03 17:26 -0700
  Re: Thwarting DoS attacks Denis McMahon <denismfmcmahon@gmail.com> - 2012-10-03 22:13 +0000
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:20 -0600
  Re: Thwarting DoS attacks dann90038@gmail.com - 2012-10-03 15:45 -0700
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:24 -0600
  Re: Thwarting DoS attacks Stefan Weiss <krewecherl@gmail.com> - 2012-10-04 00:51 +0200
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:28 -0600

csiph-web