Path: csiph.com!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!news.musoftware.de!wum.musoftware.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: "Mel Smith" Newsgroups: comp.lang.javascript Subject: Thwarting DoS attacks Date: Wed, 3 Oct 2012 09:41:17 -0600 Lines: 50 Message-ID: X-Trace: individual.net OgXum/u3gRSxvCkN3wTSsQa8RqJEPDNbbGqocPycZZMzYLoXng Cancel-Lock: sha1:gBcQFyskN0eOHdTlbNs1t/oqa3c= X-Priority: 3 X-MSMail-Priority: Normal X-Newsreader: Microsoft Outlook Express 6.00.2900.5931 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.6157 X-RFC2646: Format=Flowed; Original Xref: csiph.com comp.lang.javascript:16347 Hi: I have a download site for C/C++ programmers where they can download the most current versions of our Harbour Language. For the past many months I have been undergoing DoS attacks whereby a person(s) bypasses the 'manual' way of 'clicking' and downloading, and instead, automates this process with a program to begin many downloads simultaneously to attempt to 'drown' my home office server (Apache 2.2.22). These downloads are aborted part way thru and more downloads are started up. Of course, I can 'Deny' the IPs access, but this person just uses a different client proxy. I have approx 20 different anchors/links of the style below: Download Some File JAVASCRIPT: In the link statement above, and with javascript I regularly modify the 'files' word in the above statement to a different sub-directory at my site -- when loading is complete. However, my 'attacker' has again outsmarted me, and uses source investigation techniques to determine the actual download sub-dir. Examining my Apache logs I see the vast stream of aborted downloads resulting in '206' errors Question: Is there a different download technique whereby my 'script' (actually a C-based executable) could intercept the download request, investigate it, then (perhaps) refuse the download request. As it is now, my script doesn't even know that this attack is happening. Thanks for any Javascript guidance offered. -Mel Smith