Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #16374

Re: Thwarting DoS attacks

From "Mel Smith" <med_cutout_syntel@aol.com>
Newsgroups comp.lang.javascript
Subject Re: Thwarting DoS attacks
Date 2012-10-03 18:28 -0600
Message-ID <ad43i4Frej3U1@mid.individual.net> (permalink)
References <ad34l0Fka06U1@mid.individual.net> <k4ifhf$qjk$1@news.albasani.net>

Show all headers | View raw


Stefan said:

"Stefan Weiss" <krewecherl@gmail.com> wrote in message 
news:k4ifhf$qjk$1@news.albasani.net...
> On 2012-10-03 17:41, Mel Smith wrote:
>>    For the past many months I have been undergoing DoS attacks whereby a
>> person(s)
>> bypasses the 'manual' way of 'clicking' and downloading, and instead,
>> automates this
>> process with a program to begin many downloads simultaneously to attempt 
>> to
>> 'drown'
>> my home office server (Apache 2.2.22). These downloads are aborted part 
>> way
>> thru and
>> more downloads are started up.
>
> Since you asked in comp.lang.javascript: the most relevant topical
> suggestion has already been made - captchas or similar human-agent
> checks. That should be enough to fend off casual griefers, as long as
> there's no fixed URL for the download.
>
> If your attacker is serious enough, and has more resources that the
> usual script kiddies, your only hope is to fight this on the server
> side. You can either add more resources than he can swamp (more
> bandwidth, more servers, maybe a CDN), but that can quickly get very
> expensive. Or you could try to automatically ban misbehaving users:
> http://www.fail2ban.org/
>
> The simplest and easiest solution would be to let a big site host the
> download. This shouldn't be a problem in your case, because Harbour is
> free/open-source. For example, harbour-project.org is a SourceForge
> site, and all of their downloads are also hosted by SourceForge. DoSing
> SF is still possible, but probably out of reach for somebody with a
> personal grudge.
>
> - stefan

Stefan:

    I just want to identify and stop him.

    and I've been hosting my own site in my own office for three years now. 
I have no intention of changingh this mode of operation.

    I'll be looking at the 'captcha' and email approaches over the coming 
days

    btw,  each of my downloads is approx 14-15 megabytes, and comprise the 
harbour language built for about 7 different C compilers.

-Mel

Back to comp.lang.javascript | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 09:41 -0600
  Re: Thwarting DoS attacks Dr.Kral@nyc.rr.com - 2012-10-03 14:29 -0400
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 14:39 -0600
  Re: Thwarting DoS attacks Daniel Pitts <newsgroup.nospam@virtualinfinity.net> - 2012-10-03 14:49 -0700
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:15 -0600
      Re: Thwarting DoS attacks Gene Wirchenko <genew@ocis.net> - 2012-10-03 17:26 -0700
  Re: Thwarting DoS attacks Denis McMahon <denismfmcmahon@gmail.com> - 2012-10-03 22:13 +0000
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:20 -0600
  Re: Thwarting DoS attacks dann90038@gmail.com - 2012-10-03 15:45 -0700
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:24 -0600
  Re: Thwarting DoS attacks Stefan Weiss <krewecherl@gmail.com> - 2012-10-04 00:51 +0200
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:28 -0600

csiph-web