Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #16366

Re: Thwarting DoS attacks

From Stefan Weiss <krewecherl@gmail.com>
Newsgroups comp.lang.javascript
Subject Re: Thwarting DoS attacks
Date 2012-10-04 00:51 +0200
Organization albasani.net
Message-ID <k4ifhf$qjk$1@news.albasani.net> (permalink)
References <ad34l0Fka06U1@mid.individual.net>

Show all headers | View raw


On 2012-10-03 17:41, Mel Smith wrote:
>    For the past many months I have been undergoing DoS attacks whereby a 
> person(s)
> bypasses the 'manual' way of 'clicking' and downloading, and instead, 
> automates this
> process with a program to begin many downloads simultaneously to attempt to 
> 'drown'
> my home office server (Apache 2.2.22). These downloads are aborted part way 
> thru and
> more downloads are started up.

Since you asked in comp.lang.javascript: the most relevant topical
suggestion has already been made - captchas or similar human-agent
checks. That should be enough to fend off casual griefers, as long as
there's no fixed URL for the download.

If your attacker is serious enough, and has more resources that the
usual script kiddies, your only hope is to fight this on the server
side. You can either add more resources than he can swamp (more
bandwidth, more servers, maybe a CDN), but that can quickly get very
expensive. Or you could try to automatically ban misbehaving users:
http://www.fail2ban.org/

The simplest and easiest solution would be to let a big site host the
download. This shouldn't be a problem in your case, because Harbour is
free/open-source. For example, harbour-project.org is a SourceForge
site, and all of their downloads are also hosted by SourceForge. DoSing
SF is still possible, but probably out of reach for somebody with a
personal grudge.

- stefan

Back to comp.lang.javascript | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 09:41 -0600
  Re: Thwarting DoS attacks Dr.Kral@nyc.rr.com - 2012-10-03 14:29 -0400
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 14:39 -0600
  Re: Thwarting DoS attacks Daniel Pitts <newsgroup.nospam@virtualinfinity.net> - 2012-10-03 14:49 -0700
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:15 -0600
      Re: Thwarting DoS attacks Gene Wirchenko <genew@ocis.net> - 2012-10-03 17:26 -0700
  Re: Thwarting DoS attacks Denis McMahon <denismfmcmahon@gmail.com> - 2012-10-03 22:13 +0000
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:20 -0600
  Re: Thwarting DoS attacks dann90038@gmail.com - 2012-10-03 15:45 -0700
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:24 -0600
  Re: Thwarting DoS attacks Stefan Weiss <krewecherl@gmail.com> - 2012-10-04 00:51 +0200
    Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:28 -0600

csiph-web