Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.javascript > #16347 > unrolled thread
| Started by | "Mel Smith" <med_cutout_syntel@aol.com> |
|---|---|
| First post | 2012-10-03 09:41 -0600 |
| Last post | 2012-10-03 18:28 -0600 |
| Articles | 12 — 7 participants |
Back to article view | Back to comp.lang.javascript
Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 09:41 -0600
Re: Thwarting DoS attacks Dr.Kral@nyc.rr.com - 2012-10-03 14:29 -0400
Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 14:39 -0600
Re: Thwarting DoS attacks Daniel Pitts <newsgroup.nospam@virtualinfinity.net> - 2012-10-03 14:49 -0700
Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:15 -0600
Re: Thwarting DoS attacks Gene Wirchenko <genew@ocis.net> - 2012-10-03 17:26 -0700
Re: Thwarting DoS attacks Denis McMahon <denismfmcmahon@gmail.com> - 2012-10-03 22:13 +0000
Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:20 -0600
Re: Thwarting DoS attacks dann90038@gmail.com - 2012-10-03 15:45 -0700
Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:24 -0600
Re: Thwarting DoS attacks Stefan Weiss <krewecherl@gmail.com> - 2012-10-04 00:51 +0200
Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:28 -0600
| From | "Mel Smith" <med_cutout_syntel@aol.com> |
|---|---|
| Date | 2012-10-03 09:41 -0600 |
| Subject | Thwarting DoS attacks |
| Message-ID | <ad34l0Fka06U1@mid.individual.net> |
Hi:
I have a download site for C/C++ programmers where they can download the
most current versions of our Harbour Language.
For the past many months I have been undergoing DoS attacks whereby a
person(s)
bypasses the 'manual' way of 'clicking' and downloading, and instead,
automates this
process with a program to begin many downloads simultaneously to attempt to
'drown'
my home office server (Apache 2.2.22). These downloads are aborted part way
thru and
more downloads are started up.
Of course, I can 'Deny' the IPs access, but this person just uses a
different client proxy.
I have approx 20 different anchors/links of the style below:
<a href="http://www.mysite.com/files/somefile.zip">Download Some
File</a>
JAVASCRIPT:
In the link statement above, and with javascript I regularly modify the
'files' word in the
above statement to a different sub-directory at my site -- when loading is
complete.
However, my 'attacker' has again outsmarted me, and uses source
investigation techniques
to determine the actual download sub-dir.
Examining my Apache logs I see the vast stream of aborted downloads
resulting in
'206' errors
Question:
Is there a different download technique whereby my 'script' (actually a
C-based executable)
could intercept the download request, investigate it, then (perhaps) refuse
the download request.
As it is now, my script doesn't even know that this attack is happening.
Thanks for any Javascript guidance offered.
-Mel Smith
[toc] | [next] | [standalone]
| From | Dr.Kral@nyc.rr.com |
|---|---|
| Date | 2012-10-03 14:29 -0400 |
| Message-ID | <qj0p689tmim34bfg7ee91234ab0k7sth1r@4ax.com> |
| In reply to | #16347 |
On Wed, 3 Oct 2012 09:41:17 -0600, "Mel Smith" <med_cutout_syntel@aol.com> wrote in <ad34l0Fka06U1@mid.individual.net>: > For the past many months I have been undergoing DoS attacks whereby a >person(s) >bypasses the 'manual' way of 'clicking' and downloading, and instead, >automates this >process with a program to begin many downloads simultaneously Try putting in a 'human check' by making the link a form with a Captcha test. K.
[toc] | [prev] | [next] | [standalone]
| From | "Mel Smith" <med_cutout_syntel@aol.com> |
|---|---|
| Date | 2012-10-03 14:39 -0600 |
| Message-ID | <ad3m3lFoi2fU1@mid.individual.net> |
| In reply to | #16352 |
Dr. Kral said:
> Try putting in a 'human check' by making the link a form with a Captcha
> test.
I've thought (but very lightly) on that 'Captcha' concept, but now I'll
really dig in to it !
Thank you.
-Mel Smith
[toc] | [prev] | [next] | [standalone]
| From | Daniel Pitts <newsgroup.nospam@virtualinfinity.net> |
|---|---|
| Date | 2012-10-03 14:49 -0700 |
| Message-ID | <Jp2bs.1437$MA1.812@newsfe18.iad> |
| In reply to | #16347 |
On 10/3/12 8:41 AM, Mel Smith wrote: > However, my 'attacker' has again outsmarted me, and uses source > investigation techniques > to determine the actual download sub-dir. > > Examining my Apache logs I see the vast stream of aborted downloads > resulting in > '206' errors 206 is not an error, nor is it an aborted download. <http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html#sec10.2.7> This may not be a DoS, but instead someone might be using a "download-accelerator", which may be attempting to fetch several parts of the file in parallel, in an attempt to speed up the download. You might look at the User-Agent, to see if it is indeed a accelerator. If it is, then I wouldn't do anything about it. Another thing you can try is to find a way to "throttle" downloads by IP. Until the supposed attacker starts doing DDoS, you'll save your bandwidth. Or, perhaps you need a real hosting solution since you're serving up apparently large files.
[toc] | [prev] | [next] | [standalone]
| From | "Mel Smith" <med_cutout_syntel@aol.com> |
|---|---|
| Date | 2012-10-03 18:15 -0600 |
| Message-ID | <ad42p0Fr9jkU1@mid.individual.net> |
| In reply to | #16361 |
Daniel:
No this is a personal insidious attacker which has been going on for
approx a year
-Mel
[toc] | [prev] | [next] | [standalone]
| From | Gene Wirchenko <genew@ocis.net> |
|---|---|
| Date | 2012-10-03 17:26 -0700 |
| Message-ID | <eslp689kb35h1qloshie3rd4mccgpaeurp@4ax.com> |
| In reply to | #16370 |
On Wed, 3 Oct 2012 18:15:21 -0600, "Mel Smith"
<med_cutout_syntel@aol.com> wrote:
>Daniel:
>
> No this is a personal insidious attacker which has been going on for
>approx a year
How do you know? Is it possible that you are misinterpreting
what is happening? (This could make quite a difference in what you
ought to do.)
Sincerely,
Gene Wirchenko
[toc] | [prev] | [next] | [standalone]
| From | Denis McMahon <denismfmcmahon@gmail.com> |
|---|---|
| Date | 2012-10-03 22:13 +0000 |
| Message-ID | <k4ida6$1pq$1@dont-email.me> |
| In reply to | #16347 |
On Wed, 03 Oct 2012 09:41:17 -0600, Mel Smith wrote: > Question: > Is there a different download technique whereby my 'script' > (actually a > C-based executable) > could intercept the download request, investigate it, then (perhaps) > refuse the download request. Another technique: Ask them for an email addr. Email a unique link to each addr that is submitted. Something like: "Hi You (or someone pretending to be you) submitted a request for a download link for [name of software]. To confirm that you want this link, click the following url: http://host/confirm1?x=some_hash_here Otherwise, please ignore this email. Best Wishes Mel Smith, blah blah blah" When they click on the confirm link, email a unique (using a different hash) download link to the email addy for that hash. In your download handler, check for valid second stage hashes. A bit more fiddly to program and use, but possibly less fiddly to the user than a captcha, and if / once the attacker catches up with the new system, you may over time be able to identify email providers that are being used in the attacks. Rgds Denis McMahon
[toc] | [prev] | [next] | [standalone]
| From | "Mel Smith" <med_cutout_syntel@aol.com> |
|---|---|
| Date | 2012-10-03 18:20 -0600 |
| Message-ID | <ad432fFrbbrU1@mid.individual.net> |
| In reply to | #16362 |
Denis said:
> Another technique:
>
> Ask them for an email addr. Email a unique link to each addr that is
> submitted. Something like:
>
> "Hi
>
> You (or someone pretending to be you) submitted a request for a download
> link for [name of software].
>
> To confirm that you want this link, click the following url:
>
> http://host/confirm1?x=some_hash_here
>
> Otherwise, please ignore this email.
>
> Best Wishes
>
> Mel Smith, blah blah blah"
>
> When they click on the confirm link, email a unique (using a different
> hash) download link to the email addy for that hash. In your download
> handler, check for valid second stage hashes.
>
> A bit more fiddly to program and use, but possibly less fiddly to the
> user than a captcha, and if / once the attacker catches up with the new
> system, you may over time be able to identify email providers that are
> being used in the attacks.
Denis:
This is another good idea !
I'll investigate it.
Thanks,
-Mel
[toc] | [prev] | [next] | [standalone]
| From | dann90038@gmail.com |
|---|---|
| Date | 2012-10-03 15:45 -0700 |
| Message-ID | <72cc51e1-8680-4ed2-aa76-c6262d885cb1@googlegroups.com> |
| In reply to | #16347 |
First of all, What leads you to think is a DoS? Why would anyone bother doing so to your webserver? I'm inclined to think like Daniel Pitts, that it may just be a multi-threaded Download Manager someone is using. If so, yes, throttling the bandwidth per IP will do the trick. PS: a long long time ago, I happen to have found this site with lots of files, anyhow, to click on each to download will give me a sore hand, so I used a download manager, well, after a few minutes the server sent me some broken packets, this was in win98 btw, so win98 went down and I got a reboot. Well, I got my firewall up, didn't get rebooted or shut, restarted the manager, after a few minutes the server cut off my downloads. I gather they thought I might have been DoS'ing or just Leeching the bandwidth, dunno. :|
[toc] | [prev] | [next] | [standalone]
| From | "Mel Smith" <med_cutout_syntel@aol.com> |
|---|---|
| Date | 2012-10-03 18:24 -0600 |
| Message-ID | <ad43a3FrcpqU1@mid.individual.net> |
| In reply to | #16365 |
Dann said:
First of all, What leads you to think is a DoS? Why would anyone bother
doing so to your webserver? I'm inclined to think like Daniel Pitts, that
it may just be a multi-threaded Download Manager someone is using. If so,
yes, throttling the bandwidth per IP will do the trick.
Dann:
There is no doubt its a pointed attack on me alone that is long term
(about a year), and its (probably) because that I provide free downloads
where the attacker has a money-motive for discouraging me from my activity
because he makes money selling a package which includes these downloads
-Mel
[toc] | [prev] | [next] | [standalone]
| From | Stefan Weiss <krewecherl@gmail.com> |
|---|---|
| Date | 2012-10-04 00:51 +0200 |
| Message-ID | <k4ifhf$qjk$1@news.albasani.net> |
| In reply to | #16347 |
On 2012-10-03 17:41, Mel Smith wrote: > For the past many months I have been undergoing DoS attacks whereby a > person(s) > bypasses the 'manual' way of 'clicking' and downloading, and instead, > automates this > process with a program to begin many downloads simultaneously to attempt to > 'drown' > my home office server (Apache 2.2.22). These downloads are aborted part way > thru and > more downloads are started up. Since you asked in comp.lang.javascript: the most relevant topical suggestion has already been made - captchas or similar human-agent checks. That should be enough to fend off casual griefers, as long as there's no fixed URL for the download. If your attacker is serious enough, and has more resources that the usual script kiddies, your only hope is to fight this on the server side. You can either add more resources than he can swamp (more bandwidth, more servers, maybe a CDN), but that can quickly get very expensive. Or you could try to automatically ban misbehaving users: http://www.fail2ban.org/ The simplest and easiest solution would be to let a big site host the download. This shouldn't be a problem in your case, because Harbour is free/open-source. For example, harbour-project.org is a SourceForge site, and all of their downloads are also hosted by SourceForge. DoSing SF is still possible, but probably out of reach for somebody with a personal grudge. - stefan
[toc] | [prev] | [next] | [standalone]
| From | "Mel Smith" <med_cutout_syntel@aol.com> |
|---|---|
| Date | 2012-10-03 18:28 -0600 |
| Message-ID | <ad43i4Frej3U1@mid.individual.net> |
| In reply to | #16366 |
Stefan said:
"Stefan Weiss" <krewecherl@gmail.com> wrote in message
news:k4ifhf$qjk$1@news.albasani.net...
> On 2012-10-03 17:41, Mel Smith wrote:
>> For the past many months I have been undergoing DoS attacks whereby a
>> person(s)
>> bypasses the 'manual' way of 'clicking' and downloading, and instead,
>> automates this
>> process with a program to begin many downloads simultaneously to attempt
>> to
>> 'drown'
>> my home office server (Apache 2.2.22). These downloads are aborted part
>> way
>> thru and
>> more downloads are started up.
>
> Since you asked in comp.lang.javascript: the most relevant topical
> suggestion has already been made - captchas or similar human-agent
> checks. That should be enough to fend off casual griefers, as long as
> there's no fixed URL for the download.
>
> If your attacker is serious enough, and has more resources that the
> usual script kiddies, your only hope is to fight this on the server
> side. You can either add more resources than he can swamp (more
> bandwidth, more servers, maybe a CDN), but that can quickly get very
> expensive. Or you could try to automatically ban misbehaving users:
> http://www.fail2ban.org/
>
> The simplest and easiest solution would be to let a big site host the
> download. This shouldn't be a problem in your case, because Harbour is
> free/open-source. For example, harbour-project.org is a SourceForge
> site, and all of their downloads are also hosted by SourceForge. DoSing
> SF is still possible, but probably out of reach for somebody with a
> personal grudge.
>
> - stefan
Stefan:
I just want to identify and stop him.
and I've been hosting my own site in my own office for three years now.
I have no intention of changingh this mode of operation.
I'll be looking at the 'captcha' and email approaches over the coming
days
btw, each of my downloads is approx 14-15 megabytes, and comprise the
harbour language built for about 7 different C compilers.
-Mel
[toc] | [prev] | [standalone]
Back to top | Article view | comp.lang.javascript
csiph-web