Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #16347 > unrolled thread

Thwarting DoS attacks

Started by"Mel Smith" <med_cutout_syntel@aol.com>
First post2012-10-03 09:41 -0600
Last post2012-10-03 18:28 -0600
Articles 12 — 7 participants

Back to article view | Back to comp.lang.javascript


Contents

  Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 09:41 -0600
    Re: Thwarting DoS attacks Dr.Kral@nyc.rr.com - 2012-10-03 14:29 -0400
      Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 14:39 -0600
    Re: Thwarting DoS attacks Daniel Pitts <newsgroup.nospam@virtualinfinity.net> - 2012-10-03 14:49 -0700
      Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:15 -0600
        Re: Thwarting DoS attacks Gene Wirchenko <genew@ocis.net> - 2012-10-03 17:26 -0700
    Re: Thwarting DoS attacks Denis McMahon <denismfmcmahon@gmail.com> - 2012-10-03 22:13 +0000
      Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:20 -0600
    Re: Thwarting DoS attacks dann90038@gmail.com - 2012-10-03 15:45 -0700
      Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:24 -0600
    Re: Thwarting DoS attacks Stefan Weiss <krewecherl@gmail.com> - 2012-10-04 00:51 +0200
      Re: Thwarting DoS attacks "Mel Smith" <med_cutout_syntel@aol.com> - 2012-10-03 18:28 -0600

#16347 — Thwarting DoS attacks

From"Mel Smith" <med_cutout_syntel@aol.com>
Date2012-10-03 09:41 -0600
SubjectThwarting DoS attacks
Message-ID<ad34l0Fka06U1@mid.individual.net>
Hi:

   I have a download site for C/C++ programmers where they can download the
most current versions of our Harbour Language.

   For the past many months I have been undergoing DoS attacks whereby a 
person(s)
bypasses the 'manual' way of 'clicking' and downloading, and instead, 
automates this
process with a program to begin many downloads simultaneously to attempt to 
'drown'
my home office server (Apache 2.2.22). These downloads are aborted part way 
thru and
more downloads are started up.

   Of course, I can 'Deny' the IPs access, but this person just uses a 
different client proxy.

   I have approx 20 different anchors/links of the style below:

      <a  href="http://www.mysite.com/files/somefile.zip">Download Some 
File</a>

JAVASCRIPT:
   In the link statement above, and with javascript I regularly modify the 
'files' word in the
above statement to a different sub-directory at my site -- when loading is 
complete.

   However, my 'attacker' has again outsmarted me, and uses source 
investigation techniques
to determine the actual download sub-dir.

   Examining my Apache logs I see the vast stream of aborted downloads 
resulting in
'206' errors

Question:
   Is there a different download technique whereby my 'script'  (actually a 
C-based executable)
could intercept the download request, investigate it, then (perhaps) refuse 
the download request.

   As it is now, my script doesn't even know that this attack is happening.

Thanks for any Javascript guidance offered.

-Mel Smith

[toc] | [next] | [standalone]


#16352

FromDr.Kral@nyc.rr.com
Date2012-10-03 14:29 -0400
Message-ID<qj0p689tmim34bfg7ee91234ab0k7sth1r@4ax.com>
In reply to#16347
On Wed, 3 Oct 2012 09:41:17 -0600, "Mel Smith" <med_cutout_syntel@aol.com>
wrote in <ad34l0Fka06U1@mid.individual.net>:

>   For the past many months I have been undergoing DoS attacks whereby a 
>person(s)
>bypasses the 'manual' way of 'clicking' and downloading, and instead, 
>automates this
>process with a program to begin many downloads simultaneously

Try putting in a 'human check' by making the link a form with a Captcha
test.

K.

[toc] | [prev] | [next] | [standalone]


#16359

From"Mel Smith" <med_cutout_syntel@aol.com>
Date2012-10-03 14:39 -0600
Message-ID<ad3m3lFoi2fU1@mid.individual.net>
In reply to#16352
Dr. Kral said:
> Try putting in a 'human check' by making the link a form with a Captcha
> test.


    I've thought (but very lightly) on that 'Captcha' concept, but now I'll 
really dig in to it !

Thank you.

-Mel Smith

[toc] | [prev] | [next] | [standalone]


#16361

FromDaniel Pitts <newsgroup.nospam@virtualinfinity.net>
Date2012-10-03 14:49 -0700
Message-ID<Jp2bs.1437$MA1.812@newsfe18.iad>
In reply to#16347
On 10/3/12 8:41 AM, Mel Smith wrote:
>     However, my 'attacker' has again outsmarted me, and uses source
> investigation techniques
> to determine the actual download sub-dir.
>
>     Examining my Apache logs I see the vast stream of aborted downloads
> resulting in
> '206' errors
206 is not an error, nor is it an aborted download.
<http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html#sec10.2.7>

This may not be a DoS, but instead someone might be using a 
"download-accelerator", which may be attempting to fetch several parts 
of the file in parallel, in an attempt to speed up the download.

You might look at the User-Agent, to see if it is indeed a accelerator. 
  If it is, then I wouldn't do anything about it.

Another thing you can try is to find a way to "throttle" downloads by 
IP. Until the supposed attacker starts doing DDoS, you'll save your 
bandwidth.

Or, perhaps you need a real hosting solution since you're serving up 
apparently large files.

[toc] | [prev] | [next] | [standalone]


#16370

From"Mel Smith" <med_cutout_syntel@aol.com>
Date2012-10-03 18:15 -0600
Message-ID<ad42p0Fr9jkU1@mid.individual.net>
In reply to#16361
Daniel:

    No this is a personal insidious attacker which has been going on for 
approx a year

-Mel

[toc] | [prev] | [next] | [standalone]


#16373

FromGene Wirchenko <genew@ocis.net>
Date2012-10-03 17:26 -0700
Message-ID<eslp689kb35h1qloshie3rd4mccgpaeurp@4ax.com>
In reply to#16370
On Wed, 3 Oct 2012 18:15:21 -0600, "Mel Smith"
<med_cutout_syntel@aol.com> wrote:

>Daniel:
>
>    No this is a personal insidious attacker which has been going on for 
>approx a year

     How do you know?  Is it possible that you are misinterpreting
what is happening?  (This could make quite a difference in what you
ought to do.)

Sincerely,

Gene Wirchenko

[toc] | [prev] | [next] | [standalone]


#16362

FromDenis McMahon <denismfmcmahon@gmail.com>
Date2012-10-03 22:13 +0000
Message-ID<k4ida6$1pq$1@dont-email.me>
In reply to#16347
On Wed, 03 Oct 2012 09:41:17 -0600, Mel Smith wrote:

> Question:
>    Is there a different download technique whereby my 'script' 
>    (actually a
> C-based executable)
> could intercept the download request, investigate it, then (perhaps)
> refuse the download request.

Another technique:

Ask them for an email addr. Email a unique link to each addr that is 
submitted. Something like:

"Hi

You (or someone pretending to be you) submitted a request for a download 
link for [name of software].

To confirm that you want this link, click the following url:

http://host/confirm1?x=some_hash_here

Otherwise, please ignore this email.

Best Wishes

Mel Smith, blah blah blah"

When they click on the confirm link, email a unique (using a different 
hash) download link to the email addy for that hash. In your download 
handler, check for valid second stage hashes.

A bit more fiddly to program and use, but possibly less fiddly to the 
user than a captcha, and if / once the attacker catches up with the new 
system, you may over time be able to identify email providers that are 
being used in the attacks.

Rgds

Denis McMahon

[toc] | [prev] | [next] | [standalone]


#16371

From"Mel Smith" <med_cutout_syntel@aol.com>
Date2012-10-03 18:20 -0600
Message-ID<ad432fFrbbrU1@mid.individual.net>
In reply to#16362
Denis said:

> Another technique:
>
> Ask them for an email addr. Email a unique link to each addr that is
> submitted. Something like:
>
> "Hi
>
> You (or someone pretending to be you) submitted a request for a download
> link for [name of software].
>
> To confirm that you want this link, click the following url:
>
> http://host/confirm1?x=some_hash_here
>
> Otherwise, please ignore this email.
>
> Best Wishes
>
> Mel Smith, blah blah blah"
>
> When they click on the confirm link, email a unique (using a different
> hash) download link to the email addy for that hash. In your download
> handler, check for valid second stage hashes.
>
> A bit more fiddly to program and use, but possibly less fiddly to the
> user than a captcha, and if / once the attacker catches up with the new
> system, you may over time be able to identify email providers that are
> being used in the attacks.

Denis:

    This is another good idea !

    I'll investigate it.

Thanks,

-Mel



[toc] | [prev] | [next] | [standalone]


#16365

Fromdann90038@gmail.com
Date2012-10-03 15:45 -0700
Message-ID<72cc51e1-8680-4ed2-aa76-c6262d885cb1@googlegroups.com>
In reply to#16347
First of all, What leads you to think is a DoS?  Why would anyone bother doing so to your webserver?  I'm inclined to think like Daniel Pitts, that it may just be a multi-threaded Download Manager someone is using.  If so, yes, throttling the bandwidth per IP will do the trick.

PS:  a long long time ago, I happen to have found this site with lots of files, anyhow, to click on each to download will give me a sore hand, so I used a download manager, well, after a few minutes the server sent me some broken packets, this was in win98 btw, so win98 went down and I got a reboot.  Well, I got my firewall up, didn't get rebooted or shut, restarted the manager, after a few minutes the server cut off my downloads.  I gather they thought I might have been DoS'ing or just Leeching the bandwidth, dunno. :|

[toc] | [prev] | [next] | [standalone]


#16372

From"Mel Smith" <med_cutout_syntel@aol.com>
Date2012-10-03 18:24 -0600
Message-ID<ad43a3FrcpqU1@mid.individual.net>
In reply to#16365
Dann said:

First of all, What leads you to think is a DoS?  Why would anyone bother 
doing so to your webserver?  I'm inclined to think like Daniel Pitts, that 
it may just be a multi-threaded Download Manager someone is using.  If so, 
yes, throttling the bandwidth per IP will do the trick.

Dann:

    There is no doubt its a pointed attack on me alone that is long term 
(about a year), and its (probably) because that I provide free downloads 
where the attacker has a money-motive for discouraging me from my activity 
because he makes money selling a package which includes these downloads

-Mel

[toc] | [prev] | [next] | [standalone]


#16366

FromStefan Weiss <krewecherl@gmail.com>
Date2012-10-04 00:51 +0200
Message-ID<k4ifhf$qjk$1@news.albasani.net>
In reply to#16347
On 2012-10-03 17:41, Mel Smith wrote:
>    For the past many months I have been undergoing DoS attacks whereby a 
> person(s)
> bypasses the 'manual' way of 'clicking' and downloading, and instead, 
> automates this
> process with a program to begin many downloads simultaneously to attempt to 
> 'drown'
> my home office server (Apache 2.2.22). These downloads are aborted part way 
> thru and
> more downloads are started up.

Since you asked in comp.lang.javascript: the most relevant topical
suggestion has already been made - captchas or similar human-agent
checks. That should be enough to fend off casual griefers, as long as
there's no fixed URL for the download.

If your attacker is serious enough, and has more resources that the
usual script kiddies, your only hope is to fight this on the server
side. You can either add more resources than he can swamp (more
bandwidth, more servers, maybe a CDN), but that can quickly get very
expensive. Or you could try to automatically ban misbehaving users:
http://www.fail2ban.org/

The simplest and easiest solution would be to let a big site host the
download. This shouldn't be a problem in your case, because Harbour is
free/open-source. For example, harbour-project.org is a SourceForge
site, and all of their downloads are also hosted by SourceForge. DoSing
SF is still possible, but probably out of reach for somebody with a
personal grudge.

- stefan

[toc] | [prev] | [next] | [standalone]


#16374

From"Mel Smith" <med_cutout_syntel@aol.com>
Date2012-10-03 18:28 -0600
Message-ID<ad43i4Frej3U1@mid.individual.net>
In reply to#16366
Stefan said:

"Stefan Weiss" <krewecherl@gmail.com> wrote in message 
news:k4ifhf$qjk$1@news.albasani.net...
> On 2012-10-03 17:41, Mel Smith wrote:
>>    For the past many months I have been undergoing DoS attacks whereby a
>> person(s)
>> bypasses the 'manual' way of 'clicking' and downloading, and instead,
>> automates this
>> process with a program to begin many downloads simultaneously to attempt 
>> to
>> 'drown'
>> my home office server (Apache 2.2.22). These downloads are aborted part 
>> way
>> thru and
>> more downloads are started up.
>
> Since you asked in comp.lang.javascript: the most relevant topical
> suggestion has already been made - captchas or similar human-agent
> checks. That should be enough to fend off casual griefers, as long as
> there's no fixed URL for the download.
>
> If your attacker is serious enough, and has more resources that the
> usual script kiddies, your only hope is to fight this on the server
> side. You can either add more resources than he can swamp (more
> bandwidth, more servers, maybe a CDN), but that can quickly get very
> expensive. Or you could try to automatically ban misbehaving users:
> http://www.fail2ban.org/
>
> The simplest and easiest solution would be to let a big site host the
> download. This shouldn't be a problem in your case, because Harbour is
> free/open-source. For example, harbour-project.org is a SourceForge
> site, and all of their downloads are also hosted by SourceForge. DoSing
> SF is still possible, but probably out of reach for somebody with a
> personal grudge.
>
> - stefan

Stefan:

    I just want to identify and stop him.

    and I've been hosting my own site in my own office for three years now. 
I have no intention of changingh this mode of operation.

    I'll be looking at the 'captcha' and email approaches over the coming 
days

    btw,  each of my downloads is approx 14-15 megabytes, and comprise the 
harbour language built for about 7 different C compilers.

-Mel

[toc] | [prev] | [standalone]


Back to top | Article view | comp.lang.javascript


csiph-web