November 05, 2010 01:08PM
Hey Malte,

During a ddos attack, you are sending $possible_bad-ip to a different
server that just sits there and does nothing but Captcha. The cost for
showing a captcha to a host is far less than the impact it would have on
your network/servers.

also on the captcha you can implement cookie checks and if the host does
not become valid say after seeing the page $n_times then you can add the
ip to an acl block list. Layer3-4 blocking cost is much less than
layer7, same goes for if you are taking the threat away from your
production internet facing servers and forcing the possible bad hosts go
through a captcha system.

the last time i setup a network to handle 400mbps and 140k connection
(not packets) a second attack it was with the suggestions and topology
ive described, its worked without issues for me but perhaps you are
seeing something that i have not.

Regards,
-Payam



malte wrote:
> unclepieman Wrote:
> -------------------------------------------------------
>
>> Hey,
>>
>> Instead of a 503, i would redirect them
>> localhost:81 and allow them to
>> validly themselves via captcha system in case its
>> a false positive.
>> Like above, if a host logs the same src_ip more
>> than $x times in $xy
>> min, u should be moving the acl up the chain, your
>> sub-distribution,
>> distribution cor or even edge routers.
>>
>
> It would be nice to have it configurable either way, but when you are
> hit with a 50k bot attack and you have IPs requesting 50 pages per
> second, you want to put them down immediately, not spend server time
> serving them a dynamic captcha page.
>
> Posted at Nginx Forum: http://forum.nginx.org/read.php?2,147105,148021#msg-148021
>
>
> _______________________________________________
> nginx mailing list
> nginx@nginx.org
> http://nginx.org/mailman/listinfo/nginx
>
>


_______________________________________________
nginx mailing list
nginx@nginx.org
http://nginx.org/mailman/listinfo/nginx
Subject Author Posted

DDoS protection module suggestion

malte November 02, 2010 10:19PM

Re: DDoS protection module suggestion

Weibin Yao November 02, 2010 10:58PM

Re: DDoS protection module suggestion

malte November 02, 2010 11:21PM

Re: DDoS protection module suggestion

unclepieman November 03, 2010 12:02AM

Re: DDoS protection module suggestion

malte November 03, 2010 05:00PM

Re: DDoS protection module suggestion

unclepieman November 03, 2010 05:15PM

Re: DDoS protection module suggestion

malte November 03, 2010 10:30PM

Re: DDoS protection module suggestion

Redd Vinylene November 04, 2010 04:52AM

Re: DDoS protection module suggestion

malte November 04, 2010 03:47PM

Re: DDoS protection module suggestion

Weibin Yao November 04, 2010 10:28PM

Re: DDoS protection module suggestion

unclepieman November 05, 2010 12:10AM

Re: DDoS protection module suggestion

Weibin Yao November 05, 2010 01:08AM

Re: DDoS protection module suggestion

malte November 05, 2010 01:58AM

Re: DDoS protection module suggestion

unclepieman November 05, 2010 03:34AM

Re: DDoS protection module suggestion

Weibin Yao November 05, 2010 05:56AM

Re: DDoS protection module suggestion

Eugaia November 05, 2010 06:44AM

Re: DDoS protection module suggestion

姚伟斌 November 05, 2010 08:52AM

Re: DDoS protection module suggestion

malte November 05, 2010 12:16PM

Re: DDoS protection module suggestion

姚伟斌 November 05, 2010 09:50PM

Re: DDoS protection module suggestion

malte November 05, 2010 12:11PM

Re: DDoS protection module suggestion

unclepieman November 05, 2010 01:08PM

Re: DDoS protection module suggestion

malte November 05, 2010 05:52PM

Re: DDoS protection module suggestion

malte November 05, 2010 05:53PM

Re: DDoS protection module suggestion

Weibin Yao November 05, 2010 05:42AM

Re: DDoS protection module suggestion

Rainer Duffner November 03, 2010 05:42PM

Re: DDoS protection module suggestion

malte November 03, 2010 10:22PM

Re: DDoS protection module suggestion

ken107 December 26, 2010 04:49AM

Re: DDoS protection module suggestion

Weibin Yao December 26, 2010 09:32PM

Re: DDoS protection module suggestion

Waleed G. March 25, 2012 01:04PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 310
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready