Pages: [1] 2   Go Down
Send this topic | Print
Author Topic: ADDED: Yet another abuse script (Anti-Dos), to kill abusers in seconds...  (Read 7699 times)
admin
Administrator
Advanced Authority Member
*****
Offline Offline

Posts: 1355


« on: August 16, 2007, 05:20:15 AM »

We can't reveal how the algorithms works, but it's to kill abusers behavior (testing/refreshing, creating multiple connections like crazy) in seconds. It instantly blocks the attackers IP. Changing IP would naturally equal the same IP ban if abuse from it continues also.

Blockage is for 1 hour. During that time, server (for YOU ONLY) will appear dead/offline/down including FTP.

PURPOSE OF SCRIPT: To protect everyone and everyones sites from being DoSed or abused. Eg. (If any), your site enemies would get blocked instantly if they were to flood your site with a bot designed to spam your site with whatever.

This is an extra measure to maintain the server you're on is fast at all times.

YOU TOO MAY GET BLOCKED IF...: Script is still being adjusted to identify abuse from legit actions which seem similar.

If you get blocked, let me know what you were doing for last 30 minutes before you got blocked. This will help adjust the algorithm.
« Last Edit: August 16, 2007, 05:54:22 AM by admin » Logged

NOTE: ALL PM'S WILL BE IGNORED. UNLESS I ASKED YOU TO PRIVATE MESSAGE ME.

-- Use the "Search" on top-right before posting.
-- If your topic is resolved, put [Resolved] at end of subject.
soren121
I eat lots of those
Advanced Authority Member
*****
Offline Offline

Posts: 1476


I shall stare you down with mah kitteh powahs!


WWW
« Reply #1 on: August 16, 2007, 05:24:35 AM »

Blockage is for 1 hour. During that time, server will appear dead/offline/down including FTP.

So when the guy gets banned, the whole server goes down? I'm confused.  huh
Logged

LightBlog Developer -- Fueled by Linkin Park, Sprite, and LOLCats
admin
Administrator
Advanced Authority Member
*****
Offline Offline

Posts: 1355


« Reply #2 on: August 16, 2007, 05:29:17 AM »

Nothing goes down. lol

Only you get blocked and you may think the server is down. But it's not since it's not allowing any incoming connections from your computers (or abusers computer) IP address.
Logged

NOTE: ALL PM'S WILL BE IGNORED. UNLESS I ASKED YOU TO PRIVATE MESSAGE ME.

-- Use the "Search" on top-right before posting.
-- If your topic is resolved, put [Resolved] at end of subject.
Mop (Gb)
Loyal 110MB Member
*******
Offline Offline

Posts: 4297


Don't Panic!


WWW
« Reply #3 on: August 16, 2007, 05:30:39 AM »

They get banned so that only to them 110mb seems non-existant.

@ Admin(s): Good work! This will stop those ddoses  grin
Logged




Support conficker! Add dino to your sig!
soren121
I eat lots of those
Advanced Authority Member
*****
Offline Offline

Posts: 1476


I shall stare you down with mah kitteh powahs!


WWW
« Reply #4 on: August 16, 2007, 05:37:45 AM »

Nothing goes down. lol

Only you get blocked and you may think the server is down. But it's not since it's not allowing any incoming connections from your computers (or abusers computer) IP address.
They get banned so that only to them 110mb seems non-existant.

Oh...ok. That particular sentence just confused me. Anyway, good job on the script. Hopefully this will prevent another DDos like what we had in May (I think).
Logged

LightBlog Developer -- Fueled by Linkin Park, Sprite, and LOLCats
Slittzle
He touched me with noodle appendage
Loyal 110MB Member
*******
Online Online

Posts: 2992


©®ªÞ


WWW
« Reply #5 on: August 16, 2007, 06:14:28 AM »

what's max # of connections allowed at one time? Me thinks that firefox users using pipelining are going to start getting banned as a result.
Logged

soren121
I eat lots of those
Advanced Authority Member
*****
Offline Offline

Posts: 1476


I shall stare you down with mah kitteh powahs!


WWW
« Reply #6 on: August 16, 2007, 06:29:21 AM »

what's max # of connections allowed at one time? Me thinks that firefox users using pipelining are going to start getting banned as a result.

I see what you mean. Is Fasterfox going to get me banned?  undecided
Logged

LightBlog Developer -- Fueled by Linkin Park, Sprite, and LOLCats
Slittzle
He touched me with noodle appendage
Loyal 110MB Member
*******
Online Online

Posts: 2992


©®ªÞ


WWW
« Reply #7 on: August 16, 2007, 09:54:15 AM »

yea it will. I got banned..and the script is faulty, it doesn't unban you after an hour - it's been more then a couple hours and I'm still banned.
I'm writing this via a proxy btw.

So basically at first I opened 3 windows with Firefox, one of them being this post - and with fasterfox enabled (I have it on courteous) that meant something like max of 8 connections per a window - so 8*3=24 connections say.  I wasn't able to use 110mb forums but I could still visit all 110mb hosted sites. So I assumed that I would get unbanned and post my findings, so I worked on my site a bit - waiting for the ban to disable but then after say 30 minutes, I was banned from all 110mb sites and the ban isn't lifting so I guess it's working to some degree, except that the ban never lifts.

This is not an effective way to stop DDos'ers. I won't offer any tips to DDosers here obviously, but I think this block is going to stop a lot of legitimate users. For one thing, anyone surfing on a 110mb hosted site could easily hit the max connections and be banned from seeing any other site. Also it raises the idea of 110mb abuse - basically by creating a simple html page I can make it so that anyone viewing the page incurrs the ban and thereby is not only unable to see my site, but all other 110mb hosted sites - think of what someone who hates 110mb (do they exist?) could do, proof of code concept here:

index.html:
Code:
<iframe src="index.html"></iframe>

The page is an infinite loop and would cause max-connections to eventually get called. Basically it puts an iframe on screen, which loads the  same page within the iframe. And the page being loaded again recreates another iframe, which again creates another iframe, and so forth. Basically (untested of course - but it should work), will cause a user to hit the max-connection limit - and the server will temp-ban them, during that time the user will not be able to view any 110mb sites, nor access the forum to report that they can't access it. Instead do something like this, make the max-connection limit something like 1000 - that's more likely to be a DDos then say 100 connections or 500 connections (which is a lot still).
« Last Edit: August 16, 2007, 09:57:39 AM by Slittzle » Logged

inp o҉rtb
The Gangsta
Global Moderator
Official 110mb Guru
*****
Offline Offline

Posts: 15633


experimental theologian


WWW
« Reply #8 on: August 16, 2007, 10:03:18 AM »

Interesting loop you got there... You might want to post up your IP address to get unbanned rolleyes

Now, as far as I know, DoS does not have to be executed by opening lots of connections on the attacker's side -- as long as the resources get used up, the purpose is served. Some attacks involve sending malformed packets that keep connections half-open, and some mirror such packets from other servers to hide their identity. Using these techniques, a single machine can overload a server. I suppose a system tool capable of closing all half-open sockets would be useful. There are other methods too, which should be taken care of.
Logged

Hi! I’m a signature virus! Add me to your signature to help me spread.
spam me: ispamspot@gmail.com

blog | my work @ deviantART | Imagine-ng image editor
kriššyafc
Super Authority member
******
Offline Offline

Posts: 1946


« Reply #9 on: August 16, 2007, 10:05:43 AM »

Well i have being blocked 3 times, all i was doing was viewing the forum?
Logged

Slittzle
He touched me with noodle appendage
Loyal 110MB Member
*******
Online Online

Posts: 2992


©®ªÞ


WWW
« Reply #10 on: August 16, 2007, 11:43:40 AM »

I don't think I need to post my ip, seeing as how the mods should have it (just look at any of my posts besides the ones in this one - since I'm using a proxy to access). BTW the html iframe thingy will work, firefox will stop it after a few runs but IE and opera will run it continuously. The admins are nowhere to be found lol, I have a networking background so my 2 cents is to just put up an acl and block ips that did the previous dos attacks, limit max connections of each user to 250-400 connections (even that's a lot but still leaves no room for mistakes). And maybe use some useragent blocking to stop preventable bots, and of course use an iplist to block spambots and other nefarious bots - which can be obtained at any anti-spam site.
Logged

aldo
Official 110mb Guru
********
Offline Offline

Posts: 8004


SMF is ftw :D


WWW
« Reply #11 on: August 16, 2007, 12:03:22 PM »

Actually Slittzle if you access via proxy it will change the IP of the Proxy IP on every single post, just like when you post it changes it on everyone of your posts. All your posts are synced Duh
Logged


admin
Administrator
Advanced Authority Member
*****
Offline Offline

Posts: 1355


« Reply #12 on: August 16, 2007, 03:56:35 PM »

Yea script doesn't ever unblock I just found out. lol

The next change will ban for 30 min and I'll increase the lever x3 higher.
Logged

NOTE: ALL PM'S WILL BE IGNORED. UNLESS I ASKED YOU TO PRIVATE MESSAGE ME.

-- Use the "Search" on top-right before posting.
-- If your topic is resolved, put [Resolved] at end of subject.
phenomless
Hyper-Active Member
***
Offline Offline

Posts: 204


WWW
« Reply #13 on: August 16, 2007, 05:22:03 PM »

Hi I can't access my site and pannel on box 4.
Did not do much... just looked at the forum few times and tried to access my site...

Admin - The first time you activated the script it blocked my IP, then yesterday it was o.k,
and now I'm apparently blocked again...

Edited: It's back after 4 hours...
« Last Edit: September 15, 2009, 04:26:34 PM by phenomless » Logged

The new open-source project for the Hebrew community:
PHP-Fusion now in Hebrew!
100% Translated and RTL
ericsspace
Member
*
Offline Offline

Posts: 28


« Reply #14 on: August 24, 2007, 01:36:57 AM »

Good i hate anyone who will lag the server by spamming or attacking it. It totally sucks that everyone else has to suffer just because one or a few people want to be the annoying hacker.
Logged
TDSii
Best warez site!!
Loyal 110MB Member
*******
Offline Offline

Posts: 2056


..:: skdown.net ::..


WWW
« Reply #15 on: June 17, 2008, 10:50:50 PM »

i wounder why i am not having such issues with my site.although i got too many hits and activity!
the script seems to work fine as i was once blocked when i tried to use a prohibited script Duh

Logged


meep-online
Authority Member
****
Offline Offline

Posts: 983


WWW
« Reply #16 on: August 30, 2008, 10:10:00 AM »

This seems like an epic fail to me :\
Logged

selangor-online
MaLaYsiA
Active Member
**
Offline Offline

Posts: 83


www.selangor-online.110mb.com


WWW
« Reply #17 on: September 27, 2008, 08:56:16 AM »

Nothing goes down. lol

Only you get blocked and you may think the server is down. But it's not since it's not allowing any incoming connections from your computers (or abusers computer) IP address.
admin, since i'm in a univ., will my IP get BAN too if a lot of my friends assessing my webpage?  huh shocked

if admin just google my IP, there r lot of connection.....
« Last Edit: September 27, 2008, 09:02:47 AM by selangor-online » Logged

stevediraddo
Member
*
Offline Offline

Posts: 17

Box 14 - YAY! >_>


WWW
« Reply #18 on: September 29, 2008, 05:50:15 PM »

so if i browse to my page and hit F5 really fast, what will happen?
Logged

Box 14 - WOOHOO!
http://www.stevediraddo.com - "If it aint' broke, fix it anyway!"
antimatter15
Loyal 110MB Member
*******
Online Online

Posts: 4082


WWW
« Reply #19 on: September 30, 2008, 10:50:34 AM »

They get banned so that only to them 110mb seems non-existant.

@ Admin(s): Good work! This will stop those ddoses  grin
It looks like it'll only stop doses, not ddoses.
Logged

Ajax Animator, a web-based, collaborative animation authoring environment with Flash, Silverlight, and GIF export.
Pages: [1] 2   Go Up
Send this topic | Print
Jump to: