CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

How to STOP SMTP (and other) DDoS Attacks!

 
Post new topic   Reply to topic       All -> FavForums -> DDoS [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Blibit42

Cadet
Cadet


Joined: Aug 16, 2008
Posts: 5
Location: USA

PostPosted: Mon Aug 18, 2008 10:18 pm    Post subject: How to STOP SMTP (and other) DDoS Attacks!
Reply with quote

Download and Read the PDF file here:
http://www.wakeupyouidiots.com/How_To_Stop_SMTP_DDOS_Attacks.pdf

Then get the package here:
http://www.wakeupyouidiots.com/Logs2List.zip

It is comprehensive, and provides information on
how to stop these attacks. You do need control
of the server (admin access), but it works and
it works well. We must STOP these criminals.

PLEASE disseminate the PDF and the ZIP (listed
in the PDF) as widely as possible. Pardon the Domain
name, but I assume that I will be attacked before
long and need a "disposable" domain, so get it now!!

Thanks,
Mr. Blibit42

Back to top
View users profile Send private message
Blibit42

Cadet
Cadet


Joined: Aug 16, 2008
Posts: 5
Location: USA

PostPosted: Tue Aug 19, 2008 3:15 pm    Post subject:
Reply with quote

Also, I'd like to hear of any success stories, and I am willing to help with advice and more ideas.

And I apologize to the hosting Company of the domain I used. It will disappear shortly, anyway. Get it while its HOT and post it everywhere you can get it exposure. If it worked for me, it can work for others.

Cheers,
Mr. Blibit42

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2943

Blue Security Premium

PostPosted: Wed Aug 20, 2008 4:13 am    Post subject:
Reply with quote

When you get up to 2,000 or 3,000 banned IPs, at what stage does the IP DENY list performance degrade the operation of the system? Is there a point at which the DENY list becomes so large that the system can not handle it?

I am wondering whether you can kep the list in place after a DDoS attack ends, without any significant impact.

Back to top
View users profile Send private message Visit posters website AIM Address
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1118
Location: USA

PostPosted: Wed Aug 20, 2008 2:38 pm    Post subject:
Reply with quote

Neat read, nifty tool and a nice idea (if it works).

A co-worker of mine was recently talking about something like this in fear of getting attacked himself, in the near future.


As far as the reading, I noticed it recommends PeerGuardian2. I will say, I've used PeerGuardian2 and it does drop the packets fine. Even blocking 95% of the internet IP address ranges, it blocks the connections "quick".

As far as Moblock, I've not tried that, since I don't have *NIX access....but I think development has been done closely with that of Peerguardian, so it may work the same way.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Blibit42

Cadet
Cadet


Joined: Aug 16, 2008
Posts: 5
Location: USA

PostPosted: Wed Aug 20, 2008 3:29 pm    Post subject:
Reply with quote

We reached 43000 blocked addresses on a Windows 2000 server box with a Pentium D930 and 2GB of RAM, and it blocked them all and didn't even slow the server down at all!! I did have to buy a new Ethernet switch that I use between the ISP and my servers - they had it all clogged up (had to reset it every hour or so) and it was pretty old. But I got a good one for 195 dollars (about all I could afford right then).

It literally saved my business. I lost one customer before I got it finished and working, but they were leaving us anyway for Exchange services with someone else. Our server has about 20 domains and about 150 users and we were blocking 43000 addresses, updated DAILY from the logs. It really works for the LONG SLOW session attacks that the other methods will not stop (like blocking over X connections per minute). I had to do something. It was all or nothing. I was expecting a "SEND ME MONEY AND I'LL STOP" message any day. I am going to update it to also look for TOO MANY HTTP connections per minute in in HTTP logs. I don't "like" these people and we must beat them with technology. I will post the new one when it is done.

Cheers,
Mr. Blibit42

Back to top
View users profile Send private message
Blibit42

Cadet
Cadet


Joined: Aug 16, 2008
Posts: 5
Location: USA

PostPosted: Wed Aug 20, 2008 4:00 pm    Post subject:
Reply with quote

As far as:
"I am wondering whether you can keep the list in place after a DDoS attack ends, without any significant impact."

At one point I was blocking 4 days of 100 MB per day logs and I had them in for a week. As long as you are sure that you are not accidentally blocking one of your own Mail users, I can't see any reason why it could hurt. It will certainly partially slow down a second "sneak" attack - And, you can bet I have saved my OLD Original lists with the old Bot Army addresses. But as we all know, the Bots do change IPs over time due to what I call the "Homer Simpson Effect" (HSE).

I now update it every morning, and I am sure that the original blocked addresses have all filtered out of it, but now, since I am blocking everything that goes into my email server intrusion detection (which is now set to 3 or more "no such users" per IP) I have cut my SPAM by about 30% - I think it is because PGLite is blocking for 24 hours (or more) and my Intrusion detection is only doing 12 hours - but I would have to do some studying to be sure that is why. I just have to make very sure I don't block one of my users who ended up in the 12 hour block for BAD typing of user names - that could be ME as bad as my typing is...! <grin> (but then again, my IP is in the NeverBlock.txt ;0>)

Cheers,
Mr Blibit42

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1118
Location: USA

PostPosted: Thu Aug 21, 2008 12:24 am    Post subject:
Reply with quote

That's about the only concern I could see, particularly for large scale sites/domains...i.e.: something like CastleCops Smile

The amount of users here....a range of innocents would end up in the filter sooner or later....hell, in the earlier DoS attack this year, my BellSouth static IP landed in Paul's blocklist so I couldn't connect for a couple days due to it.

A possible work-around would be to grab the IPs of "frequent customers" (or "regulars" lol) - and add them to the AlwaysAllow....but if they are on dynamic addresses, those addresses could be used maliciously in due time...


So, how far are you willing to code all the IFs, ANDs, and ORs? ^^ lol. only joking - more of just "food for thought" for users who choose to go this route Wink There will always be pros and cons to nearly every system, but hey, this is free. Smile

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
spamislame

SIRT Handler


Joined: Apr 19, 2006
Posts: 217


PostPosted: Thu Aug 21, 2008 7:11 pm    Post subject:
Reply with quote

This is great stuff.

I haven't admin'd a server at this level (yet) but it's definitely on my list of things to learn. Thanks for providing this resource.

SiL

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> DDoS All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer