<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Denial Of Service resource</title>
	<atom:link href="http://www.ddosblog.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ddosblog.com</link>
	<description>Know your enemy, stop and prevent Denial Of Service attacks</description>
	<pubDate>Tue, 19 Aug 2008 15:19:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Free tools to protect your Windows box from ddos attacks</title>
		<link>http://www.ddosblog.com/free-tools-to-protect-your-windows-box-from-ddos-attacks/</link>
		<comments>http://www.ddosblog.com/free-tools-to-protect-your-windows-box-from-ddos-attacks/#comments</comments>
		<pubDate>Tue, 19 Aug 2008 15:19:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Preventing ddos attacks]]></category>

		<category><![CDATA[Ddos]]></category>

		<category><![CDATA[denial of service]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[windows]]></category>

		<category><![CDATA[windows server]]></category>

		<guid isPermaLink="false">http://www.ddosblog.com/?p=45</guid>
		<description><![CDATA[Harden-it
Harden-it is a security tool for your Windows box to harden the TCP/IP stack and thereby provide protection from denial of service attacks. It also hardens your local system thereby blocking many worms and other sort of malware. Some of Harden-it features include enabling SYN flood protection once the attack is detected and specifying the [...]]]></description>
			<content:encoded><![CDATA[<h3>Harden-it</h3>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small; font-family: Calibri;">Harden-it is a security tool for your Windows box to harden the TCP/IP stack and thereby provide protection from denial of service attacks. It also hardens your local system thereby blocking many worms and other sort of malware. Some of Harden-it features include enabling SYN flood protection once the attack is detected and specifying the maximum total amount of both free connections plus those in the SYN_RCVD state. You can download Harden-it from </span><a href="http://www.yasc.net/hardenit.shtml"><span style="font-size: small; font-family: Calibri;">http://www.yasc.net/hardenit.shtml</span></a><span style="font-size: small;"><span style="font-family: Calibri;">.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><br />
</span></span></span></p>
<h3>PC tools firewall plus</h3>
<p>PC tools firewall plus is a freeware Windows firewall software that allows none-sophisticated users a change to setup the firewall easily however allows advanced users to write custom packet filtering rules.<span style="mso-spacerun: yes;">  </span>Even though PC tools firewall plus is a firewall rather for home user than server you can also use it on Windows Server 2003. Download PC tools firewall plus from http://www.pctools.com/firewall/</p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><br />
</span></span></span></p>
<h3>WIPFW</h3>
<p>WIPFW (Windows IP Firewall) is Windows version of open source FreeBSD project, IPFW, a packet filtering and accounting system. IPFW consists of 2 parts – firewall part that does packet filtering and IP accounting part that tracks the use of router.</p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">You can download WIPFW here: http://sourceforge.net/project/showfiles.php?group_id=113599</span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosblog.com/free-tools-to-protect-your-windows-box-from-ddos-attacks/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Using mod_evasive to protect your Linux box</title>
		<link>http://www.ddosblog.com/using-mod_evasive-to-protect-your-linux-box/</link>
		<comments>http://www.ddosblog.com/using-mod_evasive-to-protect-your-linux-box/#comments</comments>
		<pubDate>Sun, 17 Aug 2008 15:18:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Preventing ddos attacks]]></category>

		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Apache]]></category>

		<category><![CDATA[Ddos]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[mod_evasive]]></category>

		<guid isPermaLink="false">http://www.ddosblog.com/?p=43</guid>
		<description><![CDATA[Mod_evasive is an Apache module designed to prevent Denial of service attacks by monitoring traffic and blocking IP addresses when an attacks is detected. 
 
Installing mod_evasive
First thing you must do is download mod_evasive source code from http://www.zdziarski.com/projects/mod_evasive/. After downloading the package you have to extract it using tar zvxf mod_evasive_1.10.1.tar.gz. After you have unpacked the files [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Mod_evasive is an Apache module designed to prevent Denial of service attacks by monitoring traffic and blocking IP addresses when an attacks is detected. </span></span></span><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"> </p>
<h3>Installing mod_evasive</h3>
<p>First thing you must do is download mod_evasive source code from <a href="http://www.zdziarski.com/projects/mod_evasive/">http://www.zdziarski.com/projects/mod_evasive/</a>. After downloading the package you have to extract it using <em>tar zvxf mod_evasive_1.10.1.tar.gz. </em>After you have unpacked the files you are almost ready to compile mod_evasive, but you must have 2 dependencies installed (<a href="http://rpmfind.net/linux/rpm2html/search.php?query=apache2-devel">apache2-devel</a> and  <a href="http://rpmfind.net/linux/rpm2html/search.php?query=apache2-prefork&amp;submit=Search+...&amp;system=&amp;arch=">apache2-prefork</a>). If you already have these dependencies installed or have finished installing them compile mod_evasive20.c file. For Apache 2.0 use<em> </em><span style="mso-ansi-language: EN-US;" lang="EN-US"><em>/usr/local/apache/bin/apxs -i -a -c mod_evasive20.c</em> and for 1.3 <span style="mso-ansi-language: EN-US;" lang="EN-US"><em>/usr/local/apache/bin/apxs -i -a -c mod_evasive.c.</em> If your Apache is not located at /usr/local/apache/bin/apxs replace it with path your Apache directory.</span></span></p>
<p><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="mso-ansi-language: EN-US;" lang="EN-US">Next thing you must do is enable mod_evasive whenever Apache is started, for that locate etc/sysconfig/apache2 and add mod_evasive20 to APACHE_MODULES if you are using Apache 2.0, just mod_evasive in case you are using Apache 1.3. Once you have done that create file mod_evasive.conf to your Apache directory with following content:</span></span></p>
<p><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="mso-ansi-language: EN-US;" lang="EN-US"><em>&lt;IfModule mod_evasive20.c&gt;<br />
    DOSHashTableSize    3097<br />
    DOSPageCount        2<br />
    DOSSiteCount        50<br />
    DOSPageInterval     1<br />
    DOSSiteInterval     1<br />
    DOSBlockingPeriod   10<br />
&lt;/IfModule&gt;</em> </span></span></p>
<p><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="mso-ansi-language: EN-US;" lang="EN-US">That&#8217;s the most common mod_evasive configuration. You don&#8217;t probably need to change any of the configuration values. If you are installing mod_evasive to Apache 1.3 replace the <span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="mso-ansi-language: EN-US;" lang="EN-US"><em>&lt;IfModule mod_evasive20.c&gt; </em>with <span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="mso-ansi-language: EN-US;" lang="EN-US"><em>&lt;IfModule mod_evasive.c&gt;.</em> Now restart Apache webserver for the changes to take effect and mod_evasive to activate</span></span></span></span></span></span></p>
<p></span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosblog.com/using-mod_evasive-to-protect-your-linux-box/feed/</wfw:commentRss>
		</item>
		<item>
		<title>What is Proxy Shield and how to get one</title>
		<link>http://www.ddosblog.com/what-is-proxy-shield-and-how-to-get-one/</link>
		<comments>http://www.ddosblog.com/what-is-proxy-shield-and-how-to-get-one/#comments</comments>
		<pubDate>Thu, 14 Aug 2008 18:30:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Preventing ddos attacks]]></category>

		<category><![CDATA[Ddos]]></category>

		<category><![CDATA[denial of service]]></category>

		<category><![CDATA[dos]]></category>

		<category><![CDATA[proxy]]></category>

		<category><![CDATA[proxy shield]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ddosblog.com/?p=41</guid>
		<description><![CDATA[Proxy shield technology allows you to have a „wall“ between the server and the internet that filters out all the malicious packets without having to have either software or hardware firewall. For unprotected server that suddenly becomes under attack, proxy shield is probably the best solution to eliminate the attack as fast as possible. As [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Proxy shield technology allows you to have a „wall“ between the server and the internet that filters out all the malicious packets without having to have either software or hardware firewall. For unprotected server that suddenly becomes under attack, proxy shield is probably the best solution to eliminate the attack as fast as possible. As proxy shield is a service, not an application or physical device you can stop using it once the attack stops. Furthermore, proxy shields can do the job without you even having to relocate any of your data! Sounds neat? Yes, but it is as expensive. </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Using proxy shield is only worth the money as a short term solution. However if you are looking for a long time security, consider investing the money in hardware and software based firewall and security consulting. Having said this I still have to stress, that proxy shields are efficient and probably one of the best solutions for a starting business or temporary service.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">How to get Proxy wall? I’ll list some service providers as follows:</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><a href="http://www.gtcomm.net/ddos-protection.php"><span style="font-size: small; color: #0000ff; font-family: Calibri;">http://www.gtcomm.net/ddos-protection.php</span></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><a href="http://gigenet.com/ddos-protection.htm"><span style="font-size: small; font-family: Calibri;">http://gigenet.com/ddos-protection.htm</span></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><a href="http://www.ddosprotection.com/ddos_protection.htm"><span style="font-size: small; color: #0000ff; font-family: Calibri;">http://www.ddosprotection.com/ddos_protection.htm</span></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><a href="http://dragonara.net/ddos-protection.html"><span style="font-size: small; color: #0000ff; font-family: Calibri;">http://dragonara.net/ddos-protection.html</span></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><a href="http://www.blockdos.net/"><span style="font-size: small; color: #0000ff; font-family: Calibri;">http://www.blockdos.net/</span></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><a href="http://www.armoraid.com/solutions/"><span style="font-size: small; color: #0000ff; font-family: Calibri;">http://www.armoraid.com/solutions/</span></a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosblog.com/what-is-proxy-shield-and-how-to-get-one/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Installing and configuring APF (Linux security)</title>
		<link>http://www.ddosblog.com/installing-and-configuring-apf-linux-security/</link>
		<comments>http://www.ddosblog.com/installing-and-configuring-apf-linux-security/#comments</comments>
		<pubDate>Wed, 13 Aug 2008 11:44:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Ddos]]></category>

		<category><![CDATA[denial of service]]></category>

		<category><![CDATA[dos]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[linux security]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ddosblog.com/?p=37</guid>
		<description><![CDATA[Advanced Policy Firewall (APF) is, like (D)DoS fleat, a iptables based firewall software for Linux box. APF is a powerful, yet easy to install and configure firewall. 





Installing APF


 
 

Type the following into shell:
cd /usr/local/src
wget http://rfxnetworks.com/downloads/apf-current.tar.gz
tar -zxf apf-current.tar.gz
cd apf-0.*
./install.sh
After you have installed the firewall you will see a message: “Listening TCP ports: 1,21,22,25,53,80,110,111,143,443,465,993,995,2082,2083,2086,2087,2095,2096,3306
  Listening UDP ports: [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Advanced Policy Firewall (APF) is, like <a href="http://www.ddosblog.com/using-ddos-fleat-to-protect-your-linux-system/">(D)DoS </a>fleat, a iptables based firewall software for Linux box. APF is a powerful, yet easy to install and configure firewall. </span></span></span></p>
<div class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"></p>
<div class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"></span></span></div>
<p></span></span></span></div>
<p><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;">
<h3>Installing APF</h3>
<div><span style="mso-ansi-language: EN-US;" lang="EN-US"></span></div>
<p><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"> </p>
<p> </p>
<p></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Type the following into shell:</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><em>cd /usr/local/src<br />
wget http://rfxnetworks.com/downloads/apf-current.tar.gz<br />
tar -zxf apf-current.tar.gz<br />
cd apf-0.*<br />
./install.sh</em></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">After you have installed the firewall you will see a message: “Listening TCP ports: 1,21,22,25,53,80,110,111,143,443,465,993,995,2082,2083,2086,2087,2095,2096,3306<br />
  Listening UDP ports: 53,55880“. This is just an output example, these ports are not auto configured. You have to configure the firewall manually. </span></span></span></p>
<div class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"></p>
<div class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"></span></span></div>
<p></span></span></span></div>
<p><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;">
<h3>Configuring APF</h3>
<div><span style="mso-ansi-language: EN-US;" lang="EN-US"></span></div>
<p><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"> </p>
<p> </p>
<p></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><em>pico /etc/apf/conf.apf</em></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">At first you must enable development mode in the firewall configuration file. To do that, you must find DEVEL_MODE and set its value to 1.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><strong>Enabling </strong><a href="http://www.ddosblog.com/ingress-and-egress-filtering"><strong>ingress filtering</strong></a></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Find line # Common ingress (inbound) TCP ports -3000_3500 = passive port range for Pure FTPD from configuration file. In next line you can list all the ports to which you want to apply ingress filtering, for example:<br />
IG_TCP_CPORTS=&#8221;21,22,25,53,80,110,143&#8243;</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><strong>Enabling </strong><a href="http://www.ddosblog.com/ingress-and-egress-filtering"><strong>egress filtering</strong></a></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Find line # Egress filtering [0 = Disabled / 1 = Enabled]. To enable egress filtering set EGF=&#8221;1&#8243; followed by the list of ports where egress filtering will be applied. For example:</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"># Common egress (outbound) TCP ports</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">EG_TCP_CPORTS=&#8221;21,25,80&#8243;</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">#</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"># Common egress (outbound) UDP ports</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">EG_UDP_CPORTS=&#8221;20,21,53&#8243;</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><strong>Configuring Anti DOS</strong></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">AntiDOS is a new feature to APF, which is meant to protect your system from Denial of Service attacks. The configuration file is located at /etc/apf/and log file at /var/log/apfados_log. </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Find USE_AD and set it to 1. Now make the machine rune AntiDOS in every 2 minutes. It is not recommended to run it more often because it will create a bottleneck. Running it with more than 5 minutes gaps will most likely blank it’s use, thereby 2 minutes it the most optimal setting. </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><em>*/2 * * * * /etc/apf/ad/antidos -a &gt; /dev/null 2&gt;&amp;1</em></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">You should also make APF start at boot time with <em>chkconfig &#8211;level 2345 apf on</em></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">After you have finished configuring the firewall restart it with <em>apf –r</em>.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Now disable the development mode again by setting DEVEL_MODE to 0.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Start the firewall with <em>/usr/local/sbin/apf -s</em></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"> </p>
<p></span></span></span></span></span></span></p>
<p></span></span></span></span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosblog.com/installing-and-configuring-apf-linux-security/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Using (D)DoS Fleat to protect your Linux system</title>
		<link>http://www.ddosblog.com/using-ddos-fleat-to-protect-your-linux-system/</link>
		<comments>http://www.ddosblog.com/using-ddos-fleat-to-protect-your-linux-system/#comments</comments>
		<pubDate>Mon, 11 Aug 2008 11:16:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Preventing ddos attacks]]></category>

		<category><![CDATA[Ddos]]></category>

		<category><![CDATA[ddos fleat]]></category>

		<category><![CDATA[denial of service]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[linux security]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ddosblog.com/?p=35</guid>
		<description><![CDATA[(D)DoS Fleat is one of the best software based solutions for protection your Linux box against Ddos attacks.  Like many best things in life, (D)DoS Fleat is freeware and open source. Developed by MediaLayer, it is probably the cheapest solution to defend your system. Of cause just software based solution is not enough to provide [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">(D)DoS Fleat is one of the best software based solutions for protection your Linux box against Ddos attacks. <span style="mso-spacerun: yes;"> </span>Like many best things in life, (D)DoS Fleat is freeware and open source. Developed by MediaLayer, it is probably the cheapest solution to defend your system. Of cause just software based solution is not enough to provide sufficient protection, but it is a start. </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Installing (D)DoS fleat is very easy. Start by logging to your box as a root and type into schell:</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><em>wget http://www.inetbase.com/scripts/ddos/install.sh</em></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><em>chmod 0700 install.sh</em></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><em>./install.sh</em></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">By default (D)DoS fleat is configured to </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="font-size: small; font-family: Calibri;"><em>FREQ=1<br />
NO_OF_CONNECTIONS=50<br />
APF_BAN=1<br />
KILL=1<br />
EMAIL_TO=”root”<br />
BAN_PERIOD=600</em></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;">In ddos.conf – Fleats configuration file. You can change these settings easily. <span style="mso-ansi-language: EN-US;"><span style="mso-spacerun: yes;"> </span><span style="mso-spacerun: yes;"> </span><span lang="EN-US"></span></span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosblog.com/using-ddos-fleat-to-protect-your-linux-system/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HTTP flood ddos</title>
		<link>http://www.ddosblog.com/http-flood-ddos/</link>
		<comments>http://www.ddosblog.com/http-flood-ddos/#comments</comments>
		<pubDate>Thu, 07 Aug 2008 15:35:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Attack types]]></category>

		<category><![CDATA[Ddos]]></category>

		<category><![CDATA[denial of service]]></category>

		<category><![CDATA[dos]]></category>

		<category><![CDATA[http]]></category>

		<category><![CDATA[http flood]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[TCP/IP]]></category>

		<guid isPermaLink="false">http://www.ddosblog.com/?p=31</guid>
		<description><![CDATA[Using HTTP flood hacker sends randomized HTTP queries at victim system. It is hard to deal with HTTP flood attacks because there is almost no way to identify legitimate packets from the ones sent by the hacker. Furthermore, unlike with ICMP flood attacks, you cannot block all HTTP traffic without making your web server inaccessible. [...]]]></description>
			<content:encoded><![CDATA[<p>Using HTTP flood hacker sends randomized HTTP queries at victim system. It is hard to deal with HTTP flood attacks because there is almost no way to identify legitimate packets from the ones sent by the hacker. Furthermore, unlike with <a href="http://www.ddosblog.com/icmp-flood/">ICMP flood </a>attacks, you cannot block all HTTP traffic without making your web server inaccessible. The target of HTTP flood ddos attack is not just the servers TCP/IP stack but the web server running on it making the attack much more dangerous in terms of crashing the server.</p>
<p>How to block and prevent HTTP flood?</p>
<p>The most efficient way o fight HTTP flood is a technique called tarpitting. You can enable tarpitting on Linux based systems by <em>iptables -A INPUT -s x.x.x.x -p tcp -j TARPIT . </em>Tarpitting automatically sets connections window size to few bytes once it is established. According to TCP/IP protocol design, the connecting device will initially only send as much data to target as it takes to fill the window until the server responds. If the connecting device does not receive out response it will start sending the packets again and again over longer period of time. The point of tarpitting is not to respond again to the packets, that didn&#8217;t get the response at first time (and were thereby spoofed).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosblog.com/http-flood-ddos/feed/</wfw:commentRss>
		</item>
		<item>
		<title>UDP flood</title>
		<link>http://www.ddosblog.com/udp-flood/</link>
		<comments>http://www.ddosblog.com/udp-flood/#comments</comments>
		<pubDate>Wed, 06 Aug 2008 21:12:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Attack types]]></category>

		<category><![CDATA[Ddos]]></category>

		<category><![CDATA[dos]]></category>

		<category><![CDATA[flood]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[UDP]]></category>

		<category><![CDATA[UDP flood]]></category>

		<guid isPermaLink="false">http://www.ddosblog.com/?p=29</guid>
		<description><![CDATA[Using UDP (User Datagram Protocol) computers can exchange short messages called datagrams.  During UDP attack hacker will send a large amount of UDP packets with spoofed source addresses at victim. As UDP is a connectionless protocol it does not require a connection to be set up between computers to be processed. Victim system will search [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="MARGIN: 0cm 0cm 10pt"><span style="mso-ansi-language: EN-US" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Using UDP (User Datagram Protocol) computers can exchange short messages called datagrams. <span style="mso-spacerun: yes"> </span>During UDP attack hacker will send a large amount of UDP packets with spoofed source addresses at victim. As UDP is a connectionless protocol it does not require a connection to be set up between computers to be processed. Victim system will search for applications using the port and if it can’t find any it will respond with a <a href="http://www.ddosblog.com/icmp-flood/">ICMP</a> Destination Unreachable packet.</span></span></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 10pt"><span style="mso-ansi-language: EN-US" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">With many UDP packets sent, the victim system will respond with a huge amount of ICMP packets thereby not being able to respond to legimate traffic.</span></span></span></p>
<p class="MsoNormal" style="MARGIN: 0cm 0cm 10pt"><span style="mso-ansi-language: EN-US" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;"><br />
<h3>How to stop and prevent UDP attack?</h3>
<p></span></span></span></p>
<ol>
<li>
<div class="MsoListParagraphCxSpFirst" style="MARGIN: 0cm 0cm 0pt 36pt; TEXT-INDENT: -18pt; mso-list: l0 level1 lfo1"><span style="mso-ansi-language: EN-US; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin" lang="EN-US"><span style="mso-list: Ignore"><span style="font-family: 'Times New Roman';"> </span></span></span><span style="mso-ansi-language: EN-US" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Disable all unused UDP services</span></span></span></div>
</li>
<li>
<div class="MsoListParagraphCxSpLast" style="MARGIN: 0cm 0cm 10pt 36pt; TEXT-INDENT: -18pt; mso-list: l0 level1 lfo1"><span style="mso-ansi-language: EN-US" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Block all IP addresses sending UDP packets to ports not used by any application installed to the server.</span></span></span></div>
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosblog.com/udp-flood/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Identifying and stopping ddos attack on Linux box</title>
		<link>http://www.ddosblog.com/identifying-and-stopping-ddos-attack-on-linux-box/</link>
		<comments>http://www.ddosblog.com/identifying-and-stopping-ddos-attack-on-linux-box/#comments</comments>
		<pubDate>Tue, 05 Aug 2008 17:11:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Preventing ddos attacks]]></category>

		<category><![CDATA[Ddos]]></category>

		<category><![CDATA[dos]]></category>

		<category><![CDATA[firewall configuration]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ddosblog.com/?p=27</guid>
		<description><![CDATA[If you suspect that your system might be under ddos attack it is definitely worth your time to further investigate the problem and take actions if necessary. Some of the symptoms of ddos attack (like slow network connection) might be cause by other conditions, but if they continue over longer period of time you can [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">If you suspect that your system might be under ddos attack it is definitely worth your time to further investigate the problem and take actions if necessary. Some of the symptoms of ddos attack (like slow network connection) might be cause by other conditions, but if they continue over longer period of time you can be pretty sure, that this is an attack.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">First you should check your system load using <em style="mso-bidi-font-style: normal;">uptime </em>command. This will give you a line that looks something like this: <span style="mso-spacerun: yes;"> </span>18:43:32 up 9 days, 21:09, 1 user, load average: 5.33, 6.42, 14.25. If the load average is bigger than usually (or if you haven’t checked it before – just ridiculously large like over 40 for a system that is not under heavy load under normal circumstances) you can suspect ddos attack.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Next thing you should do is check the active connections to your computer. You can do that with <em style="mso-bidi-font-style: normal;">netstat -an</em> command. <span style="mso-spacerun: yes;"> </span>Some other useful commands include <em style="mso-bidi-font-style: normal;">netstat -anp |grep ‘tcp\|udp’ | awk ‘{print $5}’ | cut -d: -f1 | sort | uniq -c | sort –n </em>which lists the connections taking most bandwidth. </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Now you can see active connections to your server and the ones that take the most of your resources. If you can see several connections from one IP address or some connection taking much more bandwidth than it should add it to the list of blocked IP addresses using command <em style="mso-bidi-font-style: normal;">route add ip-address-to-be-banned reject.</em> After you have blacklisted all the suspicious IP addresses kill all connections to your HTTP server and restart it using <em style="mso-bidi-font-style: normal;">killall -KILL httpd </em>and <em style="mso-bidi-font-style: normal;">service httpd startssl</em>.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Alternatively you can install a shell script to do that for you. Sadly I don’t know the author of the script, so I can’t name him/her. What that script does is it automatically checks for double connections from same IP address and blocks them if it finds any. Install it using</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><em style="mso-bidi-font-style: normal;"><span style="font-size: small; font-family: Calibri;">wget </span><a href="http://www.inetbase.com/scripts/ddos/install.sh"><span style="font-size: small; font-family: Calibri;">http://www.inetbase.com/scripts/ddos/install.sh</span></a></em></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><em style="mso-bidi-font-style: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">chmod 0700 install.sh</span></span></em></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><em style="mso-bidi-font-style: normal;"><span style="font-size: small;"><span style="font-family: Calibri;">./install.sh</span></span></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosblog.com/identifying-and-stopping-ddos-attack-on-linux-box/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Ingress and Egress Filtering</title>
		<link>http://www.ddosblog.com/ingress-and-egress-filtering/</link>
		<comments>http://www.ddosblog.com/ingress-and-egress-filtering/#comments</comments>
		<pubDate>Mon, 04 Aug 2008 09:00:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Preventing ddos attacks]]></category>

		<category><![CDATA[Ddos]]></category>

		<category><![CDATA[Egress Filtering]]></category>

		<category><![CDATA[filtering]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[Ingress filtering]]></category>

		<category><![CDATA[preventing DDOS]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ddosblog.com/?p=22</guid>
		<description><![CDATA[Ingress and egress filtering are firewall/network configuration methods that help to secure your system from Denial of service attacks. Ingress filtering controls the traffic thats entering your network, egress filtering is the same for traffic leaving your network. Using ingress filtering rulebase you can sort out all the spoofed packets heading for your network. No [...]]]></description>
			<content:encoded><![CDATA[<p>Ingress and egress filtering are firewall/network configuration methods that help to secure your system from Denial of service attacks. Ingress filtering controls the traffic thats entering your network, egress filtering is the same for traffic leaving your network. Using ingress filtering rulebase you can sort out all the spoofed packets heading for your network. No packets with private IP address should be allowed to pass the filter. This might block some none-malicious traffic, but ensures network safety.  You can configure the filter to either just ignore the packet that has been detected as malicious or send it back to the source saying it has been denied.</p>
<p>Egress filtering restricts traffic not bearing an IP address of your network from heading out of your network. This ensures that your computer cannot be used as an amplifier for <a href="http://www.ddosblog.com/smurf-attack/">SMURF attacks</a>. Of cause you can develop more complicated rulesets like limiting traffic by ports but just validating IP addresses for inbound and outbound traffic is almost foolproof  and easiest way to prevent Ddos attacks.</p>
<p>You can use mixture of ingress and egress filtering for your maximum security or just stick to one of them. Ideally you wouldn&#8217;t need egress filtering if you have a perfect ingress filter as malicious packets can&#8217;t enter your network and thereby you can&#8217;t broadcast any spoofed packets. But we all know that nothing is perfect and it&#8217;s better to have more security, thereby I advise to implement both.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosblog.com/ingress-and-egress-filtering/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Ping of death</title>
		<link>http://www.ddosblog.com/ping-of-death/</link>
		<comments>http://www.ddosblog.com/ping-of-death/#comments</comments>
		<pubDate>Mon, 04 Aug 2008 07:26:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Attack types]]></category>

		<category><![CDATA[attack]]></category>

		<category><![CDATA[Ddos]]></category>

		<category><![CDATA[ping]]></category>

		<category><![CDATA[ping of death]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.ddosblog.com/?p=20</guid>
		<description><![CDATA[Most operating systems to year 1998 had defined maximum size of ping packet to 64 bytes. During ping of death attack, hacker sent packets larger than 64 bytes to the system to crash it. This vulnerability is fixed in all of modern Operating systems making it rather historical bug, though still worth examining. Even though [...]]]></description>
			<content:encoded><![CDATA[<p>Most operating systems to year 1998 had defined maximum size of ping packet to 64 bytes. During ping of death attack, hacker sent packets larger than 64 bytes to the system to crash it. This vulnerability is fixed in all of modern Operating systems making it rather historical bug, though still worth examining. Even though packers that large weren&#8217;t not allowed in network protocol they could be sent in fragments and caused buffer overflow while receiving system reassembled back together. Buffer overflow means, that application is trying to store more data than it&#8217;s allowed in memory space defined for it thereby pushing additional bytes to random locations in computer memory. Ping of death attacks were especially dangerous because most operating systems were vulnerable to it and attacker didn&#8217;t have to have any information about the target system other than it&#8217;s IP address. As all the requests could be spoofed, identifying the attacker was nearly impossible.<br id="aggw" /> Even though ping of death attack in it&#8217;s literal sense is dead a modern day equivalent for it is just sending more ping requests to victim than their system can handle, thereby causing a denial of service.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosblog.com/ping-of-death/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
