Prevent and Stop DoS or DDoS Attacks on Web Server (D)DOS-Deflate预防和阻止DOS或DDoS攻击Web服务器(四) DOS的deflate

All web servers been connected to the Internet subjected to DoS (Denial of Service) or DDoS (Distrubuted Denial of Service) attacks in some kind or another, where hackers or attackers launch large amount connections consistently and persistently to the server, and in advanced stage, distributed from multiple IP addresses or sources, in the hope to bring down the server or use up all network bandwidth and system resources to deny web pages serving or website not responding to legitimate visitors.所有Web服务器被连接到互联网受到DOS的(拒绝服务)或分布式拒绝服务攻击(分布式拒绝服务)攻击,在一些这样或那样的,如果黑客或攻击者发射了大量的联系,始终坚持到服务器,并在高级阶段,分布在多个IP地址或来源,在希望把服务器或使用所有的网络带宽和系统资源,以否认网页服务或网站没有回应的合法旅客。

There are plenty of ways to prevent, stop, fight and kill off DDoS attack, such as using firewall.有很多途径来预防,制止,打击和杀死DDoS攻击,例如使用防火墙。 A low cost, and probably free method is by using software based firewall or filtering service.一,成本低,可能和自由的方法是使用基于软件的防火墙或过滤服务。 (D)DoS-Deflate is a free open source Unix/Linux script by MediaLayer that automatically mitigate (D)DoS attacks. (四) DOS的deflate是一个自由开放源码的Unix / Linux脚本medialayer自动减轻(四) DoS攻击。 It claims to be the best, free, open source solution to protect servers against some of the most excruciating DDoS attacks.它声称是最好的,免费,自由,开放原始码解决方案来保护服务器免遭一些最痛苦的DDoS攻击。

(D)DoS-Deflate (四) DOS的deflate script basically monitors and tracks the IP addresses are sending and establishing large amount of TCP network connections such as mass emailing, DoS pings, HTTP requests) by using “netstat” command, which is the symptom of a denial of service attack.脚本基本上是监测和跟踪IP地址发送和建立大量的TCP网络连接,如大规模电子邮件,多坪, HTTP请求)用“ netstat ”命令,这是症状的拒绝服务攻击。 When it detects number of connections from a single node that exceeds certain preset limit, the script will automatically uses APF or IPTABLES to ban and block the IPs.当它侦测到的连接数从一个单一的节点超过一定的预设上限,该脚本将自动使用的APF或iptables的禁止和阻挠的IPS 。 Depending on the configuration, the banned IP addresses would be unbanned using APF or IPTABLES (only works on APF v 0.96 or better).视乎有关的配置,禁止IP地址将unbanned使用的APF或iptables的(只适用于武装警察部队v 0.96或更高) 。

Installation and setup of (D)DOS-Deflate on the server is extremely easy.安装和设置的(四) DOS的deflate在服务器上是非常容易的。 Simply login as root by open SSH secure shell access to the server, and run the the following commands one by one:简单地以root登入,透过公开的SSH安全shell访问服务器,并运行以下命令,一个又一个:

wget http://www.inetbase.com/scripts/ddos/install.sh wget http://www.inetbase.com/scripts/ddos/install.sh
chmod 0700 install.sh chmod 0700 install.sh
./install.sh 。 / install.sh

To uninstall the (D)DOS-Deflate, run the following commands one by one instead:卸载(四) DOS的deflate ,运行下面的命令了一个又一个,而是:

wget http://www.inetbase.com/scripts/ddos/uninstall.ddos wget http://www.inetbase.com/scripts/ddos/uninstall.ddos
chmod 0700 uninstall.ddos chmod 0700 uninstall.ddos
./uninstall.ddos 。 / uninstall.ddos

The configuration file for (D)DOS-Deflate is ddos.conf , and by default it will have the following values:配置文件(四) DOS的deflate是ddos.conf ,默认情况下,将会有以下值:

FREQ=1频率= 1
NO_OF_CONNECTIONS=50 no_of_connections = 50
APF_BAN=1 apf_ban = 1
KILL=1杀人= 1
EMAIL_TO=”root” email_to = “根”
BAN_PERIOD=600 ban_period = 600

Users can change any of these settings to suit the different need or usage pattern of different servers.用户可以更改这些设置,以适应不同的需要或使用模式不同的服务器。 It’s also possible to whitelist and permanently unblock (never ban) IP addresses by listing them in /usr/local/ddos/ignore.ip.list file.它也可能白名单和永久解除封锁(从来没有禁止)的IP地址列出他们在/ usr / local /的DDoS / ignore.ip.list档案。 If you plan to execute and run the script interactively, users can set KILL=0 so that any bad IPs detected are not banned.如果您计划执行和运行该脚本交互方式,用户可以设置杀= 0 ,使任何坏的IPS检测所不禁止的。

IMPORTANT : This is a machine translated page which is provided "as is" without warranty. 重要说明 :这是一个机器翻译网页是“按原样”提供的担保。 Machine translation may be difficult to understand.机器翻译可能很难理解。 Please refer to请参阅 original English article原来的英语文章 whenever possible.只要有可能。

Share and contribute or get technical support and help at分享和贡献,或取得技术的支持和帮助,在 My Digital Life Forums 我的数字生活论坛 .



Leave a Reply离开的答复

You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> 您可以使用这些标签:的<a href="" title=""> <abbr title=""> <acronym title="">的<b> <blockquote cite=""> <cite>的<code> <删除日期时间= “ ” >的<em>的<i> <q cite=""> <strike>的<strong>

Subscribe without commenting订阅无评论


Custom Search

New Articles新的条款,

Incoming Search Terms for the Article传入的搜索条件文章

iptables ddos iptables的的DDoS - - iptables dos iptables的DOS的 - - ddos deflate DDoS的deflate - - ddos iptables DDoS的iptables的 - - how to stop DDOS 如何停止的DDoS - - stop ddos 停止的DDoS - - how to stop a ddos attack 如何阻止DDoS攻击 - - how to prevent ddos 如何防止DDoS的 - - dos deflate DOS的deflate - - Prevent DDoS 防止的DDoS - - how to stop ddos attack 如何阻止DDoS攻击 - - How to stop DDOS Attacks 如何阻止DDoS攻击 - - how to stop Dos 如何阻止DOS的 - - DOS-Deflate DOS的deflate - - dos iptables DOS的iptables的 - - iptables dos attack iptables的DOS攻击 - - DDOS Deflate DDoS的deflate - - iptables prevent ddos iptables的防止的DDoS - - stop ddos attacks 停止DDoS攻击 - - iptables block ddos iptables的座的DDoS - - stop dos attack 阻止DOS攻击 - - DDOS-Deflate 的DDoS - deflate - - how to prevent DDOS attack 如何防止DDoS攻击 - - stopping a ddos 制止的DDoS - - stop ddos attack 停止DDoS攻击 - - (D)DoS-Deflate ) DOS的deflate - - how to stop DOS attacks 如何阻止DoS攻击 - - stopping DoS attacks 阻止DoS攻击 - - iptables Ddos attack iptables的DDoS攻击 - - wget http://www.inetbase.com/scripts/ddos/install.sh wget http://www.inetbase.com/scripts/ddos/install.sh - - stopping ddos 停车的DDoS - - how to prevent from apache dos attack 如何防止从Apache的DOS攻击 - - prevent dos 防止DOS的 - - linux prevent dos Linux的防止DOS的 - - stopping ddos attacks 停车DDoS攻击 - - ddos prevent DDoS的防止 - - stop a DDoS 停止的DDoS - - iptables+dos iptables的+多 - - DDOS iptable DDoS的iptable - - mysql ddos attack MySQL的DDoS攻击 - - stop dos attacks 停止DoS攻击 - - iptables ddos attacks iptables的DDoS攻击 - - stop dos 停止DOS的 - - stop a ddos attack 阻止DDoS攻击 - - how to stop a dos attack 如何阻止DoS攻击 - - iptables ddos iptables的的DDoS - - apache ddos 阿帕奇的DDoS - - how to prevent a ddos 如何防止DDoS的 - - iptables ddos limit iptables的DDoS的限制 - - iptables for http dos attacks iptables的为HTTP DoS攻击 - -