vBulletin Modifications

I'm under a HTTP attack.

Welcome to vBHackers.com! - vBHackers Updates:

Go Back   vBulletin Modifications > General vBulletin Section > General vBulletin Discussion

Reply
 
LinkBack Thread Tools
Old 07-07-2006, 08:51 AM   #1
Vaz
vB User
Vaz's Avatar
Join Date: Apr 2006
Vaz is on a distinguished road

Default I'm under a HTTP attack.

Hi everyone,

Since yesterday 8am gmt my forums have been under a http attack. The application that is doing the attack seems to be doing it through multiple proxies so i cant simply ban the ip. It's been going on for over a day now. How can I stop this?




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 07-07-2006, 08:55 AM   #2
vBulletin Guru
Arnoud's Avatar
Join Date: Nov 2004
Real Name: Arnoud Kuipers
Location: Europe, Flanders
Arnoud is on a distinguished road

Default

What exactly is it doing? There's a lot of different types of http attacks.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-07-2006, 09:30 AM   #3
Vaz
vB User
Vaz's Avatar
Join Date: Apr 2006
Vaz is on a distinguished road

Default

Okay basically it's running multiple search queries through multiple proxies (hundreds and hundreds and thousands) in the hope to crash the server. Temporarily I've taken the forums down (renamed the dir).




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-07-2006, 09:42 AM   #4
vBulletin Guru
Arnoud's Avatar
Join Date: Nov 2004
Real Name: Arnoud Kuipers
Location: Europe, Flanders
Arnoud is on a distinguished road

Default

Ah right, so its basicly constantly "refreshing" a search string with different IPs?




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-07-2006, 10:54 AM   #5
Vaz
vB User
Vaz's Avatar
Join Date: Apr 2006
Vaz is on a distinguished road

Default

Yes.... yes (wouldnt let me post with 3 characters)




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-07-2006, 01:21 PM   #6
Advanced Coder
Niels's Avatar
Join Date: Jun 2004
Real Name: Niels
Location: NL
Niels is on a distinguished road

Default

Quote:
Originally Posted by Vaz
Yes.... yes (wouldnt let me post with 3 characters)
Disable the search, or add the 30sec / 1 minute delay in it.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-07-2006, 01:32 PM   #7
Vaz
vB User
Vaz's Avatar
Join Date: Apr 2006
Vaz is on a distinguished road

Default

Adding any time limit wont really matter as it's lots of different ip's. I've also blocked guests from searching. What i've done as a temporary solution is simply rename search.php.

Is there anyway of limiting the maximum people that can be on the forums at a giventime?




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-07-2006, 01:37 PM   #8
vBulletin Guru
Arnoud's Avatar
Join Date: Nov 2004
Real Name: Arnoud Kuipers
Location: Europe, Flanders
Arnoud is on a distinguished road

Default

Nope, there is a way of limiting the server load though. This should be in the vBulletin options.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-13-2006, 09:37 AM   #9
vB Newbie
Join Date: May 2006
MONKEY_MAN is on a distinguished road

Default

can you not set/ move your forums to a secure directory/ root and run your site as https: rather than http: and if its set properly on registered users can view the forums but, this also means the spiders cans scan your forums??
its up to you i cant think of any other solution at the minute. i would have thought that setting it so only registered users can search would have fixed it and spiders can still scan your forums and achieves.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-13-2006, 12:57 PM   #10
Coder
Code Monkey's Avatar
Join Date: May 2006
Code Monkey is on a distinguished road

Default

Quote:
Originally Posted by Vaz
How can I stop this?
Contact your host. Their servers are under atack and they will know what to do. If you fail to contact them and it escalates to a point that it interupts service to their other customers they may not be happy with you for not notifying them earlier. It will only escalate so notify them.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -3. The time now is 12:32 PM.


SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc. (Patent Pending)