Zen Cart Logo

Ddos

Views: 64

Results 1 to 2 of 2
30 Aug 2013, 09:38
#1
solo_400 avatar

solo_400

Zen Follower

Join Date:
Aug 2009
Posts:
369
Plugin Contributions:
0

Ddos

I would like to share with you a story ( 2 years of maximum stress ) , after I moved my domain over few hosting companies trying to escape from ...

"
I don't think you quite get the nature of the attack. Several hundred IP
addresses were spamming junk packets to port 80 (on TCP) to the IP that
runs the apache daemon that runs your site. They were sending around
500-600 megabits worth of packets. Because the server is only on a
100mbit interface it completely took down the entire server (nobody being
hosted off the server had working sites when the bandwidth-based attack
happened).

It was being hit by soo many IPs it wasn't even feasible for me block at
our border router (I gave up after blocking around 50 IP addresses and
the server was still being taken off line). I had to actually null-route
the IP address which is shared with about 30-40 other domains/customers
and assign a new IP address to the apache daemon which means all the
customers that suffered about a 40 minute downtime from the DDoS attack
would also have an additional 1-12 hour downtime until DNS propagates to
the new IP address for the ones that were hosted on the same IP as you.

Even after completely blocking the IP 5+ hours later I am still seeing
several hundred megabits of traffic hitting our border-router (where it
stops). You can see the spike at a bit past 2 AM on just one of our 5
transit providers

Blocking these types of attacks at this level effectively requires
special hardware designed to mitigate DDoS attacks which we do not have
which is why we do not provide DDoS protection.

When one customer is causing downtime for hundreds of others we simply
can't continue to host them when they are a target for DDoS attacks as we
can't allow one customer to keep causing downtime for our many other
customers. Even if the first attack is blocked it typically just
escalates. If it was double the size it came it would have actually taken
out an entire switch which means 2 racks worth of servers (over 10,000
customers) would have had an outage.

I am sorry if it seems unreasonable but we simply cannot continue to host
customers that receive DDoS attacks in this nature

In our AUP we outline this:

Any conduct that is likely to result in retaliation against HOSTING COMPANY
network or website, or HOSTING COMPANY employees, officers or other agents,
including engaging in behavior that results in any server being the
target of a denial of service attack (DoS).

You are free to transfer your domain registration to a third-party once
the initial 60 days have passed (internet registry regulation) and you
still have control of DNS from Domains -> Registrations to change the
name-server to a different provider. We simply cannot allow any domain
that is hit with large scale DDoS attacks to be hosted on our servers due
to the possibility of downtime to our other customers caused by future
attacks.
"

30 Aug 2013, 19:51
#2
responsivezc avatar

responsivezc

New Zenner

Join Date:
Aug 2013
Posts:
85
Plugin Contributions:
8

Re: Ddos

Hi,

I am sorry to hear about your story.
I simply want to subscribe to see how it ends.
It can happen to anyone.