[advanced search]
Results from the most recent live auction are here.
15 members in the live chat room. Join Chat!
Register Rules & FAQ NP$ Store Active Threads Mark Forums Read
Go Back   NamePros.Com > Design and Development > Web Hosting Discussion
User Name
Password

Old 07-14-2007, 05:36 PM   · #1
xdomainer
NamePros Regular
 
xdomainer's Avatar
 
Trader Rating: (30)
Join Date: Feb 2006
Posts: 647
NP$: 1780.00 (Donate)
xdomainer is a glorious beacon of lightxdomainer is a glorious beacon of lightxdomainer is a glorious beacon of lightxdomainer is a glorious beacon of lightxdomainer is a glorious beacon of light
Expecting DDoS and Hack attempts

What would be a host and hosting package to choose if I expect some DDoS and hacking activity on a website ? Maybe one or two attempts in a year.


Please register or log-in into NamePros to hide ads
__________________

XtremeCooling.com|ThermalEnergy.org| MrCop.com |Gadarene.com |OatmealCrunch.com |E-Cellphone.com |Justice.co.in
xdomainer is online now   Reply With Quote
Old 07-14-2007, 07:04 PM   · #2
King Justice
NamePros Regular
 
Name: Justice McCay
Location: New Jersey
Trader Rating: (18)
Join Date: Mar 2006
Posts: 735
NP$: 16.00 (Donate)
King Justice is just really niceKing Justice is just really niceKing Justice is just really niceKing Justice is just really nice
Go with a host that has a firewall and such DDoS prevention measures/detectors.

Check out aplus.net for shared hosting with those kind of features.
__________________
Green rep is always appreciated.

Online Gaming - MMORPG Accounts
Cheap Game Gold
King Justice is offline   Reply With Quote
Old 07-15-2007, 06:27 AM   · #3
sdsinc
Law and disorder
 
sdsinc's Avatar
 
Name: Kate
Location: Expat
Trader Rating: (57)
Join Date: Aug 2005
Posts: 5,291
NP$: 1117.11 (Donate)
sdsinc has a reputation beyond reputesdsinc has a reputation beyond reputesdsinc has a reputation beyond reputesdsinc has a reputation beyond reputesdsinc has a reputation beyond reputesdsinc has a reputation beyond reputesdsinc has a reputation beyond reputesdsinc has a reputation beyond reputesdsinc has a reputation beyond reputesdsinc has a reputation beyond reputesdsinc has a reputation beyond repute
Third World Education Find Marrow Donors! Find Marrow Donors! Find Marrow Donors! Find Marrow Donors! Animal Rescue Animal Cruelty AIDS/HIV
It could be a good idea to use managed DNS services too in order to mitigate any possible attack.
__________________
Now on sale: BudgetLettings.com
sdsinc is offline   Reply With Quote
Old 07-15-2007, 07:02 AM   · #4
iNod
Eating Pie
 
iNod's Avatar
 
Name: Steve
Location: Canada
Trader Rating: (66)
Join Date: Nov 2004
Posts: 2,284
NP$: 91.30 (Donate)
iNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud ofiNod has much to be proud of
Special Olympics AIDS/HIV Cystic Fibrosis Save The Children Baby Health Cystic Fibrosis
Most DDoS protection is garbage.. You would need a 50,000 CISCO router just for DDOS protection. Most companies simplely find the port the traffic is coming on and redirect the entire C class to somewhere where it doesn't do damage.

If you are expecting attacks, do this.

1. Get a extremely secure root password (upper & lowercase, and alphanumerical)
2. Delete the root account and use something less popular
3. Change the SSH port
4. Install RFNetwork scripts (APF Firewall, BFD, etc) and logwatch and monitor ALL logs.
5. Monitor Apaches usage log
6. Get some cpanel mods (security, etc)
7. Upgrade to PHP 5 (Entirely)
8. Upgrade Apache to version 2
9. Run cPanel update and make sure it is the latest tree (don't worry about being stable.. cpanel has yet to release a non-working package to the public)
10. Follow al the normal locking down of server (harden files, /tmp folders, etc)
11. The best way to block hacking is is disallow perl/cgi scripts on user accounts (cpanel needs perl and cgi in order to work, but I mean your clients, google how to do this).

If you do all that it will take along time for them to get it and you might even see them trying to get in and be able to block them before they can.

- Steve
__________________
RegisterDub.com - 200th Customer Milestone
ZuneParts.net - International Zune Parts and Accessories
FeaturedFont.com - One Top Free Font a Day!
iNod is offline   Reply With Quote
Old 07-15-2007, 02:23 PM   · #5
xdomainer
NamePros Regular
 
xdomainer's Avatar
 
Trader Rating: (30)
Join Date: Feb 2006
Posts: 647
NP$: 1780.00 (Donate)
xdomainer is a glorious beacon of lightxdomainer is a glorious beacon of lightxdomainer is a glorious beacon of lightxdomainer is a glorious beacon of lightxdomainer is a glorious beacon of light
Originally Posted by iNod
Most DDoS protection is garbage.. You would need a 50,000 CISCO router just for DDOS protection. Most companies simplely find the port the traffic is coming on and redirect the entire C class to somewhere where it doesn't do damage.

If you are expecting attacks, do this.

1. Get a extremely secure root password (upper & lowercase, and alphanumerical)
2. Delete the root account and use something less popular
3. Change the SSH port
4. Install RFNetwork scripts (APF Firewall, BFD, etc) and logwatch and monitor ALL logs.
5. Monitor Apaches usage log
6. Get some cpanel mods (security, etc)
7. Upgrade to PHP 5 (Entirely)
8. Upgrade Apache to version 2
9. Run cPanel update and make sure it is the latest tree (don't worry about being stable.. cpanel has yet to release a non-working package to the public)
10. Follow al the normal locking down of server (harden files, /tmp folders, etc)
11. The best way to block hacking is is disallow perl/cgi scripts on user accounts (cpanel needs perl and cgi in order to work, but I mean your clients, google how to do this).

If you do all that it will take along time for them to get it and you might even see them trying to get in and be able to block them before they can.

- Steve



Regarding 3,4,5,6,8, and 10. Where do I do this ? In the cPanel controls ?
Will I need managed hosting ? Dedicated server ? Or can I get away with hosting costing around $75 per year ?

As for upgrading to PHP 5 do you mean changing all file extensions to .php ? So no .htm or .html ...etc ?
__________________

XtremeCooling.com|ThermalEnergy.org| MrCop.com |Gadarene.com |OatmealCrunch.com |E-Cellphone.com |Justice.co.in
xdomainer is online now   Reply With Quote
Old 07-16-2007, 04:49 AM   · #6
novelty
NamePros Member
 
Trader Rating: (0)
Join Date: Dec 2006
Posts: 159
NP$: 0.00 (Donate)
novelty is an unknown quantity at this point
Well, definitely, dedicated is far safer environment than shared, if you don't feel your server management skills will allow you to run the server go for a fully managed pack, alternatively you may want hourly administration.
novelty is offline   Reply With Quote
Old 07-23-2007, 07:35 PM   · #7
greatness008
New Member
 
Trader Rating: (0)
Join Date: May 2007
Posts: 12
NP$: 0.00 (Donate)
greatness008 is an unknown quantity at this point
yea my site got hacked too. they said someone hacked my password and uploaded a ddos script so they suspended my account and notified the authorities...it sucks
greatness008 is offline   Reply With Quote
Old 07-27-2007, 08:55 AM   · #8
dilipkhanolkar
New Member
 
Trader Rating: (0)
Join Date: Jul 2007
Posts: 11
NP$: 0.00 (Donate)
dilipkhanolkar is an unknown quantity at this point
DDOS or DOS nothing in this world can be done to actually avoid them, both theoretically can be stopped but practically no you cannot differentiate between an actual user & a ddos user
dilipkhanolkar is offline   Reply With Quote
Old 07-27-2007, 02:56 PM   · #9
infinitomagazine
Senior Member
 
infinitomagazine's Avatar
 
Name: eduardo
Location: peru
Trader Rating: (67)
Join Date: May 2005
Posts: 2,589
NP$: 21.15 (Donate)
infinitomagazine is a splendid one to beholdinfinitomagazine is a splendid one to beholdinfinitomagazine is a splendid one to beholdinfinitomagazine is a splendid one to beholdinfinitomagazine is a splendid one to beholdinfinitomagazine is a splendid one to beholdinfinitomagazine is a splendid one to beholdinfinitomagazine is a splendid one to behold
Looks like any new dedicated server which is configurated is a DDOS target.
I did rent a server months ago, and I recieved massive Sync attack more than 30 days.
I had to hire a linux expert to defend my server, after 30 days looks like work finally began to stop attacks.

some basic aspects:
change ssh port
much ram increase posibilities that your server can tolerate attacks.
lot of banwith

If someone is planning to buy a server and run a bussines, well think that is possible that your server will be attacked and probably you will loose 2 weeks making everything to protect your server.
__________________
Shoutcast - Web Radio - AutoDJ - Playlist available
TRIBALHOST.NET Shoutcast & more
1 day Trial - Custom packages
Chicago servers located
infinitomagazine is offline   Reply With Quote
Old 08-01-2007, 10:15 PM   · #10
felosi
NamePros Member
 
Trader Rating: (0)
Join Date: May 2006
Posts: 25
NP$: 0.00 (Donate)
felosi is an unknown quantity at this point
Originally Posted by iNod
Most DDoS protection is garbage.. You would need a 50,000 CISCO router just for DDOS protection. Most companies simplely find the port the traffic is coming on and redirect the entire C class to somewhere where it doesn't do damage.


ha ha, where did you hear that?
__________________
SecureServerTech - Premium Ddos protected shared, reseller, and vps hosting. Adult, IRC, and Free Speech supported.http://secureservertech.com

Last edited by felosi : 08-01-2007 at 10:18 PM.
felosi is offline   Reply With Quote
Closed Thread

NamePros is a revenue sharing forum.

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


Site Sponsors
http://www.mobisitetrader.com/ Find out how! Traffic Down Under
Advertise your business at NamePros
All times are GMT -7. The time now is 09:27 AM.


Powered by: vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 2.4.0