DOS / DDOS Attacks / Firewall Testing

Status
Not open for further replies.

Scott Greczkowski

Welcome HOME!
Original poster
Staff member
HERE TO HELP YOU!
Cutting Edge
Sep 7, 2003
103,234
27,884
Newington, CT
Our ISP where we host our servers has notified us that our servers are frequently being hit by DOS / DDOS and other cyber attacks. They have recommended that I put our web server behind a firewall to stop these attacks and they suggested a few options. Some costing thousands of dollars and other less expensive options.

In looking at our options, I am going to try the Website Firewall by Sucuri. We already use Sucuri for website monitoring and server side monitoring for viruses and Malware. Sucuri came in handy in the past in securing and hardening the security on the servers.

According to Sucuri there CloudProxy Website Firewall offers a powerful security layer to your site, blocking attacks before they can reach your site. It prevents infections and reinfections, specially on sites that are running outdated or insecure software. It includes a full web application firewall protection, virtual patching, IPS (intrusion prevention system) and log monitoring.

In addition Sucuri’s DDoS Protection service can detect and block the following types of DDoS attacks. Note that Sucuri proxies Web requests, so network layer DDoS attacks are never relayed to the client’s origin servers. Therefore, Sucuri’s DDoS protection can mitigate all network level attacks.
  • TCP SYN+ACK
  • Slowloris
  • DNS Flood
  • TCP FIN
  • Spoofing
  • NXDomain
  • TCP RESET
  • ICMP
  • Mixed SYB + UDP + ICMP + UDP Flood
  • TCP ACK
  • IGMP
  • Ping of Death
  • TCP ACK + PSH
  • HTTP Flood
  • Smurf
  • TCP Fragment
  • Brute Force
  • Reflected ICMP & UDP
  • UDP
  • Connection Flood
  • As well as other attacks
So we are going to give it a shot, it requires no changes to our servers, only some minor DNS server changes. However with that said I can not find any website using this Firewall with XenForo which is our forum software. So I will need to see if it has any issues with the software, but I believe there should be none. I do know other forums like MacRumors uses the Sucuri Firewall.

Hopefully this works as at this time we can not afford a few thousand dollars on a commercial grade firewall, not to mention the addition monthly fee we would need to pay for the space the firewall machine would take up in the ISP's rack. :)

So I will sign up for a one month trial and see how it goes. If you notice anything odd please let me know.

Thanks for your understanding and THANKS for being SatelliteGuys!
 
Good luck Scott!
fingerscrossed_80.png
 
The Firewall came with Caching Turned on, So for some it was displaying the page of the person who last looked at it. This was quickly fixed, however took a few moments for it to propagate through their cloud.

I will contact the user who was cached and let him know what happened. Also as a safety I have changed that users password.
 
  • Like
Reactions: Mr Tony
Who the heck is rnye1? When I first used my favorites shortcut this guy shows up. I cleaned up everything on my end, now sometimes after being longed in his page is displayed for a few seconds and then I receive an error massage with no error number instructing me to back page and try again.
 
There is caching and then there is CACHING but that was crazy!

Got to admit I am going through the Firewall now and its a little snappier then it was before. I will be interested in seeing the logs to see what it blocks. :D
 
Who the heck is rnye1? When I first used my favorites shortcut this guy shows up. I cleaned up everything on my end, now sometimes after being longed in his page is displayed for a few seconds and then I receive an error massage with no error number instructing me to back page and try again.
That's the user that showed for me too.:rolleyes:
 
Thanks Scott for fixing it. Kinda scared me when I went to the site and saw the same name as posted above. I logged out from the main page but it wouldn't let me. I had to go into the forums THEN log out

Again thanks for finding the issue and fixing it. Thought maybe I had a virus or something. Much happier now :)
 
I must be lucky; I haven't seen anybody already logged in on my computers other than myself.
 
  • Like
Reactions: dare2be
Status
Not open for further replies.

ForumRunner Support Removed

Explorer and chrome issues

Users Who Are Viewing This Thread (Total: 0, Members: 0, Guests: 0)

Who Read This Thread (Total Members: 1)