Brute force, DDOS attacks - How do you prevent such kind of stuff?

Epicster

Power Member
Joined
Jan 2, 2012
Messages
763
Reaction score
299
Hi there,

So here's the case.

The site is receiving constant DDOS and brute force attacks which I have done my best to mitigate, but till not been able to get properly rid of it.

So far, I have

- Blocking XMLRPC through CloudFlare.
- Blocking Origin Access except for Cloudflare
- Blocking login page
- WordFence Protection

Still, I am seeing people crawling my site for vulnerabilities and end up receiving 403, 404, and 503 pages, which is obviously eating up my bandwidth. It is getting blocked by wordfence.

Capture.PNG


Is there anything that can be done to stop these also?
 
A good web host should take care of it, you can temporarily block those countries and remove block after a bit not much I think uou can do besides it
I am on the Vultr Cloud Platform; I am using their firewall. But now I am stuck with other services getting blocked.
 
You can never achieve "zero attacks" on any site. It's like spam, you will always get some of it and there's no way to reduce it to absolute zero.

You have enough protection in-place for any of these basic attacks to do any harm. Also, unless a huge botnet tries ddosing you and isn't catched by Cloudflare (which is unlikely) you shouldn't worry about these attacks doing much harm. They also don't consume as much bandwidth as you think.

If wordfence blocks those pages, you will hardly spend any bandwidth. Cloudflare will simply serve a cached 403 forbidden page.

You can try looking into Cloudflare Not and DDos protection if you are just using their free plan. It's quite effective. In fact, bhw uses it too :^)
 
You can never achieve "zero attacks" on any site. It's like spam, you will always get some of it and there's no way to reduce it to absolute zero.

You have enough protection in-place for any of these basic attacks to do any harm. Also, unless a huge botnet tries ddosing you and isn't catched by Cloudflare (which is unlikely) you shouldn't worry about these attacks doing much harm. They also don't consume as much bandwidth as you think.

If wordfence blocks those pages, you will hardly spend any bandwidth. Cloudflare will simply serve a cached 403 forbidden page.

You can try looking into Cloudflare Not and DDos protection if you are just using their free plan. It's quite effective. In fact, bhw uses it too :^)
But now I am facing a new problem here.

The origin server is blocking all incoming requests except Cloudflare and my whitelisted ones and I am doing that with the VULTR firewall. It only has 50 rules but I need to whitelist more which i can't.

I am thinking of removing the Vultr firewall, do you think it will be safe? I can whitelist IPs with the UFW rules, but I am scared that I will block all legitimate traffic.
 
That's only good for Cloudflare, what about the origin?
Don't trust on what Rufai said...

The ONLY WAY to block it is THROUGH your Hosting Provider. Vultr doesn't have DDoS Protection decent like others.

I will suggest you some of them
https://fastpipe.iohttps://javapipe.com (they are good dealing with ddos attacks)
https://flokinet.ishttps://buyvm.nethttps://ovh.com (if is legal you can use OVH)

Because when traffic passes away through Cloudflare, if cloudflare doesn't filter the dirt traffic it will HIT your Hosting (Origin)
You can't do nothing without a good hosting provider with good ddos protection. That's the reality.

Rufai is only a guy who literally thinks cloudflare will save his a$$ with 512MB of RAM and no ddos protection from hosting provider lool.

Trust me, first you need a good anti-ddos protection.
 
You have to talk with your hosting provider in order to start filtering ip's to a secundary machine, also know as a mitigation system.

https://ovh.com (if is legal you can use OVH)
Don't use OVH, there is a actual bypass for their mitigation system since they don't filter their own ip's and some providers have their botnets inside OVH servers in order to bypass it.
Also, OVH support is a joke.

I would advise you to have a dedicated server with a decent DDOS protection.
I've had a good experience fighting DDOS attacks at:

1. waac.pt
2. hydraservers.net
3. blazingfast.io

Note: Not affiliated in any way with the mentioned providers.
 
You have to talk with your hosting provider in order to start filtering ip's to a secundary machine, also know as a mitigation system.


Don't use OVH, there is a actual bypass for their mitigation system since they don't filter their own ip's and some providers have their botnets inside OVH servers in order to bypass it.
Also, OVH support is a joke.

I would advise you to have a dedicated server with a decent DDOS protection.
I've had a good experience fighting DDOS attacks at:

1. waac.pt
2. hydraservers.net
3. blazingfast.io

Note: Not affiliated in any way with the mentioned providers.
Don't trust on what Rufai said...

The ONLY WAY to block it is THROUGH your Hosting Provider. Vultr doesn't have DDoS Protection decent like others.

I will suggest you some of them
https://fastpipe.iohttps://javapipe.com (they are good dealing with ddos attacks)
https://flokinet.ishttps://buyvm.nethttps://ovh.com (if is legal you can use OVH)

Because when traffic passes away through Cloudflare, if cloudflare doesn't filter the dirt traffic it will HIT your Hosting (Origin)
You can't do nothing without a good hosting provider with good ddos protection. That's the reality.

Rufai is only a guy who literally thinks cloudflare will save his a$$ with 512MB of RAM and no ddos protection from hosting provider lool.

Trust me, first you need a good anti-ddos protection.
Thanks for the suggestions, Right now, I am with the VULTR. Are there any solutions I can work with the cloud providers? Vultr has good DDOS protection.

Do you think it will be good enough to protect from these silly crawlable bots? Or Wordfence premium might be useful? Or should i just ignore them?

The DDOS and brute force attacks are not that big right now. 500-1000 Attacks a day
 
Other than Cloudflare and TIME nothing much. Just wait it off.
I would agree with Gioware here. Not much can be done when you are having a big attack on your site. Let Cloudflare do its thing and just wait it out. Otherwise, contact Vultr and see if you can resolve it with them. Best to explain the issue to your hosting provider.
 
You have to talk with your hosting provider in order to start filtering ip's to a secundary machine, also know as a mitigation system.


Don't use OVH, there is a actual bypass for their mitigation system since they don't filter their own ip's and some providers have their botnets inside OVH servers in order to bypass it.
Also, OVH support is a joke.

I would advise you to have a dedicated server with a decent DDOS protection.
I've had a good experience fighting DDOS attacks at:

1. waac.pt
2. hydraservers.net
3. blazingfast.io

Note: Not affiliated in any way with the mentioned providers.
Exactly, but if he doesn't receive large ddos attacks, ovh works fine.. I mean, generally those websites are targeted by high know-how people.
OVH still good filtering ddos attacks that isn't from their network.

Thanks for the suggestions, Right now, I am with the VULTR. Are there any solutions I can work with the cloud providers? Vultr has good DDOS protection.

Do you think it will be good enough to protect from these silly crawlable bots? Or Wordfence premium might be useful? Or should i just ignore them?

The DDOS and brute force attacks are not that big right now. 500-1000 Attacks a day

Then if you are fine why you do this thread? No sense, at my point of view...
 
Exactly, but if he doesn't receive large ddos attacks, ovh works fine.. I mean, generally those websites are targeted by high know-how people.
OVH still good filtering ddos attacks that isn't from their network.



Then if you are fine why you do this thread? No sense, at my point of view...
I was just asking if it's possible to block these DDoS requests or not and if not then are these safe to ignore or not?
 
Lol. Seem like you don't know what cloudflare.
I don't think you know what I meant; I know what Cloudflare is; I am using it for over 5 years now.

Cloudflare is only useful if your origin is not bypassed. Once it's bypassed, it will give you nightmares.
 
I don't think you know what I meant; I know what Cloudflare is; I am using it for over 5 years now.

Cloudflare is only useful if your origin is not bypassed. Once it's bypassed, it will give you nightmares.
OP will be able to prevent those attacks by creating a firewall rule to block access to the pages which the attackers are targeting or create a rule to present Captcha to anyone with high threat score.

At least read the thread I linked to and you'll understand what I mean.

The way you responded to my comment seems like you're trying to sell something to OP or promote your own product.

Over and out.
 
OP will be able to prevent those attacks by creating a firewall rule to block access to the pages which the attackers are targeting or create a rule to present Captcha to anyone with high threat score.

At least read the thread I linked to and you'll understand what I mean.

The way you responded to my comment seems like you're trying to sell something to OP or promote your own product.

Over and out.
Seriously, dude? duh

I am the original poster; the thread has been started by me. And if you have read from the start you would have known, the problem is with the Cloudflare and without the Cloudflare, I mean bypassing the Origin.
 
Seriously, dude? duh

I am the original poster; the thread has been started by me. And if you have read from the start you would have known, the problem is with the Cloudflare and without the Cloudflare, I mean bypassing the Origin.
Sorry I wanted to respond to this post. But have you tried creating the firewall rules shared the thread I linked to?
Don't trust on what Rufai said...

The ONLY WAY to block it is THROUGH your Hosting Provider. Vultr doesn't have DDoS Protection decent like others.

I will suggest you some of them
https://fastpipe.iohttps://javapipe.com (they are good dealing with ddos attacks)
https://flokinet.ishttps://buyvm.nethttps://ovh.com (if is legal you can use OVH)

Because when traffic passes away through Cloudflare, if cloudflare doesn't filter the dirt traffic it will HIT your Hosting (Origin)
You can't do nothing without a good hosting provider with good ddos protection. That's the reality.

Rufai is only a guy who literally thinks cloudflare will save his a$$ with 512MB of RAM and no ddos protection from hosting provider lool.

Trust me, first you need a good anti-ddos protection.
 
Sorry I wanted to respond to this post. But have you tried creating the firewall rules shared the thread I linked to?
What is happening here is, people are just crawling my website for all the vulnerabilities, and IDK if there is any way to block this kind of attacks, I did have some firewall rules in place but the thing is,

The IPs are getting changed, the pages which are getting DDOs are basically 404's on my site.
 
Back
Top